Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 7 pages
Exam (elaborations)

Ethical Hacking Final Exam Review Questions and Correct Answers

Document preview thumbnail
Preview 2 out of 7 pages

GET Request Used for requests for pages, resources, etc. POST Requests Used for form submissions, logins, etc. OS Command Attacks a web security vulnerability that allows an attacker to execute arbitrary operating system (OS) commands on the server that is running an application, and typically fully compromise the application and all its data. SQL injection attack a common attack vector that uses malicious SQL code for backend database manipulation to access information that was not intended to be displayed. Insert, Select, Update, Delete Use to access records in SQL Databases CREATE, DROP Used to add or delete a table in a SQL Database How SQL attack happens occurs when the application accepts a malicious user input and then uses it as a part of SQL statement to query a backend database. An attacker can inject SQL control characters and command keywords (e.g., single quote ('), double quote ("), equal (=), comment (- -), etc.) to change the query structure SQL countermeasures utilizing parameterized database queries with bound, typed parameters and careful use of parameterized stored procedures in the database. Web Security Ensuring that your website or web application is secure Goals of Web Security Safely Browse the web a malicious website cannot steal information from or modify legitimate sites or otherwise harm the user Web Browser Many different clients all implanted differently What vulnerabilities consul be in web browsers Browsers (like any software) can contain exploitable bugs Often enable remote code execution by websites Web applications Online banking, shopping, blogs, social media, Office Docs, Mix of server-side and client-side code

Content preview

Ethical Hacking Final Exam Review
Questions and Correct Answers
GET Request ✅Used for requests for pages, resources, etc.

POST Requests ✅Used for form submissions, logins, etc.

OS Command Attacks ✅a web security vulnerability that allows an attacker to execute
arbitrary operating system (OS) commands on the server that is running an application,
and typically fully compromise the application and all its data.

SQL injection attack ✅a common attack vector that uses malicious SQL code for
backend database manipulation to access information that was not intended to be
displayed.

Insert, Select, Update, Delete ✅Use to access records in SQL Databases

CREATE, DROP ✅Used to add or delete a table in a SQL Database

How SQL attack happens ✅occurs when the application accepts a malicious user
input and then uses it as a part of SQL statement to query a backend database.
An attacker can inject SQL control characters and command keywords (e.g., single
quote ('), double quote ("), equal (=), comment (- -), etc.) to change the query structure

SQL countermeasures ✅utilizing parameterized database queries with bound, typed
parameters and careful use of parameterized stored procedures in the database.

Web Security ✅Ensuring that your website or web application is secure

Goals of Web Security ✅Safely Browse the web
a malicious website cannot steal information from or modify legitimate sites or otherwise
harm the user

Web Browser ✅Many different clients
all implanted differently

What vulnerabilities consul be in web browsers ✅Browsers (like any software) can
contain exploitable bugs
Often enable remote code execution by websites

Web applications ✅Online banking, shopping, blogs, social media, Office Docs,
Mix of server-side and client-side code

, Server-side written in multiple languages E.g., PHP, Ruby, ASP, JSP
Client-side code written in JavaScript
Often written with little consideration for security

Web Browser Security ✅Responsible for security confining content presented by
visited websites

SQL Injection ✅when browser sends malicious input to server changing SQL query

XSS ✅Bad website sends innocent Victor a script that steals information from honest
website

CSRF ✅Bad website sends request to good website, using credentials of innocent
victim who visits site

Web Browser security issues ✅Browse design vulnerabilities
Browser implementation vulnerabilities
attacks running under host os
attacks from network

Browser Sandbox ✅protect local system from web attack
protect/isolate web content from another web content

Same Origin Policy ✅protect web content from another web content

Browser Security Model ✅Website from different domains can't interact except in
limited ways
Same origin
Browser cookies
Including external scripts isn't prohibited by SOP, therefore attacker can steal cookies.
Cross-Origin Communication

What is Penetration testing ✅a stimulated cyber attack against your computer system
to check for exploitable vulnerabilities

why perform a penetration test ✅tests an organizations security to help personnel
learn how to handle any type of breaking from a malicious entity

challenges of penetration testing ✅PT is intentionally breaking into systems
(virtually/physical); What if you break into the wrong systems? Either those that they
didn't want to be tested or even worse, not the
organization's systems at all! What if you cause damage as a result of your testing?
Downtime, loss of data, PII data breach; What if you embarrass someone powerful who
wasn't part of
arranging the PT?

Document information

Uploaded on
September 23, 2024
Number of pages
7
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$9.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
twishfrancis
3.9
(42)
Sold
225
Followers
43
Items
10596
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions