Security Scenarios
20 questions · Fundamental Engineering
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company P conducts training sessions for junior security analysts within its security team. As part of this training activity, the team reviews simulated authentication log data and discusses how different password attack techniques may manifest in real-world systems. The purpose of this exercise is to help analysts accurately identify attack patterns, understand attacker behavior, and evaluate the defensive controls that are effective against each type of attack.
During the exercise, the team focuses on three major password attack techniques, understanding that their visibility in authentication logs varies as summarized in Table 1.
Table 1 Major password attack techniques
As part of the training, the security team reviews multiple sample authentication logs recorded at an authentication server, as summarized in Tables 2 and 3. The participants analyze the authentication patterns observed in both tables and determine the correspondence of each pattern corresponds to the password attack techniques listed in Table 1.
Table 2 Sample authentication logs (Pattern A)
Table 3 Sample authentication logs (Pattern B)
Based on this analysis, they conclude that the pattern observed in Table 2 is categorized as A, and that observed in Table 3 is categorized as B, as summarized in Table 1.
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
A research laboratory at University Q plans to introduce a cloud-based database to centrally store and manage data for one of its research projects. This database will be used by professors, researchers, students, and administrative staff participating in the project. Table 1 summarizes the data types, descriptions, and the roles and permitted operations for each user group.
Table 1 Data Types and User Requirements (Excerpt)
The system administrator at University Q, who is responsible for introducing the database, reviewed the data types and user roles with the information security officer of the university. According to the information security policy of University Q, users must be granted only the permissions necessary for their roles to minimize potential damage in the event of account compromise. Based on this policy, the system administrator created user groups and configured access permissions for each content type. Table 2 lists the resulting access right assignments for the database.
Table 2 Access Right Assignments (Excerpt)
Note:
R: Read-only (viewing allowed)
RW: Read and Write (includes creating and modifying)
(-): Not allowed (no access)
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company R is an e-commerce company that sells smartphone accessories through its website. In response to the increasing prevalence of SQL injection attacks in recent years, Company R decided to conduct a security training program for its security analysts, focusing specifically on SQL injection vulnerabilities.
[Explanation of SQL Behavior]
As part of the training, an explanation was provided to help the security analysts understand the working mechanism of SQL statements. In typical web applications, authentication is performed by constructing an SQL statement based on a predefined template. The application inserts the user-provided username and the hashed value of the user-provided password into the template and submits the resulting SQL statement to the database to check whether a matching record exists. An example of such an SQL query template is shown in figure given below.
Figure SQL Query Template for Authentication
If user input is incorporated into an SQL statement without proper handling, the structure of the SQL query may be altered, enabling attacks such as SQL injection. For instance, SQL syntax elements included in the input may be interpreted by the database. One common element is “--”, which starts a comment; any text that follows “--” is ignored by the database engine, effectively disabling the remaining part of the SQL statement, including the password check.
[Hands-on Verification]
The security analysts participated in a hands-on lab using a dedicated training server. They submitted crafted input values through the application’s authentication form. The application processed these inputs, inserted the username and the hashed password value into the SQL template shown in the figure above, generated a complete SQL statement, and executed it against the database.
The database contained a preregistered admin user with a hashed password that was not disclosed to the participants. They tested several input values for <input_username> while leaving the password input field empty in the authentication form to determine whether authentication could be bypassed, and summarized the results in table given below.
Table Evaluation Results
Answer Group
From the answer group below, select the most appropriate answer to be inserted into blank in the description.
Company S had recently released a photo editing application named Application Y for mobile platforms.
As storage for users to upload the photos they wish to process, Application Y utilizes a cloud storage service. The cloud storage service exposes REST API endpoints that accept requests from REST client. Application Y makes direct REST API calls to the cloud storage service, and the access tokens required to invoke these APIs are embedded directly within the application logic. Figure 1 shows the portion of the Application Y architecture related to access to the cloud storage service. Other components are omitted for simplicity.
Figure 1 Application Y architecture related to access to the backend storage service
A security researcher discovered that the access token embedded in Application Y could be extracted from Application Y. The researcher was able to invoke the REST API directly and access the storage service using the extracted token.
The developer team of Company S proposed the following for architectures to prevent future exposure of storage access tokens.
Architecture One: Use a Secure Vault to manage access tokens.
In this architecture, access tokens are stored in a Secure Vault, which is a digital safe for protecting sensitive data such as API access tokens. When Application Y needs to access the storage service, it retrieves a temporary token from the Secure Vault and uses the token to make REST API calls directly to the cloud storage service over HTTPS.
Figure 2 Architecture One
Architecture Two: Use a VPN to secure communication.
In this architecture, Application Y establishes a VPN connection to the cloud environment. All REST API calls from Application Y to the cloud storage service are transmitted through the VPN. The client application continues to use an access token to invoke the REST APIs of the storage service.
Figure 3 Architecture Two
Architecture Three: Use an API Server.
In this architecture, an API server is introduced between Application Y and the cloud storage service. The API server securely stores the access tokens and performs REST API Calls. Application Y communicates only with the API server over HTTPS and does not possess access tokens for the cloud storage service. All authentication, authorization, and business logic are enforced on the API server, which performs REST API calls to the storage service on behalf of the client.
Figure 4 Architecture Three
Architecture Four: Use a proxy server.
In this architecture, a proxy server is deployed between Application Y and the cloud storage service. The proxy server stores the access credentials required to access the storage service. Application Y sends REST API requests to the proxy server over HTTPS, and the proxy server forwards these requests to the cloud storage service using the stored credentials. The proxy server does not perform application-specific authentication, authorization, or business logic enforcement, and simply relays REST API requests from the client to the storage service.
Figure 5 Architecture Four
By comparing them, the security team of Company S suggested the application development team redesign the application architecture to Architecture blank .
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company P is a small business that recently formed a data analytics team to perform business data analytics using internal business data. This data is stored on a database system configured with a synchronous (real-time) mirror. The database is backed up regularly. The database servers and IT infrastructure are maintained by a third-party IT support provider.
A junior data analyst was mistakenly granted database superuser privileges to the production database. This decision was made due to a lack of security understanding in the company. The data analyst, unfamiliar with the sensitivity of their access level, was tasked with executing a series of routine database queries and migrations. However, due to an error in a script, the data analyst accidentally ran a command that dropped critical tables, resulting in a significant loss of data. This caused the company’s internal applications to stop working.
The company engaged their IT support provider, and the database system was quickly put back in service by A. To prevent this incident from happening again, their IT support provider recommended that the company implement B.
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company Q is a mid-sized online retailer selling a wide range of daily necessities to a large number of general consumers. Customers are required to create an account and log in to the company’s e-commerce website to make purchases. The e-commerce website is constructed using an open-source content management system (CMS) with various plugins. It is hosted on the company’s on-premise web servers located in the Demilitarized Zone (DMZ). Customer data is stored in the database installed on the web server as well. Since the e-commerce site received orders from many customers, availability of the e-commerce website is critical, and the maximum tolerable downtime (MTD) is limited to one hour per week.
The server is protected by a packet filtering firewall that permits access only through ports 80 and 443. Mr. K is an administrator responsible for both the operations and security of the company’s e-commerce website. He maintains the configuration of the firewall and other security measures as well as patch management. For patching the company’s e-commerce website, compatibility testing is important to maintain website stability. It takes at least three days to complete compatibility testing for one component. Due to limited human resource, it is unrealistic to perform compatibility tests in parallel and finish them quickly. Therefore, the patch management rule is to apply patches for the web server’s OS and the core CMS components within a week of their release, while updates for other components including plugins are scheduled to be applied within six months. Patches for the web server’s OS and the core CMS components are released on a monthly basis, while updates for other components including plugins are released each month as well.
One day, Company Q’s e-commerce website was compromised and the database on the webserver was accessed by an unauthorized third party. The investigation revealed that this was caused by an unpatched vulnerability in a plugin enabled on the CMS. This plug-in was critical to the functioning of the e-commerce website. The latest version of the plugin, which includes a fix for this vulnerability, was released by the vendor three months ago. The exploitation of this vulnerability has been reported publicly since last month. Company Q was still conducting compatibility testing, and the update to the latest version was scheduled for a later time.
To prevent similar incidents from occurring, Mr. K is required to revise the patch management rules for Q’s e-commerce website. In consideration of the workload associated with compatibility testing, Mr. K proposed updating the patch management rule for the e-commerce website to A. Furthermore, as a protective measure to prevent the servers from exploitation during the interim period before patches are applied, Mr. K proposed B.
Answer group
From the answer group below, select the correct combination of answers to be inserted into A and B in the description.
Company R is a software company that sells video editing software for consumers. The company has branch offices in multiple countries, all managed by its head office. In Company R’s customer support department, customer satisfaction surveys are sent to selected customer who have received support. The survey results are aggregated at each branch, and must be sent to the customer survey analysis team at the head office every day. Ms. T at the customer survey analysis team at the head office is responsible for managing and securing the survey data. The considerations for collecting survey data from each branch office are as follows:
- •The employees responsible for sending the survey data at each branch office changes daily.
- •At the head office, Ms. T in the customer survey analysis team is responsible for receiving and analyzing the survey data from the branch offices. After receiving the survey data from the branch offices, she saves the data to a shared folder that only the customer survey analysis team can access.
- •The file size of survey data is large, so using inefficient encryption methods would take too much time and is therefore not suitable.
- •Since the survey data contains confidential information, it must be ensured that no one other than the sender and the intended recipients can view the contents during transmission between the head office and branch offices.
- •The key used to encrypt the files must be transmitted in a way that prevents it from being stolen by a man-in-the-middle attacker.
- •There are many branch offices and it is not practical to visit each office in person to distribute keys.
Ms. T decided to adopt a new method in which the branch offices upload the survey data, encrypted using file encryption, to a shared folder. She set up this shared folder with access permissions granted to both the head office and branch office staff, and instructed the branch office staff to upload the encrypted survey data to it. Taking into account the considerations related to collecting information from the branches, Ms. T decided to use A as the encryption method. In this method, the key used for encrypting the survey data is encrypted using the public key of B .
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company S is a software company that develops web applications. Some of web applications that Company S develops are open-sourced. The web application code is made publicly available in a repository accessible to anyone. These open-source web applications include features that interact with external services using API keys.
One day, an external security researcher reported to Company S’s security team that the code published in the company’s repository contained an API key. Company S immediately made the repository private and deactivated the API key. Upon further investigation, it was found that a developer on the web application development team accidentally hard-coded the API key when testing a new feature, and committed the code to the source code repository. As a result, this allowed unauthorized users to access external services using the API key.
To prevent a recurrence of such an incident, the security team has proposed adding a coding rule that instead of hard-coding the secrets including the API, use environment variables that allow the application code to be accessed dynamically. Additionally, the team suggested A to detect any secrets that might have been missed by this rule before committing code to a publicly accessible repository. Furthermore, to minimize damage in case any secrets still evade detection, he proposed B.
Answer group
From the answer group below, select the correct combination of answers to be inserted into A and B in the description.
Recently, an e-commerce company X was cyber-attacked by an attacker. Mr. Y, the security team leader at the company, is investigating the incident and considering future countermeasures. The following is the summary of the incident:
The first half of the attack: An attacker visited company X's website to collect valuable information and knew the name of a senior worker of the IT department who was only responsible for system administration. One day, a receptionist for Company X received a phone call from a man with a fantastic voice. He asked some personal questions about the senior IT guy, Mr. Z. The caller skillfully manipulated the receptionist into giving him personal information about the IT guy. The caller was the attacker who got helpful information for further attacks on the company's server.
The second half of the attack: After that, the attacker dug into social sites and other resources to get additional information about Mr. Z and the servers of Company X, and then he created a password file based on Mr. Z's information and a file with the company server's IP address list. Then, the attacker remotely attacked a server of the company using the password list and an IP address of the server.
Mr. Y implemented two measures as future countermeasures for a similar attack. The measure for the first half of the attack is A. The other for the second half is B.
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company Z wants to provide secure file transfer service especially for very large files for their customers. Mr. K, the system architect of the company, designed the sequence of uploading, storing, and downloading customer files on the web service. In this system, customers register their email addresses and their public keys during sign up. The associated private keys reside on the customers’ computers and the email address is used as the user id. The requirements for the file transfer service are as follows:
Figure 1 shows the sequence of uploading file by customer P for customer Q.
Figure 1 Sequence on file uploading
In this system, Mr.K uses KDF (Key Derivation Function) to improve the strength of the supplied password and uses A and B algorithms to accomplish above requirements. Note that the format of encryption algorithms used here is algorithm(data, key).
Answer group
From the answer group below, select the correct combination of answers to be inserted into A and B in the description.
Company V, a small-sized company specializing in manufacturing and selling home appliances, has recently expanded its team of website administrators to five. In addition, they have renovated their website to allow customers to download user manuals for their products. One day, an external security researcher highlighted that files containing a watermark with "For Internal Use" were publicly accessible in the public directory of the company’s website and available for download. Company V has a system that ensures all documents stored in the internal folder have this watermark by default, and a rule exists stating that the watermark must be removed when files are published or shared external. The website administrator immediately confirmed the issue and removed the document from the public directory. Then, the website administrator reported this issue to Company V's security team. The investigation of the security team revealed that the issue was caused by a website administrator accidentally uploading internal documents instead of the intended public catalog files. Those publicly accessible files were a draft version of the catalogs, and they did not contain credential information such as API keys for website management. When uploading files to the website's public directory, another website administrator, other than the uploader, was supposed to verify the correctness of the files. However, they failed to notice the mistake. To prevent similar issues in the future, the security team suggested implementing A to the website administrators. Additionally, to quickly detect issues, the security team suggested implementing B.
Answer group
From the answer group below, select the correct combination of answers to be inserted into A and B in the description.
Company A recently experienced a security incident where confidential data were exfiltrated by a compromised employee account. Ms. T, a security analyst at Company A, investigated the compromised employee account and found that the password used by the employee's account involved in this breach was a complex password that met the company's password policy. However, the same password was used across several web services. Additionally, Ms. T investigated the login logs of Company A’s system and discovered 1,000 failed login attempts recorded within 3 hours before a successful login was recorded. These failed login logs included attempts to log in with different account IDs and password sets. These login attempts occurred from a county where Company A does not have an office. Company A has no employees who travel abroad.
To prevent future account compromise by the same attack pattern, Ms. T suggested that the system administrators of Company V implement A. Additionally, to quickly detect any account compromise, she suggested implementing a monitoring system to alert administrators of B.
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company A is an e-commerce company specializing in sporting goods. One morning, employee X of the company's accounting department starts up his PC to begin his work. When he logged into his PC, he saw an unfamiliar screen with the following message:
The accounting department immediately requested the security team in company A to help resolve the situation. The security team analyzed all the PCs in the accounting department, including that of employee X, and noted the following:
The security team and the accounting department decided to take the following approaches and specific measures as a plan to strengthen the measures against future ransomware attacks.
Table 1. Approaches and Specific Measures (excerpts)
Answer group
From the answer group below, select the correct answer to be inserted into blank in the description.
Company B runs several web services. Mr. Y is a software engineer in the company. He was directed to develop a feature that prevents web service users from setting weak passwords. Mr. Y investigated and found that “Password Entropy” is the important factor for the password strength.
Password entropy measures the strength of a password based on the difficulty of cracking the password through guessing or a brute-force attack. The entropy of a password is typically based on the type of characters used—lowercase letters, uppercase letters, numerical digits, or special characters—and the length of the password or total number of characters.
Password entropy formula:
You can measure the entropy of a password in bits using the following formula:
E = ⌊L ×Log2 (R)⌋
In this formula:
The following totals show the breakdown for each character set as they appear on a typical American QWERTY keyboard:
Lowercase letters (a–z) = 26.
Uppercase letters (A–Z) = 26.
Numerical digits (0–9) = 10.
Special characters (!, @, #, $, %, ^, etc.) = 32.
The password vfssxfrb has a pool of 26 characters (lowercase letters);
Changing the password to JAAdMAdE would increase the pool to 52 characters (lowercase letters and uppercase letters);
Changing it further to u7aHqsbt would increase the pool to 62 characters (lowercase letters, uppercase letters along with numbers) and
Finally, Re*ct7$% has a pool of 26 + 26 + 10 + 32 = 94 characters (lowercase letters, uppercase letters, numbers, and special characters).
In our example:
- •For vfssxfrb, we have R = 26 and L = 8; thus,
E = ⌊8 × log2(26) ⌋ ≈ ⌊8 × 4.700⌋ ≈ ⌊37.60⌋ = 37 bits - •For JAAdMAdE, we have R = 52 and L = 8; thus,
E = ⌊8 × log2(52) ⌋ ≈ ⌊8 × 5.700⌋ ≈ ⌊45.60⌋ = 45 bits - •For u7aHqsbt, we have R = 62 and L = 8; thus,
E = ⌊8 × log2(62) ⌋ ≈ ⌊8 × 5.954⌋ ≈ ⌊47.63⌋ = 47 bits - •For Re*ct7$%, we have R = 94 and L = 8; thus,
E = ⌊8 × log2(94) ⌋ ≈ ⌊8 × 6.555⌋ ≈ ⌊52.44⌋ = 52 bits
Here, when the password is A6GmyVyOC (Using numerical digits, lowercase letters, and uppercase letters. L = 9), the password entropy is blank bits.
Answer group
From the answer group below, select the correct combination of answers to be inserted into A and B in the description.
Company X is an investment company. Recently, one of their database servers was attacked by an attacker.
Mr. L, the security team leader of company X, decided to ask Ms. A, a security analyst working for the same company, to analyze the logs. Mr. L will extract log entries related to database access from the log file of the attacked database server and send the extracted log entries to Ms. A.
When sending access log data from Mr. L to Ms. A, the following conditions were agreed upon in advance:
They each have an RSA key pair and have already exchanged their public keys with each other. They sign, verify, encrypt, and decrypt using those keys and a previously shared cryptographic processing software.
This time, the log entries must be A and then B.
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the description.
Company Y, a trading company, is developing an e-commerce web application for selling products to customers directly. The web server hosting the web application is installed on-premise and the web application is to be developed in-house. The communications to the web server are allowed only with HTTPS and the server certificate is already signed by the third party and installed on the web server. Company Y has an IT department comprising three teams—Developer, Security, and Tech Support—and the requirements for the web application are specified as follows (excerpt):
- •The web application is user-friendly and easy to navigate.
- •The web application is cost-effective to develop and maintain.
- •The web application can prevent malicious inputs into the system.
- •The web application is scalable and can handle a large number of customers.
- •The purchase orders and invoices are digitally signed to confirm integrity and authenticity.
During the initial project meeting, the members from each department discuss their respective tasks. The developer team requests the security team to derive specific tasks for the above requirements related to security. Ms. B, a member of the security team, suggests the following tasks:
- •Set up a A to provide the infrastructure.
- •Install a B in front of the web server.
Answer group
From the answer group below, select the correct combination of answers to be inserted into A and B in the description.
An information systems company S has a guideline related to any issue for workers doing their daily job. The company has an information security team responsible for related issues and updates workers’ knowledge on information security.
One morning, a company worker who had just started his daily job and successfully signed into the company’s enterprise system received the following email:
Soon, the worker realized that something wrong. He followed the guideline instead of clicking on the link in the email because he suspected this is a A attack, and it is typically conducted through B. He also informed the company’s information security team to deal with the issue.
A few days later, the worker received an email from the information security team leader. The email was to notify that the issue was resolved, thanking the worker for his responsibility in handling the case according to the guideline.
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A through C in Table 1.
Company X is a small trading company. The company is about to provide a new e-commerce web site for customers to make purchases online. The company will also hosts its own email service for the employees to conduct business with partners and customers. Company X will utilize public key infrastructure (PKI) to provide security for both the web server and email service. PKI uses public key cryptography to manage the identity of servers or persons and is widely used on the Internet.
Mr. T, the IT support person of company X is assigned to prepare the web server and email service in accordance with the following requirements:
- •The e-commerce web application will run on the web server that is certified by a third-party certification authority. All connections to the web server will be secured using HTTPS.
- •The staff directory along with the contact information will be published on the web site to enable business partners and customers to use the information to securely communicate with employees of company X.
The actions taken by Mr. T are shown in Table 1.
Table 1 Actions taken by Mr. T
Answer group
From the answer group below, select the most appropriate combination of answers to be inserted into A and B in the following description.
Company Y is an online retailer providing e-commerce web applications for customers to make purchases online and also allows customers to post product reviews. The web application was developed and maintained in-house. The properties of the e-commerce web application are shown in Figure 1.
Figure 1 Properties of the e-commerce web application
Due to recent incidents with multiple customers reporting that their accounts were compromised, the management tasked the IT team to investigate and address the issues. The IT team found that many customer accounts logins were unnoticed by the actual account owners, and some of the accounts were used to post fake reviews. The IT team also discovered unauthorized access to the database with illegal queries executed with no trace of administration login.
The IT team concluded that the incidents are most likely caused by using the same password on other leaked sites and A. They proposed to implement 2-factor authentication and B to mitigate respective issues in the future. The management then agreed to the plan, and the solutions was implemented accordingly.
Answer group
From the answer group below, select the correct combination of answers to be inserted into A through C in the description.
A zone is a group of interfaces that have similar functions or features. Zones establish the security borders of a network. A zone defines a boundary where traffic is subjected to policy restrictions when crossing into another region of a network. An inspection policy is applied to traffic moving between zones. Inter-zone policies offer considerable flexibility. Hence, different inspection policies can be applied to multiple host groups connected to the same router interface.
Company Z, intends to apply a zone-based policy firewall in their datacenter. Thus, they develop the network topology shown in Figure 1.
Figure 1 Network topology
These zones have the following characteristics:
- •The DMZ zone represents a zone where servers accessed from the Internet are located. Even if a server in the DMZ zone is breached, direct access to the internal PCs of the datacenter is prevented.
- •The PUBLIC zone represents the entire network outside the datacenter.
- •The PRIVATE zone represents the internal network. All datacenter PCs are located in this zone.
The security policy for the datacenter should be:
- •Hosts in the A zone cannot connect to hosts in the B zone.
- •Hosts in the A zone can only access the DNS service on all hosts in the C zone and HTTP/HTTPS service on limited hosts in the C zone to retrieve software updates.
- •Hosts in the B zone can connect to hosts in the A zone on all TCP, UDP and ICMP services.
- •Hosts in the B zone can reach the C zone but not vice versa.
- •Hosts in the C zone can reach HTTPS service on hosts in the A zone. This policy will restrict access to other services available on each server.
Answer group