dg dg dg dg dg
s of Information Security Exam | Que
dg dg dg dg dg dg
stions and Correct Answers | Western
dg dg dg dg dg
dg Governors University | Just Released
dg dg dg dg
todgsetdgadglimitdgondgthedgamountdgofdgdatadgwedgexpectdgtodgreceivedgtodgsetdgasidedgstora
gedgfordgthatdgdata
*requireddgindgmostdgprogrammingdglanguages
*dgpreventsdgbufferdgoverflowsdg-dgcorrectdganswerdg✔✔boundsdgchecking
Adgtypedgofdgsoftwaredgdevelopmentdgvulnerabilitydgthatdgoccursdgwhendgmultipledgprocess
esdgordgmultipledgthreadsdgwithindgadgprocessdgcontroldgordgsharedgaccessdgtodgadgparticular
dg resource,dganddgthedgcorrectdghandlingdgofdgthatdgresourcedgdependsdgondgthedgproperdgo
rderingdgordgtimingdgofdgtransactionsdg-dgcorrectdganswerdg✔✔racedgconditions
adgtypedgofdgattackdgthatdgcandgoccurdgwhendgwedgfaildgtodgvalidatedgthedginputdgtodgourdgapp
licationsdgordgtakedgstepsdgtodgfilterdgoutdgunexpecteddgordgundesirabledgcontentdg-
dg correctdganswerdg✔✔inputdgvalidation
adgtypedgofdginputdgvalidationdgattacksdgindgwhichdgcertaindgprintdgfunctionsdgwithindgadgprog
rammingdglanguagedgcandgbedguseddgtodgmanipulatedgordgviewdgthedginternaldgmemorydgofd
andgapplicationdg-dgcorrectdganswerdg✔✔formatdgstringdgattack
g
Adgtypedgofdgattackdgthatdgcandgoccurdgwhendgwedgfaildgtodgusedgstrongdgauthenticationdgme
chanismsdgfordgourdgapplicationsdg-dgcorrectdganswerdg✔✔authenticationdgattack
,Adgtypedgofdgattackdgthatdgcandgoccurdgwhendgwedgfaildgtodgusedgauthorizationdgbestdgpractic
esdgfordgourdgapplicationsdg-dgcorrectdganswerdg✔✔authorizationdgattack
Adgtypedgofdgattackdgthatdgcandgoccurdgwhendgwedgfaildgtodgproperlydgdesigndgourdgsecuritydg
mechanismsdgwhendgimplementingdgcryptographicdgcontrolsdgindgourdgapplicationsdg-
correctdganswerdg✔✔cryptographicdgattack
dg
Adgtypedgofdgattackdgthatdgtakesdgadvantagedgofdgweaknessesdgindgthedgsoftwaredgloadeddg
ondgclientdgmachinesdgordgonedgthatdgusesdgsocialdgengineeringdgtechniquesdgtodgtrickdgusdg
intodggoingdgalongdgwithdgthedgattackdg-dgcorrectdganswerdg✔✔client-sidedgattack
andgattackdgcarrieddgoutdgbydgplacingdgcodedgindgthedgformdgofdgadgscriptingdglanguagedginto
a webdgpagedgordgotherdgmediadgthatdgisdginterpreteddgbydgadgclientdgbrowserdg-
dg dg
correctdganswerdg✔✔XSSdg(CrossdgSitedgScripting)
dg
andgattackdgindgwhichdgthedgattackerdgplacesdgadglinkdgondgadgwebdgpagedgindgsuchdgadgwaydg
thatdgitdgwilldgbedgautomaticallydgexecuteddgtodginitiatedgadgparticulardgactivitydgondganotherdg
webdgpagedgordgapplicationdgwheredgthedguserdgisdgcurrentlydgauthenticateddg-
correctdganswerdg✔✔XSRFdg(cross-sitedgrequestdgforgery)
dg
Attacksdgagainstdgadgwebdgsitedgthatdgtakedgadvantagedgofdgvulnerabilitiesdgindgpoorlydgcod
eddgSQLdg(adgstandarddganddgcommondgdatabasedgsoftwaredgapplication)dgapplicationsdgin
orderdgtodgintroducedgmaliciousdgprogramdgcodedgintodgadgcompany'sdgsystemsdganddgnet
dg
works.dg-dgcorrectdganswerdg✔✔SQLdgInjectiondgAttack
Andgattackdgthatdgtakesdgadvantagedgofdgthedggraphicaldgdisplaydgcapabilitiesdgofdgourdgbro
wserdgtodgtrickdgusdgintodgclickingdgondgsomethingdgwedgmightdgnotdgotherwisedg-
correctdganswerdg✔✔clickjacking
dg
,Adgtypedgofdgattackdgondgthedgwebdgserverdgthatdgcandgtargetdgvulnerabilitiesdgsuchdgasdglac
kdgofdginputdgvalidation,dgimproperdgordginadequatedgpermissions,dgordgextraneousdgfilesdgle
ftdgondgthedgserverdgfromdgthedgdevelopmentdgprocessdg-dgcorrectdganswerdg✔✔server-
sidedgattack
Namedgthedg4dgmaindgcategoriesdgofdgdatabasedgsecuritydgissuesdg-dgcorrectdganswerdg✔
✔
Protocoldgissues,dgunauthenticateddgaccess,dgarbitrarydgcodedgexecution,dganddgprivilegedg
escalation
Adgtypedgofdgtooldgthatdganalyzesdgwebdgpagesdgordgweb-
baseddgapplicationsdganddgsearchesdgfordgcommondgflawsdgsuchdgasdgXSSdgordgSQLdginjec
tiondgflaws,dganddgimproperlydgsetdgpermissions,dgextraneousdgfiles,dgoutdateddgsoftwaredg
versions,dganddgmanydgmoredgsuchdgitemsdg-dgcorrectdganswerdg✔✔
webdgapplicationdganalysisdgtool
unauthenticateddgflawsdgindgnetworkdgprotocols,dgauthenticateddgflawsdgindgnetworkdgproto
cols,dgflawsdgindgauthenticationdgprotocolsdg-dgcorrectdganswerdg✔✔protocoldgissues
Andgattackdgthatdgexploitsdgandgapplicationsdgvulnerabilitydgintodgallowingdgthedgattackerdgto
executedgcommandsdgondgadguser'sdgcomputer.
dg
*dgarbitrarydgcodedgexecutiondgindgintrinsicdgordgsecurabledgSQLdgelementsdg-
correctdganswerdg✔✔arbitrarydgcodedgexecution
dg
Andgattackdgthatdgexploitsdgadgvulnerabilitydgindgsoftwaredgtodggaindgaccessdgtodgresourcesdg
thatdgthedguserdgnormallydgwoulddgbedgrestricteddgfromdgaccessing.
*dgviadgSQLdginjectiondgordglocaldgissuesdg-dgcorrectdganswerdg✔✔PrivilegedgEscalation
adgsecuritydgbestdgpracticedgfordgalldgsoftware
, *dgthedgmostdgeffectivedgwaydgofdgmitigatingdgSQLdginjectiondgattacksdg-dgcorrectdganswerdg
✔✔validatingdguserdginputs
Adgwebdgserverdganalysisdgtooldgthatdgperformsdgchecksdgfordgmanydgcommondgserver-
sidedgvulnerabilitiesdg&dgcreatesdgandgindexdgofdgalldgthedgfilesdganddgdirectoriesdgitdgcandgse
edgondgthedgtargetdgwebdgserverdg(adgprocessdgknowndgasdgspidering)dg-dgcorrectdganswerdg
✔✔Niktodg(anddgWikto)
Adgwell-
knowndgGUIdgwebdganalysisdgtooldgthatdgoffersdgadgfreedganddgprofessionaldgversion;dgthedg
prodgversiondgincludesdgadvanceddgtoolsdgfordgconductingdgmoredgin-depthdgattacksdg-
correctdganswerdg✔✔burpdgsuite
dg
Adgtypedgofdgtooldgthatdgworksdgbydgbombardingdgourdgapplicationsdgwithdgalldgmannerdgofdgd
atadganddginputsdgfromdgadgwidedgvarietydgofdgsources,dgindgthedghopedgthatdgwedgcandgcaus
edgthedgapplicationdgtodgfaildgordgtodgperformdgindgunexpecteddgwaysdg-dgcorrectdganswerdg✔
✔fuzzer
AdgtooldgdevelopeddgbydgMicrosoftdgtodgfinddgflawsdgindgfile-handlingdgsourcedgcodedg-
correctdganswerdg✔✔MiniFuzzdgFiledgFuzzer
dg
AdgtooldgdevelopeddgbydgMicrosoftdgtodgexaminedgsourcedgcodedgfordggeneraldggooddgpracti
cesdg-dgcorrectdganswerdg✔✔BinScopedgBinarydgAnalyzer
AdgtooldgdevelopeddgbydgMicrosoftdgfordgtestingdgcertaindgpattern-
matchingdgexpressionsdgfordgpotentialdgvulnerabilitiesdg-dgcorrectdganswerdg✔✔
SDLdgRegexdgFuzzer
CERT,dgNISTdg800,dgBSI,dgandgorganization'sdginternaldgcodingdgguidelinesdg-
correctdganswerdg✔✔gooddgsourcesdgofdgsecuredgcodingdgguidelines
dg