Ch. 5- Analyzing Vulnerability Scans

Ace your homework & exams now with Quizwiz!

A. In a SQL injection attack, the attacker seeks to use a web application to gain access to an underlying database. Semicolons and apostrophes are characteristic of these attacks.

Alan is reviewing web server logs after an attack and finds many records that contain semicolons and apostrophes in queries from end users. What type of attack should he suspect? A. SQL injection B. LDAP injection C. Cross-site scripting D. Buffer overflow

D. TLS 1.1 is a secure transport protocol that supports web traffic. The other protocols listed all have flaws that render them insecure and unsuitable for use.

Betty is selecting a transport encryption protocol for use in a new public website she is creating. Which protocol would be the best choice? A. SSL 2.0 B. SSL 3.0 C. TLS 1.0 D. TLS 1.1

D. Buffer overflow attacks occur when an attacker manipulates a program into placing more data into an area of memory than is allocated for that program's use. The goal is to overwrite other information in memory with instructions that may be executed by a different process running on the system.

In what type of attack does the attacker place more information in a memory location than is allocated for that use? A. SQL injection B. LDAP injection C. Cross-site scripting D. Buffer overflow

A. VM escape vulnerabilities are the most serious issue that can exist in a virtualized environment, particularly when a virtual host runs systems of differing security levels. In an escape attack, the attacker has access to a single virtual host and then manages to leverage that access to intrude on the resources assigned to a different virtual machine.

In what type of attack does the attacker seek to gain access to resources assigned to a different virtual machine? A. VM escape B. Management interface brute force C. LDAP injection D. DNS amplification

C. Vulnerabilities with a CVSSv2 score higher than 6.0 but less than 10.0 fall into the High risk category.

Kevin recently identified a new security vulnerability and computed its CVSSv2 base score as 6.5. Which risk category would this vulnerability fall into? A. Low B. Medium C. High D. Critical

D. In a cross-site scripting (XSS) attack, an attacker embeds scripting commands on a website that will later be executed by an unsuspecting visitor accessing the site. The idea is to trick a user visiting a trusted site into executing malicious code placed there by an untrusted third party.

Monica discovers that an attacker posted a message attacking users who visit a web forum that she manages. Which one of the following attack types is most likely to have occurred? A. SQL injection B. Malware injection C. LDAP injection D. Cross-site scripting

A. A false positive error occurs when the vulnerability scanner reports a vulnerability that does not actually exist.

Tara recently analyzed the results of a vulnerability scan report and found that a vulnerability reported by the scanner did not exist because the system was actually patched as specified. What type of error occurred? A. False positive B. False negative C. True positive D. True negative

B. In October 2016, security researchers announced the discovery of a Linux kernel vulnerability dubbed Dirty COW. This vulnerability, present in the Linux kernel for nine years, was extremely easy to exploit and provided successful attackers with administrative control of affected systems.

The Dirty COW attack is an example of what type of vulnerability? A. Malicious code B. Privilege escalation C. Buffer overflow D. LDAP injection

B. Although the network can support any of these protocols, internal IP disclosure vulnerabilities occur when a network uses Network Address Translation (NAT) to map public and private IP addresses but a server inadvertently discloses its private IP address to remote systems.

Tom is reviewing a vulnerability scan report and finds that one of the servers on his network suffers from an internal IP address disclosure vulnerability. What protocol is likely in use on this network that resulted in this vulnerability? A. TLS B. NAT C. SSH D. VPN

D. Version 3.0 of CVSS is currently available but is not as widely used as the more common CVSS version 2.0.

What is the most recent version of CVSS that is currently available? A. 1.0 B. 2.0 C. 2.5 D. 3.0

D. In a virtualized data center, the virtual host hardware runs a special operating system known as a hypervisor that mediates access to the underlying hardware resources.

What software component is responsible for enforcing the separation of guest systems in a virtualized infrastructure? A. Guest operating system B. Host operating system C. Memory controller D. Hypervisor

C. The authentication metric describes the authentication hurdles that an attacker would need to clear to exploit a vulnerability.

Which one of the CVSS metrics would contain information about the number of times an attacker must successfully authenticate to execute an attack? A. AV B. C C. Au D. AC

B. Digital certificates are intended to provide public encryption keys, and this would not cause an error. The other circumstances are all causes for concern and would trigger an alert during a vulnerability scan.

Which one of the following conditions would not result in a certificate warning during a vulnerability scan of a web server? A. Use of an untrusted CA B. Inclusion of a public encryption key C. Expiration of the certificate D. Mismatch in certificate name

B. It is unlikely that a database table would contain information relevant to assessing a vulnerability scan report. Logs, SIEM reports, and configuration management systems are much more likely to contain relevant information.

Which one of the following is not a common source of information that may be correlated with vulnerability scan results? A. Logs B. Database tables C. SIEM D. Configuration management system

B. The CVSS exploitability score is computed using the access vector, access complexity, and authentication metrics.

Which one of the following metrics is not included in the calculation of the CVSS exploitability score? A. Access vector B. Vulnerability age C. Access complexity D. Authentication

A. Microsoft discontinued support for Windows Server 2003, and it is likely that the operating system contains unpatchable vulnerabilities.

Which one of the following operating systems should be avoided on production networks? A. Windows Server 2003 B. Red Hat Enterprise Linux 7 C. CentOS 7 D. Ubuntu 16

D. Telnet is an insecure protocol that does not make use of encryption. The other protocols mentioned are all considered secure.

Which one of the following protocols should never be used on a public network? A. SSH B. HTTPS C. SFTP D. Telnet

B. Intrusion detection systems (IDSs) are a security control used to detect network or host attacks. The Internet of Things (IoT), supervisory control and data acquisition (SCADA) systems, and industrial control systems (ICSs) are all associated with connecting physical world objects to a network.

Which one of the following terms is not typically used to describe the connection of physical devices to a network? A. IoT B. IDS C. ICS D. SCADA

C. An access complexity of Low indicates that exploiting the vulnerability does not require any specialized conditions.

Which one of the following values for the CVSS access complexity metric would indicate that the specified attack is simplest to exploit? A. High B. Medium C. Low D. Severe

D. If any of these measures is marked as C, for Complete, it indicates the potential for a complete compromise of the system.

Which one of the following values for the confidentiality, integrity, or availability CVSS metric would indicate the potential for total compromise of a system? A. N B. A C. P D. C


Related study sets

Chapter 6: Texas statutes and rules pertaining to life and health insurance

View Set

ICP/head injury NCLEX style questions

View Set

ARE SS 3- Structural Fundamentals

View Set

1 - ¿Cómo son? Write a sentence describing each subject using the appropriate adjective in parentheses. Follow the model. Modelo: (gordo, delgada) Lidia: Lidia es delgada. el novio de Olga: El novio de Olga es gordo.

View Set

Public Speaking Final Short Answers

View Set

Foundations in Microbiology, Final Exam Learnsmart Practice Questions

View Set

Unit 2 - Introduction to Mobile Apps & Pair Programming (2019)

View Set

Cybersecurity final Multiple choice

View Set

Master educator chapter 8: effective classroom management & supervision

View Set