Configuring security questions
"Security questions" is a common method used by applications and websites to add an additional layer of security to user accounts. These questions are typically personal and require users to provide specific answers that only they should know. This extra step helps verify the user's identity, especially during password recovery or when accessing sensitive information.
About this task
To add security questions:
Procedure
- Click + Add.
- Type in the question exactly as defined in your application.
- Type in the answer exactly as defined in your application.
- Optionally define the parameter.
-
Click Apply.
Note:Ensure to include all security questions and answers used by your application. Failure to do so might lead to complications when scanning, recording logins, and accessing sensitive information using AppScan.
-
When using this feature, it is recommended to enable the
SessionManagement:ShowActionBasedPlayerWindowflag to check that the questions are answered correctly. To enable this setting:- Go to Tools > Options > Advanced.
-
Locate
SessionManagement:ShowActionBasedPlayerWindow, and change its setting toTrue. - Run a scan. The browser will open when scanning, and you can watch as AppScan explores your site including answers.