• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 1 out of 4 pages
Exam (elaborations)

Computer Security - Principles and Practice Chapter 5 Questions with Correct Answers Graded A+

Document preview thumbnail
Preview 1 out of 4 pages

Computer Security - Principles and Practice Chapter 5 Questions with Correct Answers Graded A+ Database - Answers A structured collection of data stored for use by one or more applications Database Management System (DBMS) - Answers A suite of programs for constructing and maintaining the database and for offering ad hoc query facilities to multiple users and applications Query Language - Answers Provides a uniform interface to the database for users and applications Relation - Answers A flat table Tuples - Answers Are rows Attributes - Answers Are columns Primary Key - Answers Is a portion of a row to be used to uniquely identify a row in a table Foreign Key - Answers Creates a relationship between two tables. Appears as attributes in another table View - Answers A virtual table. The result of a query that returns selected rows and columns from one or more tables SQL - Answers A query language. Stands for Structured Query Language SQLi User Input - Answers Attackers inject SQL commands via suitably crafted user input SQLi Server Variables - Answers Attackers forge values that are placed in HTTP and network headers. When the query to log the server variable is issued to the database, the attack in the forged header is triggered SQLi Second-order Injection - Answers Attack occurs when incomplete prevention mechanisms against attacks are in place. Malicious user relies on data that is already present within the system. So when the input modifies the query, it causes an attack that doesn't come from the user, but the system itself SQLi Cookies - Answers Attacker modifies cookies, to create a query based on the cookies content SQLi Physical User Input - Answers SQL injection that is made possible by supplying user inputs that construct an attack outside the realm of web requests. This input could take many forms, such as barcodes, RFID, or even paper forms which are scanned using optical character recognition Inband Attack - Answers An attack that used the same communication for injecting code and retrieving results Tautology (Inband) - Answers Injects code in one or more conditional statements so they always evaluate to true to circumvent security measures End-of-line Comment (Inband) - Answers Injecting code into a a field and adding a legitimate code into the comments Piggybacked Queries - Answers Attack adds additional queries beyond the intended query. Adding an attack on top of the legitimate request allowing several queries at once Inferential Attack - Answers No transfer of data is made, but the attacker is able to reconstruct the info by sending requests and observing the behavior of the Website or Database Illegal/Logically incorrect Queries (Infer) - Answers Gathers information via error messages returned by the server. This often reveals vulnerabilities and injection parameters Blind SQL Injection (Infer) - Answers Series of true false questions are asked in order to damage site functionality when statement evaluates to false Out of Band Attack - Answers Data retrieval is made using a different channel. Such as an email sending query results Defensive Coding - Answers An effective way to dramatically reduce threats from SQLi Manual Defensive Coding Practices - Answers Straightforward approach to eliminating vulnerabilities by checking input type. Also covers pattern matching to distinguish normal inputs and abnormal Parameterized Query Insertion - Answers Prevents SQLi by creating predefined query structures and only passing value parameters. Query structures cannot be modified SQL DOM - Answers Automated datatype evaluation. Encapsulates queries to provide safe and reliable way to access databases. Developers are able to systematically apply coding best practices such as input filtering and rigorous type checking of input

Content preview

Computer Security - Principles and Practice Chapter 5 Questions with Correct Answers Graded A+

Database - Answers A structured collection of data stored for use by one or more applications

Database Management System (DBMS) - Answers A suite of programs for constructing and maintaining
the database and for offering ad hoc query facilities to multiple users and applications

Query Language - Answers Provides a uniform interface to the database for users and applications

Relation - Answers A flat table

Tuples - Answers Are rows

Attributes - Answers Are columns

Primary Key - Answers Is a portion of a row to be used to uniquely identify a row in a table

Foreign Key - Answers Creates a relationship between two tables. Appears as attributes in another table

View - Answers A virtual table. The result of a query that returns selected rows and columns from one or
more tables

SQL - Answers A query language. Stands for Structured Query Language

SQLi User Input - Answers Attackers inject SQL commands via suitably crafted user input

SQLi Server Variables - Answers Attackers forge values that are placed in HTTP and network headers.
When the query to log the server variable is issued to the database, the attack in the forged header is
triggered

SQLi Second-order Injection - Answers Attack occurs when incomplete prevention mechanisms against
attacks are in place. Malicious user relies on data that is already present within the system. So when the
input modifies the query, it causes an attack that doesn't come from the user, but the system itself

SQLi Cookies - Answers Attacker modifies cookies, to create a query based on the cookies content

SQLi Physical User Input - Answers SQL injection that is made possible by supplying user inputs that
construct an attack outside the realm of web requests. This input could take many forms, such as
barcodes, RFID, or even paper forms which are scanned using optical character recognition

Inband Attack - Answers An attack that used the same communication for injecting code and retrieving
results

Tautology (Inband) - Answers Injects code in one or more conditional statements so they always
evaluate to true to circumvent security measures

End-of-line Comment (Inband) - Answers Injecting code into a a field and adding a legitimate code into
the comments

Document information

Uploaded on
April 4, 2025
Number of pages
4
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.89

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TutorJosh
3.5
(76)
Sold
500
Followers
16
Items
32943
Last sold
2 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions