Light

Episode #943 Quiz

The Top 10 Cybersecurity Misconfigurations
Date: 2023-10-10 | Length: 2 hrs | Episode page at twit.tv

About this episode

NSA and CISA’s advisory lists ten common misconfigurations: default credentials, privilege separation failures, poor monitoring, no segmentation, weak patching, access-control bypasses, flawed MFA, permissive ACLs, poor credential hygiene, and unrestricted code execution. Recommended mitigations include hardening defaults, disabling unused services, automating patches, tightening admin accounts, and mandating phishing-resistant MFA.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the NSA/CISA advisory discussed in the episode, which misconfiguration is listed as number one on the Top 10 list?
Question 2: What did the NSA and CISA recommend software manufacturers do regarding multifactor authentication in the advisory?
Question 3: What mechanism did the episode say malicious actors can use when LLMNR and NetBIOS Name Service are enabled on a network?
Question 4: How did the episode describe the impact of Encrypted ClientHello on enterprise content filtering?
Question 5: What explanation did Steve give for why Matthew's 140-bit-entropy password would make PBKDF iteration count effectively irrelevant?
Cancel