Ask Computer Network & Security Expert

Question 1:

In an SSL/TLS certificate, explain the trust chain and the difference between a Root certificate authority (CA) and an Intermediate CA? Why would end-user certificates be issued by the Intermediate CA and not the Root CA?

Question 2:

Assume you are looking for a new bank to join to do your online banking. In addition to the normal characteristics of banks that interest the average consumer such as the interest rates and customer service; you hold online security in high regard and you want to evaluate the safety of the entity to ensure your online transactions will be secure.

Answer the following questions:

A. Who is the "Issued by:" of the Root CA certificate?
B. Who is the "Issued to:" of the Intermediate CA certificate?
C. What is the expiration date of the end user certificate?
D. What is the Signature Algorithm of the Root CA? Is this considered a secure algorithm?

E. Repeat steps

Question 3:

Give a detailed explanation of the differences between a qualitative risk assessment and a quantitative risk assessment and give a brief example of each. What requirements or circumstances may lead you to choose one over the other?

Question 4:

Is a cryptographic hash function/digest considered encryption? Why or why not?

Question 5:

Fully describe, fully define, and fully explain three vulnerabilities from the latest Open Web Application Security Project (OWASP) Top Ten that has been covered in this course.

Question 6:

You are the Information Systems Security Officer (ISSO) for your organization and you see the following job posting on your company's website:

Web Application Developer

ISEC615 Inc. is a progressive software development company specializing in tracking solutions with a strong commitment to our customers. We are growing and adding new Developers to our Engineering Department. We are looking for dynamic, results oriented, enthusiastic individuals at all experience levels who thrive in a fast paced environment and enjoy staying up to date on technologies.
Application Stack:

•Apache 2.2

•Tomcat 6.x, 6.0.35, 6.0.36

•HTML

•CSS

•Javascript

•1+ year RDMS/SQL experience

•1+ year Unix/Linux environment experience

•2+ years web application development experience with any of the following languages:

?JavaScript, Perl, PHP, Python, Ruby

Your qualifications will stand out if you have:

• A strong knowledge of information security principles Ideal Attributes:

•Willingness to learn/expand Perl knowledge

•Willingness to participate in Agile methodologies

•Willingness to participate in on-call rotation for production support

•Self-motivated and confident with an ownership mentality

•Autonomous producer

Education: B.S. in Computer Science, Information Technology, or similar specialization.

From the perspective of an information security practitioner, answer the following question about the above job posting:

* Giving a detailed explanation; what is wrong with this job posting that may be of use to an attacker?

* Perform research and describe exactly where an attacker may find the information in the previous question based on this job posting. Provide links to what you have found that may be of use to an attacker pertaining to that specific job posting.

Question 7:

Your organization has a Web based information system and it is discovered that your information system vulnerable to several high risk Open Web Application Security Project (OWASP) Top Ten vulnerabilities.

- What reason, conditions or circumstances may exist that may cause you to accept (risk control strategy) all of the vulnerabilities and do nothing to protect your system?

- What reason, conditions or circumstances may exist that may cause you to terminate (risk control strategy) the information system as opposed to remedying the issues associated with the vulnerabilities?

Computer Network & Security, Computer Science

  • Category:- Computer Network & Security
  • Reference No.:- M91370649
  • Price:- $70

Priced at Now at $70, Verified Solution

Have any Question?


Related Questions in Computer Network & Security

Security challenges in emerging networksassignment

Security Challenges in Emerging Networks Assignment Description The purpose of this assignment is to develop skills to independently think of innovation. In this assignment students will first learn how to develop knowle ...

Security challenges in emerging networksassignment

Security Challenges in Emerging Networks Assignment Description The purpose of this assignment is to develop skills to independently think of innovation. In this assignment students will first learn how to develop knowle ...

Security challenges in emerging networksassignment

Security Challenges in Emerging Networks Assignment Description The purpose of this assignment is to develop skills to independently think of innovation. In this assignment students will first learn how to develop knowle ...

Security challenges in emerging networksassignment

Security Challenges in Emerging Networks Assignment Description The purpose of this assignment is to develop skills to independently think of innovation. In this assignment students will first learn how to develop knowle ...

Advanced network design assessment - human factors in

Advanced Network Design Assessment - Human factors in network analysis and design Purpose of the assessment - This assignment is designed to assess students' knowledge and skills related to the following learning outcome ...

Advanced network design assessment - human factors in

Advanced Network Design Assessment - Human factors in network analysis and design Purpose of the assessment - This assignment is designed to assess students' knowledge and skills related to the following learning outcome ...

Assignment descriptionproject scope a typical network

Assignment Description Project Scope: A typical network layout diagram of a firm is given below for illustrative purposes only. The service requirements are enclosed. Figure. Network layout of a firm Service requirements ...

Assignment descriptionproject scope a typical network

Assignment Description Project Scope: A typical network layout diagram of a firm is given below for illustrative purposes only. The service requirements are enclosed. Figure. Network layout of a firm Service requirements ...

After reading this weeks materials please respond to two 2

After reading this week's materials, please respond to TWO (2) of the following questions. AND PROVIDE CITATION IN APA 1. Describe the differences between bus, ring, star and mesh topologies. 2. Explain the TCP/IP Model ...

The abstract should not be more than 250 words describe

The abstract should not be more than 250 words. Describe your project, focusing on research questions and research method for next stage of the project. 1. Introduction [The introduction should describe what the project ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As