Practice Resources Flashcards
(33 cards)
What to do first to before changing firewall rules?
Follow change management process.
How to prevent buffer overflow, sql injection and integer overflow?
Input validation
Stored procedure - saved code in sql
How to push out an update to password policies?
Group policy object
How to check a USB device?
Sandbox
How to isolate an app from os?
Containers
What device joins multiple networks together?
Router
What device sitting in the screened subnet authenticates incoming users and decrypts incoming traffic?
Reverse proxy
What do digital sigs and hashes have in common?
Prove non repudation.
What records are created by dns poisoning and how to prevent?
rrsig records (resourse record signature). Use dnssec (dns security extensions) which validate data.
What prevents people from stealing PII and sensitive info?
dlp (data loss prevention)
What attack affects weak database configs.
Sql injection
What attack is too many characters into a datafield on a web server?
Buffer overflow.
What type of control is SIEM?
Detective
What type of data does a lan protect?
In transit
What type of threat actor might be employed by Nation State or APT?
Organized crime.
What threat actor would buy a program from the dark web?
Script kitty. Novice
How to remotely protect a device when they are away from the office?
Secure web gateway SWG.
Sits between users and internet.
On premises or cloud
Comprehensive web security
How to circumvent a captive portal at an airport?
MAC spoofing
How to guage vulnerabilities?
CVSS (common vulnerability scoring system)
How to verify the last time a file was updated?
Metadata or version control
In an IaaS model, who secures the data?
The client.
What are you searching for when you are trying to find out the cause of an incident?
Root cause analysis
What can be used in a database to only see the last 3 digits of a credit card?
Masking
What involves a meticulous examination of a companies processes, practices, and policies to see if the align with regulatory requirements?
Due diligence