← Indietro
EsameEsame completoTesto d’esame

27 06 14

Esame completo di Computer Security per il corso di Computer Engineering presso Politecnico di Milano. Materiale proveniente dall’archivio storico Studwiz e classificato per la consultazione online.

Computer SecurityEsame completo

Informazioni sul documento

Cosa trovi in questo materiale

Esame completo di Computer Security per il corso di Computer Engineering presso Politecnico di Milano. Materiale proveniente dall’archivio storico Studwiz e classificato per la consultazione online.

Qualità dell’importazione: il testo è stato estratto direttamente dal documento originale.

Contenuti estratti dal documento

Passaggi rappresentativi riconosciuti nelle diverse parti del materiale. Il testo completo resta presente nella pagina per la ricerca, mentre l’anteprima compatta rende più semplice la lettura.

Pagina 1

Computer Security 2013/2014 - Proff. Maggi & Zanero Premise In addition to the questions presented in this document, in this year exam there will be 2 types of exercises taken from previous years' exams: ● memory errors (e.g., buffer overflows) ● scenarios (e.g., description of a network layout and implementation of firewall rules), yet a bit more "guided" ● web application vulnerabilities (e.g., SQL injections, XSSs) The points assigned to each question depend on how many questions there will be at the exam. Focus on giving a concise yet complete answer in the space provided. Long answers will not be accepted because most of the time they are harder and more ambiguous to understand. Example Questions (answers given separately) Question 1 (2–4 pts) You are attending a hacking conference and you notice that a software vendor offers 10.000 Euro to whoever reports a previously unknown vulnerability to them, and an additional 20.000 Euro to whoever reports a working exploit for that vulnerability. Please tell us how you would respond (True or False). Note that you have to answer with an explanation to get any points: A. the company is basically asking to report zero­day vulnerabilities. True (by definition, a zero­day vulnerability is that the vulnerability is unknown until its disclosure). B. the existence of an undisclosed vulnerability implies a high level of risk for that vendor. False (the risk depends on other factors than the existence of a vulnerability). True (the vulnerability could be known to someone, who may have a zero­day exploit). Both true and false answers are accepted, if reasons are correctly explained. Question 2 (2-4 pts) Say if the following statements are True or False. Note that you have to answer with an explanation to get any points. Example You…

Anteprima

Prima pagina del documento.

Prima pagina: 27 06 14