| Home > Security Security Schools > Intrusion Defense School > Preventing Web server attacks: Spyware and malware defense > Web security pre-test > Entrance exam: Web attack prevention and defense | |
| Security Schools: Intrusion Defense School: |
|
||||||||||||||
|
|||||||||||||||
Preventing Web server attacks: Spyware and malware defense
![]() Web security pre-test
|
||
![]() by Michael Cobb Sure, IIS has its fair share of problems, but you could be your Web server's No. 1 vulnerability if you aren't Web security savvy. Take this exam to see if it's time to go back to school -- Web Security School, that is!
1.) What is SSL used for?
2.) Which port does HTTPS use?
3.) True or False: An IT security risk analysis is the same as an IT vulnerability assessment.
4.) Phishing differs from adware and spyware because…
5.) Which is the recommended setting for auditing policy settings to audit Object Access?
6.) As the administrator for a Windows-based network, you are installing Windows 2000 Server on a computer, which will run IIS
and be connected to the Internet. Your domain name is mycompany.com. During the setup the installer asks whether you want this computer to be a
member of a domain. Which option do you select?
7.) Which of the following services is not required to run a Windows server solely configured to run IIS and publish a Web
site?
8.) By default, IIS is configured to support many different common file name extensions that are related to a variety of
features in IIS. Your site uses Active Server Pages and PHP for creating pages on the fly. Besides .asp and .php, what other file name extensions
should be mapped to IIS?
9.) Which is the recommended log file format for logging IIS events?
10.) Web server A is set up to log system and IIS activity. Which is the best set up from the list below?
11.) Which of the following network designs is considered the most secure?
12.) Which of the following steps is not required to configure IIS to handle encrypted sessions?
13.) True or False: You don't need a digital certificate installed on your Web server to be able to securely manage it
remotely using Windows Terminal Services.
14.) True or False: You can use the Microsoft Event Viewer snap-in to view your Windows and IIS log files.
15.) Which of the following is the best definition of risk analysis when discussing IT security?
16.) Which is the correct set of network components that need to be available for the Internet-facing network card of a
dual-homed IIS Web server running on Windows 2000?
17.) Which is the correct definition of the Windows user right assignment "Log on locally"?
18.) What are the correct ACLs for IIS-generated log files?
19.) Which one of the following components does not need to be installed to run IIS on a Windows server?
20.) The Security Accounts Manager database stores usernames, account privileges and security context information for every
user allowed to log on to a Windows machine locally. Which copy of the SAM database should you delete on a Windows Web server?
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||