Question

A security administrator has uncovered a covert channel used to exfiltrate confidential data from an internal...

A security administrator has uncovered a covert channel used to exfiltrate confidential data from an internal database server through a compromised corporate web server. Ongoing exfiltration is accomplished by embedding a small amount of data extracted from the database into the metadata of images served by the web server. File timestamps suggest that the server was initially compromised six months ago using a common server misconfiguration.

Which of the following BEST describes the type of threat being used?

(choose one and why)

A. APT
B. Zero-day attack
C. Man-in-the-middle attack

D. XSS

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Solution

Explanation

APT means Advanced Persistent Threat

It is a prolonged and targeted security attack

Intruders or hackers access a network and remains undetected for an extended period of ime

the main goal of APT attack is monitor network activity and steal data rather than cause damage to network or company

from the question we can clearly understand it is an APT attack

because data was extracted from the server

server was compromised six months ago so it remains undetected for certain period of time

--

all the best

Add a comment
Know the answer?
Add Answer to:
A security administrator has uncovered a covert channel used to exfiltrate confidential data from an internal...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT