Computer Networks & Security Flashcards
6 cards from real B.S.W.E. Bachelor of Software Engineering practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Computer Networks & Security flashcards as text
What is a SQL injection attack?
Answer: Inserting malicious SQL code into an input field to manipulate or exploit a database
SQL injection occurs when an attacker inserts malicious SQL statements into an input field that is directly incorporated into a database query, allowing unauthorized data access or manipulation.
What does HTTPS provide that HTTP does not?
Answer: Encrypted communication using TLS, ensuring confidentiality and integrity
HTTPS uses TLS (Transport Layer Security) to encrypt data in transit, preventing eavesdropping, tampering, and ensuring the authenticity of the server.
What is a firewall in network security?
Answer: A network security device or software that monitors and controls incoming and outgoing traffic based on defined rules
A firewall enforces a security policy by filtering network traffic based on rules, blocking unauthorized access while allowing legitimate communication.
Which attack involves overwhelming a server with traffic to make it unavailable to legitimate users?
Answer: Denial-of-Service (DoS) attack
A DoS (Denial-of-Service) attack floods a target server with excessive requests, exhausting its resources and making it unavailable to legitimate users.
What is Cross-Site Scripting (XSS)?
Answer: A vulnerability where an attacker injects malicious scripts into web pages viewed by other users
XSS allows attackers to inject malicious client-side scripts into web pages, which execute in victims' browsers to steal cookies, session tokens, or perform actions on the user's behalf.
What is the purpose of a VPN (Virtual Private Network)?
Answer: To create an encrypted tunnel over a public network, enabling secure private communication
A VPN creates an encrypted connection (tunnel) over the internet, allowing remote users to securely access a private network as if they were physically connected to it.