CYS401 past paper Term unknown

Major Exam C · Term unknown

Page 1 of 6 was not photographedThe cover page (student details and instructions).
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات
Question No.1:[ /5 Marks]

A) Choose the Correct Option. [2.5 Marks]

1.

The following message is encrypted using Caesar Cipher, find its associated key assuming the space is replaced by the letter “X”.
Message = THE IDES OF MARCH ARE COME
Plaintext = THEXIDESXOFXMARCHXAREXCOME
Ciphertext = AOLEPKLZEVMETHYJOEHYLEJVTL

T (19) → A (0): 19 + 7 = 26 ≡ 0. Check: H (7) → O (14). Every letter shifts 7, so K = 7.
2.

Sarah, a financial analyst at a multinational company located in London, needs to share a confidential financial report with her manager, before a very important meeting in Riyadh as part of LEAP conference. She is considering different ways to send the file and wants to ensure that the data remains secure. Which of the following security controls should Sarah follow when storing, accessing, and transferring confidential data?

Email itself is fine; unencrypted email is the problem. Encrypting the file protects its confidentiality in storage and in transit.
3.

You are a cybersecurity officer for the SAB bank in Riyadh. A customer reports seeing an unauthorized transaction in their account history, even though they claim they never made any transaction. Upon investigating the network traffic, you discover that an attacker (Man-in-the-Middle) intercepted the communication between the customer and your servers. The attacker altered the data in transit to divert the funds to their own account. This is considered as a violation to:

The attacker changed the data in transit (tampering), so integrity is violated.
4.

A hospital categorizes its data as Confidential, Internal Use, or Public. Which data classification is correct?

Patient records are the most sensitive (confidential), payroll is for internal staff only, and awareness brochures are meant for the public.
5.

Knowledge of letter frequencies, including pairs and triples can be used in cryptologic attacks against ______________ ciphers.

Substitution ciphers keep each letter's frequency pattern (just relabelled), so frequency analysis breaks them. Transposition keeps the letters themselves and is attacked by rearranging, not by letter frequencies.
Page 2 of 6
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات

B) For each statement, choose the appropriate term from the given table. [2.5 Marks]

Declassification Degaussing Destruction
Purging Erasing Overwriting
a)

Prepares media for reuse in less secure environments.

Purging is a more intense form of clearing that prepares media for reuse in a less secure environment.
b)

Any process that purges media or a system in preparation for reuse in an unclassified environment.

Declassification purges media or a system so it can be reused in an unclassified environment.
c)

Process of preparing media for reuse and ensuring that the cleared data cannot be recovered using traditional recovery tools.

Clearing, or overwriting, prepares media for reuse so that traditional recovery tools can't recover the data. Degaussing is the distractor: it is a purging technique for magnetic media.
d)

Simply performing a delete operation against a file, a selection of files, or the entire media.

Erasing is just a delete, so the data remains recoverable.
e)

The most secure method of sanitizing media.

Destruction (shredding, incineration, disintegration) is the most secure method.
Question No.2:[ /8 Marks]

A) You are part of the security team for a fintech company developing a mobile banking app. The app allows users to: view account balances and recent transactions, transfer money between accounts, pay bills and receive notifications about suspicious activity. The backend system includes APIs for authentication, account management, and transaction processing, all hosted in the cloud behind a web application firewall (WAF). The app uses 2FA for user authentication.
Using the STRIDE threat modeling framework, complete the following table:

  1. Identify one potential threat on any given assets for the given STRIDE threats (Column 2).
  2. write the security property it violates (Column 3).
  3. For each threat, one possible mitigation. (Column 4)
STRIDE THREAT POTENTIAL THREAT ON ASSETS [1 Marks] PROPERTY VIOLATED [1 Marks] MITIGATION/ SECURITY CONTROL [1 Marks]
Spoofing
Model answer · 0.25 marksAn attacker logs in as a customer with stolen credentials (or a stolen 2FA code) and transfers money.
Model answer · 0.25 marksEnforce 2FA/MFA, strong password policy, lock accounts after repeated failures.
Tampering
Model answer · 0.25 marksA man-in-the-middle alters the amount or recipient of a transfer request sent to the transaction API.
Model answer · 0.25 marksTLS for all API traffic; sign/HMAC transaction requests; server-side validation.
Denial of Service
Model answer · 0.25 marksFlooding the authentication or transaction APIs so customers can't view balances or pay bills.
Model answer · 0.25 marksRate limiting and WAF rules, DDoS protection, load balancing / autoscaling.
Elevation of Privileges
Model answer · 0.25 marksA normal user exploits an account-management API flaw to reach admin functions or other users' accounts.
Model answer · 0.25 marksLeast privilege with role-based access control; server-side authorization checks on every request.
Properties: Spoofing → Authentication, Tampering → Integrity, Denial of Service → Availability, Elevation of Privileges → Authorization. On the marked copy the property names went into the threat column; the threat column needs an actual attack on one of the app's assets.
Page 3 of 6
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات

B) What is ASP? When using an ASP, what should be conducted to ensure the protection of the data. [1 Marks]

Model answer · 1 marks

ASP = Application Service Provider: a third party that hosts and maintains software on its own servers and delivers it to customers over the internet.

The organization stays accountable for its data, so it must perform due diligence on the provider before engaging it, and sign contracts and SLAs that define security requirements, responsibilities and breach notification (and audit the provider's controls).

C) For the commercial classification systems, write any THREE criteria’s used to classify information [1.5 Marks]

Model answer · 1.5 marks

Any three of: business value of the information; legal and regulatory impact (e.g. PDPL, GDPR); reputational damage if it is disclosed; operational impact if it is altered or lost. (Also accepted in the textbooks: age / useful life and personal association.)

Tactical, operational and strategic are types of plans, not classification criteria — the answer on the marked copy scored 0 for that reason.

D) Analyze why symmetric encryption algorithms are preferred for encrypting large amounts of data compared to asymmetric algorithms. [1 Mark]

Model answer · 1 marks

Symmetric algorithms use one shared key and simple, fast operations (substitution, permutation, XOR), so they are much faster and need far less computation than asymmetric algorithms, which do heavy maths on very large numbers. That speed makes symmetric encryption practical for bulk data; asymmetric encryption is used only to exchange the symmetric key or sign (hybrid encryption).

Symmetric uses one key, not two; "more keys means more security" scored 0 on the marked copy.

E) You are presented with the following scenarios related to a company's cybersecurity practices. For each scenario, classify it as either an example of due care, due diligence or both, and briefly explain your reasoning. [1.5 Marks]

Scenario A: After detecting a data breach, a company immediately activates its incident response plan, notifies affected customers, and begins remediation efforts.
Model answer · 0.25 marksDue care: responding to the breach, notifying customers and fixing the damage is the reasonable action a responsible company takes. It is not research or assessment, so it is not due diligence ("Both" scored 0 on the marked copy).
Scenario B: A company suffers a ransomware attack that encrypts all their files. An investigation reveals that the company hadn’t updated its antivirus software in over a year and ignored security examination advise from their software vendors.
Model answer · 0.25 marksBoth are missing: not updating the antivirus is a failure of due care, and ignoring the vendors' security examination advice is a failure of due diligence. Answering only "due care" earned half marks.
Scenario C: The company requires all third-party vendors to sign a data protection agreement and undergo security audits before accessing sensitive information.
Model answer · 0.25 marksDue diligence: vetting and auditing third parties before giving them access is investigating risk before acting.
Page 4 of 6
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات
Question No.3:[ /7 Marks]

A) (a) Decrypt the Ciphertext: “FPPUUEBFTSIEWG”, using Playfair Cipher with the keyword “EFFECTIVENESS”. Show the complete working. [1.5 Marks]

Build the matrix here (checked, not marked), then write the plaintext.

Plaintext:

Matrix rows: E F C T I / V N S A B / D G H K L / M O P Q R / U W X Y Z. Decrypt each pair (same row → letter to the left, same column → letter above, rectangle → own row, other letter's column): FP→CO PU→MX UE→MU BF→NI TS→CA IE→TI WG→ON. That gives COMXMUNICATION; drop the filler X between the double M: COMMUNICATION. The marked copy lost a quarter for decrypting FP as OC: in a rectangle each letter takes the corner in its own row, so FP → CO.

(b) In Playfair Cipher, the cryptanalysis depends on which factor? [1 Marks]

The whole cipher is the 5×5 matrix built from the keyword, so breaking Playfair means recovering the keyword / key square (usually through digram frequency analysis).

B) Using a Hill Cipher, answer the following questions.

Plaintext Alphabet a b c d e f g h i j k l m n o p q r s t u v w x y z
Plaintext Value 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
a)

Is the key K = [2  6] suitable for use as a Hill Cipher encryption matrix? Give the reason. [0.5 Marks]

Model answer · 0.25 marks

No. A Hill key must be a square (n × n, here 2 × 2) matrix that is invertible mod 26 (its determinant must have no common factor with 26), otherwise the ciphertext can't be decrypted. [2 6] is a 1 × 2 row, so it has no inverse.

b)

Given the matrix k = 2336 and k−1 = 2252518, choose a suitable key to decrypt the ciphertext “FKMFIO” [1.5 Marks]

Key used:   Plaintext:

Decryption uses the inverse key. Row approach, plaintext pair = ciphertext pair × k−1:
  1. FK = (5, 10) × K−1 = (260, 305) mod 26 = (0, 19) → AT
  2. MF = (12, 5) × K−1 = (149, 390) mod 26 = (19, 0) → TA
  3. IO = (8, 14) × K−1 = (366, 452) mod 26 = (2, 10) → CK
Plaintext ATTACK.
Page 5 of 6
Prince Sultan University
College of Computer and Information Sciences
جامعة الأمير سلطان
كلية علوم الحاسب ونظم المعلومات

C) Read the scenarios below carefully, and answer the questions based on the information provided with no further assumptions

Scenario 1:
A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an executable ran and compromised the administrator account on each workstation. Management is demanding the information security team prevent this from happening again.
Which action do you need to take to prevent this from happening again? [0.5 Marks]

Model answer · 0.5 marks

Run security awareness training on phishing so users stop clicking malicious links (the action the marked copy got full marks for). Technical backups to mention: application whitelisting so unknown executables can't run, and removing administrator rights from everyday accounts (least privilege).

Scenario 2:
You receive a message on Instagram from a friend, asking if you would like to invest in a new cryptocurrency that’s "guaranteed to make huge returns." They provide a link to an investment website that looks very professional, and they urge you to act quickly.
What type of phishing attack is targeting you and What action should you take? [1 Marks]

Type:

Model answer · 0.5 marks

Don't open the link or send money. Verify with the friend through another channel (their account may be compromised), check the URL with a link checker, and report the account.

Phishing through social media is angler phishing.

Scenario 3:
A company employee receives a call from someone claiming to be from the IT department, offering a free software upgrade in exchange for the employee’s login credentials. The caller insists that the credentials are necessary to complete the upgrade remotely. The employee, wanting to take advantage of the upgrade, provides their username and password.
Identify the type of social engineering attack used in this scenario and write one way an organization can protect against such attacks. [1 Marks]

Type:

Model answer · 0.5 marks

Security awareness training, plus a policy that IT never asks for passwords and that callers are verified by calling back the official help-desk number.

Something offered in exchange for information is quid pro quo (it arrives by phone, so vishing is also a fair description). Baiting — the answer on the marked copy, which got half marks — leaves a lure such as an infected USB drive for the victim to pick up; it doesn't trade a service for credentials.
GOODLUCK ☺
Page 6 of 6