Version B of the 221 final: hashing and PKI, access-control models and rings, Bell-LaPadula, Diffie-Hellman with a man in the middle, and RSA.
In case of data loss, ______ must be available to restore the affected data to its correct state.
PASTA is a ______ that aims at selecting or developing countermeasures in relation to the value of the assets to be protected.
SHA-3 supports hash lengths of ______, and its internal structure differs significantly from the rest of the SHA family.
MD4 is the ______ algorithm and ______ secure than MD5.
Which of the following is not a key step while doing threat modeling?
______ can be used to control what data is accessed during certain types of functions and what commands can be carried out on the data.
______ gives control of access to the people who are closer to the resources and lacks proper consistency.
Processes in ______ can access more resources and interact with the operating system more directly than processes in ______.
Operating in what is called the problem state is associated with ______.
Which is not an appropriate technique to protect web applications against SQL injection?
The ______ model makes sure conflicts of interest are recognised and that people are prevented from taking advantage of data they should not have access to.
S/MIME relies on the use of ______ for exchanging cryptographic keys.
Which reason is not appropriate for a Certificate Authority to revoke a certificate?
A coworker suggests reducing the number of logins and passwords by investigating single sign-on. Which of the following is a type of single sign-on system?
Answer each description by choosing the appropriate option.
Identification, authentication, authorization and accountability are divided into two phases. What are those phases, and how do they divide these parts? (2 marks)
How is hashing different from encryption? Give two differences. (1 mark)
Where can you search for a revoked certificate? Briefly explain. (2 marks)
Which keys are used for the issuance and signature validation of an X.509 certificate, and who is responsible for issuing it? (1 mark)
Briefly explain the Type I and Type II errors generated by biometric devices, and what CER is used for. (4 marks)
Why is RADIUS considered less secure than TACACS? Give two reasons. (2 marks)
Bell-LaPadula. Top Secret: Duke (Patents, Trade Secrets). Secret: Claire (Project plans, Contracts). Confidential: Kevin (E-Mails, Project files). Unclassified: Emme (Telephone List, Newsletters). Apply each rule.
A company blocks www.youtube.com, but employees still reach it. Is that possible, how, and which trust property does it exploit? (1 mark)
Diffie-Hellman with P = 13 and G = 5. Mark's secret is 4 and Malory's first secret is 6. Malory intercepts and completes the exchange with Mark. What is the shared secret K1 between Mark and Malory?
Same exchange: Ava's secret is 3 and Malory's second secret is 2. What is the shared secret K2 between Ava and Malory?
You want to secure email with RSA where n = 33. Which value is usable to generate a public key: e = 10 or e = 11?
Dexter chooses p = 11 and q = 3 with e = 3 (the smallest odd prime). Find d such that e × d ≡ 1 (mod φ(n)).
Using that key pair, Dexter signs the message M = 3. What is the signed value S?
Alice and Bob use p = 13 and g = 7. Alice's public key is Pₐ = 8. Bob's secret is 3. What shared secret do they establish?