Major Exam C · Term unknown
- Source: photos of a marked copy (pages 2–6 of 6; the cover page wasn't photographed, so the term and instructor are unknown).
- The answers are corrected where the marked copy lost marks, and each one explains what the marker was looking for.
كلية علوم الحاسب ونظم المعلومات
A) Choose the Correct Option. [2.5 Marks]
The following message is encrypted using Caesar Cipher, find
its associated key assuming the space is replaced by the
letter “X”.
Message = THE IDES OF MARCH ARE COME
Plaintext =
THEXIDESXOFXMARCHXAREXCOME
Ciphertext =
AOLEPKLZEVMETHYJOEHYLEJVTL
Sarah, a financial analyst at a multinational company located in London, needs to share a confidential financial report with her manager, before a very important meeting in Riyadh as part of LEAP conference. She is considering different ways to send the file and wants to ensure that the data remains secure. Which of the following security controls should Sarah follow when storing, accessing, and transferring confidential data?
You are a cybersecurity officer for the SAB bank in Riyadh. A customer reports seeing an unauthorized transaction in their account history, even though they claim they never made any transaction. Upon investigating the network traffic, you discover that an attacker (Man-in-the-Middle) intercepted the communication between the customer and your servers. The attacker altered the data in transit to divert the funds to their own account. This is considered as a violation to:
A hospital categorizes its data as Confidential, Internal Use, or Public. Which data classification is correct?
Knowledge of letter frequencies, including pairs and triples can be used in cryptologic attacks against ______________ ciphers.
كلية علوم الحاسب ونظم المعلومات
B) For each statement, choose the appropriate term from the given table. [2.5 Marks]
| Declassification | Degaussing | Destruction |
| Purging | Erasing | Overwriting |
Prepares media for reuse in less secure environments.
Any process that purges media or a system in preparation for reuse in an unclassified environment.
Process of preparing media for reuse and ensuring that the cleared data cannot be recovered using traditional recovery tools.
Simply performing a delete operation against a file, a selection of files, or the entire media.
The most secure method of sanitizing media.
A) You are part of the security team for a fintech company
developing a mobile banking app. The app allows users to: view
account balances and recent transactions, transfer money between
accounts, pay bills and receive notifications about suspicious
activity. The backend system includes APIs for authentication,
account management, and transaction processing, all hosted in the
cloud behind a web application firewall (WAF). The app uses 2FA for
user authentication.
Using the STRIDE threat modeling
framework, complete the following table:
- Identify one potential threat on any given assets for the given STRIDE threats (Column 2).
- write the security property it violates (Column 3).
- For each threat, one possible mitigation. (Column 4)
| STRIDE THREAT | POTENTIAL THREAT ON ASSETS [1 Marks] | PROPERTY VIOLATED [1 Marks] | MITIGATION/ SECURITY CONTROL [1 Marks] |
|---|---|---|---|
| Spoofing |
Model answer · 0.25 marksAn
attacker logs in as a customer with stolen credentials
(or a stolen 2FA code) and transfers money.
|
Model answer · 0.25 marksEnforce 2FA/MFA, strong password policy, lock accounts
after repeated failures.
|
|
| Tampering |
Model answer · 0.25 marksA
man-in-the-middle alters the amount or recipient of a
transfer request sent to the transaction API.
|
Model answer · 0.25 marksTLS
for all API traffic; sign/HMAC transaction requests;
server-side validation.
|
|
| Denial of Service |
Model answer · 0.25 marksFlooding the authentication or transaction APIs so
customers can't view balances or pay bills.
|
Model answer · 0.25 marksRate
limiting and WAF rules, DDoS protection, load balancing
/ autoscaling.
|
|
| Elevation of Privileges |
Model answer · 0.25 marksA
normal user exploits an account-management API flaw to
reach admin functions or other users' accounts.
|
Model answer · 0.25 marksLeast
privilege with role-based access control; server-side
authorization checks on every request.
|
كلية علوم الحاسب ونظم المعلومات
B) What is ASP? When using an ASP, what should be conducted to ensure the protection of the data. [1 Marks]
ASP = Application Service Provider: a third party that hosts and maintains software on its own servers and delivers it to customers over the internet.
The organization stays accountable for its data, so it must perform due diligence on the provider before engaging it, and sign contracts and SLAs that define security requirements, responsibilities and breach notification (and audit the provider's controls).
C) For the commercial classification systems, write any THREE criteria’s used to classify information [1.5 Marks]
Any three of: business value of the information; legal and regulatory impact (e.g. PDPL, GDPR); reputational damage if it is disclosed; operational impact if it is altered or lost. (Also accepted in the textbooks: age / useful life and personal association.)
Tactical, operational and strategic are types of plans, not classification criteria — the answer on the marked copy scored 0 for that reason.
D) Analyze why symmetric encryption algorithms are preferred for encrypting large amounts of data compared to asymmetric algorithms. [1 Mark]
Symmetric algorithms use one shared key and simple, fast operations (substitution, permutation, XOR), so they are much faster and need far less computation than asymmetric algorithms, which do heavy maths on very large numbers. That speed makes symmetric encryption practical for bulk data; asymmetric encryption is used only to exchange the symmetric key or sign (hybrid encryption).
Symmetric uses one key, not two; "more keys means more security" scored 0 on the marked copy.
E) You are presented with the following scenarios related to a company's cybersecurity practices. For each scenario, classify it as either an example of due care, due diligence or both, and briefly explain your reasoning. [1.5 Marks]
| Scenario A: After detecting a data breach, a company immediately activates its incident response plan, notifies affected customers, and begins remediation efforts. |
|
Model answer · 0.25 marksDue
care: responding to the breach, notifying customers and
fixing the damage is the reasonable action a responsible
company takes. It is not research or assessment, so it is
not due diligence ("Both" scored 0 on the marked copy).
|
| Scenario B: A company suffers a ransomware attack that encrypts all their files. An investigation reveals that the company hadn’t updated its antivirus software in over a year and ignored security examination advise from their software vendors. |
|
Model answer · 0.25 marksBoth are
missing: not updating the antivirus is a failure of due
care, and ignoring the vendors' security examination
advice is a failure of due diligence. Answering only "due
care" earned half marks.
|
| Scenario C: The company requires all third-party vendors to sign a data protection agreement and undergo security audits before accessing sensitive information. |
|
Model answer · 0.25 marksDue
diligence: vetting and auditing third parties before
giving them access is investigating risk before acting.
|
كلية علوم الحاسب ونظم المعلومات
A) (a) Decrypt the Ciphertext: “FPPUUEBFTSIEWG”, using Playfair Cipher with the keyword “EFFECTIVENESS”. Show the complete working. [1.5 Marks]
Build the matrix here (checked, not marked), then write the plaintext.
Plaintext:
(b) In Playfair Cipher, the cryptanalysis depends on which factor? [1 Marks]
B) Using a Hill Cipher, answer the following questions.
| Plaintext Alphabet | a | b | c | d | e | f | g | h | i | j | k | l | m | n | o | p | q | r | s | t | u | v | w | x | y | z |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Plaintext Value | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 |
Is the key K = [2 6] suitable for use as a Hill Cipher encryption matrix? Give the reason. [0.5 Marks]
No. A Hill key must be a square (n × n, here 2 × 2) matrix that is invertible mod 26 (its determinant must have no common factor with 26), otherwise the ciphertext can't be decrypted. [2 6] is a 1 × 2 row, so it has no inverse.
Given the matrix k = 2336 and k−1 = 2252518, choose a suitable key to decrypt the ciphertext “FKMFIO” [1.5 Marks]
Key used: Plaintext:
- FK = (5, 10) × K−1 = (260, 305) mod 26 = (0, 19) → AT
- MF = (12, 5) × K−1 = (149, 390) mod 26 = (19, 0) → TA
- IO = (8, 14) × K−1 = (366, 452) mod 26 = (2, 10) → CK
كلية علوم الحاسب ونظم المعلومات
C) Read the scenarios below carefully, and answer the questions based on the information provided with no further assumptions
Scenario 1:
A company has gone through a round of phishing attacks.
More than 200 users have had their workstation infected because
they clicked on a link in an email. An incident analysis has
determined an executable ran and compromised the administrator
account on each workstation. Management is demanding the
information security team prevent this from happening again.
Which action do you need to take to prevent this from happening
again? [0.5 Marks]
Run security awareness training on phishing so users stop clicking malicious links (the action the marked copy got full marks for). Technical backups to mention: application whitelisting so unknown executables can't run, and removing administrator rights from everyday accounts (least privilege).
Scenario 2:
You receive a message on Instagram from a friend, asking if
you would like to invest in a new cryptocurrency that’s
"guaranteed to make huge returns." They provide a link to an
investment website that looks very professional, and they urge you
to act quickly.
What type of phishing attack is targeting you and What action
should you take? [1 Marks]
Type:
Don't open the link or send money. Verify with the friend through another channel (their account may be compromised), check the URL with a link checker, and report the account.
Scenario 3:
A company employee receives a call from someone claiming to
be from the IT department, offering a free software upgrade in
exchange for the employee’s login credentials. The caller insists
that the credentials are necessary to complete the upgrade
remotely. The employee, wanting to take advantage of the upgrade,
provides their username and password.
Identify the type of social engineering attack used in this
scenario and write one way an organization can protect against
such attacks. [1 Marks]
Type:
Security awareness training, plus a policy that IT never asks for passwords and that callers are verified by calling back the official help-desk number.