how we conduct security testing in realtime,for every
project we conduct security testig or not



how we conduct security testing in realtime,for every project we conduct security testig or not..

Answer / js_sabharwal

No, we dont conduct security testing for every project. For
example , I am developing Software for Primary Rimes or
Small Game.. I dont need to perform security testing.

Security Testing depends on the Risk of you project.
For example, Airplane Software, Health Care Softwares,
Banking Domains ..etc

How do we conduct ?
There are several ways to perform it again entirely depends
on your project/product, methods for web security testing
can be :

- Check for session hijacking.
- Check for session time out.
- Check for cross site scripting
- SQL Injection
- Http/Https
- Attempt of breach should log in 'Server Logs'
- Cookies Testing - Accepting/rejecting, invalid, decrypting
- Unauthorized access
- Multiple user login at same time

..etc

Is This Answer Correct ?    15 Yes 1 No

Post New Answer

More Manual Testing Interview Questions

what type of testing you are doing ?

3 Answers  


Relative to other technical groups in the company? Relative to your staff?

0 Answers  


What different sources are needed to verify authenticity for CMMI implementation?

0 Answers  


tell me some gud sites for testing??

2 Answers  


What exactly we have to say when interviewer asked "Tell me about your self"?

2 Answers  






Why does Software have bugs? urgent pls .....

5 Answers  


What is configuration Management What is change management What are Severity and priority levels What is Data integrity and Data validity What are the browsers available and explain their versions Is it possible that Quality variates project to project What are GUI Map files and explain their Contents What is Data base check point and why we go for that What is the difference between the Client server application and a Web application Does Winrunner Supports Web applications What is process Management What is an Error, Defect, Bug What is Quality Which version of Winrunner you are using What is Build Verification and why we go for it What is Defect density What is Integration testing What is Static testing and types of Static testing What is Validation testing what is Data driven testing and why we go for data driven testing what is the definition of Testing What is Sanitation Testing

1 Answers   Semantic Space,


Hiei have cleared 2technical and hr round at sasken.hr even discussed about salary,he said there would be a client round which final.Can any one tell how to prepare for this round and what type questions i can expect.By the way this job is regarding 1+ exp on mobile app testing

3 Answers   Sasken,


What are the Test Deliverables?

10 Answers   Banking, Burndy Technology and Global Business Services,


1.what is Exhaustive Testing, Statement Testing, coverage Testing, Decision Testing & Condition Testing?

0 Answers  


what are the do's and dont's of a tester?

1 Answers  


what is deadlock in manual testing?what is another name for this deadlock?

1 Answers  


Categories