A company is concerned about man-in-the-middle attacks against its web applicati
ID: 3751486 • Letter: A
Question
A company is concerned about man-in-the-middle attacks against its web application The company's web server is using TLS encryption, the session cookies are using long, high-entropy values and are sent after successful authentication Which of the following additional recommendations should the cybersecurity analyst make to prevent this type of attack? (Select TWO) Disable the use of TLSv1.2 Allow connections only from trusted IP addresses Use certificate pinning on the web server Use HTTP strict transport security Allow only high-security ciphering suites in the web server DEExplanation / Answer
The first and for most important thing to ensure avoidance of man in the middle attack is the use of certificate. As using this method we can actually verify the authenticity of the other party. And apart for this, it would be same measure to only allow connections from trusted IP addresses.
So, option B and C should be selected.
Related Questions
Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.