PrepAway - Latest Free Exam Questions & Answers

Tag: Exam CISSP (update August 5th, 2017)

Exam CISSP: Certified Information Systems Security Professional (update August 5th, 2017)

what did Debbie install without her knowledge?

Debbie from finance called to tell you that she downloaded and installed a free wallpaper program that sets the
wallpaper on her computer to match the current weather outside but now her computer runs slowly and the disk
drive activity light is always on. You take a closer look and when you do a simple port scan to see which ports
are open on her computer, you notice that TCP/80 is open. You point a web browser at her computer’s IP
Address and port and see a site selling prescription drugs.
Apart from the wallpaper changing software, what did Debbie install without her knowledge?

What would you call an attack where an attacker can inf…

What would you call an attack where an attacker can influence the state of the resource between check and
use?
This attack can happen with shared resources such as files, memory, or even variables in multithreaded
programs. This can cause the software to perform invalid actions when the resource is in an unexpected state.
The steps followed by this attack are usually the following: the software checks the state of a resource before
using that resource, but the resource’s state can change between the check and the use in a way that
invalidates the results of the check.


Page 2 of 12112345...102030...Last »