Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 6 pages
Exam (elaborations)

WGU C836 Task 1 Updated 2024 with complete solution

Document preview thumbnail
Preview 2 out of 6 pages

WGU C836 Task 1 Updated 2024 with complete solution

Content preview

WGU C836 Task 1 Updated 2024 with complete solution


bounds checking - ANSWERto set a limit on the amount of data we expect to receive to
set aside storage for that data
*required in most programming languages
* prevents buffer overflows

race conditions - ANSWERvulnerability occur when two computer program processes,
or threads, attempt to access the same resource at the same time and cause problems
in the system.

input validation - ANSWERThis vulnerability is caused when the product does not
validate or incorrectly validates input that can affect the control flow or data flow of a
program.

format string attack - ANSWERa type of input validation attacks in which certain print
functions within a programming language can be used to manipulate or view the internal
memory of an application

authentication attack - ANSWERA type of attack that can occur when we fail to use
strong authentication mechanisms for our applications

authorization attack - ANSWERA type of attack that can occur when we fail to use
authorization best practices for our applications

cryptographic attack - ANSWERA type of attack that can occur when we fail to properly
design our security mechanisms when implementing cryptographic controls in our
applications

client-side attack - ANSWERA type of attack that takes advantage of weaknesses in the
software loaded on client machines or one that uses social engineering techniques to
trick us into going along with the attack

XSS (Cross Site Scripting) - ANSWERan attack carried out by placing code in the form
of a scripting language into a web page or other media that is interpreted by a client
browser

XSRF (cross-site request forgery) - ANSWERan attack in which the attacker places a
link on a web page in such a way that it will be automatically executed to initiate a
particular activity on another web page or application where the user is currently
authenticated

, clickjacking - ANSWERAn attack that takes advantage of the graphical display
capabilities of our browser to trick us into clicking on something we might not otherwise

server-side attack - ANSWERtarget vulnerabilities such as lack of input validation,
improper or inadequate permissions, or extraneous files left on the server from the
development process

Lack of input validation - ANSWERStructured Query Language (SQL) injection gives us
a strong example of what might happen if we do not properly validate the input of our
Web applications.

Extraneous Files - ANSWERunnecessary files that aren't cleaned up when the
application moves from development to production. Leaving files may be handing
attackers materials they need to compromise the system.

Protocol issues, unauthenticated access, arbitrary code execution, and privilege
escalation - ANSWERName the 4 main categories of database security issues

web application analysis tool - ANSWERA type of tool that analyzes web pages or web-
based applications and searches for common flaws such as XSS or SQL injection flaws,
and improperly set permissions, extraneous files, outdated software versions, and many
more such items

protocol issues - ANSWERunauthenticated flaws in network protocols, some common
software development issues, such as buffer overflows.

arbitrary code execution - ANSWERSecurity flaw in scripting languages used to talk to
database, generally these are concentrated on SQL.
allows the attacker to execute commands on a user's computer.

Privilege Escalation - ANSWERAn attack that exploits a vulnerability in software to gain
administrative access to resources that the user normally would be restricted from
accessing.
* via SQL injection or local issues

validating user inputs - ANSWERa security best practice for all software
* the most effective way of mitigating SQL injection attacks

Nikto (and Wikto) - ANSWERA web server analysis tool that performs checks for many
common server-side vulnerabilities & creates an index of all the files and directories it
can see on the target web server (a process known as spidering)

burp suite - ANSWERWeb analysis tool for penetration, identifies vulnerabilities, and
verify attack vector that affect web applications

Document information

Uploaded on
October 7, 2024
Number of pages
6
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$16.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PremiumExamBank
4.8
(1058)
Sold
443
Followers
71
Items
6914
Last sold
6 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions