CYS401 past paper Term unknown

Major Exam B · Term unknown

Page 1 of 7 was not photographedThe cover page (student details and instructions).
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات
Question No.1:[ /5 Marks]

A) Choose the Correct Option. [2.5 Marks]

1.

Given the nested DES encryption operation C = EKC(DKB(EKA(P))); what is the correct sequence of decryption operations?

Undo the outermost step first, each with its inverse: P = DKA(EKB(DKC(C))). So decrypt with KC, feed that output into encryption with KB, then decrypt with KA.
2.

The following message is encrypted using Caesar Cipher, find its associated key assuming the space is replaced by the letter “X”.
Message = THE IDES OF MARCH ARE COME
Plaintext = THEXIDESXOFXMARCHXAREXCOME
Ciphertext = AOLEPKLZEVMETHYJOEHYLEJVTL

T (19) → A (0): 19 + 7 = 26 ≡ 0. Check: H (7) → O (14). Every letter shifts 7, so K = 7.
3.

Sarah, a financial analyst at a multinational company located in London, needs to share a confidential financial report with her manager, before a very important meeting in Riyadh as part of LEAP conference. She is considering different ways to send the file and wants to ensure that the data remains secure. Which of the following security controls should Sarah follow when storing, accessing, and transferring confidential data?

Email itself is fine; unencrypted email is the problem. Encrypting the file protects its confidentiality in storage and in transit.
4.

A hospital categorizes its data as Confidential, Internal Use, or Public. Which data classification is correct?

Patient records are the most sensitive (confidential), payroll is for internal staff only, and awareness brochures are meant for the public.
5.

You have been tasked with crafting a fairly stable security plan. It also needs to define the security function and align it to the goals, mission, and objectives of the organization. What are you being asked to create?

A strategic plan is the long-term, stable plan that defines the security function and aligns it with the organization's goals, mission and objectives. Tactical plans are mid-term; operational plans are day-to-day.
Page 2 of 7
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات

B) For each statement, choose the appropriate Term from the given table to fill the blank. [2.5 Marks]

Utility Authenticity Brute-Force Attack
Cyber criminal Tailgating Confidentiality
Two factor authentication Firewall Phishing
a)

refers to the quality or state of preventing disclosure or exposure to unauthorized individuals.

Confidentiality is about preventing disclosure to unauthorized people.
b)

a physical security breach where an unauthorized person gains access to a restricted area by following an authorized individual without proper authentication.

Following someone through a secured door is tailgating (piggybacking).
c)

The main motivation of is to gain financial benefits and make money.

Cyber criminals are driven by money; hacktivists by causes, nation states by politics.
d)

if information is available, but not in a format meaningful to the end user. For example if a doctor tries to access a patient’s file but receives the data in raw hexadecimal code instead of a readable medical report

Utility is the value of information for a purpose: raw hexadecimal is available but useless to the doctor, so it lacks utility.
e)

can prevent unauthorized access even if a user’s password is compromised.

A second factor (a token, a code on the phone) is still needed after the password leaks.
Question No.2:[ /9 Marks]

A)

  1. List down the STRIDE threats. (Column 1)
  2. For each threat, write the security property it violates (Column 2).
  3. For each STRIDE threat, write an appropriate Cyber security threat category (given below) (Column 3).
Interruption
Interception
Modification
Fabrication
STRIDE THREAT [1.5 Marks] PROPERTY VIOLATED [1.5 Marks] CYBER SECURITY THREAT CATEGORY [1.5 Marks]
Threat Property Category
Spoofing Authentication Fabrication
Tampering Integrity Modification
Repudiation Non-repudiation Fabrication (Modification also accepted)
Information disclosure Confidentiality Interception
Denial of service Availability Interruption
Elevation of privilege Authorization Modification
The four threat categories each attack one property: interruption → availability, interception → confidentiality, modification → integrity, fabrication → authenticity. Map each STRIDE threat through the property it violates. Repudiation (forging or denying a record) is marked as fabrication or modification; elevation of privilege as modification, as on the marked paper.
Page 3 of 7
Page 4 of 7 was not photographedThis page held Question 2 parts B, C and D (3.5 marks). They aren't included, so this paper is marked out of 16.5.
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات

E) You are presented with the following scenarios related to a company’s cybersecurity practices. For each scenario, classify it as either an example of due care or due diligence, and briefly explain your reasoning. [1 marks]

Scenario A: A company in Riyadh implements a robust employee training program that includes regular workshops on phishing awareness and secure password practices to meet NCA requirements.
Model answer · 0.25 marksDue care: running the training to meet NCA requirements is the reasonable protective action itself.
Scenario B: The company conducts risk assessments every two months to identify potential security threats and vulnerabilities in its systems.
Model answer · 0.25 marksDue diligence: regular risk assessments are the ongoing investigation that identifies what needs protecting.
Question No.3:[ /6 Marks]

A) Assuming the block size b=64 bits. The plaintext is “wewillattentandenjoyLEAPinKSA”.[1 mark]

I.

How many Padded bits are needed to send the complete data? bits

II.

How many blocks will be used?

“wewillattentandenjoyLEAPinKSA” has 29 characters = 29 bytes. A 64-bit block holds 8 bytes, so 4 blocks (32 bytes) are needed. Padding = 32 − 29 = 3 bytes = 24 bits.

B) Using the Playfair cipher, construct a Playfair matrix, and encrypt the message ” COMMITTEES ” with the keyword ” EFFECTIVENESS ” considering that (I/J) will be in the same cell. Show your answer. [1.5 mark]

Ciphertext:

Matrix: keyword letters without repeats (E F C T I V N S), then the rest of the alphabet:
E F C T I/J
V N S A B
D G H K L
M O P Q R
U W X Y Z
Split into pairs, putting X between the double letters: CO MX MI TX TE ES. Encrypt each pair: FP PU RE CY IF CV → FPPURECYIFCV.
Page 5 of 7
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات

C) Using Vigenère cipher, decrypt the Ciphertext: “CMRUVLERMYOLRX” with key “ RIYADH ”. [1 Marks]

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
A A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
B B C D E F G H I J K L M N O P Q R S T U V W X Y Z A
C C D E F G H I J K L M N O P Q R S T U V W X Y Z A B
D D E F G H I J K L M N O P Q R S T U V W X Y Z A B C
E E F G H I J K L M N O P Q R S T U V W X Y Z A B C D
F F G H I J K L M N O P Q R S T U V W X Y Z A B C D E
G G H I J K L M N O P Q R S T U V W X Y Z A B C D E F
H H I J K L M N O P Q R S T U V W X Y Z A B C D E F G
I I J K L M N O P Q R S T U V W X Y Z A B C D E F G H
J J K L M N O P Q R S T U V W X Y Z A B C D E F G H I
K K L M N O P Q R S T U V W X Y Z A B C D E F G H I J
L L M N O P Q R S T U V W X Y Z A B C D E F G H I J K
M M N O P Q R S T U V W X Y Z A B C D E F G H I J K L
N N O P Q R S T U V W X Y Z A B C D E F G H I J K L M
O O P Q R S T U V W X Y Z A B C D E F G H I J K L M N
P P Q R S T U V W X Y Z A B C D E F G H I J K L M N O
Q Q R S T U V W X Y Z A B C D E F G H I J K L M N O P
R R S T U V W X Y Z A B C D E F G H I J K L M N O P Q
S S T U V W X Y Z A B C D E F G H I J K L M N O P Q R
T T U V W X Y Z A B C D E F G H I J K L M N O P Q R S
U U V W X Y Z A B C D E F G H I J K L M N O P Q R S T
V V W X Y Z A B C D E F G H I J K L M N O P Q R S T U
W W X Y Z A B C D E F G H I J K L M N O P Q R S T U V
X X Y Z A B C D E F G H I J K L M N O P Q R S T U V W
Y Y Z A B C D E F G H I J K L M N O P Q R S T U V W X
Z Z A B C D E F G H I J K L M N O P Q R S T U V W X Y

Plaintext:

Repeat the key under the ciphertext (RIYADHRIYADHRI) and subtract each key letter: C−R = L, M−I = E, R−Y = T, U−A = U, V−D = S, L−H = E, … → LETUSENJOYLEAP (“let us enjoy LEAP”).

D) Given the following figure, answer the following questions. [2.5 Marks]

Encryption V Eₖ P[0] C[0] Eₖ P[1] C[1] Eₖ P[2] C[2] Eₖ P[3] C[3] Decryption: V Dₖ P[0] C[0] Dₖ P[1] C[1] Dₖ P[2] C[2] Dₖ P[3] C[3]
i.

What is the encryption Mode? [1 Mark]

Plaintext is XORed with the previous ciphertext block (the IV first) before encryption: Cipher Block Chaining.
Page 6 of 7
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات
ii.

Write the encryption function for C[2] / decryption function for P[2]. [1.5 Mark]

Model answer · 1.5 marks

Encryption: C[2] = EK(P[2] ⊕ C[1])

Decryption: P[2] = DK(C[2]) ⊕ C[1]

General form: C[i] = EK(P[i] ⊕ C[i−1]) and P[i] = DK(C[i]) ⊕ C[i−1], with C[−1] = IV (the V in the figure).

GOODLUCK ☺
Page 7 of 7