| Home > Security Security Schools > Intrusion Defense School > Preventing Web server attacks: Spyware and malware defense > Web security final exam > Final exam: Web attack prevention and defense | |
| Security Schools: Intrusion Defense School: |
|
||||||||||||||
|
|||||||||||||||
Preventing Web server attacks: Spyware and malware defense
![]() Web security final exam
|
||
1.) Which of the following services is not required to run a Windows server solely configured to run IIS and publish a Web site on the Internet?
b. Net Logon c. Performance Logs and Alerts d. Protected Storage e. World Wide Web Publishing Service Answer
2.) Which of the following statements is true about script kiddies?
3.) Which of the following properties must a "reliable" system demonstrate to be able to deliver essential services?
4.) Your Web server should be placed in a DMZ or "perimeter network," because…
5.) Which of the following would you allow to attack your Web site?
6.) You are running an e-commerce Web site that uses SSL to encrypt your customers' address and credit card information when they purchase goods via the site. You have blocked all unused ports on your Web server except ports 25, 80, 1433 and 1434. Will your customers be able to pay for their orders?
7.) Which of the following is not a true statement about the advantages of backing up system log files on a dedicated server?
8.) Phishing differs from adware and spyware because…
9.) Which one of the following components does not need to be installed to run IIS on a Windows server?
10.) Which of the following directories should be deleted from a live IIS Web server connected to the Internet?
11.) True or False: Client-side validation of form data is the same as server-validation except that it happens on the client's machine.
12.) Which of the following file types do you need to delete from your production IIS Web server?
13.) Which of the following are signs that computers on your network may have been infected by spyware?
14.) Internet Explorer divides the Internet into zones, so that you can assign a Web site to a zone with a suitable security level. To which level would you assign the site \\fileserver\documents?
15.) The NTFS file format allows you to…
16.) True or False: You do not need a Terminal Server Client Access License to run Terminal Services to manage a Windows server remotely.
17.) Which phrase best fits the following sentence? Web form input is _________. The data is not blocked; it is allowed into the server and could be manipulated to compromise security.
18.) You run a Web site that provides ASP script examples that are stored in an Access database. What is the correct way to display the text <script> on a Web page?
19.) Microsoft's cipher.exe program…
20.) True or False: Null sessions are required on Windows IIS Web servers in order to allow anonymous access to the Web site using the Internet Guest account.
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||