CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
An attacker silently positions himself between a customer's device and a bank's server on an unsecured public Wi-Fi network, reading and possibly altering the data exchanged. Which attack is this, and which measure best counters it?
This is a man-in-the-middle attack, where the attacker intercepts and may alter communication between two parties. The best countermeasure is strong encryption such as TLS with certificate validation, so intercepted data cannot be read or modified undetected, especially on unsecured public Wi-Fi.
- AMan-in-the-middle attack; end-to-end encryption such as TLS with certificate validationCorrect
- BSmishing; blocking all SMS messages
- CZero-day exploit; installing a printer driver
- DDictionary attack; lengthening the screen saver timeout
Explanation
Intercepting communication between two parties without their knowledge is a man-in-the-middle attack. Encrypted channels such as TLS with proper certificate validation prevent the attacker from reading or tampering usefully. The other pairings mismatch the attack and the control.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- Which of the following best describes 'two-factor authentication' as a cyber security control?
- In the standard incident response lifecycle followed in cyber security practice, which phase comes immediately after 'Detection and Analysis…
- Rohit, an employee of a Pune firm, uses a colleague's login credentials without permission and downloads confidential client files from the …
- Meera receives an email that appears to come from her bank and asks her to enter her net-banking password on a look-alike website. She does …
- A Mumbai-based fintech company discovers that an attacker has gained unauthorised access to its customer database through a compromised serv…
- As part of cyber security governance, a listed company's board wants a single accountable executive to design the information security progr…