SlideShare a Scribd company logo
1 of 2
Chapter 9
1- How does the source of your software code affect the overall
security of the system? Justify your position for a general
system.
2- Why is it beneficial to develop a software system in a
language that is well known to the development team? What are
the risks of using a language that is unknown or less common to
them?
3- What protections can you place within an organization on
code that is developed externally? Give examples to support
your recommendation.
4- How can modular code developed within an organization be
helpful or harmful to the security of the system? Justify your
position.
5- Why is it important to limit the attack surface of the system?
Give examples to support your argument.
Chapter 10
1- Why is it important to probe and attack a system both at rest
and in action? Give examples of information that is provided by
each that the other could not provide.
2- Why is it important to simulate the deployment environment
as closely as possible when performing a penetration test? What
could happen if the conditions vary significantly from the live
environment?
3- What advantages do actual attackers have over-penetration
testers in attempting to compromise a system? Justify your
conclusions.
4- What are the important considerations in choosing a Red
Team (or attack team) for your software system? Give examples
to justify your position.
5- What are the risks of using a Red Team that is not qualified?
How could this negatively affect system deployment in the live
environment?

More Related Content

Similar to Chapter 91- How does the source of your software code affect.docx

Software Security Engineering (Learnings from the past to fix the future) - B...
Software Security Engineering (Learnings from the past to fix the future) - B...Software Security Engineering (Learnings from the past to fix the future) - B...
Software Security Engineering (Learnings from the past to fix the future) - B...DebasisMohanty43
 
The Art of Penetration Testing in Cybersecurity.
The Art of Penetration Testing in Cybersecurity.The Art of Penetration Testing in Cybersecurity.
The Art of Penetration Testing in Cybersecurity.Expeed Software
 
WIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMSWIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMScscpconf
 
Appsec2013 assurance tagging-robert martin
Appsec2013 assurance tagging-robert martinAppsec2013 assurance tagging-robert martin
Appsec2013 assurance tagging-robert martindrewz lin
 
What is Remote Buffer Overflow Attack.pdf
What is Remote Buffer Overflow Attack.pdfWhat is Remote Buffer Overflow Attack.pdf
What is Remote Buffer Overflow Attack.pdfuzair
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing ProfessionalsTechWell
 
Sec 572 Education Specialist-snaptutorial.com
Sec 572 Education Specialist-snaptutorial.comSec 572 Education Specialist-snaptutorial.com
Sec 572 Education Specialist-snaptutorial.comrobertlesew79
 
Barcamp: Open Source and Security
Barcamp: Open Source and SecurityBarcamp: Open Source and Security
Barcamp: Open Source and SecurityJoshua L. Davis
 
Sec 572 Education Organization / snaptutorial.com
Sec 572  Education Organization / snaptutorial.comSec 572  Education Organization / snaptutorial.com
Sec 572 Education Organization / snaptutorial.comBaileya109
 
Software development group 3 questions .pptx
Software development group 3 questions .pptxSoftware development group 3 questions .pptx
Software development group 3 questions .pptxHarris430768
 
Security operations center 5 security controls
 Security operations center 5 security controls Security operations center 5 security controls
Security operations center 5 security controlsAlienVault
 
Sec 572 Enhance teaching / snaptutorial.com
Sec 572  Enhance teaching / snaptutorial.comSec 572  Enhance teaching / snaptutorial.com
Sec 572 Enhance teaching / snaptutorial.comHarrisGeorg69
 
Chapter 5Overview of SecurityTechnologiesWe can’t h
Chapter 5Overview of SecurityTechnologiesWe can’t hChapter 5Overview of SecurityTechnologiesWe can’t h
Chapter 5Overview of SecurityTechnologiesWe can’t hWilheminaRossi174
 
Vulnerability Analyst interview Questions.pdf
Vulnerability Analyst interview Questions.pdfVulnerability Analyst interview Questions.pdf
Vulnerability Analyst interview Questions.pdfinfosec train
 
How to Build and Validate Ransomware Attack Detections (Secure360)
How to Build and Validate Ransomware Attack Detections (Secure360)How to Build and Validate Ransomware Attack Detections (Secure360)
How to Build and Validate Ransomware Attack Detections (Secure360)Scott Sutherland
 
Project Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docxProject Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docxwkyra78
 
SEC 572 Inspiring Innovation / tutorialrank.com
SEC 572 Inspiring Innovation / tutorialrank.comSEC 572 Inspiring Innovation / tutorialrank.com
SEC 572 Inspiring Innovation / tutorialrank.comBromleyz38
 

Similar to Chapter 91- How does the source of your software code affect.docx (20)

Software Security Engineering (Learnings from the past to fix the future) - B...
Software Security Engineering (Learnings from the past to fix the future) - B...Software Security Engineering (Learnings from the past to fix the future) - B...
Software Security Engineering (Learnings from the past to fix the future) - B...
 
The Art of Penetration Testing in Cybersecurity.
The Art of Penetration Testing in Cybersecurity.The Art of Penetration Testing in Cybersecurity.
The Art of Penetration Testing in Cybersecurity.
 
WIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMSWIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMS
 
Appsec2013 assurance tagging-robert martin
Appsec2013 assurance tagging-robert martinAppsec2013 assurance tagging-robert martin
Appsec2013 assurance tagging-robert martin
 
Open port vulnerability
Open port vulnerabilityOpen port vulnerability
Open port vulnerability
 
What is Remote Buffer Overflow Attack.pdf
What is Remote Buffer Overflow Attack.pdfWhat is Remote Buffer Overflow Attack.pdf
What is Remote Buffer Overflow Attack.pdf
 
Security Testing for Testing Professionals
Security Testing for Testing ProfessionalsSecurity Testing for Testing Professionals
Security Testing for Testing Professionals
 
Sec 572 Education Specialist-snaptutorial.com
Sec 572 Education Specialist-snaptutorial.comSec 572 Education Specialist-snaptutorial.com
Sec 572 Education Specialist-snaptutorial.com
 
Metaploit
MetaploitMetaploit
Metaploit
 
Barcamp: Open Source and Security
Barcamp: Open Source and SecurityBarcamp: Open Source and Security
Barcamp: Open Source and Security
 
Sec 572 Education Organization / snaptutorial.com
Sec 572  Education Organization / snaptutorial.comSec 572  Education Organization / snaptutorial.com
Sec 572 Education Organization / snaptutorial.com
 
Software development group 3 questions .pptx
Software development group 3 questions .pptxSoftware development group 3 questions .pptx
Software development group 3 questions .pptx
 
Security operations center 5 security controls
 Security operations center 5 security controls Security operations center 5 security controls
Security operations center 5 security controls
 
Sec 572 Enhance teaching / snaptutorial.com
Sec 572  Enhance teaching / snaptutorial.comSec 572  Enhance teaching / snaptutorial.com
Sec 572 Enhance teaching / snaptutorial.com
 
Chapter 5Overview of SecurityTechnologiesWe can’t h
Chapter 5Overview of SecurityTechnologiesWe can’t hChapter 5Overview of SecurityTechnologiesWe can’t h
Chapter 5Overview of SecurityTechnologiesWe can’t h
 
Vulnerability Analyst interview Questions.pdf
Vulnerability Analyst interview Questions.pdfVulnerability Analyst interview Questions.pdf
Vulnerability Analyst interview Questions.pdf
 
SentinelOne Buyers Guide
SentinelOne Buyers GuideSentinelOne Buyers Guide
SentinelOne Buyers Guide
 
How to Build and Validate Ransomware Attack Detections (Secure360)
How to Build and Validate Ransomware Attack Detections (Secure360)How to Build and Validate Ransomware Attack Detections (Secure360)
How to Build and Validate Ransomware Attack Detections (Secure360)
 
Project Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docxProject Quality-SIPOCSelect a process of your choice and creat.docx
Project Quality-SIPOCSelect a process of your choice and creat.docx
 
SEC 572 Inspiring Innovation / tutorialrank.com
SEC 572 Inspiring Innovation / tutorialrank.comSEC 572 Inspiring Innovation / tutorialrank.com
SEC 572 Inspiring Innovation / tutorialrank.com
 

More from tiffanyd4

CHAPTER 3Understanding Regulations, Accreditation Criteria, and .docx
CHAPTER 3Understanding Regulations, Accreditation Criteria, and .docxCHAPTER 3Understanding Regulations, Accreditation Criteria, and .docx
CHAPTER 3Understanding Regulations, Accreditation Criteria, and .docxtiffanyd4
 
Chapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docx
Chapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docxChapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docx
Chapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docxtiffanyd4
 
CHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docx
CHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docxCHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docx
CHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docxtiffanyd4
 
Chapter 4Legal Construction of the Employment Environment©vi.docx
Chapter 4Legal Construction of the Employment Environment©vi.docxChapter 4Legal Construction of the Employment Environment©vi.docx
Chapter 4Legal Construction of the Employment Environment©vi.docxtiffanyd4
 
Chapter 2 The Law of EducationIntroductionThis chapter describ.docx
Chapter 2 The Law of EducationIntroductionThis chapter describ.docxChapter 2 The Law of EducationIntroductionThis chapter describ.docx
Chapter 2 The Law of EducationIntroductionThis chapter describ.docxtiffanyd4
 
CHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docx
CHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docxCHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docx
CHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docxtiffanyd4
 
CHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docx
CHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docxCHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docx
CHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docxtiffanyd4
 
CHAPTER 20 Employment Law and Worker ProtectionWashington DC.docx
CHAPTER 20 Employment Law and Worker ProtectionWashington DC.docxCHAPTER 20 Employment Law and Worker ProtectionWashington DC.docx
CHAPTER 20 Employment Law and Worker ProtectionWashington DC.docxtiffanyd4
 
Chapter 1 Global Issues Challenges of GlobalizationA GROWING .docx
Chapter 1 Global Issues Challenges of GlobalizationA GROWING .docxChapter 1 Global Issues Challenges of GlobalizationA GROWING .docx
Chapter 1 Global Issues Challenges of GlobalizationA GROWING .docxtiffanyd4
 
CHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docx
CHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docxCHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docx
CHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docxtiffanyd4
 
Chapter 18 When looking further into the EU’s Energy Security and.docx
Chapter 18 When looking further into the EU’s Energy Security and.docxChapter 18 When looking further into the EU’s Energy Security and.docx
Chapter 18 When looking further into the EU’s Energy Security and.docxtiffanyd4
 
CHAPTER 17 Investor Protection and E-Securities TransactionsNe.docx
CHAPTER 17 Investor Protection and E-Securities TransactionsNe.docxCHAPTER 17 Investor Protection and E-Securities TransactionsNe.docx
CHAPTER 17 Investor Protection and E-Securities TransactionsNe.docxtiffanyd4
 
Chapter 13 Law, Ethics, and Educational Leadership Making the Con.docx
Chapter 13 Law, Ethics, and Educational Leadership Making the Con.docxChapter 13 Law, Ethics, and Educational Leadership Making the Con.docx
Chapter 13 Law, Ethics, and Educational Leadership Making the Con.docxtiffanyd4
 
Chapter 12 presented strategic planning and performance with Int.docx
Chapter 12 presented strategic planning and performance with Int.docxChapter 12 presented strategic planning and performance with Int.docx
Chapter 12 presented strategic planning and performance with Int.docxtiffanyd4
 
ChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docx
ChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docxChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docx
ChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docxtiffanyd4
 
CHAPTER 12Working with Families and CommunitiesNAEYC Administr.docx
CHAPTER 12Working with Families and CommunitiesNAEYC Administr.docxCHAPTER 12Working with Families and CommunitiesNAEYC Administr.docx
CHAPTER 12Working with Families and CommunitiesNAEYC Administr.docxtiffanyd4
 
Chapter 10. Political Socialization The Making of a CitizenLear.docx
Chapter 10. Political Socialization The Making of a CitizenLear.docxChapter 10. Political Socialization The Making of a CitizenLear.docx
Chapter 10. Political Socialization The Making of a CitizenLear.docxtiffanyd4
 
Chapters one and twoAnswer the questions in complete paragraphs .docx
Chapters one and twoAnswer the questions in complete paragraphs .docxChapters one and twoAnswer the questions in complete paragraphs .docx
Chapters one and twoAnswer the questions in complete paragraphs .docxtiffanyd4
 
ChapterTool KitChapter 1212912Corporate Valuation and Financial .docx
ChapterTool KitChapter 1212912Corporate Valuation and Financial .docxChapterTool KitChapter 1212912Corporate Valuation and Financial .docx
ChapterTool KitChapter 1212912Corporate Valuation and Financial .docxtiffanyd4
 
Chapters 4-6 Preparing Written MessagesPrepari.docx
Chapters 4-6  Preparing Written MessagesPrepari.docxChapters 4-6  Preparing Written MessagesPrepari.docx
Chapters 4-6 Preparing Written MessagesPrepari.docxtiffanyd4
 

More from tiffanyd4 (20)

CHAPTER 3Understanding Regulations, Accreditation Criteria, and .docx
CHAPTER 3Understanding Regulations, Accreditation Criteria, and .docxCHAPTER 3Understanding Regulations, Accreditation Criteria, and .docx
CHAPTER 3Understanding Regulations, Accreditation Criteria, and .docx
 
Chapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docx
Chapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docxChapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docx
Chapter 3 Human RightsINTERNATIONAL HUMAN RIGHTS–BASED ORGANIZ.docx
 
CHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docx
CHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docxCHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docx
CHAPTER 13Contributing to the ProfessionNAEYC Administrator Co.docx
 
Chapter 4Legal Construction of the Employment Environment©vi.docx
Chapter 4Legal Construction of the Employment Environment©vi.docxChapter 4Legal Construction of the Employment Environment©vi.docx
Chapter 4Legal Construction of the Employment Environment©vi.docx
 
Chapter 2 The Law of EducationIntroductionThis chapter describ.docx
Chapter 2 The Law of EducationIntroductionThis chapter describ.docxChapter 2 The Law of EducationIntroductionThis chapter describ.docx
Chapter 2 The Law of EducationIntroductionThis chapter describ.docx
 
CHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docx
CHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docxCHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docx
CHAPTER 1 Legal Heritage and the Digital AgeStatue of Liberty,.docx
 
CHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docx
CHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docxCHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docx
CHAPTER 1 BASIC CONCEPTS AND DEFINITIONS OF HUMAN SERVICESPAUL F.docx
 
CHAPTER 20 Employment Law and Worker ProtectionWashington DC.docx
CHAPTER 20 Employment Law and Worker ProtectionWashington DC.docxCHAPTER 20 Employment Law and Worker ProtectionWashington DC.docx
CHAPTER 20 Employment Law and Worker ProtectionWashington DC.docx
 
Chapter 1 Global Issues Challenges of GlobalizationA GROWING .docx
Chapter 1 Global Issues Challenges of GlobalizationA GROWING .docxChapter 1 Global Issues Challenges of GlobalizationA GROWING .docx
Chapter 1 Global Issues Challenges of GlobalizationA GROWING .docx
 
CHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docx
CHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docxCHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docx
CHAPTER 23 Consumer ProtectionRestaurantFederal and state go.docx
 
Chapter 18 When looking further into the EU’s Energy Security and.docx
Chapter 18 When looking further into the EU’s Energy Security and.docxChapter 18 When looking further into the EU’s Energy Security and.docx
Chapter 18 When looking further into the EU’s Energy Security and.docx
 
CHAPTER 17 Investor Protection and E-Securities TransactionsNe.docx
CHAPTER 17 Investor Protection and E-Securities TransactionsNe.docxCHAPTER 17 Investor Protection and E-Securities TransactionsNe.docx
CHAPTER 17 Investor Protection and E-Securities TransactionsNe.docx
 
Chapter 13 Law, Ethics, and Educational Leadership Making the Con.docx
Chapter 13 Law, Ethics, and Educational Leadership Making the Con.docxChapter 13 Law, Ethics, and Educational Leadership Making the Con.docx
Chapter 13 Law, Ethics, and Educational Leadership Making the Con.docx
 
Chapter 12 presented strategic planning and performance with Int.docx
Chapter 12 presented strategic planning and performance with Int.docxChapter 12 presented strategic planning and performance with Int.docx
Chapter 12 presented strategic planning and performance with Int.docx
 
ChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docx
ChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docxChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docx
ChapterTool KitChapter 7102715Corporate Valuation and Stock Valu.docx
 
CHAPTER 12Working with Families and CommunitiesNAEYC Administr.docx
CHAPTER 12Working with Families and CommunitiesNAEYC Administr.docxCHAPTER 12Working with Families and CommunitiesNAEYC Administr.docx
CHAPTER 12Working with Families and CommunitiesNAEYC Administr.docx
 
Chapter 10. Political Socialization The Making of a CitizenLear.docx
Chapter 10. Political Socialization The Making of a CitizenLear.docxChapter 10. Political Socialization The Making of a CitizenLear.docx
Chapter 10. Political Socialization The Making of a CitizenLear.docx
 
Chapters one and twoAnswer the questions in complete paragraphs .docx
Chapters one and twoAnswer the questions in complete paragraphs .docxChapters one and twoAnswer the questions in complete paragraphs .docx
Chapters one and twoAnswer the questions in complete paragraphs .docx
 
ChapterTool KitChapter 1212912Corporate Valuation and Financial .docx
ChapterTool KitChapter 1212912Corporate Valuation and Financial .docxChapterTool KitChapter 1212912Corporate Valuation and Financial .docx
ChapterTool KitChapter 1212912Corporate Valuation and Financial .docx
 
Chapters 4-6 Preparing Written MessagesPrepari.docx
Chapters 4-6  Preparing Written MessagesPrepari.docxChapters 4-6  Preparing Written MessagesPrepari.docx
Chapters 4-6 Preparing Written MessagesPrepari.docx
 

Recently uploaded

_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting DataJhengPantaleon
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Arihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfArihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfchloefrazer622
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsKarinaGenton
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentInMediaRes1
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxheathfieldcps1
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...Marc Dusseiller Dusjagr
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesFatimaKhan178732
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAssociation for Project Management
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxpboyjonauth
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application ) Sakshi Ghasle
 

Recently uploaded (20)

_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data_Math 4-Q4 Week 5.pptx Steps in Collecting Data
_Math 4-Q4 Week 5.pptx Steps in Collecting Data
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Arihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfArihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdf
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its Characteristics
 
Alper Gobel In Media Res Media Component
Alper Gobel In Media Res Media ComponentAlper Gobel In Media Res Media Component
Alper Gobel In Media Res Media Component
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
Staff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSDStaff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSD
 
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
 
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
“Oh GOSH! Reflecting on Hackteria's Collaborative Practices in a Global Do-It...
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and Actinides
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across Sectors
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptx
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application )
 

Chapter 91- How does the source of your software code affect.docx

  • 1. Chapter 9 1- How does the source of your software code affect the overall security of the system? Justify your position for a general system. 2- Why is it beneficial to develop a software system in a language that is well known to the development team? What are the risks of using a language that is unknown or less common to them? 3- What protections can you place within an organization on code that is developed externally? Give examples to support your recommendation. 4- How can modular code developed within an organization be helpful or harmful to the security of the system? Justify your position. 5- Why is it important to limit the attack surface of the system? Give examples to support your argument. Chapter 10 1- Why is it important to probe and attack a system both at rest and in action? Give examples of information that is provided by each that the other could not provide. 2- Why is it important to simulate the deployment environment as closely as possible when performing a penetration test? What could happen if the conditions vary significantly from the live environment?
  • 2. 3- What advantages do actual attackers have over-penetration testers in attempting to compromise a system? Justify your conclusions. 4- What are the important considerations in choosing a Red Team (or attack team) for your software system? Give examples to justify your position. 5- What are the risks of using a Red Team that is not qualified? How could this negatively affect system deployment in the live environment?