1. An attacker compromises the Washington Post's web server and proceeds to modify the homepage slightly by inserting a 1x1 pixel iframe that directs all website visitors to a webpage of his choosing that then installs malware on the visitors' computers. The attacker did this explicitly because he knows that US policymakers frequent the website. This would be an example of a ___________ attack.
2. During a log review, you discover a series of logs that shows the following multiple failed login attempts:
Jan 31 11:39:20 ip-10.0.0.2
sshd[10102]: Invalid user admin from remotehost passwd=bears
Jan 31 11:39:20 ip-10.0.0.2 sshd[10108]: Invalid user admin from
remotehost passwd=eat
Jan 31 11:39:20 ip-10.0.0.2 sshd[10114]: Invalid user admin from
remotehost passwd=beats
Jan 31 11:39:20 ip-10.0.0.2 sshd[10118]: Invalid user admin from
remotehost passwd=battlestar
Jan 31 11:39:20 ip-10.0.0.2 sshd[10120]: Invalid user admin from
remotehost passwd=galactica
What type(s) of attack have you discovered?
d. A dictionary attack
3. In a virtualized environment, the ___________ is responsible for managing resources and requests from the guest operating systems.
1. An attacker compromises the Washington Post's web server and proceeds to modify the homepage slightly...
Chapter 06 Applied Cryptography 1. How is integrity provided? A. Using two-way hash functions and digital signatures B. Using one-way hash functions and digital signatures C. By applying a digital certificate D. By using asymmetric encryption 2. Which term refers to the matching of a user to an account through previously shared credentials? A. Nonrepudiation B. Digital signing C. Authentication D. Obfuscation 3. Which term refers to an arranged group of algorithms? A. Crypto modules B. Cryptographic service providers (CSPs)...
Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...