WGU C836 EXAM WITH 100% VERIFIED
SOLUTIONS NEW!!
bounds checking - ANSWER>>to set a limit on amount of data we expect to receive to
set aside storage for that data
*required in most programming languages
* prevents buffer overflows
race conditions A software development vulnerability where multiple processes, or
threads within a single process, control or have shared access to a particular resource,
and the proper behavior of that resource depends on proper ordering or timing of
transactions
input validation - ANSWER>>an attack type of attack that may occur by not validating
input into our applications or failing to filter unexpected and undesirable content within
them
format string attack - ANSWER>>type of input validation attacks where some print
functions inside a programming language can be utilized in order to view or manipulate
an application's internal memory
Authentication attack - ANSWER>> An attack that could happen when we are unable to
use a strong authentication mechanism for our application
Authorization attack - ANSWER>> An attack that could happen when we are unable to
implement the best practice in authorizations of applications
Cryptographic attack - ANSWER>> An attack that could happen when we are unable to
correctly design our security mechanism while implementing cryptography controls in
an application
,client-side attack - ANSWER>>An attack that exploits weaknesses in the software
loaded on client machines or one that uses social engineering to trick us into going
along with the attack
XSS (Cross Site Scripting) - ANSWER>>an attack executed by inserting code, typically in
the form of a scripting language, into a web page or other media that is interpreted by a
client browser
XSRF Cross-site request forgery - ANSWER>>an attack in which the attacker places a
link on a web page in such a way that it will be automatically executed to initiate a
particular activity on another web page or application where the user is currently
authenticated
SQL Injection Attack - ANSWER>>Attacks against a web site that take advantage of
vulnerabilities in poorly coded SQL-a standard and common database software
application-applications in order to introduce malicious program code into a company's
systems and networks.
clickjacking - ANSWER>>An attack that takes advantage of the graphical display
capabilities of our browser to trick us into clicking on something we might not otherwise
server-side attack - ANSWER>>A method of attacking the web server looking for items
such as not validating input, permissions set too permissive or just plain too open and
files left on the server that were used in development but not meant to be left there.
Protocol issues, unauthenticated access, arbitrary code execution, and privilege
escalation - ANSWER>>The names of the 4 major categories of database security issues
web application analysis tool - ANSWER>>A type of tool that analyzes web pages or
web-based applications and searches for common flaws such as XSS or SQL injection
flaws, and improperly set permissions, extraneous files, outdated software versions,
and many more such items
, protocol issues - ANSWER>>unauthenticated flaws in network protocols,
authenticated flaws in network protocols, flaws in authentication protocols
arbitrary code execution - ANSWER>>An attack that takes advantage of an
applications vulnerability into allowing the attacker to execute commands on a user's
computer.
* arbitrary code execution in intrinsic or securable SQL elements
Privilege Escalation - ANSWER>>An attack that takes advantage of a weakness in
software to gain access to resources that the user normally would be restricted from
accessing.
* via SQL injection or local issues
testing user inputs -- ANSWER>>a security best practice for all software
* the most effective way of mitigating SQL injection attacks
Nikto (and Wikto) -- ANSWER>>A web server analysis tool that performs checks for
many common server-side vulnerabilities & creates an index of all the files and
directories it can see on the target web server (a process known as spidering)
Burp Suite - ANSWER>>One of the well-known GUI Web analysis tools has a free and
professional version. The latter includes tools that can be used to conduct further
advanced attacks
fuzzer - ANSWER>>A type of tool that works by bombarding our applications with all
manner of data and inputs from a wide variety of sources, in the hope that we can cause
the application to fail or to perform in unexpected ways
MiniFuzz File Fuzzer - ANSWER>>A tool developed by Microsoft to find flaws in
file-handling source code
BinScope Binary Analyzer - ANSWER>>A tool provided by Microsoft to scan source
SOLUTIONS NEW!!
bounds checking - ANSWER>>to set a limit on amount of data we expect to receive to
set aside storage for that data
*required in most programming languages
* prevents buffer overflows
race conditions A software development vulnerability where multiple processes, or
threads within a single process, control or have shared access to a particular resource,
and the proper behavior of that resource depends on proper ordering or timing of
transactions
input validation - ANSWER>>an attack type of attack that may occur by not validating
input into our applications or failing to filter unexpected and undesirable content within
them
format string attack - ANSWER>>type of input validation attacks where some print
functions inside a programming language can be utilized in order to view or manipulate
an application's internal memory
Authentication attack - ANSWER>> An attack that could happen when we are unable to
use a strong authentication mechanism for our application
Authorization attack - ANSWER>> An attack that could happen when we are unable to
implement the best practice in authorizations of applications
Cryptographic attack - ANSWER>> An attack that could happen when we are unable to
correctly design our security mechanism while implementing cryptography controls in
an application
,client-side attack - ANSWER>>An attack that exploits weaknesses in the software
loaded on client machines or one that uses social engineering to trick us into going
along with the attack
XSS (Cross Site Scripting) - ANSWER>>an attack executed by inserting code, typically in
the form of a scripting language, into a web page or other media that is interpreted by a
client browser
XSRF Cross-site request forgery - ANSWER>>an attack in which the attacker places a
link on a web page in such a way that it will be automatically executed to initiate a
particular activity on another web page or application where the user is currently
authenticated
SQL Injection Attack - ANSWER>>Attacks against a web site that take advantage of
vulnerabilities in poorly coded SQL-a standard and common database software
application-applications in order to introduce malicious program code into a company's
systems and networks.
clickjacking - ANSWER>>An attack that takes advantage of the graphical display
capabilities of our browser to trick us into clicking on something we might not otherwise
server-side attack - ANSWER>>A method of attacking the web server looking for items
such as not validating input, permissions set too permissive or just plain too open and
files left on the server that were used in development but not meant to be left there.
Protocol issues, unauthenticated access, arbitrary code execution, and privilege
escalation - ANSWER>>The names of the 4 major categories of database security issues
web application analysis tool - ANSWER>>A type of tool that analyzes web pages or
web-based applications and searches for common flaws such as XSS or SQL injection
flaws, and improperly set permissions, extraneous files, outdated software versions,
and many more such items
, protocol issues - ANSWER>>unauthenticated flaws in network protocols,
authenticated flaws in network protocols, flaws in authentication protocols
arbitrary code execution - ANSWER>>An attack that takes advantage of an
applications vulnerability into allowing the attacker to execute commands on a user's
computer.
* arbitrary code execution in intrinsic or securable SQL elements
Privilege Escalation - ANSWER>>An attack that takes advantage of a weakness in
software to gain access to resources that the user normally would be restricted from
accessing.
* via SQL injection or local issues
testing user inputs -- ANSWER>>a security best practice for all software
* the most effective way of mitigating SQL injection attacks
Nikto (and Wikto) -- ANSWER>>A web server analysis tool that performs checks for
many common server-side vulnerabilities & creates an index of all the files and
directories it can see on the target web server (a process known as spidering)
Burp Suite - ANSWER>>One of the well-known GUI Web analysis tools has a free and
professional version. The latter includes tools that can be used to conduct further
advanced attacks
fuzzer - ANSWER>>A type of tool that works by bombarding our applications with all
manner of data and inputs from a wide variety of sources, in the hope that we can cause
the application to fail or to perform in unexpected ways
MiniFuzz File Fuzzer - ANSWER>>A tool developed by Microsoft to find flaws in
file-handling source code
BinScope Binary Analyzer - ANSWER>>A tool provided by Microsoft to scan source