List of questions
Related questions
Question 340 - CS0-003 discussion
A web application has a function to retrieve content from an internal URL to identify CSRF attacks in the logs. The security analyst is building a regular expression that will filter out the correctly formatted requests. The target URL is https://10.1.2.3/api, and the receiving API only accepts GET requests and uses a single integer argument named 'id.' Which of the following regular expressions should the analyst use to achieve the objective?
A.
(?!https://10\.1\.2\.3/api\?id=[0-9]+)
B.
'https://10\.1\.2\.3/api\?id=\d+
C.
(?:'https://10\.1\.2\.3/api\?id-[0-9]+)
D.
https://10\.1\.2\.3/api\?id[0-9J$
Your answer:
0 comments
Sorted by
Leave a comment first