Unit 5: Securing Applications and Data
Cybersecurity · Unit 5 · Paper 3

Securing Applications and Data unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 46 terms and is the same for everyone, so a teacher can assign “Unit 5, Paper 3” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Attribute-based access control (ABAC)

2

Data loss prevention (DLP)

3

Personally identifiable information

4

Public key infrastructure (PKI)

5

End-to-end encryption

6

Data at rest, in transit, in use

7

Digital signature

8

Rainbow table

9

Why backups must be tested and offline

10

Privilege creep

11

Hashing

12

Key stretching

Short answer 1. Define or explain: Code review and static analysis

3 pts

Short answer 2. Define or explain: Insecure deserialization

3 pts

Short answer 3. Define or explain: Why both are used together

3 pts

Short answer 4. Define or explain: Account lifecycle

3 pts

Free response

6 pts

A student-built web application lets users search a course catalog. The developer builds the database query by concatenating the user's search text directly into a SQL string, and displays the search term back on the results page exactly as typed. (a) Name the vulnerability created by the query construction and explain the mechanism by which it is exploited. (b) Explain why parameterized queries fix it, and why filtering out the word "DROP" does not. (c) Name the separate vulnerability created by echoing the search term back to the page, and describe its impact on other users. (d) Explain what defense in depth means and apply it to this application with two distinct layers.