nerdexam
EC-Council

412-79V8 · Question #93

Today, most organizations would agree that their most valuable IT assets reside within applications and databases. Most would probably also agree that these are areas that have the weakest levels of…

The correct answer is B. Insecure cryptographic storage attack. See the full explanation below for the reasoning.

Question

Today, most organizations would agree that their most valuable IT assets reside within applications and databases. Most would probably also agree that these are areas that have the weakest levels of security, thus making them the prime target for malicious activity from system administrators, DBAs, contractors, consultants, partners, and customers. Which of the following flaws refers to an application using poorly written encryption code to securely encrypt and store sensitive data in the database and allows an attacker to steal or modify weakly protected data such as credit card numbers, SSNs, and other authentication credentials?

Exhibit

412-79V8 question #93 exhibit

Options

  • ASSI injection attack
  • BInsecure cryptographic storage attack
  • CHidden field manipulation attack
  • DMan-in-the-Middle attack

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    84% (31)
  • C
    8% (3)
  • D
    5% (2)

Community Discussion

No community discussion yet for this question.

Full 412-79V8 Practice