An IS auditor reviewing digital rights management (DRM) applications should expect to find an extensive use for which of the following technologies?
An information security policy stating that ‘the display of passwords must be masked or suppressed’ addresses which of the following attack methods?