100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CS6262 Lecture Quizzes with complete solutions

Rating
-
Sold
-
Pages
20
Grade
A+
Uploaded on
31-01-2025
Written in
2024/2025

CS6262 Lecture Quizzes with complete solutions

Institution
CS6262
Course
CS6262










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CS6262
Course
CS6262

Document information

Uploaded on
January 31, 2025
Number of pages
20
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CS6262 Lecture Quizzes with complete
solutions

Random Scanning ANSWERS Each compromised computer probes random
addresses.

Permutation Scanning ANSWERS All compromised computers shared a common
pseudo-random permutation of the IP address space.

Signpost Scanning ANSWERS Uses the communication patterns of the
compromised computer to find new target.

Hitlist Scanning ANSWERS A portion of a list of targets is supplied to a
compromised computer.

Subnet spoofing ANSWERS Generate random addresses with a given address
space

Random spoofing ANSWERS Generate 32-bit numbers and stamp packets with
them.

Fixed spoofing ANSWERS The spoofed address is the address of the target.

Server Application ANSWERS The attack is targeted to a specific application on a
server.

What is a "network access" attack used for? ANSWERS The attack is used to
overload or crash the communication mechanism of a network.

Infrastructure ANSWERS The motivation of this attack is a crucial service of a
global internet operation, for example a core router.

Why is the UDP-based NTP protocol particularly vulnerable to amplification attacks?
ANSWERS • a small command can generate a large response.
• Vulnerable to source IP spoofing.
• It is difficult to ensure computers communicate only with legitimate NTP servers.

SYN Cookie - True Statement ANSWERS The server must reject all TCP options
because the server discards the SYN queue entry.

,True statements regarding UDP flood attacks ANSWERS • Attackers can spoof
the IP address of their UDP packets.
• Firewalls cannot stop a flood because the firewall is susceptible to flooding.

True statements regarding CAPTCHA puzzles ANSWERS • Client puzzles should
be stateless.
• Puzzle complexity should increase as the strength of the attack increases.

What assumptions can be made about trace backs? ANSWERS Attackers may
work alone or in groups

What assumptions can be made regarding edge sampling? ANSWERS • Multiple
attackers can be identified since edge identifies splits in reverse path.
• Requires space in the IP packet header.

Self defense against reflector attacks should incorporate the following: ANSWERS
• Server redundancy - servers should be located in multiple networks and locations.
• Traffic limiting - traffic from a name server should be limited to reasonable thresholds.

Deep Web ANSWERS It is not indexed by standard search engines

Dark Web ANSWERS Web content that exists on darknets

Surface Web ANSWERS Readily available to the public, and searchable with
standard search engines.

Doorway pages ANSWERS A webpage that lists many keywords, in hopes of
increasing search engine ranking. Scripts on the page redirect to the attackers page.

Crypters ANSWERS A program that hides malicious code from anti-virus
software.

Blackhat Search Engine Optimizer ANSWERS It increases traffic to the attacker's
site by manipulating search engines.

Trojan Download Manager ANSWERS Software that allows an attacker to update
or install malware on a victim's computer.

Name two identifying characteristics of Spam: ANSWERS 1) Inappropriate or
irrelevant
2) Large number of recipients

Name the top three countries where spam directed visitors added items to their
shopping carts: ANSWERS 1) United States
2) Canada
3) Philippines

, Which events should trigger a penetration test?
• Infastructure is added or modified
• Applications are added of modified
• End user policies are changed
• Security patches are installed ANSWERS • Infastructure is added or modified
• Applications are added of modified
• End user policies are changed
• Security patches are installed

Steps attackers used to access RSA's Adobe Flash software: ANSWERS •
Identify employees that are vulnerable
• Craft an email subject line that entices an employee to open it.
• Hide an executable file in the email that will install onto the victim's computer when the
email is opened.

(Describe the social engineering tool) Flash or CD Autoplay ANSWERS A flash is
created that has a program that creates a connection to the exploit server.

(Describe the social engineering tool) Reverse Shell Applet ANSWERS A signed
Java applet is sent to the user, if they accept it, a shell is sent back to the exploit server.

(Describe the social engineering tool) Click Logger ANSWERS used to determine
which users click on links in emails.

(Describe the social engineering tool) Download Connection ANSWERS An email
contains an attachment. When the attachment is downloaded a connection is made to
the exploit server.

Top three industries that were targets of cyber attacks in 2016 ANSWERS 1)
Defense contractor
2) Restaurant
3) Software

(Describe the motivation) Liking ANSWERS A desire to fit and to be more easily
influenced by someone you like.

(Describe the motivation) Scarcity ANSWERS A desire to pursue a limited or
exclusive item or service.

(Describe the motivation) Commitment ANSWERS A desire to act in a consistent
manner

(Describe the motivation) Social Proof ANSWERS Looking to others for clues on
how to behave.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
millyphilip West Virginia University
View profile
Follow You need to be logged in order to follow users or courses
Sold
2817
Member since
3 year
Number of followers
1959
Documents
41186
Last sold
3 days ago
white orchid store

EXCELLENCY IN ACCADEMIC MATERIALS ie exams, study guides, testbanks ,case, case study etc

3.7

535 reviews

5
234
4
84
3
103
2
31
1
83

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions