• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 39 pages
Exam (elaborations)

Wgu_C836_Multi_Comprehensive_Final_Paper_2026_Tested_Questions_With.pdf

Document preview thumbnail
Preview 4 out of 39 pages

WGU_C836_MULTI_COMPREHENSIVE_FINAL_PAPER_2026_TESTED_QUESTIONS_WITH.pdf

Content preview

WGU C836 MULTI COMPREHENSIVE FINAL
PAPER TESTED QUESTIONS WITH

◉ race conditions. Answer: A type of software development
vulnerability that occurs when multiple processes or multiple
threads within a process control or share access to a particular
resource, and the correct handling of that resource depends on the
proper ordering or timing of transactions


◉ input validation. Answer: a type of attack that can occur when we
fail to validate the input to our applications or take steps to filter out
unexpected or undesirable content


◉ format string attack. Answer: a type of input validation attacks in
which certain print functions within a programming language can be
used to manipulate or view the internal memory of an application


◉ authentication attack. Answer: A type of attack that can occur
when we fail to use strong authentication mechanisms for our
applications


◉ authorization attack. Answer: A type of attack that can occur
when we fail to use authorization best practices for our applications

,◉ cryptographic attack. Answer: A type of attack that can occur
when we fail to properly design our security mechanisms when
implementing cryptographic controls in our applications


◉ client-side attack. Answer: A type of attack that takes advantage of
weaknesses in the software loaded on client machines or one that
uses social engineering techniques to trick us into going along with
the attack


◉ XSS (Cross Site Scripting). Answer: an attack carried out by
placing code in the form of a scripting language into a web page or
other media that is interpreted by a client browser


◉ XSRF (cross-site request forgery). Answer: an attack in which the
attacker places a link on a web page in such a way that it will be
automatically executed to initiate a particular activity on another
web page or application where the user is currently authenticated


◉ clickjacking. Answer: An attack that takes advantage of the
graphical display capabilities of our browser to trick us into clicking
on something we might not otherwise


◉ server-side attack. Answer: A type of attack on the web server
that can target vulnerabilities such as lack of input validation,

,improper or inadequate permissions, or extraneous files left on the
server from the development process


◉ Protocol issues, unauthenticated access, arbitrary code execution,
and privilege escalation. Answer: Name the 4 main categories of
database security issues


◉ web application analysis tool. Answer: A type of tool that analyzes
web pages or web-based applications and searches for common
flaws such as XSS or SQL injection flaws, and improperly set
permissions, extraneous files, outdated software versions, and many
more such items


◉ protocol issues. Answer: unauthenticated flaws in network
protocols, authenticated flaws in network protocols, flaws in
authentication protocols


◉ arbitrary code execution. Answer: An attack that exploits an
applications vulnerability into allowing the attacker to execute
commands on a user's computer.
* arbitrary code execution in intrinsic or securable SQL elements


◉ Privilege Escalation. Answer: An attack that exploits a
vulnerability in software to gain access to resources that the user
normally would be restricted from accessing.

, * via SQL injection or local issues


◉ validating user inputs. Answer: a security best practice for all
software
* the most effective way of mitigating SQL injection attacks


◉ Nikto (and Wikto). Answer: A web server analysis tool that
performs checks for many common server-side vulnerabilities &
creates an index of all the files and directories it can see on the
target web server (a process known as spidering)


◉ burp suite. Answer: A well-known GUI web analysis tool that
offers a free and professional version; the pro version includes
advanced tools for conducting more in-depth attacks


◉ fuzzer. Answer: A type of tool that works by bombarding our
applications with all manner of data and inputs from a wide variety
of sources, in the hope that we can cause the application to fail or to
perform in unexpected ways


◉ MiniFuzz File Fuzzer. Answer: A tool developed by Microsoft to
find flaws in file-handling source code


◉ BinScope Binary Analyzer. Answer: A tool developed by Microsoft
to examine source code for general good practices

Document information

Uploaded on
September 28, 2026
Number of pages
39
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
0
Items
4878
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions