During a routine security review of an automated corporate accounting system, an auditor discovers that financial data transmitted between remote branch operations and the central ledger server was intercepted and modified in transit by an unauthorized entity. Which security threat was experienced in this scenario, and what primary control measure directly protects accounting data against such transit-level compromise?
- AA phishing attack, which is primarily mitigated by conducting periodic staff awareness training on email verification.
- BA ransomware infection, which is primarily mitigated by maintaining daily off-site database backups.
- A man-in-the-middle data interception attack, which is primarily mitigated by enforcing strong cryptographic network encryption protocols.Answer
- DA logic bomb vulnerability, which is primarily mitigated by implementing routine hard drive defragmentation schedules.
Answer
The threat experienced is a man-in-the-middle data interception attack, and the primary preventive control measure is enforcing strong cryptographic network encryption protocols.
Intercepting and altering active accounting data transmissions between remote branch terminals and central servers describes a man-in-the-middle network attack. Implementing cryptographic network encryption protocols protects data confidentiality and integrity by ensuring intercepted packets cannot be read or altered by unauthorized entities.
Step-by-Step Solution
Key Concept
Data Security Threats and Network Controls in Computerized Accounting Systems