QuestionQ546

Managing Application Security

Which of the following actions should not be taken to help prevent buffer-overflow attacks against an IIS Web server?

  • A Implement the IPP printing capability.
  • B Conduct frequent scans for server vulnerabilities.
  • C Install the upgrades of Microsoft service packs.
  • D Implement effective firewalls.
Explanation

Internet Printing Protocol (IPP) functionality adds an IIS service that can itself be vulnerable. Microsoft’s guidance for an IIS IPP vulnerability identifies servers with IPP enabled as primarily at risk and recommends disabling the IPP service as a workaround. Keeping systems updated, scanning for vulnerabilities, and using firewalls reduce exposure to buffer-overflow exploits.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!