Equifax and the Latest Round of Identity Theft Roulette Flashcards

1
Q

What data was leaked in the Equifax breach?

A

The personal data on 145 million people

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What was the nature of the vulnerability?

A

Resulted from a known vulnerability in the Apache Struts server software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What was the specific attack vector?

A

Execute commands via the #cmd in content-type HTTP headers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

According to Forbes Magazine, what penalties did the CEO of Equifax receive from the Board of Directors?

A

63 cents for every customer whose data was potentially exposed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

To what extent was information about the Struts vulnerability known before the attack?

A

To the full extent. They knew of the vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Was Equifax aware that a patch was available for the Struts vulnerability? If so, how much time did they delay in applying the patch?

A

Yes. For 3 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What was the educational and training background of the Equifax CIO?

A

Music major

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What was the education and training background of the Equifax CISO?

A

Music composition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Describe the “too big to fail era”?

A

When the accused institution is so large that its failure might damage the economy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Are credit reporting companies held liable for PII data loss?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly