Source: a marked copy (Dr. Rabia Latif, 1 February 2024, sections
1242/1249, 5 marks). The answers here are corrected, not copied from
the student.
MCQs, the blanks and the McCumber labels are checked automatically;
the SecSDLC and defense-in-depth answers show a model answer to mark
yourself against.
Instructor: Dr. Rabia LatifDate: 1 February 2024
CYS401- Fundamentals of Cybersecurity Semester 232- Sec:
1242/1249 Quiz 1
Q1: Choose the best option: [0.5 Mark Each = 1 Marks]
1.
Which of the following is not a physical security measure to
protect against physical hacking?
Patching software is a technical control; it does nothing against
someone who walks up to the machine. A phishing policy (a) is also
not physical (it is administrative), so the question has two
defensible answers; (b) is keyed, matching the same question on the
Semester 222 quiz.
2.
What is a characteristic of a layered defense-in-depth security
approach?
Defense in depth stacks independent safeguards, so losing one leaves
the others working. (d) describes fail-over redundancy, which
protects availability, not layering.
Q2: For each statement, choose the appropriate option from the given
table. [1 Marks]
Utility
Authentic
Integrity
Accuracy
a)
When the information is the same as it was originally created,
placed, stored, or transferred, it is
.
Authenticity is the quality of being genuine or original — unchanged
since it was created, placed, stored or transferred.
b)
If information contains a value different from the user's
expectations due to intentional or unintentional modification of
the content, it means no
.
Accuracy means free from errors and holding the value the user
expects; modified content is no longer accurate.
c)
If information is available, but not in the format meaningful to
the end user, it means no
.
Utility is the quality of being useful for a purpose. Data that is
present but unreadable to the user has no utility.
d)
If an unauthorized user obtains an organization's procedure, this
poses a threat to the
of the information.
This is the answer the marked paper accepted for full marks.
Q3: For the given McCumber Graph, label it with THREE different
dimensions. [0.75 Marks]
Axis 1 · vertical axis
Axis 2 · diagonal axis
Axis 3 · horizontal axis
Each axis earns 0.25 when its dimension name and its three labels
belong together. The cube's dimensions:
Security goals (confidentiality, integrity, availability),
Information states (processing, storage, transmission) and
Security measures (technology, policy, education).
Q4: For the given SDLC phases, write any TWO points for each phase to
make it SecSDLC. [1 Marks]
System Design
Model answer · 0.5 marks
Security planning and secure architecture design
Threat modelling and risk assessment of the design
Define security functional and assurance requirements
Design review against security requirements
(attack-surface analysis)
Operation and Maintenance
Model answer · 0.5 marks
Apply patches and security updates
Continuously monitor performance and logs with respect to
security
Incident response and periodic vulnerability assessments /
audits
Secure disposal of the system and its data at end of life
Q5: You are working as a security analyst in Hitech security company.
The company assigns you the task of implementing a defense-in-depth
approach to protect it from various cyber-attacks. For the given
scenario, suggest any ONE security control for the given layers
(in figure) to protect the company from cyber-attacks. [0.25 marks
each = 1.25 marks]
Layer
One security control
Data
Model answer · 0.25 marksEncryption at rest, or backup and restore