CYS401 · Fundamentals of Cybersecurity

Final Exam 221 (Version A)

Dr. Suliman Mohamed Fati · 21 December 2022 · 3 hours · 40 marks

Version A of the 221 final: security pillars and attacks, cryptography, access-control models, and attack identification from scenarios.

Q1 Part 1 · Multiple choice

0.5 marks each
Q1

To achieve security we combine three key elements, the cybersecurity pillars. All of the following are pillars except ______.

Q2

______ is the attack that causes company assets to become unusable or unavailable on a temporary or permanent basis.

Q3

______ is social-engineering-based malware that asks the victim to pay in order to unlock or decrypt the system or the data.

Q4

In the governmental context, data should be classified rigidly into one of the following classes except ______.

Q5

The ______ is an advanced version of the Caesar cipher in which the alphabetic text is encrypted by matching the plaintext with ciphertext based on a provided keyword.

Q6

Triple DES applies three phases of encryption to the plaintext with different keys. Which order is correct for decryption?

Q7

To watch the World Cup final you subscribe to a sports channel, which gives you a licence to decrypt the scrambled channel. Which key does the decryption use?

Q8

Which is a generally accepted implementation of a role-based authentication model?

Q9

______ allows the systems admin to grant users the exact privileges they need to accomplish a task, with no additions.

Q10

______ is an access-control model that lets you reason about the access rights in a system and find whether a leakage of rights has occurred.

Q11

New access rights are assigned to an employee without the old permissions being reviewed and removed. This is called ______.

Q12

______ is the security measure whereby a process is allowed to read from and write to only certain memory locations and resources.

Q13

A separate authentication server validates the login once, and the user then reaches all services without re-entering credentials. This is:

Q14

Frequent emails from someone impersonating a bank, with a story about an account breach, trying to convince you specifically to disclose your credentials, is called ______.

Q1 Part 2 · Match the access-control concept

3 marks · an option may be used twice
Q15

Choose the concept that matches each description.

As the sole owner of a very small startup's website, with no assistance, you monitor user registrations and grant access based on what you think is good for your company.
You are the security admin in a ministry responsible for a classified resource, and you assign internal users based on their security clearance levels.
As an LMS admin you ensure that the 'edit' buttons for creating a quiz only appear according to the user's privilege.
In a supermarket, the cashier needs the supervisor's approval to cancel a bill and refund a customer, following a predefined refund policy.
A small business has 10 computers in a peer-to-peer network. All users are responsible for their own security and set file and folder privileges as they see fit.
Filtering traffic in a firewall to block blacklisted websites based on preconfigured rules.

Q2 · Short answers

15 marks
Q16

Explain how IPSec in tunnel mode provides confidentiality, integrity, authentication and non-repudiation. (3 marks)

Q17

Explain how the accuracy of biometric devices is measured using FAR, FRR and CER. (3 marks)

Q18

Sniffing can be carried out by duplicating MAC records through MAC poisoning. Give one way to detect sniffing on your network and one way to prevent MAC poisoning. (2 marks)

Q19

You want to reuse a hard disk (HDD). What is the best sanitization technique to ensure no single bit can be recovered? Explain. (2 marks)

Q20

Differentiate between the Biba model and the Bell-LaPadula model, in terms of the aim and the mechanism of each. (2 marks)

Q21

Using an example, differentiate between due care and due diligence, and show the relation between the two. (3 marks)

Q3 · Cryptography and attack identification

15 marks
Q22

Given P = 5 and Q = 7, use RSA to sign the message "B" (M = 2) with e = 5. What is the signature S?

Q23

A manager complains that an employee who moved to another team still reaches her department's sensitive data. Staff keep gaining new rights while retaining the old ones. Which term describes this?

Q24

Identify the attack behind each scenario.

A flood of ICMP responses from every PC in the company targets the web server. The server never sent any ICMP requests, and the network log shows the source address of those requests was the server's own IP.
A staff member subscribed to three free magazines. One asked for his birth details, another for his national ID, the third for his bank account. He suspects one entity collected all of it.
Malware has run in the background for a week. Antivirus, firewall and every other control missed it, no information exists online, and the relevant organisations are still investigating.
Mukhtar logged out of Gmail in a computer lab and cleared the browsing history. Someone later used the same PC, obtained his credentials and sent unwanted emails.
Malicious pop-ups appeared and the PC behaved strangely. The victim recalled a technician who had warned him about exactly this, called him for help, handed over credentials and confidential data, and the technician vanished.