Major Exam A · Term unknown
- Source: photos of a marked copy (pages 2–7 of 7; the cover page wasn't photographed, so the term and instructor are unknown).
- Every cipher answer is computed and checked automatically. Written parts show a model answer and, where the marked copy lost marks, why.
كلية علوم الحاسب ونظم المعلومات
A) Choose the Correct Option. [2.5 Marks]
To Decrypt the ciphertext (C) using Triple DES, where K1≠K2≠K3, which of the following could be used:
The following message is encrypted using Caesar Cipher, find
its associated key assuming the space is replaced by the
letter “X”.
Plaintext = GLOBALCYBERSECURITYFORUM
Ciphertext
= QVYLKVMILOBCOMEBSDIPYBEW
Which of the following is better representing the Cipher Feedback (CFB) Mode:
Which role is directly responsible for deciding who has access to information systems and with what privileges, according to NIST SP 800-18?
Identify the term which denotes the protection of data from modification by unknown users.
كلية علوم الحاسب ونظم المعلومات
B) Read carefully the following wrong statements and correct them. [2.5 Marks]
Secure SDLC means applying security to only requirement and implementation phases.
Security attackers are always external.
Regarding the McCumber Cube, data needs to be protected only during transmission.
Strategic plan is usually a short-term plan with too many details.
The information assets within the same organization have the same risk value.
A) A hospital IT administrator simply deletes patient records from its system but does not follow NIST SP 800-88r1 guidelines for sanitization. Later, attackers recover fragments of those records using a simple recovery tool. Explain how data remanence occurred in this case. Suggest two methods of destroying data to prevent data remanence. [1.5 marks]
How: deleting a file only removes its directory entry and marks the space as free. The bits stay on the media until they are overwritten, so this residual data (data remanence) can be read back with simple recovery tools.
Two methods (any two): purging, e.g. degaussing or cryptographic erase; physical destruction (shredding, disintegration, incineration, pulverizing); clearing by overwriting the media before reuse.
B) SmartHealth Cloud, a cloud-based healthcare platform, stores sensitive patient medical records, including lab results, prescriptions, and diagnostic imaging. The platform also manages user authentication for doctors, nurses, and administrative staff through a centralized Identity and Access Management (IAM) system. During a routine security assessment, the cybersecurity team discovered that: Some patient data storage buckets were misconfigured and publicly accessible. The platform’s API endpoints for uploading and retrieving medical records were not rate-limited, allowing brute-force attacks. Certain staff members used weak passwords for accessing the IAM system. A malicious hacker or a ransomware attacker may exploit these weaknesses, they could access confidential patient records, alter medical data, or impersonate medical staff, potentially leading to data breaches, compromised patient care, and regulatory violations. Based on this scenario, identify two Assets, two Threats, two Vulnerabilities. [1.5 Marks] (0.25 for each point)
كلية علوم الحاسب ونظم المعلومات
| Asset | Threat | Vulnerability |
|---|---|---|
| Assets | Threats | Vulnerabilities |
|---|---|---|
| Patient medical records (lab results, prescriptions, imaging) | Malicious hacker / ransomware attacker; data breach | Misconfigured, publicly accessible storage buckets |
| IAM system (or the API endpoints) | Brute-force attack; impersonation of medical staff; alteration of medical data | API endpoints not rate-limited; weak staff passwords |
A vulnerability is the weakness; the threat is who or what exploits it. "Data breach" is a threat or impact, never a vulnerability.
C) A fintech company located in Riyadh has developed a mobile banking app that allows customers to:
- Log in using their username and password.
- View account balances, monthly statements, and transaction history.
- Transfer money to other accounts and Pay bills and receive real-time payment notifications.
Before launching the app nationwide, the company wants to perform a STRIDE threat modeling analysis to identify potential security risks.
- List down the STRIDE threats. (Column 1)
- For each threat, write an example presenting an associated threat (Column 2).
- For each STRIDE threat, write an appropriate Cyber security threat category (given below) (Column 3).
| Interruption |
| Interception |
| Modification |
| Fabrication |
| STRIDE THREAT [1.5 Marks] | Threat Example [1.5 Marks] | CYBER SECURITY THREAT CATEGORY [1.5 Marks] |
|---|---|---|
Columns 1 and 3 are checked automatically; mark column 2 yourself below.
- Spoofing: logging in with a stolen customer username and password, pretending to be that customer.
- Tampering: altering the amount or recipient of a transfer, or editing the transaction history.
- Repudiation: a customer denies making a transfer that they did make, and there are no logs to prove it.
- Information disclosure: leaking customers' balances, statements or credentials.
- Denial of service: flooding the app's servers so customers can't log in or pay bills.
- Elevation of privilege: a regular customer gains admin rights or reaches other customers' accounts.
كلية علوم الحاسب ونظم المعلومات
D) You are presented with the following scenarios related to a company’s cybersecurity practices. For each scenario, classify it as either an example of due care or due diligence, and briefly explain your reasoning. [1.5 marks] (0.5 for each point)
| Scenario A: A fintech company in Riyadh implements a robust employee training program that includes regular workshops on some security practices to comply with NCA standards. |
|
Model answer · 0.25 marksDue
care: the company is doing what a responsible organization
should do — training staff to meet the NCA standards it
must comply with.
|
| Scenario B: A company is implementing a new incident response plan. The security team investigates each single potential threats, reviews best practices, and assesses all risks. |
|
Model answer · 0.25 marksDue
diligence: investigating threats, reviewing best practices
and assessing risks is the research and analysis done
before acting.
|
| Scenario C: Medwin Hospital implements a comprehensive cybersecurity awareness program for all staff, including regular workshops on data privacy, secure handling of patient health records, and AI system ethics, to comply with national healthcare and data protection regulations. |
|
Model answer · 0.25 marksDue
care: implementing an awareness program to comply with
regulations is the protective action itself.
|
A) Assuming the block size b=128 bits. The plaintext is “Incomprehensibilities”. How many total blocks needed to send the complete plaintext. Calculate the number of padded bits needed to complete the last block. [1 mark] (0.5 mark for each point)
How many blocks will be used?
How many Padded bits are needed to send the complete data? bits
كلية علوم الحاسب ونظم المعلومات
B) Apply Whether Encryption or Decryption to each of the following [3 marks]:
| Plaintext | Cipher Algorithm | Ciphertext | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| DEAR |
Playfair cipher Key: “NO” Key matrix
|
Pairs: DE AR. DE share a row (D E F G H), so each letter
takes the one to its right: EF. A and R form a rectangle:
each takes the letter in its own row and the other
letter’s column: A→O, R→S. Ciphertext EFOS.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| HelloThere |
Transposition cipher Key: 4, 2, 1, 5, 3
|
Write HelloThere in rows under the key (H e l l o / T h e
r e), then read the columns in key order 1, 2, 3, 4, 5: le
· eh · oe · HT · lr → leehoeHTlr.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Decryption: subtract the key letter (M = 12, E = 4,
repeating) from each ciphertext letter: Q−M = E, E−E = A,
E−M = S, C−E = Y → EASY. The ciphertext was given,
so this row is a decryption.
|
Vigenère cipher Key: “ME”
|
QEEC |
C) Encrypt the word (HELP) using the hill cipher (Using row approach) where the key and key inverse are: [1 mark]
| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z |
| 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| K | 3235 | K−1 | 1520179 |
|---|
Ciphertext:
- HE = (7, 4) × K = (7·3 + 4·2, 7·3 + 4·5) = (29, 41) mod 26 = (3, 15) → DP
- LP = (11, 15) × K = (11·3 + 15·2, 11·3 + 15·5) = (63, 108) mod 26 = (11, 4) → LE
كلية علوم الحاسب ونظم المعلومات
D) Given the following figure, answer the following questions. [1 Marks]
What is the encryption mode? [0.5 Mark]
Write the decryption function for P[2]. [0.5 Mark]
P[2] = DK(C[2]) ⊕ C[1]
General form: P[i] = DK(C[i]) ⊕ C[i−1], with C[−1] = IV. Writing the encryption formula C[i] = EK(P[i] ⊕ C[i−1]) or an unfinished expression lost marks on the marked paper.