Questions and Answers Latest 2025/2026
GRADED A+
A bank account number is modified in memory in the middle of a ATM cash
withdrawal request. - CORRECT ANSWER-Time-of-Check to Time-of-Use
A return address is modified and upon calling return, unauthorized code is executed. -
CORRECT ANSWER-Buffer Overflow
Access Control List/Matrix - CORRECT ANSWER-list of users and resources
access files on a web server not meant to be accessible
http://server.com/scripts/..%5c../Windows/System32/cmd.exe?/c+dir+c:\
filter & sanitize inputs - CORRECT ANSWER-Directory Traversal
an attack that forces an end user to execute unwanted actions on a web application in
which they're currently authenticated
, override form data to a different website by placing the attacker's values into the form
instead of the user's values
examining carefully the source header and/or referral header of all requests to ensure
the client is the origin of all requests. - CORRECT ANSWER-CSRF: Cross Site Request
Forgery
An order for a huge number of items (35,000) on a website debits their bank account
instead of crediting their bank account. - CORRECT ANSWER-Integer Overflow
An updated DLL with a backdoor is installed by a program which does not ever call the
backdoor itself. - CORRECT ANSWER-Unsafe Utility Program
C code doesn't object when an integer is correctly added to a character array. -
CORRECT ANSWER-Parameter Length, Type, and Number
Capabilities - CORRECT ANSWER-are like tokens
CIA - CORRECT ANSWER-- confidentiality, integrity, availability
- principles are definition of security
- (ex ATM)
- opposite: Interception (pirating), Modification(crashing system when it should be
available), Interruption
Code Analyzers - CORRECT ANSWER-- static: looks at source code (can't check for all
possible attacks, false positives)
- dynamic: runs the code (accurate, slow b/c trying to run all possible cases)
Code in the Linux kernal mistakenly runs this command: "if (access = root)" instead of
"if (access == root)" - CORRECT ANSWER-Undocumented Access Point