Configuring security questions

"Security questions" is a common method used by applications and websites to add an additional layer of security to user accounts. These questions are typically personal and require users to provide specific answers that only they should know. This extra step helps verify the user's identity, especially during password recovery or when accessing sensitive information.

About this task

If your application uses security questions for user authentication, it's essential to add them here. This enables AppScan to accurately identify and capture the security questions during the login recording, in-session detection, or login playback process.

To add security questions:

Procedure

  1. Click + Add.
  2. Type in the question exactly as defined in your application.
  3. Type in the answer exactly as defined in your application.
  4. Optionally define the parameter.
  5. Click Apply.
    Note:
    Ensure to include all security questions and answers used by your application. Failure to do so might lead to complications when scanning, recording logins, and accessing sensitive information using AppScan.
  6. When using this feature, it is recommended to enable the SessionManagement:ShowActionBasedPlayerWindow flag to check that the questions are answered correctly. To enable this setting:
    1. Go to Tools > Options > Advanced.
    2. Locate SessionManagement:ShowActionBasedPlayerWindow, and change its setting to True.
    3. Run a scan. The browser will open when scanning, and you can watch as AppScan explores your site including answers.

Results

When you record login (with answer to question) or start the scan, AppScan will identify the security questions in the application during login or the scanning process after a successful login.