7 Security Authentication And Authorization

NET Centric Computing · Unit 7

Security, Authentication and Authorization

Exam-focused notes for Security, Authentication and Authorization (NET Centric Computing, BIT351): what the TU syllabus asks and how it has actually been tested, with 5 solved past questions from this unit.

What this unit covers

  • Authentication purposes
  • Authorization roles and policies
  • Claims-based authorization
  • Securing controller and action methods
  • SQL injection attacks and prevention
  • Cross-site request forgery protection
  • Vulnerability detection and prevention
  • Form validation on client side

Vulnerability detection and prevention

20815 marks

How do you detect and prevent vulnerabilities in ASP.NET core application. [5]

Note: No specific reference notes were found for this topic. The following answer is based on standard ASP.NET Core security practices as taught in security/web development courses. --- - Detection: Code review for raw SQL queries; use static analysis tools...

Full solved answer →

Authentication purposes

20815 marks

What are the purposes of adding authentications to apps? Explain. [5]

Authentication is the process of verifying the identity of a user, device, or system before granting access to an application or its resources. It answers the fundamental question: "Who are you?" --- Authentication ensures that only legitimate and verified ...

Full solved answer →

Authorization roles and policies

20805 marks

Why do we need to define roles, policies and claims? Explain. [5]

Note: The reference notes did not contain specific content on this topic. The following answer is based on standard ASP.NET Core / web application security concepts as taught in BSc CSIT curriculum. --- In modern web applications, it is not enough to simply...

Full solved answer →

SQL injection attacks and prevention

2081.15 marks

Illustrate the concept of SQL injection with an example. [5]

SQL Injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It occurs when untrusted user input is directly embedded into an SQL query without proper validation or sanitizati...

Full solved answer →

Claims-based authorization

05 marks

Define authorities, role, claims and policies. Discuss about cross-site request forgery with a case.[5]

Note: No specific curriculum notes were found for this topic. The answer below is based on standard ASP.NET Core / web security concepts as typically taught in BSc CSIT. --- An authority is a trusted entity (server or service) that is responsible for issuin...

Full solved answer →