Day 3 Quiz Flashcards

0
Q

In Microsoft windows what acts as a go intermediary between the hardware and the kernel

A

The hardware abstraction layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

In an operating system what program is always running

A

The kernel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When do Microsoft normally release patches

A

Second Tuesday of the month

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which vulnerability does enum4linux exploit

A

Null sessions permitted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What folder in the Unix file system contains user command binaries

A

Bin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What acts as a broker for TCP/IP connections on a Unix system

A

Dined

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What computer security model places object access beyond the control of an individual owner of an object

A

MAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What type of organisation would typically use DAC

A

Commercial

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What type of organisation would typically use MAC

A

Military

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
Which of the following is not a primitive used in the take grant security model
A : take
B : destroy
C : grant
D : create
A

B: destroy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the error ‘Microsoft ole db provider for doc drivers error 80040e14’ suggest

A

The site is vulnerable to sql injection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Cross site scripting allows an attacker to…

A

Inject client side scripting languages into a web application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is this url an example of?
Www.bum.com/download.php?file=felch.txt

XD
Sql injection
Direct object reference
Csrf

A

Direct object reference

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is nikto

A

A web app scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can sql injection be prevented

A

User input validation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a data processor when referencing the 1998 dpa act?

A

Any person other than an employee of the data controller who processes the data on behalf of the data controller

16
Q

Which section of the computer misuse act covers using a computer to facilitate further crime

A

Section 2

17
Q

RIPA is?

A

An act to make provision for and about the interception of communications

18
Q

What does guessing a friends Facebook password without their permission violate?

A

Computer misuse act 1990 section 1

19
Q

When would aggressive port scanning which may lead to Availibility issues be legal

A

When this is being conducted as part of a penetration test and is clearly defined in the scope of work

20
Q

Which of the following is not a default Microsoft sql table

Sysobjects
Sysprocesses
Systypes
Syssys

A

Syssys