Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Exam CAP All Questions
Exam CAP All Questions

View all questions & answers for the CAP exam

The SecOps Group Certified AppSec Practitioner Exam CAP Question # 10 Topic 2 Discussion

CAP Exam Topic 2 Question 10 Discussion:
Question #: 10
Topic #: 2

An application’s forget password functionality is described below:

The user enters their email address and receives a message on the web page:

“If the email exists, we will email you a link to reset the password”

The user also receives an email saying:

“Please use the link below to create a new password:”

http://example.com/reset_password?userId=5298

Which of the following is true?


A.

The reset link uses an insecure channel


B.

The application is vulnerable to username enumeration


C.

The application will allow the user to reset an arbitrary user’s password


D.

Both A and C


Get Premium CAP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.