Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 48 discussion

Actual exam question from ISC's CISSP
Question #: 48
Topic #: 1
[All CISSP Questions]

Which of the following technologies can be used to monitor and dynamically respond to potential threats on web applications?

  • A. Field-level tokenization
  • B. Web application vulnerability scanners
  • C. Runtime application self-protection (RASP)
  • D. Security Assertion Markup Language (SAML)
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Mekd
Highly Voted 2 years, 2 months ago
Selected Answer: C
C https://www.crowdstrike.com/cybersecurity-101/cloud-security/runtime-application-self-protection-rasp/ Application protection: Detecting and blocking security vulnerabilities and malicious activity within the application during runtime Threat intelligence: Providing deep, code-level visibility within the application and producing insights that help the security team understand who is attacking their organization, their methods and motivations
upvoted 14 times
jackdryan
1 year, 7 months ago
C is correct
upvoted 1 times
...
...
robervalchocolat
Most Recent 2 months, 3 weeks ago
Runtime application self-protection (RASP) is the technology that best fits the description. RASP agents are embedded within web applications and can monitor application behavior in real time, detecting and responding to potential threats as they occur. This makes RASP a powerful tool for protecting web applications from attacks like SQL injection, cross-site scripting, and others
upvoted 1 times
...
Ezebuike
3 months, 1 week ago
Web application vulnerability scanners find vulnerabilities before an attacker can exploit them, but Runtime Application Self-Protection (RASP) is technology that incorporates security functionality within software applications to prevent malicious attacks while the application is running. RASP focuses on the application itself, using sensors embedded within the software, as well as contextual information, to monitor the application during runtime, address specific vulnerabilities that exist within each piece of software, and stop threats automatically and in real time. Based on this I will go for C
upvoted 1 times
...
Jenkins3mol
6 months, 3 weeks ago
Selected Answer: C
RASP and Cloud Security RASP is an important component within the organization’s cloud security strategy, more particularly for cloud application security. As companies increasingly leverage the cloud to advance business transformation efforts, enable new business models and activate a remote workforce, they must also ensure that all business conducted in a cloud or hybrid environment is safe and secure. Traditional security measures are not equipped to deliver protection in the cloud, which means that organizations must craft a new strategy and adopt new tooling, including application-level policies, tools, technologies and rules — chief among them RASP — to maintain visibility into all cloud-based assets, protect cloud-based applications from cyberattacks and limit access only to authorized users.
upvoted 1 times
...
25cbb5f
7 months, 3 weeks ago
The BEST technology for monitoring and dynamically responding to potential web application threats is: C. Runtime application self-protection (RASP) Here's why RASP is the most suitable choice: Real-time Defense: RASP operates within the application itself, meaning it can detect and block attacks in real-time as they're happening, unlike other options that are often more focused on pre-deployment checks. Behavior-Based Detection: RASP analyzes application behavior and looks for anomalies or malicious code execution attempts. This allows it to catch attacks that traditional signature-based tools might miss. Dynamic Response: A key feature of RASP is its ability to dynamically respond to attacks. It can block the malicious request, send an alert, or even quarantine suspicious code, preventing harm.
upvoted 1 times
...
e58c193
7 months, 3 weeks ago
Selected Answer: C
RASP, vulnerability scanners do not respond
upvoted 1 times
...
GuardianAngel
9 months, 3 weeks ago
Vulnerabiity scanners just scan for vulnerabilities, they dont respond to vulnerabilities
upvoted 2 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: C
Answer C) Runtime Application Self-Protection (RASP) https://en.wikipedia.org/wiki/Runtime_application_self-protection
upvoted 1 times
...
aape1
1 year, 1 month ago
Selected Answer: C
C. Runtime Application Self-Protection (RASP) is a security technology that is designed to protect web applications and APIs by monitoring and defending against attacks in real-time while the application is running. RASP solutions are typically integrated directly into the application or its runtime environment.
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
The technology that can be used to monitor and dynamically respond to potential threats on web applications is option C: Runtime application self-protection (RASP). Runtime application self-protection (RASP) is a security technology that is integrated directly into an application's runtime environment. It is designed to monitor the application's behavior and detect and respond to potential security threats in real-time. RASP solutions have the ability to detect and prevent attacks such as SQL injection, cross-site scripting (XSS), and other common web application vulnerabilities.
upvoted 1 times
...
Azurefox79
1 year, 8 months ago
Selected Answer: C
RASP for the same reasons provided by Dee83 and mekd
upvoted 1 times
...
Dee83
1 year, 10 months ago
C- correct answer Runtime application self-protection (RASP) can be used to monitor and dynamically respond to potential threats on web applications. Runtime Application Self-Protection (RASP) is a security technology that provides real-time monitoring of web applications and dynamically responds to potential threats. RASP is integrated into the web application and runs alongside the application code, providing visibility into the application's runtime environment and the ability to detect and respond to threats in real-time. RASP can detect and block attacks such as SQL injection, cross-site scripting (XSS), and file inclusion vulnerabilities. Web application vulnerability scanners are tools that automate the process of identifying security vulnerabilities in web applications, but it does not provide real-time monitoring and dynamic response to potential threats.
upvoted 2 times
...
Delab202
1 year, 10 months ago
Selected Answer: C
Web application vulnerability scanners are a specialised type of vulnerability scanner which focus on finding weaknesses in web applications and websites. Run Time Application Self-Protection is designed to detect attacks on an application in real time. When an application is running, RASP can protect application from malicious attacks by analyzing both the app’s behavior and the context of that behavior. App can continuously monitor its real time behavior pattern of traffic, where attacks can be identified and mitigated immediately without human intervention.
upvoted 2 times
...
Jamati
2 years ago
Selected Answer: C
RASP is the answer
upvoted 1 times
...
rootic
2 years ago
Selected Answer: C
Web scan obviously can't dynamicly respond to threats. It's C.
upvoted 2 times
...
[Removed]
2 years, 1 month ago
B = Detect C = Respond
upvoted 2 times
...
JAckThePip
2 years, 1 month ago
Answer is C "RASP uses the context provided by deep visibility into these applications to identify and block attacks that slip by the Web Application Firewall." https://www.checkpoint.com/cyber-hub/cloud-security/what-is-runtime-application-self-protection-rasp/#
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...