filmov
tv
Chapter 4 Secure Code - Alice and Bob Learn Application Security
Показать описание
Questions to be answered:
1. When should you use your own identity on the network (user account) versus a service account? Give two examples for each and explain your reasoning.
2. Explain possible reasons or situations why C and C++ are still widely used in our industry when RUST (a memory-safe language) exists. Try to think of two or more.
3. What is your favourite programming language and/or framework, and why?
4. Which programming language and/or framework do you think is the most secure? Why?
5. Why do we need to protect user sessions?
6. If an attacker where able to get a hold of someone else’s user session while they are logged in to their online banking, what could the attacker do?
7. If you were going to explain the difference between authentication and authorization to a non-technical co-worker, how would you explain it?
8. Should C-level executives have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privileges would you give them, if you gave them any?
9. Should network system administrators have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privileges would you give them, if you gave them any?
10. Should help desk employees have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privi- leges would you give them, if you gave them any?
11. Your boss tells you that turning on logging and monitoring will cost too much. How do you explain its value and importance from a security perspective? Write a paragraph to convince your boss. Remember to make sure you explain what the potential risk is to the business, in a way your boss can understand (who is a smart, but not overly technical, person). If you speak over your audience’s head, you will not pass this question, nor will you convince your boss.
#AppSec #devsecops #applicationsecurity #cloudsecurity
1. When should you use your own identity on the network (user account) versus a service account? Give two examples for each and explain your reasoning.
2. Explain possible reasons or situations why C and C++ are still widely used in our industry when RUST (a memory-safe language) exists. Try to think of two or more.
3. What is your favourite programming language and/or framework, and why?
4. Which programming language and/or framework do you think is the most secure? Why?
5. Why do we need to protect user sessions?
6. If an attacker where able to get a hold of someone else’s user session while they are logged in to their online banking, what could the attacker do?
7. If you were going to explain the difference between authentication and authorization to a non-technical co-worker, how would you explain it?
8. Should C-level executives have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privileges would you give them, if you gave them any?
9. Should network system administrators have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privileges would you give them, if you gave them any?
10. Should help desk employees have special privileges on your network and other computer systems? If so, why? If not, why not? What types of privi- leges would you give them, if you gave them any?
11. Your boss tells you that turning on logging and monitoring will cost too much. How do you explain its value and importance from a security perspective? Write a paragraph to convince your boss. Remember to make sure you explain what the potential risk is to the business, in a way your boss can understand (who is a smart, but not overly technical, person). If you speak over your audience’s head, you will not pass this question, nor will you convince your boss.
#AppSec #devsecops #applicationsecurity #cloudsecurity
Комментарии