Security Fundamentals 7th Edition Chapter 3 Final Exam 2024 Review Questions correctly Answered
Which of these is NOT a reason why securing server-side web applications is difficult? - Answer>>The processors on clients are smaller than on web servers and thus they are easier to defend.
Which of these is not an HTTP header attack? - Answer>>Content-length
What is another name for a locally shared object? - Answer>>flash cookie
Browser plug-ins - Answer>>can be embedded inside a webpage but add-ons cannot, have additional functionality to entire browser, have been replaced by browser extensions
An attacker who manipulates the maximum size of an integer type would be performing what kin of attack. - Answer>>integer overflow
What kind of attack is performed by an attacker who takes advantages of the inadvertent and unauthorized access built through three succeeding systems that all trust one another? - Answer>>Privilege rights, heap spray, transitive, vertical escalation
Which statement is correct regarding why traditional network security devices cannot be used to block web application attacks? - Answer>>Traditional network security devices ignore the content of HTTP traffic, which is the vehicle of web application attacks.
What do attackers use buffer overflows to do? - Answer>>point to another area in data memory
that contains the attacker's malware code