Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

Denial-of-Service 2023 Practice Questions and Answers with complete solution

Beoordeling
-
Verkocht
-
Pagina's
11
Cijfer
A+
Geüpload op
14-03-2023
Geschreven in
2022/2023

Denial-of-Service 2023 Practice Questions and Answers with complete solution During the penetration testing of the MyBank public website, Marin discovered a credit/interest calculator running on server side, which calculates a credit return plan. The application accepts the following parameters: amount=&duration=10&scale=month Assuming that parameter amount is the amount of credit, the user is calculating the interest and credit return plan (in this case for 100,000 USD), parameter duration is the timeframe the credit will be paid off, and scale defines how often the credit rate will be paid (year, month, day, ...). How can Marin proceed with testing weather this web application is vulnerable to DoS? Change the parameter duration to a large number and change scale value to "day" and resend the packet few times to observe the delay. Change the parameter duration to a small number and leave scale value on "month" and resend the packet few times to observe the delay. Leave the parameter duration as is and change the scale value to "year" and resend the packet few times to observe the delay. Change the parameter duration to a small number and change scale value to "day" and resend the packet few times to observe the delay. Change the parameter duration to a large number and change scale value to "day" and resend the packet few times to observe the delay. When a client's computer is infected with malicious software which connects to the remote computer to receive commands, the client's computer is called a ___________ Bot Botnet Command and Control(C&C) Client Bot Identify the type of a DoS attack where an attacker sends e-mails, Internet relay chats (IRCs), tweets, and posts videos with fraudulent content for hardware updates to the victim with the intent of modifying and corrupting the updates with vulnerabilities or defective firmware.

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

Denial-of-Service 2023 Practice Questions and Answers
with complete solution
During the penetration testing of the MyBank public website, Marin discovered a
credit/interest calculator running on server side, which calculates a credit return plan.
The application accepts the following parameters:
amount=100000&duration=10&scale=month

Assuming that parameter amount is the amount of credit, the user is calculating the
interest and credit return plan (in this case for 100,000 USD), parameter duration is the
timeframe the credit will be paid off, and scale defines how often the credit rate will be
paid (year, month, day, ...). How can Marin proceed with testing weather this web
application is vulnerable to DoS?


Change the parameter duration to a large number and change scale value to "day" and
resend the packet few times to observe the delay.

Change the parameter duration to a small number and leave scale value on "month"
and resend the packet few times to observe the delay.

Leave the parameter duration as is and change the scale value to "year" and resend the
packet few times to observe the delay.

Change the parameter duration to a small number and change scale value to "day" and
resend the packet few times to observe the delay.
Change the parameter duration to a large number and change scale value to "day" and
resend the packet few times to observe the delay.
When a client's computer is infected with malicious software which connects to the
remote computer to receive commands, the client's computer is called a ___________


Bot

Botnet

Command and Control(C&C)

Client
Bot
Identify the type of a DoS attack where an attacker sends e-mails, Internet relay chats
(IRCs), tweets, and posts videos with fraudulent content for hardware updates to the
victim with the intent of modifying and corrupting the updates with vulnerabilities or
defective firmware.

, SYN flooding attack

Internet control message protocol(ICMP) flood attack

Ping of death attack

Phlashing attack
Phlashing attack
Which of the following is considered to be a smurf attack?


An attacker sends a large amount of ICMP traffic with a spoofed source IPaddress.

An attacker sends a large amount TCP traffic with a spoofed source IPaddress.

An attacker sends a large number of TCP connection requests with spoofed source
IPaddress.

An attacker sends a large number of TCP/user datagram protocol (UDP) connection
requests.
An attacker sends a large amount of ICMP traffic with a spoofed source IPaddress.
The DDoS tool created by anonymous sends junk HTTP GET and POST requests to
flood the target, and its second version of the tool (the first version had different name)
that was used in the so-called Operation Megaupload is called _______.


HOIC

BanglaDOS

Dereil

Pandora DDoS
HOIC
Mike works for a company "Fourth Rose Intl." as the sales manager. He was sent to Las
Vegas on a business trip to meet his clients. After the successful completion of his
meeting, Mike went back to his hotel room, connected to the hotel Wi-Fi network and
attended his other scheduled online client meetings through his laptop. After returning
back to his office headquarters, Mike connects his laptop to the office Wi-Fi network and
continues his work; however, he observes that his laptop starts to behave strangely. It
regularly slows down with blue screening from time-to-time and rebooting without any
apparent reason. He raised the issue with his system administrator. Some days later,
the system administrator in Mike's company observed the same issue in various other
computers in his organization. Meanwhile, he has also observed that large amounts of
unauthorized traffic from various IP addresses of "Fourth Rose Intl." were directed

Geschreven voor

Vak

Documentinformatie

Geüpload op
14 maart 2023
Aantal pagina's
11
Geschreven in
2022/2023
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$9.32
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
magdamwikash23 Western Governers University
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
114
Lid sinds
3 jaar
Aantal volgers
94
Documenten
5328
Laatst verkocht
1 week geleden
Magda

NURSING STUDY GUIDES/EXAMS AND NOTES ALL VERIFIED BY EXPERTS All my uploaded documents, exams and essays are verified by relevant experts.I can assure an A or at least 90% if you use any of my documents.

3.9

14 beoordelingen

5
7
4
2
3
2
2
2
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen