In which phase of the SDLC are the largest percentage of security defects introduced?
A. unit testing
B. field testing
C. post release
D. coding
Fortify's innovative Integrated Application Security Testing (IAST) is an integration with HP
Weblnspect and which other product ?
A. HP Fortify Weblnspect Real-Time (WIRT)
B. HPArcSightESM
C. HP Fortify SecurityScope
D. HP Fortify RunTime
What are application security challenges? (Select two.)
A. APT threats across the enterprise
B. procuring secure software
C. hackers are shifting their focus back to the network
D. development push-back on security findings
E. securing legacy applications
Which type of qualification questions uncover the status of the customer's current software security ?
A. situation questions
B. implication questions
C. needs-payoff questions
D. problem questions
Who are the most important cyber threat adversaries of modern time? (Select three.)
A. cyber criminals
B. spammers
C. nation states
D. script kiddies
E. hacktivists
F. competitors
A prospect calls and says; "Developers are complaining that our security testing occurs too late in the SDLC, disrupting/delaying the releases." What is the appropriate solution?
A. Weblnspect
B. Fortify Consultant license for SCA + Weblnspect
C. Fortify On Demand (FoD)
D. Static Code Analyzer (SCA)
What is the goal of HP Fortify's Software Security Suite?
A. Find security vulnerabilities in any type of software, fix security flaws in source code before it ships, and protect applications against attacks in production.
B. Find security vulnerabilities in any type of software, fix security flaws in source code before it ships, and prepare perimeter defense systems with an application context.
C. Find security vulnerabilities in Web applications, upload findings to ArcSight EMS SIEM, and block the intruder at the gate.
D. Detect security vulnerabilities during exploitation by using Runtime, upload findings to ArcSight EMS SIEM, and block the intruder at the gate.
What is the meaning of IAST in the HP Fortify Software Security suite?
A. Integrated Application Security Testing
B. Intermittent Advanced Self-Testing
C. Integrated Application Software Testing
D. Interactive Application Security Testing