CYS401 · Fundamentals of Cybersecurity

Final Exam 221 (Version B)

Dr. Rabia Latif · 21 December 2022 · 3 hours · 40 marks

Version B of the 221 final: hashing and PKI, access-control models and rings, Bell-LaPadula, Diffie-Hellman with a man in the middle, and RSA.

Q1 Part 1 · Multiple choice

0.5 marks each
Q1

In case of data loss, ______ must be available to restore the affected data to its correct state.

Q2

PASTA is a ______ that aims at selecting or developing countermeasures in relation to the value of the assets to be protected.

Q3

SHA-3 supports hash lengths of ______, and its internal structure differs significantly from the rest of the SHA family.

Q4

MD4 is the ______ algorithm and ______ secure than MD5.

Q5

Which of the following is not a key step while doing threat modeling?

Q6

______ can be used to control what data is accessed during certain types of functions and what commands can be carried out on the data.

Q7

______ gives control of access to the people who are closer to the resources and lacks proper consistency.

Q8

Processes in ______ can access more resources and interact with the operating system more directly than processes in ______.

Q9

Operating in what is called the problem state is associated with ______.

Q10

Which is not an appropriate technique to protect web applications against SQL injection?

Q11

The ______ model makes sure conflicts of interest are recognised and that people are prevented from taking advantage of data they should not have access to.

Q12

S/MIME relies on the use of ______ for exchanging cryptographic keys.

Q13

Which reason is not appropriate for a Certificate Authority to revoke a certificate?

Q14

A coworker suggests reducing the number of logins and passwords by investigating single sign-on. Which of the following is a type of single sign-on system?

Q1 Part 2 · Match the access-control concept

3 marks · an option may be used twice
Q15

Answer each description by choosing the appropriate option.

Data has a 'top secret' confidentiality level and an 'engineering project' security label, and is available only to users with both top secret clearance and authorization for engineering documents.
This model is popular because it allows users a lot of freedom to choose access rights and causes little administrative overhead.
Computer-system managers use these controls to decide who can get into a system and what tasks they can perform.
As an administrator you designate user groups such as staff, specialists or end users, and limit access to specific resources or tasks.
Restrict users' abilities by not allowing them certain types of access or the ability to request certain functions or information.
What type of access control has been used in MAC systems as an enforcement mechanism?

Q2 · Short answers

15 marks
Q16

Identification, authentication, authorization and accountability are divided into two phases. What are those phases, and how do they divide these parts? (2 marks)

Q17

How is hashing different from encryption? Give two differences. (1 mark)

Q18

Where can you search for a revoked certificate? Briefly explain. (2 marks)

Q19

Which keys are used for the issuance and signature validation of an X.509 certificate, and who is responsible for issuing it? (1 mark)

Q20

Briefly explain the Type I and Type II errors generated by biometric devices, and what CER is used for. (4 marks)

Q21

Why is RADIUS considered less secure than TACACS? Give two reasons. (2 marks)

Q3 · Models, key exchange and RSA

15 marks
Q22

Bell-LaPadula. Top Secret: Duke (Patents, Trade Secrets). Secret: Claire (Project plans, Contracts). Confidential: Kevin (E-Mails, Project files). Unclassified: Emme (Telephone List, Newsletters). Apply each rule.

Simple Confidentiality Rule (read) applied to Claire — which objects may she read?
Star Confidentiality Rule (write) applied to Kevin — where may he write?
Strong Star Confidentiality Rule applied to Duke — what may he access?
Q23

A company blocks www.youtube.com, but employees still reach it. Is that possible, how, and which trust property does it exploit? (1 mark)

Q24

Diffie-Hellman with P = 13 and G = 5. Mark's secret is 4 and Malory's first secret is 6. Malory intercepts and completes the exchange with Mark. What is the shared secret K1 between Mark and Malory?

Q25

Same exchange: Ava's secret is 3 and Malory's second secret is 2. What is the shared secret K2 between Ava and Malory?

Q26

You want to secure email with RSA where n = 33. Which value is usable to generate a public key: e = 10 or e = 11?

Q27

Dexter chooses p = 11 and q = 3 with e = 3 (the smallest odd prime). Find d such that e × d ≡ 1 (mod φ(n)).

Q28

Using that key pair, Dexter signs the message M = 3. What is the signed value S?

Q29

Alice and Bob use p = 13 and g = 7. Alice's public key is Pₐ = 8. Bob's secret is 3. What shared secret do they establish?