EC-Council
412-79V10 · Question #294
Large organizations would agree that their most valuable IT assets reside within applications and databases. Most would probably also agree that these are areas that have the weakest levels of…
The correct answer is B. Insecure cryptographic storage attack. See the full explanation below for the reasoning.
Question
Large organizations would agree that their most valuable IT assets reside within applications and databases. Most would probably also agree that these are areas that have the weakest levels of security, thus making them the prime target for malicious activity from system administrators, DBAs, contractors, consultants, partners, and customers.
Which of the following flaws refers to an application using poorly written encryption code to securely encrypt and store sensitive data in the database and allows attackers to read or modify weakly protected data such as credit card numbers, SSNs, and other authentication credentials?
Options
- ASSI injection attack
- BInsecure cryptographic storage attack
- CDenial of service injection attack
- DMan-in-the-Middle attack
How the community answered
(17 responses)- A6% (1)
- B71% (12)
- C6% (1)
- D18% (3)
Community Discussion
No community discussion yet for this question.