CYS401 · Fundamentals of Cybersecurity

Quiz 1 (Semester 222)

Dr. Rabia Latif · 29 January 2023 · Sections 360, 362, 1398 · 5 marks

The first CYS401 quiz of semester 222: defence in depth, security measures, an availability calculation and attacker classification.

Q1 · Choose the best option

0.25 marks each · 1 mark total
Q1

What is a characteristic of a layered defence-in-depth security approach?

Q2

In cybersecurity, ICT stands for ______.

Q3

Which of the following is not a physical security measure to protect against physical hacking?

Q4

______ limits the execution of files or handling of data by specific installed programs.

Q2 · Availability calculation

1 mark
Q5

Horizon Solutions hired an ethical hacker, Ms. Park, to find vulnerabilities. She tests every week for 3 months starting June 2022. Each round needs 45 minutes for the system, 1 hour 20 minutes for the network, and 15 more minutes to recover the traces; the systems and network are disconnected for that whole time. Calculate the total availability as a percentage (1 decimal place).

%

Q3 · Defence-in-depth layers

1.75 marks · match each control to the layer it belongs to
Q6

Place each pair of security controls at the defence-in-depth layer it protects.

Encryption at rest and access control lists on the records themselves
Input validation and secure coding of the software being used
Operating-system patching and host-based antivirus
Internal segmentation and auditing of traffic between departments
Border firewalls and screening routers
Guards, locks and restricted server-room entry
Security awareness training and a written acceptable-use policy

Q4 · Type of cyber attacker

0.25 each · 1.25 marks
Q7

Write the appropriate type of cyber attacker for each scenario.

In the recent Ukraine war, hackers targeted Russian government websites and launched a DDoS attack to prevent user access. Most sites are down.
The Carbanak and Cobalt malware attacks hit 100 financial firms in over 40 countries, plundering over $11 million per heist and costing the banking sector more than a billion dollars.
These attackers lack knowledge and sophistication; their attacks often exploit well-known vulnerabilities, and keeping systems up to date defends against them.
The U.S. National Security Agency recorded nearly every cell phone conversation in the Bahamas without permission, along with similar programs in Kenya, the Philippines, Mexico and Afghanistan.
Attackers take advantage of vulnerabilities in plug-ins, web browsers and apps to install malware on your device without your knowledge.