WorksheetsActivity 1
Total questions: 10
Worksheet time: 10mins
Hidden fields within web pages can be used to save information about a client session. This option can also be applied in order to store session variables that enable persistence across multiple website pages, such as maintaining the contents of a shopping cart on a retail web site. The most probable web-based attack due to the use of hidden fields is:
parameter tampering
cross-site scripting
cookie poisoning
stealth commanding
Which control is the best way to ensure that the data in a file has not been changed during transmission?
Hash values
parity bits
reasonableness check
check digits
Which of the following techniques can be used to pinpoint a transaction from a stolen credit card?
Stateful Inspection Firewall
Intrusion Detection System
Packet filtering routers
Data mining
Which of the following best ensures integrity of a Server's operating system?
Protecting the server in a secure location
Setting a boot password
Hardening Server Configuration
Implementing Activity Logging
Which of the following will MOST effectively prevent unauthorized access to a System Administration Account on a Webserver.
Two Factor Authenticaiton
Password complexity rules
Password Expiration and Lockout Policy
Host Intrusion Detection Software Installed on the Server
An Organization's IT Director has approved installation of a Wireless local area network access point in conference room for a team of consultants to access internet with their laptops. The BEST control to protect corporate servers from unauthorized access is to ensure that:
Enable Encryption on Access point
Conference Room network on a separate VLAN
Antivirus signatures and patch levels are updated on consultants' laptops
Default user IDs are disabled and strong passwords are set on Corporate Servers
An IS Auditor has been asked by Management to review a potentially fraud transaction. The PRIMARY focus of the auditor should be:
maintain impartiality
maintain IS Auditor Independence
Assuring integrity of the evidence
Assess all relevant evidence for the transaction
Which of the following is an effective preventive control to ensure that a Database Administrator complies with the custodianship of the enterprise's data?
Exception Reports
Segregation of duties
Review of access logs and activities
management supervision
An IS Auditor discovers that password controls are more stringent for business users than for IT developers. Which of the following is the BEST action for the IS auditor to take?
Determine whether this is a policy violation and document it
Document the observation as an Exception
Recommend all password settings be identical
Recommend that logs of IT developer access are reviewed periodically
An organization is developing a web based application. Which of the following security should NOT be taken at all:
Ensure that port 80 and 443 are blocked at firewall
Inspect file and access permission on server
perform a web application security review
Making sure that IP addresses are whitelisted to access the application
