ExamVeda
Login
Home
41
What is being imposed on each subset to ensure that it conforms to the subset?
Discuss
Answer & Solution
Answer: Option C
Solution:
Each subset is coupled with a static verifier that parses code to ensure that it conforms to the subset.
42
Why was “The Good Parts” designed as a language subset in JavaScript?
Discuss
Answer & Solution
Answer: Option D
Solution:
The Good Parts is a language subset designed for aesthetic reasons and with a desire to improve programmer productivity. There is a larger class of subsets that have been designed for the purpose of safely running untrusted JavaScript in a secure container or “sandbox”.
43
Which is the subset that is a secure container designed for the purpose of safely running untrusted JavaScript?
Discuss
Answer & Solution
Answer: Option A
Solution:
There is a larger class of subsets that have been designed for the purpose of safely running untrusted JavaScript in a secure container or “sandbox”.
44
Why is the this keyword forbidden in JavaScript?
Discuss
Answer & Solution
Answer: Option C
Solution:
The this keyword is forbidden or restricted because functions (in non-strict mode) can access the global object through this. Preventing access to the global object is one of the key purposes of any sandboxing system.
45
Which are the two functions that are not allowed in any secure subset?
Discuss
Answer & Solution
Answer: Option B
Solution:
eval() and the Function() constructor are not allowed in any secure subset because they allow the execution of arbitrary strings of code, and these strings cannot be statically analyzed.
46
Which is the object that defines methods that allow complete control over page content?
Discuss
Answer & Solution
Answer: Option A
Solution:
The client-side document object defines methods that allow complete control over page content.
47
Which was one of the first security subsets proposed?
Discuss
Answer & Solution
Answer: Option D
Solution:
ADsafe was one of the first security subsets proposed) It was created by Douglas Crockford (who also defined The Good Parts subset).ADsafe relies on static verification only, and it uses JSLint as its verifier. It forbids access to most global variables and defines an ADSAFE variable that provides access to a secure API, including special-purpose DOM methods. ADsafe is not in wide use, but it was an influential proof-of-concept that influenced other secure subsets.
48
Which is the subset that transforms web content into secure modules that can be safely hosted on a web page?
Discuss
Answer & Solution
Answer: Option D
Solution:
Caja is Google’s open-source secure subset. Caja (Spanish for “box”) defines two language subsets. Cajita (“little box”) is a narrow subset like that used by ADsafe and dojox.secure. Valija (“suitcase” or “baggage”) is a much broader language that is close to regular ECMAScript 5 strict mode (with the removal of eval()). Caja itself is the name of the compiler that transforms (or “cajoles”) web content (HTML, CSS, and JavaScript code) into secure modules that can be safely hosted on a web page without being able to affect the page as a whole or other modules on the page.
49
Consider the following code snippet
const pi=3.14;
var pi=4;
console.log(pi);
What will be the output for the above code snippet?
Discuss
Answer & Solution
Answer: Option A
Solution:
The above code snippet will flash an error. Attempts to alter the value or re-declaration causes errors.
50
The let keyword can be used
Discuss
Answer & Solution
Answer: Option D
Solution:
The let keyword can be used in four ways :
1. as a variable declaration like var;
2. in a for or for/in loop, as a substitute for var;
3. as a block statement, to define new variables and explicitly delimit their scope; and
4. to define variables that are scoped to a single expression.