1
جامعة الأمير سلطان
PRINCE SULTAN
UNIVERSITY
Major Sem 181
Course instructor: Dr. Gabriela Mogos
Course title: Fundamentals of Cybersecurity
Course code: CYS401
Duration: 70 minutes
Exam date: 18.11.2018
Student Name:
ID:
TOTAL MARKS: ( /20)
SECTION A. Multiple Choice Questions
Note: Answer all the questions and fill the TABLE at the end
with appropriate answers.
I. Choose the best answer/choice for the below statements:( /1 marks)
Counting up from the bottom: 1 Physical, 2 Data Link, 3 Network, 4
Transport, 5 Session, 6 Presentation, 7 Application.
A TCP wrapper sits in front of network services and allows or denies
connections by user or system ID, which makes it a basic host
firewall.
Firewalls filter traffic by rules; they log, raise alarms and cannot
stop insiders. Spotting viruses inside the content is antivirus
work.
2
Each layer wraps the data from the layer above with its own header
(and the data link layer a footer) on the way down.
TEMPEST is about reading electromagnetic emanations. Monitors give
off the strongest readable signal of these devices.
Dedicated, system-high and compartmented modes all require clearance
for the highest level. Multilevel mode lets users with lower
clearances work while the system enforces separation.
Both sides need the same secret, so getting it to them securely is
the classic problem. Symmetric encryption is faster than asymmetric,
not slower.
The two keys are a pair: whatever one encrypts only the other
decrypts. Both directions are used (encryption with the public key,
signatures with the private key), so the 'only' in (a) and (b) is
wrong.
Diffusion spreads each plaintext bit over many ciphertext bits.
Concealing the relationship (a) is confusion, which S-boxes (c)
provide.
3
The sender encrypts the message digest with their own private key;
anyone verifies it with the sender's public key.
A compromised private key means someone else can sign as the user,
so the CA puts the certificate on its revocation list. A public key
is public by design.
A CA is the trusted third party that issues certificates binding an
identity to a public key.
II. State whether these statements are True or False:( /0,5 marks)
Keyed TRUE on the instructor's answer sheet: XSS injects malicious
script through a vulnerable web application.
Layered, independent controls are the definition of defense in
depth.
WEP uses a static pre-shared key configured on the access point and
every client.
FALSE. In SMP the processors share the OS and memory and work
together. The instructor cites the CISSP book (p. 495): it is
asymmetric multiprocessing (AMP) where processors often
operate independently.
4
Multiple Choice Questions ( /1 marks)
|
TRUE/FALSE ( /0,5 marks) |
| 1 |
|
7 |
|
1 |
|
| 2 |
|
8 |
|
2 |
|
| 3 |
|
9 |
|
3 |
|
| 4 |
|
10 |
|
4 |
|
| 5 |
|
11 |
|
|
|
| 6 |
|
12 |
|
|
|
This table fills itself in from the options you pick above.
SECTION B. ESSAY Questions
Note: Section B contains Three (3) questions. Answer all
THREE (3) questions.
1. Shortly describe the Authoritative Name Server
(definition and types).( /2 marks)
Model answer · 2 marks
An Authoritative Name Server holds the actual DNS records for a
particular domain / address.
There are two types of Authoritative Name Servers:
-
Primary authoritative name server hosts the original
zone file for the domain.
-
Secondary authoritative name servers can be used to
host read-only copies of the zone file.
2. Shortly describe the Grid Computing.( /2 marks)
Model answer · 2 marks
-
Grid computing is a form of
parallel distributed processing that loosely groups
a significant number of processing nodes to work toward
a specific processing goal.
-
The biggest security concern with grid computing is that the
content of each work packet is potentially exposed to the
world.
-
Grid computing often uses a central primary core of servers to
manage the project, track work packets, and integrate returned
work segments.
-
If the central servers are overloaded or go offline, complete
failure or crashing of the grid can occur.