3.6 Detection and Prevention Flashcards
What is the purpose of penetration testing?
This is used to find any security weaknesses in a system by trying to gain access without knowledge of user names, passwords or encryption keys.
There are two main types of penetration testing - explain these.
The first simulates an external attack where the tester has little knowledge of the system with the objective of finding out if they can get into the system, how far they can get and what they can do to the system.
The second simulates a malicious insider with the objective of finding out what damage they could cause to the system.
Name 2 types of biometric measures used by mobile devices.
Facial recognition, finger prints
Give an advantage of biometric security measures.
Because they are based on unique biometric measurements it is not possible steal or forget.
State 3 characteristics of a strong password.
Upper and lower case letters, numbers, symbols
What is the purpose of CAPTCHA?
A CAPTCHA is a program that protects websites against bots by generating and grading tests that humans can pass, but current computer programs cannot.
How does email confirmation protect a system?
Sending an email to a user asking them to confirm password changes, prevents hackers from changing passwords un-noticed.
Describe one issue with out-of-date software.
If software is out-of-date it may not be supported so any bugs will be unpatched, leaving the system open to malware.
What are the advantages of automatically updating software?
You do not have to remember to update. Any bugs can be fixed quickly.
What is a firewall?
A firewall is a network security system that monitors incoming and outgoing traffic and can be set to allow or block certain connections.