Security + CIAT QUESTIONS Flashcards
exam
CAPTCHA
used to mitigate high volume of fraudulent login attempts.
Implementing input validation techniques
used to ensure that its web application is secure from SQL injection attacks.
Virtual Private Network (VPN)
used to ensure the integrity of data transferred between its internal network and remote employees.
Data Loss Prevention (DLP) system
focuses on detecting and preventing the loss, leakage, or misuse of data through breaches, exfiltration transmissions, and unauthorized use.
Enabling MAC address filtering
It adds an extra layer of security by limiting the number of devices that can connect to a network.
prepared statements in database queries
used to ensure that its web server
is **secure **from SQL injection attacks
.
email gateway with anti-phishing features
reduce the risk of email phishing
malware infections from USB drives
* prevention (company issue)*
Disable USB ports on all company computers
issues with BYOD
protection against data leakage
Port security
You can specify the maximum number of MAC addresses that can be learned on a port.
DHCP snooping
occurs when an attacker attempts to respond to DHCP requests and trying to list themselves (spoofs) as the default gateway or DNS server
SSID broadcast disabling
Unable to see SSID wi-fi network
website is frequently targeted by SQL injection attacks.
defense is to use parameterized queries in the website code
mobile device management (MDM)
solution
ensure that mobile devices are secure against data leakage.
Data encryption
ensure the confidentiality and integrity of customer data
FIRST line of defense against malware
Antivirus software
unpatched vulnerability in a critical application.
Apply a temporary workaround
Firewall rules
determine which types of traffic your firewall accepts and which are denied
File integrity monitoring
examines the integrity of sensitive files, registry keys, and folders within the host operating system and checks whether files have been altered
something they have and something they know.
Multifactor authentication
Implementing a CDN (Content Delivery Network)
ensures that no single server bears the brunt of an attack, reducing the likelihood of a successful DDoS attack.