100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

D385: Pre-Assessment Questions With Verified Answers Verified 100%

Rating
-
Sold
-
Pages
6
Grade
A+
Uploaded on
10-12-2023
Written in
2023/2024

D385: Pre-Assessment Questions With Verified Answers Verified 100% What is the primary defense against log injection attacks? - do not use parameterized stored procedures in the database - allow all users to write to these logs - sanitize outbound log messages - use API calls to log actions - ANSWER - sanitize outbound log messages An attacker exploits a cross-site scripting vulnerability. What is the attacker able to do? - execute a shell command or script - access the user's data - discover other users' credentials - gain access to sensitive files on the server - ANSWER - execute a shell command or script Which Python function is prone to a potential code injection attack? - type - eval - print - append - ANSWER - eval Which package is meant for internal use by Python for regression testing? - regress test - doctest - assert - test - ANSWER - test What are two common defensive coding techniques? - encrypt passwords and email submissions - check functional preconditions and postconditions - adjust length and encoding of messages - develop code with exceptions to find errors - ANSWER - develop code with exceptions to find errors A security analyst is reviewing code for improper input validation. Which type of input validation does this code show? isValidNumber = False while not isValidNumber: try: pickedNumber = int(input('Pick a number from 1 to 10')) if pickedNumber >= 1 and pickedNumber <= 10: isValidNumber = True except: print('You must enter a valid number from 1 to 10') print('You picked the number ' + str(pickedNumber)) - ANSWER - type and range check Consider the following penetration test: import requests urls = open("", "r") for url in urls: url = () req = (url) print (url, 'report try:transport_security = rs['Strict-TransportSecurity']except:print ('HSTS header not set properly') -------------------------------------- Which security vulnerability is shown? - cross-site scripting - denial of service - code injection - man-in-the-middle - ANSWER - man-in-the-middle A security analyst has noticed a vulnerability in which an attacker took over multiple user's accounts

Show more Read less
Institution
D385: Pre-Assessm
Course
D385: Pre-Assessm









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
D385: Pre-Assessm
Course
D385: Pre-Assessm

Document information

Uploaded on
December 10, 2023
Number of pages
6
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
norajuma13 Teachme2-tutor
View profile
Follow You need to be logged in order to follow users or courses
Sold
239
Member since
2 year
Number of followers
165
Documents
3523
Last sold
1 month ago
EXCELLENT HOMEWORK HELP AND TUTORING ,ALL KIND OF QUIZ AND EXAMS WITH GUARANTEE OF A EXCELLENT HOMEWORK HELP AND TUTORING ,ALL KIND OF QUIZ AND EXAMS WITH GUARANTEE OF A Am an expert on major courses especially; psychology,Nursing, Human resource Manageme

EXCELLENT HOMEWORK HELP AND TUTORING ,ALL KIND OF QUIZ AND EXAMS WITH GUARANTEE OF A EXCELLENT HOMEWORK HELP AND TUTORING ,ALL KIND OF QUIZ AND EXAMS WITH GUARANTEE OF A Am an expert on major courses especially; psychology,Nursing, Human resource Management and Mathemtics Assisting students with quality work is my first priority. I ensure scholarly standards in my documents and that\'s why i\'m one of the BEST GOLD RATED TUTORS in STUVIA. I assure a GOOD GRADE if you will use my work.

Read more Read less
3.4

46 reviews

5
19
4
6
3
5
2
8
1
8

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions