adplus-dvertising
frame-decoration

Question

What might an attacker aim to extract from a database using a timing-based attack if the database contains an unencrypted field named Password?

a.

Usernames

b.

Account numbers

c.

Passwords

d.

Encryption keys

Answer: (c).Passwords Explanation:In a timing-based attack, an attacker might aim to extract passwords from a database if it contains an unencrypted field named Password.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What might an attacker aim to extract from a database using a timing-based attack if the database contains an unencrypted field named Password?

Similar Questions

Discover Related MCQs

Q. What is the purpose of code injection attacks in general?

Q. Besides SQL injection, what is another example of a code injection attack?

Q. In what scenarios might code injection attacks occur?

Q. What danger is associated with application code reaching back to the operating system to execute commands?

Q. What command might an attacker supply in a command injection attack to delete a directory on a Linux system?

Q. How does the ampersand in the command 'mkdir /home/students/mchapple & rm -rf home' affect its execution?

Q. What protocol is susceptible to LDAP injection attacks, similar to SQL injection attacks on databases?

Q. What is the primary goal of LDAP injection attacks?

Q. What authentication technique is described as knowledge-based and commonly used but easily defeated?

Q. In password authentication, what happens if an attacker learns a user's password?

Q. What is a potential way for an attacker to learn a user's password through a social engineering attack?

Q. In addition to social engineering attacks, what other method might an attacker use to discover a user's password?

Q. What is a common characteristic of passwords as an authentication method?

Q. What risk is associated with default administrative accounts that remain unchanged on systems?

Q. What might penetration testers assume when encountering default passwords on applications and devices?

Q. What is a common starting point for penetration testers seeking access to a networked device?

Q. What is the primary goal of session hijacking attacks?

Q. How do most websites manage user sessions for authentication?

Q. What information does a cookie typically contain in the context of user authentication?

Q. How does a session hijacking attack typically exploit vulnerabilities?