CSIT 188 Midterm Exam Questions and Answers All Correct
CSIT 188 Midterm Exam Questions and Answers All Correct Tom is running a penetration test in a web application and discovers a flaw that allows him to shut down the web server remotely. What goal of penetration testing has Tom most directly achieved? A. Disclosure B. Integrity C. Alteration D. Denial - Answer-D. Tom's attack achieved the goal of denial by shutting down the web server and prevent-ing legitimate users from accessing it. Brian ran a penetration test against a school's grading system and discovered a flaw that would allow students to alter their grades by exploiting a SQL injection vulnerability. What type of control should he recommend to the school's cybersecurity team to prevent students from engaging in this type of activity? A. Confidentiality B. Integrity C. Alteration D. Availability - Answer-B. By allowing students to change their own grades, this vulnerability provides a pathway to unauthorized alteration of information. Brian should recommend that the school deploy integrity controls that prevent unauthorized modifications. Edward Snowden gathered a massive quantity of sensitive information from the National Security Agency and released it to the media. What type of attack did he wage? A. Disclosure B. Denial C. Alteration D. Availability - Answer-A. Snowden released sensitive information to individuals and groups who were not autho-rized to access that information. That is an example of a disclosure attack. Assuming no significant changes in an organization's cardholder data environment, how often does PCI DSS require that a merchant accepting credit cards conduct penetration testing? A. Monthly B. Semiannually C. Annually D. Biannually - Answer-C. PCI DSS requires that organizations conduct both internal and external penetration tests on at least an annual basis. Organizations must also conduct testing after any signifi-cant change in the cardholder data environment. Which one of the following is NOT a benefit of using an internal penetration testing team? A. Contextual knowledge B. Cost C. Subject matter expertise D. Independence
Written for
- Institution
- CSIT
- Course
- CSIT
Document information
- Uploaded on
- April 9, 2024
- Number of pages
- 43
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
-
csit 188 midterm exam questions and answers al
-
csit 188 midterm exam questions and answers all
Also available in package deal