Test Study 4 Flashcards
What is Type 2 XSS?
Persistent
Malicious scripts that are submitted and stored on the server to be presented to other users.
What works on port 25?
SMTP
What has an IP header of 51?
AH
What are the key concepts of Common Criteria?
Target of Evaluation Protection Profile Security Functionality Requirements Security Assurance Requirements Evaluation Assurance Level
What operates on port 515?
CUP
What is the trusted path?
A secure channel for system management activities to prevent imitation.
What is PRI in networking?
Primary Rate Interface ISDN, consists of 24 x 64 kb/s channels for a total of 1.544 Mb/s
Also known as T1 or E1
Which standard certificate format is used most often by CAs?
PEM
What port does SNMP work on?
161
What packet has an IP header of 1?
ICMP
What ISDN can provide speeds of at least 30 Mb/s?
E-3, T-3
What part of the TCB is responsible for handling user access requests?
Security kernel.
What happens in the analyze step of continuous monitoring?
Analyze the data collected and report the findings and determine the appropriate response.
What is the IP header for ESP?
50
What RMF step includes reporting findings and determining the appropriate response?
Analyze and Report
What framework will provide an indication of maturity of security controls?
COBIT
What operates on port 67/68
BootP / DHCP
What happens in the review and update step of continuous monitoring?
Review and update the monitoring program, adjusting the strategy and maturing measurement capabilities to increase visibility into assets and awareness of vulnerabilities.
What is the IP header for ICMP?
1
What port does SMTP work on?
25
What happens in the establish step of continuous monitoring?
Determine metrics, status monitoring frequencies, control assessment frequencies, and technical architecture.
What provides digital network over voice cabling?
ISDN
What encryption method replaces characters based on a fixed number of positions away?
Shift cipher
What RMF step includes collecting security related information required for metrics?
Implement