The Equifax Hack Revisited and Repurposed Flashcards

1
Q

What seems to be the purpose behind AG Barr’s indictment of the four Chinese military personnel for hacking into the Equifax servers in 2017?

A

To draw attention away from the real problems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When (month/year) did Bloomberg Businessweek speculate that the hack was state sponsored and likely done by Chinese? When did Barr announce the indictment?

A

September 2017 and February 2020

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the likelihood that China will honor the U.S. arrest warrants of the four military personnel? If the situation were reversed, would you expect the U.S. to extradite four of its military personnel to China to stand trial?

A

Not likely; I suspect the US would not extradite military personnel to China

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which service on the Equifax server infrastructure was hacked?

A

Equifax’s Online Dispute Portal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Was an Apache patch available at the time of the hack?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Approximately what percentage of the U.S. adult population had their personally identifiable information compromised?

A

Approximately 50%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Did Barr find that Equifax had taken “reasonable measures to keep their trade secrets secret?”

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Did the U.S. Senate agree with Barr that Equifax had taken reasonable measures to protect its data?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many cyber-vulnerabilities were discovered by the IT audit of Equifax network infrastructure in 2015?

A

More than 8500 vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The article lists eight security failures of Equifax prior to the breach that were identified by the U.S. Senate. List five of them.

A

Lack of IT asset inventory, no method for validating patches, no further audits, a clueless CISO, and no isolated networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

In the final Equifax settlement, how much money was paid to the Equifax victims on average?

A

US$3 per victim

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Was Equifax’ security policy adequate?

A

No it was not adequate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What educational background did the Equifax CISO have that qualified her for the position?

A

Music composition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly