Securing Networks unit test
A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.
Distributed denial-of-service (DDoS)
Next-generation firewall
ARP poisoning
Stateful firewall
Port scanning
SIEM
Rogue access point
DNS poisoning
DMZ (screened subnet)
SSID broadcast
Lateral movement
Access control list (ACL)
Short answer 1. Define or explain: On-path (man-in-the-middle) attack
3 ptsShort answer 2. Define or explain: Network segmentation
3 ptsShort answer 3. Define or explain: Deauthentication attack
3 ptsShort answer 4. Define or explain: Botnet
3 ptsFree response
6 ptsThis course has no free-response prompt tagged to this unit, so one from elsewhere in the course is used. It is still worth writing — the skill transfers.
A student-built web application lets users search a course catalog. The developer builds the database query by concatenating the user's search text directly into a SQL string, and displays the search term back on the results page exactly as typed. (a) Name the vulnerability created by the query construction and explain the mechanism by which it is exploited. (b) Explain why parameterized queries fix it, and why filtering out the word "DROP" does not. (c) Name the separate vulnerability created by echoing the search term back to the page, and describe its impact on other users. (d) Explain what defense in depth means and apply it to this application with two distinct layers.