This Essay Is About Secruity Risk List Four Possible Security Risks That The Bank And The Clients Are Facing In The Present Network Setup. Explain Clearly Why These Security Risks Exist.

Question 1a. List four (4) possible security risks that the bank and the clients are facing in the present network setup. Explain clearly why these security risks exist.There are 4 possible security risks that the bank and the clients are facing in the present network setup.Firstly, there may be a possible security risk of interception occurs. Interception means that unauthorized party gain access to an asset. Because client send their transaction data which contains personal and sensitive data to the bank's Web server through the Internet. Without any security measures to protect the data, these data will easily been accessed by somebody.Secondly, there will be modification of data occurs in the present network setup. Modification means the unauthorized party gain access to an asset and tampers with the asset. In the present network setup, there is no security measure to ensure that unauthorized party cannot gain access to the data and tempers with the data. For example, unauthorized party may access to the transaction data and modify the content. Modification of data would occur between the communication of the client and the bank's web server and the bank's internal network.Thirdly, there may be a possibility of Denial of service occurs. A denial of service attack is used by an individual to destroy, shutdown, or degrade a computer or network resource. The goal of such attacks is to flood the communication ports and memory buffers of the targeted site to prevent the receipt of legitimate messages and the service of legitimate requests for connections. A denial of service attack might be used to bring down a server that a hacker wants to spoof. For example, a hacker may attempt to spoof the bank in order to obtain PINs or credit card numbers.Finally, there may be a potential risk of Masquerade occur. Masquerade means that n intruder pretends to be a legitimate user. Many other types of attack are built on masquerade as the first stage. Masquerade can use both technological and non-technological means. For example, somebody can learn the other's passwords by observing passing traffic on a LAN, called sniffing. Using a computer to exhaustively guess passwords until the correct one is found, called password cracking.b. List three (3) security measures that are needed to protect the bank's internal network. Explain clearly why these security measures are needed and in what ways they can give protection.Firstly, the bank should use router and firewall to protect the bank's internal network. Requests must filter through a router and firewall before they are permitted to reach the server. A router, a piece of hardware, works in conjunction with the firewall, a piece of software, to block and direct traffic coming to the server. The configuration begins by disallowing all traffic and then opens holes only when necessary to process acceptable data requests, such as retrieving web pages or sending customer requests to the bank. Firewall can limit the...

