ISC Exam Questions

What most likely took place to allow this to happen?

Two months after Kathy set up her NIS+ server she found out that password file had been captured and brute forced. What most likely took place to allow this to happen?

A.
Kathy accidentally chose security level 3 when she was configuring the server.

B.
The NIS+ server was configured to be backwards compatible with NIS.

C.
Unauthorized zone transfers took place.

D.
Kathy did not encrypt the password file on the server.

Explanation:
NIS+ is backward compatible with NIS, which opens up a hole for
hackers to exploit. If a hackers system has NIS client software, and the NIS+
server is configured to be backward compatible, the NIS+ server can access files
without first having to be authenticated and authorized. So the hacker can get the
password file and start cracking away.