Securing Applications and Data unit test
A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.
Mandatory access control (MAC)
Race condition
Why both are used together
Privilege creep
Data classification
Access review (recertification)
Public key infrastructure (PKI)
Digital signature
Cross-site request forgery (CSRF)
Asymmetric encryption
Key stretching
Directory traversal
Short answer 1. Define or explain: Insecure deserialization
3 ptsShort answer 2. Define or explain: Hardcoded secrets
3 ptsShort answer 3. Define or explain: Discretionary access control (DAC)
3 ptsShort answer 4. Define or explain: Data minimization
3 ptsFree response
6 ptsThis course has no free-response prompt tagged to this unit, so one from elsewhere in the course is used. It is still worth writing — the skill transfers.
A small company stores customer passwords so that its help desk can read them back to callers who forget them. The database is encrypted at rest, and the decryption key is stored in a file on the same server. (a) Explain why storing passwords in a recoverable form is a design error, regardless of the encryption used. (b) Describe what the company should store instead, and explain the role of a salt. (c) Explain why encrypting the database provides little protection given where the key is stored. (d) The help desk still needs a way to assist users who forget passwords. Describe a secure alternative and explain why it does not require recovering the original password.