Chapters 1–5 exam cheat sheet
Every list, definition and difference from the chapter 1–5 slides, explained with the real questions the instructors asked. Built from the slides and every past paper on this site: Final 221 (Versions A and B), Quiz 1 (222), the chapter 1, 2 and 5 quizzes, and the chapters 1–2 practice exam.
How the instructors write the exam
The same nine question shapes come back on every paper. Learn to recognise the shape and you know what the question is really testing. Finals are 40 marks over 3 hours: 14 MCQs at 0.5 each, a 3-mark matching question, 15 marks of short answers and a 15-mark applied section. Quizzes are about 5 marks.
1 · "All of the following EXCEPT"
The wrong option is almost never random. It is taken from a neighbouring list, so it sounds right.
- Pillars: People, Policies, Technologies, Data. Data is what the pillars protect. (Final 221 A, Q1)
- Government classes: Top Secret, Critical, Secret, Unclassified. Critical belongs to the commercial scheme. (Final 221 A, Q4)
- McCumber dimensions: Goals, States, Controls, Security Threats. (Ch1 Quiz)
- Critical characteristics: Utility, Possession, Scalability, Authenticity. (Practice)
- Threat-modelling steps: Visualize, Identify threats, Execute, Validate. (Final 221 B, Q5)
2 · True/False with a swapped definition
They take a correct definition and attach it to the wrong term, or reverse a one-way rule.
- "Utility means information is genuine and original." False, that is Authenticity.
- "A key fob is a software token that generates a PIN." False, a key fob is hardware; a soft token is software.
- "Personnel security protects communications media." False, that is Communications security.
- "A breach of possession always breaches confidentiality." False, the rule only works the other way.
- "AAA refers to only three elements." False, there are five.
3 · Superlatives
Several "most" and "-est" facts sit in the same chapter, so they mix them up on purpose.
- Most difficult IS component to secure: Software
- Most valuable asset: Data
- Weakest component: People
- Most common SDLC approach: Waterfall
- Preferred threat-modelling approach: Proactive
- Most secure media sanitization: Destruction
- Only unbreakable cipher: One-time pad
- Latest form of phishing: Angler phishing
4 · A scenario with one decisive word
Scenario questions hide a single clue. Underline it before you read the options.
- "convince you specifically" → spear phishing (Final A Q14)
- "unusable or unavailable" → interruption (Final A Q2)
- "pay to unlock or decrypt" → ransomware (Final A Q3)
- "no information exists, still investigating" → zero-day (Final A Q24)
- "the victim called the technician" → reverse social engineering
- "typed the correct URL" → pharming
- "political DDoS on government sites" → hacktivists (Quiz 1)
5 · "Both (a) and (b)" options
When the paper offers "Both", check each half on its own. Sometimes both are right, sometimes one half is a trap.
- "In case of data loss, ___ must be available to restore data": Backup, Redundancies, Checksum, Both (a) and (b). Both is right: the slide says "backups or redundancies". (Final 221 B, Q1)
- A checksum only detects a change. It cannot restore anything.
6 · Order and direction
They test whether you know the sequence, not just the members.
- 3DES decryption: D(K3) → E(K2) → D(K1) (Final A Q6)
- AAA: Identification → Authentication → Authorization → Auditing → Accounting
- SDLC: Planning → Analysis → Design → Implementation → Support
- Defence in depth, outside in: Physical → Perimeter → Network → Host → Application → Data
- Sanitization, weakest to strongest: Erasing → Formatting → Clearing → Purging → Destruction
7 · Calculations
Marks go to the method, so always write each step.
- Availability % from downtime: MTTF ÷ (MTTF + MTTR) (Quiz 1, Q5)
- Caesar, ROT13, keyword, Playfair, Vigenère and Hill encryption and decryption
- Reading the brute-force table (DES at 10⁶ decryptions/µs ≈ 10 hours)
8 · "Differentiate between X and Y, with an example"
Usually 2–3 marks: one for each definition, one for the relationship or example.
- Due care vs due diligence, and the relation (3 marks) (Final A Q21)
- Hashing vs encryption, two differences (Final B Q17)
- Best sanitization for reusing an HDD, and why (Final A Q19)
9 · The official key is sometimes wrong
The transcribed papers flag where the key slipped. Quiz 1's availability key used 90 weeks instead of 90 days (99.9% instead of 98.6%), and it lost half a mark. If your method is right, trust it and show every step so the marker can follow it.
Introduction to Cybersecurity
The definitions, the seven characteristics of information, the McCumber Cube, the five IS components, defence in depth and the SDLC. This chapter is almost all "list it" and "which one is it" questions.
What cybersecurity is
Definition (slide wording)
Cyber security is the protection of internet-connected systems, including hardware, software and data, from cyberattacks.
The four related terms 4
- Information security: protects information in any form, including paper and speech. The broadest term.
- Computer security: protects computer systems and their components.
- IT security: protects the IT infrastructure.
- Cyber security: protects internet-connected systems.
Ch1 Quiz essay (13 marks): compare all four.
Cybersecurity pillars 3
- People: understand and follow security principles
- Policies: a framework for attempted and successful attacks
- Technologies: the tools that protect against attacks
Critical characteristics of information 7
| Characteristic | Slide definition | Keyword to spot it | Example |
|---|---|---|---|
| Confidentiality | Preventing disclosure or exposure to unauthorized individuals or systems | who can see it | Credit cards, PII, health records |
| Integrity | Being accurate, complete and authorised. Threatened by corruption, damage, destruction or disruption of its authentic state | unchanged by unauthorised parties | A file altered in transit |
| Availability | Authorised users can access it without interference or obstruction, when and where needed and in the correct format | reachable when needed | Server down = loss of availability |
| Accuracy | Free from mistakes or errors and having the value the end user expects | error-free, matches expectation | A wrong balance after any modification, intentional or not |
| Authenticity | Genuine or original rather than a reproduction or fabrication | genuine / original | Same as when originally created, stored or transferred |
| Utility | Having value for some purpose or end | useful, meaningful format | Available but unreadable format = no utility |
| Possession | Having ownership or control of the item, independent of format | holds a copy | Stolen encrypted disk |
The one-way rule (asked almost every time)
A breach of confidentiality always results in a breach of possession. A breach of possession does not always result in a breach of confidentiality.
Why: if someone reads your data, they now hold it. But if they steal an encrypted copy, they hold it without being able to read it.
Accuracy vs Integrity vs Authenticity
- Integrity: protected from unauthorised change (about who changed it).
- Accuracy: the value is correct and what the user expects (about the value).
- Authenticity: it is the original, not a copy or a fake (about origin).
Memorise the seven
McCumber Cube 3 × 3
Security goals
- Confidentiality
- Integrity
- Availability
Information states
- Storage: data at rest (DAR), in memory, tape or disk
- Transmission: between systems, data in transit (DIT)
- Processing: operations performed on the data
Security measures / controls
- Policy and practices: administrative controls (plans, guidance)
- Education: users know their roles and responsibilities
- Technology: software and hardware solutions
Five components of an information system 5
| Component | What it is | The fact they test |
|---|---|---|
| Software | Applications, operating systems, utilities | Most difficult to secure: too many bugs, and security is left out of the first implementation, so version after version ships |
| Hardware | Physical technology that houses and runs the software, stores and transmits data | Secured with locks, keys and biometric access controls |
| Data | What the organisation stores and processes | Most valuable asset and main target of intentional attacks |
| People | Users of the IS | Weakest component, so policy, agreements, education and training matter |
| Procedures | Written instructions for a specific task | If an unauthorised user obtains them, the integrity of the information is threatened |
Two different "layers" lists (do not mix them)
Defence-in-depth diagram, outside in 6
- Physical: guards, locks, tracking devices
- Perimeter: firewalls, border routers, VPNs with quarantine procedures
- Network: network segments, NIDS
- Host / computer: OS hardening, authentication, security update management, antivirus updates, auditing
- Application: application hardening
- Data: strong passwords, ACLs, backup and restore strategy
Organisation's security layers 6
- Physical security: physical items and objects
- Personnel security: the individuals authorised to access the organisation
- Operations security: the details of a particular operation or activity
- Communications security: communications media and technology
- Network security: network components and connections
- Data security: CIA of information in storage, processing and transmission
Quiz 1's seven-layer version
Quiz 1 used the extended onion, which adds an outer human layer:
- Policies and procedures (training, acceptable-use policy)
- Physical
- Perimeter
- Internal network (segmentation, auditing between departments)
- Host (OS patching, host antivirus)
- Application (input validation, secure coding)
- Data (encryption at rest, ACLs on records)
What defence in depth really means
Multiple independent controls in series. If one safeguard fails, the others still work. It is not about the number of devices, and it is not fail-over (that is redundancy, which protects availability).
SDLC and SecSDLC
SDLC phases 5
A methodology for designing and implementing an IS. Most common approach: waterfall.
- Planning: review and prioritise the project request, allocate resources, identify the team
- Analysis: study the current system, determine user requirements, recommend a solution
- Design: acquire hardware and software, develop the system details
- Implementation: develop the program, install and test, train users
- Support: identify errors and enhancements, monitor performance, update
SecSDLC phases 4
- Planning and analysis: potential impact of a breach; preliminary risk assessment → initial description of the basic security
- Design: risk assessments, security functional and assurance requirement analysis, security planning
- Implementation: inspection and acceptance, system integration bounded by the chosen controls
- Support: keep the security level when the environment changes, update, continuous monitoring
SDLC vs SecSDLC (the difference)
The SecSDLC follows the exact same phases as the SDLC. In addition it identifies specific threats and creates specific controls to counter them, in every phase.
Past-paper questions · Chapter 1
To achieve security we combine three key elements, the cybersecurity pillars. All of the following are pillars except ______.
- People
- Policies
- Technologies
- Data
Show answer
Data is what the pillars protect. It is not one of them.
Which of the following is NOT one of the critical characteristics of information?
- Utility
- Possession
- Scalability
- Authenticity
Show answer
The seven are CIA + Accuracy, Authenticity, Utility, Possession. Scalability is a system-performance property.
Information that is free from mistakes or errors and has the value the end user expects has which characteristic?
- Authenticity
- Accuracy
- Integrity
- Utility
Show answer
Integrity is the near-miss: it is about protection from unauthorised modification, not about matching the user's expectation.
Data is stolen in encrypted form, so the attacker cannot read it. Which characteristic has been breached?
- Confidentiality only
- Possession only
- Both confidentiality and possession
- Neither, because the data is encrypted
Show answer
They hold the data (possession), but nothing was disclosed (confidentiality intact).
A breach of ownership (possession) always results in a breach of confidentiality.
Show answer
Only the reverse is always true: a confidentiality breach always means a possession breach.
Which component of an information system is described as the most difficult to secure?
- Hardware
- Software
- Data
- Procedures
Show answer
Data is the most valuable; People are the weakest. Different superlatives, different components.
Which component of an Information System is considered the weakest link?
- Software
- Hardware
- Data
- People
Show answer
They fall for social engineering, make mistakes and skip policies.
An unauthorised user obtains a copy of the organisation's written work instructions. Which IS component is compromised, and what is chiefly at risk?
- Data, availability
- Procedures, integrity of the information
- People, confidentiality
- Software, accuracy
Show answer
The slide says leaked procedures threaten the integrity of the information.
Which of the following is NOT a dimension of the McCumber Cube?
- Security Goals
- Information States
- Security Controls
- Security Threats
Show answer
Also watch for "People, Policies, Technologies" (the pillars) or "Storage, Transmission, Processing" (only one axis) offered as "the three dimensions".
In the McCumber Cube, "data at rest (DAR)" such as data stored on a disk corresponds to which information state?
- Transmission
- Processing
- Storage
- Retention
Show answer
Retention is not a McCumber state.
In the defence-in-depth diagram, "network segments and NIDS" belong to which layer?
- Perimeter
- Network
- Host/Computer
- Physical
Show answer
And "strong passwords, ACLs, backup and restore" is the Data layer.
Which of the organisation's security layers protects the details of a particular operation or activity?
- Operations security
- Personnel security
- Communications security
- Physical security
Show answer
What is a characteristic of a layered defence-in-depth security approach?
- Three or more devices are used.
- Routers are replaced with firewalls.
- One safeguard failure does not affect the effectiveness of other safeguards.
- When one device fails, another one takes over.
Show answer
(d) is redundancy/fail-over, which is about availability. (b) is replacement, not layering. No device count makes it layered.
Defence in depth is used to provide a protective multilayer barrier against various forms of attack.
Show answer
Which of the following is not a physical security measure to protect against physical hacking?
- Create a phishing policy.
- Updating the patches in the software on your office laptop.
- Add a front desk and restrict unknown access to the back room.
- Analyze how employees maintain their physical data and storage devices.
Show answer
Patching is a technical control. The phishing policy (a) is administrative, so it is arguably also correct. If you get a similar question, pick the most clearly technical option and add a short note explaining why.
In cybersecurity, ICT stands for ______. And: ______ limits the execution of files or handling of data by specific installed programs.
- Encryption programs
- Anti-virus programs
- Application firewall
- Routers
Show answer
An application firewall works at the application layer and decides what a named program may run or handle.
In the SecSDLC, a preliminary risk assessment that produces an initial description of the basic security happens in which phase?
- Planning and Analysis
- Design
- Implementation
- Support
Show answer
Design does risk assessments (plural, full). "Preliminary" is the clue for the first phase.
"Study the current system, determine user requirements, recommend a solution" is which SDLC phase? And which phase identifies errors, monitors performance and updates?
Show answer
The main difference between SDLC and SecSDLC is:
- SecSDLC is faster to implement
- SecSDLC identifies threats and creates controls at every phase
- SecSDLC has fewer phases
- SecSDLC doesn't require testing
Show answer
Older past-paper extras (asked before, not on the current slides)
What is layer 4 of the OSI model?
- Presentation
- Network
- Data Link
- Transport
Show answer
Physical 1, Data Link 2, Network 3, Transport 4, Session 5, Presentation 6, Application 7.
What is a TCP wrapper?
- An encapsulation protocol used by switches
- An application that can serve as a basic firewall by restricting access based on user IDs or system IDs
- A security protocol protecting TCP/IP over WAN links
- A mechanism to tunnel TCP/IP through non-IP networks
Show answer
Which of the following is NOT true regarding firewalls?
- They are able to log traffic information
- They are able to block viruses
- They are able to issue alarms based on suspected attacks
- They are unable to prevent internal attacks
Show answer
That is the antivirus's job. Firewalls filter traffic by rules; they cannot stop internal attacks that never cross them.
What is encapsulation? And T/F: WEP uses a predefined shared secret key.
Show answer
Security Foundations and Principles
The vocabulary (vulnerability, threat, control, risk), the threat landscape, malware, social engineering, the CIA triad in depth, AAA and the protection mechanisms. This chapter has the most scenario questions.
The basics
Three entities to protect 3
- Endpoint devices (computers, smart devices, routers)
- Networks
- The cloud and data centers
Common protection technology 5
- Next-generation firewalls
- DNS filtering
- Malware protection
- Antivirus software
- Email security solutions
Vulnerability, threat, attack, control, risk
- Vulnerability: a weakness in procedures, design or implementation that might be exploited.
- Threat: a set of circumstances with the potential to cause loss or harm; a potential violation of security.
- Attack: what a human commits when they exploit a vulnerability.
- Control: an action, device, procedure or technique that removes or reduces a vulnerability.
- Risk: exists when a threat meets a vulnerability in the system or in a control.
Threat damage: the four types 4
- Interruption: asset unusable or unavailable → attacks Availability
- Interception: unauthorised party gains access → attacks Confidentiality
- Modification: unauthorised party changes the asset → attacks Integrity
- Fabrication: unauthorised party creates counterfeit assets → attacks Authenticity
Modern threat landscape and threat vectors
Modern threat landscape 5
- Supply chain and third party: compromised vendors, insecure SaaS, malicious updates. External human threats with indirect access.
- AI-enabled: AI phishing, deepfake voice/video. More scale, speed and realism.
- Cloud and API: misconfiguration, insecure APIs, token theft
- Insider (intentional vs unintentional): malicious insider or negligent insider
- Hybrid: cyber + physical, or cyber + psychological (cyber attack + fake social media campaign)
Threat vectors and techniques 9
- Malware: malicious software
- Ransomware: encrypts files, demands ransom
- Social engineering: tricks users into revealing information
- Supply chain attacks: hit trusted vendors to reach many organisations
- APTs: long-term, targeted, often state-sponsored, for espionage or data theft
- Zero-day exploits: unknown or unpatched vulnerabilities
- AI-powered attacks: automate attacks, bypass defences, deepfakes
- IoT and OT attacks: connected devices, industrial systems
- Cloud and API attacks: misconfigurations, insecure APIs
AI-driven threat vectors 5
- AI-generated malware: adapts to avoid detection, creates polymorphic variants
- AI-enhanced social engineering: personalised phishing using the target's style
- AI-driven reconnaissance: automated scanning, prioritises high-value targets
- AI deepfakes and impersonation: fake voice, video or text
- AI-optimized exploit kits: selects the most effective attack per target
Types of cyber attacker (Quiz 1)
| Attacker | Motive / signature | Quiz 1 scenario |
|---|---|---|
| Hacktivists | Political or social protest; disruption, not profit | DDoS on Russian government sites during the Ukraine war |
| Organized crime | Money; sustained, coordinated campaigns | Carbanak and Cobalt malware robbing 100 banks in 40+ countries |
| Script kiddies | Low skill, borrowed tools, known unpatched flaws; beaten by keeping systems updated | "Lack knowledge and sophistication" |
| State-based attackers | Government orders: espionage, surveillance | NSA recording phone calls in the Bahamas |
| Hackers | Generic skilled attacker exploiting technical flaws, no stated motive | Exploiting plug-ins and browsers to install malware |
Malware
Definition and types
Malware is any file or program used to harm a computer user.
- Virus: attaches to a host file, needs it to run
- Worm: spreads across networks by itself, no user action
- Trojan horse: disguised as legitimate software
- Spyware: secretly monitors activity
- Keylogger: records keystrokes (beaten by an on-screen keyboard)
- Backdoor: hidden unauthorised access
- Ransomware: encrypts or locks, demands payment
- Adware: unwanted advertising
Malware symptoms 9
- Increased CPU usage
- Slow computer or web browser
- Problems connecting to networks
- Freezing or crashing
- Modified or deleted files
- Strange files, programs or desktop icons appear
- Programs running, turning off or reconfiguring themselves
- Strange computer behaviour
- Emails/messages sent automatically without the user's knowledge
Malware countermeasures 5
- Install quality antivirus software
- Keep virus definitions regularly updated
- Never open an attachment from an untrusted source
- Take caution when surfing and downloading
- Back up data
Ransomware family (slide list)
WannaCry, Petya/NotPetya, Locky, Cerber, Jigsaw, Bad Rabbit, Ryuk, Dharma (CrySIS). The slide calls ransomware socially engineered malware.
Social engineering: spot it from the scenario
Social engineering relies on human interaction to trick users into breaking security procedures.
| Technique | Slide definition | The clue in the question |
|---|---|---|
| Phishing | Fraudulent emails that resemble reputable sources, to steal data | mass email, "click this link" |
| Spear phishing / Whaling | Targets a specific individual, group or organisation (whaling = a senior executive) | "specifically", named target, "the CEO" |
| Angler phishing | Latest form: social media, pretending to be customer service | Twitter/Instagram support account |
| Vishing / Smishing | Voice phishing / SMS phishing | phone call / text message |
| Pharming | Redirects to a fake site even when the correct URL is typed; poisons DNS or the local system | "typed the right address" |
| Pretexting | A fabricated story (pretext) to gain trust | "pretending to be from IT / the bank" |
| Baiting | Lures with attractive offers or rewards | free USB, prize, free download |
| Tailgating | Unauthorised person with a fake ID follows an authorised person through a door | "followed through the secure door" |
| Shoulder surfing | Spying on an ATM or device user to get a PIN or password (a confidentiality attack) | "watched her type" |
| Reverse social engineering | Attacker convinces the target they have a problem and offers to solve it | the victim contacts the attacker |
| Doxing | Publishing private, identifying information online with intent to harm | "posted her address online" |
| Zero-day | Unknown to those responsible for patching: no prior knowledge | "no signature, no patch, nothing online" |
Phishing vs pharming
Phishing is persuasive: the victim clicks a malicious link. Pharming is technical: DNS or the host is poisoned, so even the correct URL lands on the fake site. No click is needed.
Pretexting vs reverse social engineering
Pretexting: the attacker approaches with a made-up story. Reverse SE: the attacker causes or predicts a problem and the victim approaches the attacker for help. That is why the victim trusts them completely.
Social engineering countermeasures
- Password policies: periodic change, no guessable passwords, account blocking after failed attempts, length and complexity, secrecy
- Physical security policies: employee ID cards, area restrictions, shredding useless documents, security check before employment
- Effective training programme
- Operational guidelines
- Classification of information: top secret, proprietary, for internal use only, for public use
- Access privileges: administrator, user and guest accounts
- Two-factor authentication
The CIA triad in depth
Confidentiality: "keeping secrets secret"
Measures that protect the secrecy of data, objects or resources. Controls: encryption, access control, steganography.
Attacks:
- Stealing password files (public Wi-Fi, injected keylogger)
- Port scanning: messages sent to learn which network services (well-known ports) are running
- Shoulder surfing
- Eavesdropping: intercepting communications not meant for you (man in the middle)
- Sniffing: capturing network packets with a sniffer
- Privilege escalation: programming errors or design flaws grant elevated access
- Human errors (unintentional), intentional damage
Methods to ensure confidentiality
- Data encryption: the common method
- User IDs and passwords; two-factor is becoming the norm
- Biometric verification: fingerprints, hand and earlobe geometry, retina/iris, voice, DNA, signatures
- Security token: small hardware device carried to authorise network access
- Soft token: software token that generates a single-use login PIN
- Key fob: small programmable hardware device for access to a physical object needing 2FA/MFA
- Extra measures for extremely sensitive documents: air-gapped computers (no external connection) and disconnected storage devices
Integrity: reliable and accurate
Attacks: viruses, logic bombs, unauthorised access, errors in coding, system back doors.
Methods:
- File permissions and user access controls
- Version control: stops erroneous changes or accidental deletion by authorised users
- Checksums / hashing. Hash value = checksum. A cryptographic checksum is assigned to a file and used later to test that it has not been maliciously changed.
Restoring affected data: backups or redundancies. A checksum only detects a change.
Availability: accessible to authorised users at all times
Threats: device failure, software error, environmental issues (heat, flooding, power loss), DoS attacks, network intrusions.
To prevent data loss:
- Backup copy in a geographically isolated location, perhaps a fireproof, waterproof safe
- Firewalls and proxy servers against downtime
- Web application firewall (Cloudflare)
Availability calculation (Quiz 1)
Availability = MTTF ÷ (MTTF + MTTR) × 100. MTTR is the downtime, MTTF the uptime. Use one consistent window.
Downtime per weekly test = 45 + 80 + 15 = 140 min One week = 7 × 24 × 60 = 10,080 min MTTF = 10,080 − 140 = 9,940 A = 9,940 ÷ 10,080 × 100 = 98.6%
AAA services 5 elements
| # | Element | Slide definition | Banking example |
|---|---|---|---|
| 1 | Identification | Claiming to be an identity | Enter account number / username |
| 2 | Authentication | Proving you are that identity | Enter PIN, password, fingerprint |
| 3 | Authorization | Defining the allow/deny permissions for that identity | Which accounts you may see |
| 4 | Auditing | Recording a log of events and activities | The transaction is logged |
| 5 | Accounting / Accountability | Reviewing log files for compliance and violations to hold subjects accountable | The bank reviews the logs |
Protection mechanisms 4
Layering / defence in depth
Multiple controls in a series. Configurations: serial/parallel, mall, bank, airport.
Abstraction
Used for efficiency: similar elements put into groups, classes or roles that get controls or permissions as a collective.
Data hiding
Intentionally positioning data so it is not viewable or accessible to an unauthorised subject.
Encryption
The art and science of hiding the meaning or intent of a communication from unintended recipients.
Past-paper questions · Chapter 2
______ is the attack that causes company assets to become unusable or unavailable on a temporary or permanent basis.
- Interruption
- Interception
- Modification
- Fabrication
Show answer
Interception = confidentiality, Modification = integrity, Fabrication = authenticity.
______ is social-engineering-based malware that asks the victim to pay in order to unlock or decrypt the system or the data.
- Worm
- Virus
- Ransomware
- Adware
Show answer
Frequent emails from someone impersonating a bank, with a story about an account breach, trying to convince you specifically to disclose your credentials, is called ______.
- Phishing
- Spear phishing
- Whaling
- Pretexting
Show answer
"Specifically" decides it. Whaling needs a senior executive. Pretexting is the story inside the attack, not the attack's name.
Identify the attack: (1) ICMP replies flood the web server, and the requests' source IP was the server's own. (2) Three "free magazines" each ask for one personal detail. (3) Malware unseen for a week, nothing online, still investigating. (4) Credentials stolen from a lab PC even after logging out and clearing history. (5) Pop-ups appear; the victim calls the technician who warned him, hands over credentials, and the technician vanishes.
Show answer
1 Smurf attack (spoofed broadcast ping, amplified DoS) · 2 Salami theft (small slices that add up) · 3 Zero-day · 4 Keylogger (captured as typed) · 5 Reverse social engineering
An unauthorised person wearing a fake ID follows an authorised employee through a secure door. This is:
- Tailgating
- Baiting
- Shoulder surfing
- Reverse social engineering
Show answer
Which attack redirects a user to a fraudulent site even when the correct URL is typed?
- Phishing
- Pharming
- Pretexting
- Baiting
Show answer
Which phishing form targets people on social media by pretending to be customer service?
- Spear phishing
- Whaling
- Angler phishing
- Smishing
Show answer
An attacker convinces a target that they have (or will have) a problem, and offers to help solve it. This is:
- Pretexting
- Reverse social engineering
- Vishing
- Doxing
Show answer
A zero-day attack is best described as a threat that:
- Is unknown to the party responsible for patching the flaw
- Is launched one day after a patch
- Encrypts files and demands payment
- Publishes private information online
Show answer
"Zero days" of warning for the defenders. (c) is ransomware, (d) is doxing.
Long-term, targeted attacks, often state-sponsored, aimed at espionage or data theft are called:
- Zero-day exploits
- Advanced Persistent Threats
- Ransomware
- Hybrid threats
Show answer
Supply chain and third-party threats are classified as:
- Internal human threats with direct access
- External human threats with indirect access
- Environmental threats
- Unintentional insider threats
Show answer
A weakness in procedures, design or implementation that might be exploited to cause loss or harm is a:
- Threat
- Vulnerability
- Control
- Risk
Show answer
According to the slides, when does risk exist?
- Whenever a system is connected to the internet
- When a threat meets a vulnerability in the system or a control
- Only after a successful exploit
- When controls exist but users are untrained
Show answer
(c) is an attack that already happened. Risk is about potential.
A threat is a weakness in the security system.
Show answer
That is a vulnerability.
AAA is described in the lecture as referring to how many elements?
- Three
- Four
- Five
- Six
Show answer
Identification and Auditing are the two people forget.
Reviewing log files to check for compliance and violations, to hold subjects responsible, is:
- Auditing
- Accounting (accountability)
- Authorization
- Authentication
Show answer
Auditing is the recording. Accounting is the reviewing.
Claiming to be an identity when attempting to access a secured system is:
- Authentication
- Identification
- Authorization
- Accountability
Show answer
Which method of ensuring confidentiality is a software-based security token that generates a single-use login PIN?
- Key fob
- Security token
- Soft token
- Biometric verification
Show answer
Isolating a computer or network so it cannot establish any external connection is called:
- Air gapping
- Steganography
- Sandboxing
- Data hiding
Show answer
A series of messages sent to a machine to learn which network services are running is which confidentiality attack?
- Sniffing
- Port scanning
- Privilege escalation
- Eavesdropping
Show answer
Which set of controls does the slide name as protecting confidentiality?
- Encryption, access control and steganography
- Hashing, checksums and version control
- Backups, redundancy and firewalls
- Auditing, accounting and authorisation
Show answer
(b) is the integrity set, (c) is availability.
Viruses, logic bombs, unauthorised access, coding errors and system backdoors are attacks that violate:
- Confidentiality
- Integrity
- Availability
- Authenticity
Show answer
In case of data loss, ______ must be available to restore the affected data to its correct state.
- Backup
- Redundancies
- Checksum
- Both (a) and (b)
Show answer
A checksum detects the change but cannot restore anything.
Which of the following is listed as a threat to availability?
- Shoulder surfing
- Logic bombs
- Environmental issues such as heat, flooding and power loss
- Sniffing
Show answer
An ethical hacker tests every week for 3 months. Each round takes 45 min (system) + 1 h 20 min (network) + 15 min (recover traces), with everything disconnected. Total availability, 1 decimal place?
Show answer
140 min down out of 10,080 min per week: 9,940 ÷ 10,080 × 100.
Name the attacker: (1) DDoS on Russian government sites in the Ukraine war. (2) Carbanak and Cobalt hit 100 banks. (3) Low skill, uses well-known vulnerabilities. (4) NSA records nearly every call in the Bahamas. (5) Exploit plug-ins and browsers to install malware.
Show answer
1 Hacktivists · 2 Organized crime · 3 Script kiddies · 4 State-based attackers · 5 Hackers
Which is NOT one of the malware countermeasures given in the lecture?
- Install quality antivirus
- Keep virus definitions updated
- Disable the firewall so the antivirus can scan traffic freely
- Never open an attachment from an untrusted source
Show answer
Which AI-driven vector is malware that adapts to avoid detection and creates polymorphic variants automatically?
- AI-driven reconnaissance
- AI-generated malware
- AI-optimized exploit kits
- AI deepfakes
Show answer
Putting similar elements into groups, classes or roles that get security controls as a collective is:
- Abstraction
- Data hiding
- Layering
- Classification of information
Show answer
Under the social engineering countermeasures, information should be classified as:
- Top secret, secret, confidential, unclassified
- Top secret, proprietary, for internal use only, for public use
- Public, private, restricted, sensitive
- Storage, transmission, processing
Show answer
(a) is the government scheme from chapter 4. There are three classification lists in this course; see the Differences section.
Which pair correctly names the two kinds of insider threat in the modern threat landscape?
- Malicious insider and negligent insider
- External insider and internal insider
- Physical insider and cyber insider
- State-sponsored and criminal insider
Show answer
What is doxing?
- Creating fake documents
- Encrypting documents for ransom
- Publishing private information online with intent to harm
- Stealing documents from trash
Show answer
Threat Modeling
The vocabulary again (with slightly different wording from chapter 2), proactive vs reactive, the ways to identify threats, STRIDE, and the supply chain. STRIDE is the part most worth drilling.
What threat modeling is
Definition: a structured security process 4 steps
- Identify potential threats
- Analyze how those threats could exploit vulnerabilities
- Determine the impact on valuable assets
- Define appropriate security controls
It prevents security issues before they become real attacks.
The older papers used three key steps: Visualize → Identify threats → Validate. "Execute" is not a step. (Final B Q5)
The dictionary 7
- Asset: any element with value to the organisation that must be protected
- Threat: any potential event causing an unwanted impact
- Attack: any actual event causing an unwanted impact
- Vulnerability: the absence of a safeguard or a weakness a threat might use
- Threat agent: the entity (person or process) that initiates the threat
- Exploit: the vulnerability is found by a threat agent and the threat is initiated
- Control / countermeasure / safeguard: any step that prevents the exploit, or minimises its damage
Risk 4 elements
Risk is the possibility or likelihood that a threat will exploit a vulnerability, resulting in a loss such as harm to an asset.
Risk management reduces or eliminates vulnerabilities, or reduces the impact of threats, by implementing controls.
- Threat
- Vulnerability
- Asset
- Damage
Proactive vs reactive
| Proactive | Reactive | |
|---|---|---|
| Also called | Defensive approach | Adversarial approach |
| When | During system design and development | After deployment, or after an incident |
| Based on | Predicting threats; defences designed in while coding | Observed attacks or failures; post-deployment patches |
| Result | Security built in from the start | Security added later |
| Verdict | Proactive is the preferred and more effective approach. | |
Identifying threats
Three key approaches 3
- Focused on assets: uses asset valuation. "What is valuable?"
- Focused on attackers: identifies potential attackers and their goals. "Who would harm us and why?"
- Focused on software: threats against software the organisation develops. "Where are the weaknesses?"
Other modern approaches 5
- System / architecture-focused: components, interactions, trust boundaries (exposed internal APIs, lateral movement)
- Data-focused: how sensitive data is stored, sent, processed (breaches are the most common impact)
- Supply chain / third-party: vendors, libraries, APIs
- Environment / deployment-focused: cloud, on-prem, containers; misconfigurations are a top vector
- Emerging technology: agentic AI, IoT/OT
Three primary steps to identify threats 3
- Identify all of the technologies involved
- Identify attacks against each element of the diagram: logical/technical, physical and social
- Prevention measures
Threat models named on the slide
STRIDE, PASTA, LINDDUN, CVSS, Attack Trees, Persona non Grata, OCTAVE.
PASTA (Process for Attack Simulation and Threat Analysis) is risk-centric: countermeasures chosen against the value of the assets. (Final B Q2)
The university platform example (asset, actor, vulnerability, scenario)
| Asset | Threat actor | Vulnerability | Threat scenario |
|---|---|---|---|
| Student grades | Student | Weak authentication | Student changes their own grade |
| Exam content | Hacker | SQL injection | Extracts upcoming exam questions |
| Faculty login | Hacker | Phishing, no MFA | Accesses faculty account to manipulate data |
| Platform uptime | Insider | Misconfigured permissions | Staff deletes files causing downtime |
STRIDE (Microsoft's threat categorisation)
| Threat | Meaning | Property violated | Example | Countermeasures |
|---|---|---|---|---|
| Spoofing | Access through a falsified identity | Authentication | Logging in with stolen credentials; pretending to be PayPal.com | Digital signatures, Active Directory, LDAP, passwords, crypto tunnels |
| Tampering | Unauthorised change or manipulation of data | Integrity | Changing form prices; modifying a transfer amount in transit | Hashing, digital signatures, ACLs, crypto tunnels |
| Repudiation | Ability to deny having performed an action | Non-repudiation | "I didn't send that email"; denying a transfer | Digital signatures, logging |
| Information disclosure | Private data revealed to unauthorised entities | Confidentiality | Balances exposed via API; customer list published | Encryption, ACLs, PGP, SSL/TLS |
| Denial of service | Prevent authorised use (connection overloading, traffic flooding) | Availability | Flooding the login page | Load balancers, more capacity |
| Elevation of privilege | Limited account gets greater privileges | Authorization | Regular user exploits a bug to become admin | Isolation, input validation, firewalls, sandboxing |
Supply chain
Definitions
A supply chain is the network between a company and its suppliers to produce and distribute a product to the final buyer. Most systems are not built by a single entity.
A secure supply chain: every vendor or link is reliable, trustworthy and reputable, and discloses its practices and security requirements to partners.
Goal of a secure supply chain
- The finished product is of sufficient quality, meets performance and operational goals, and provides the stated security mechanisms
- At no point was any element counterfeited or subjected to unauthorised or malicious manipulation or sabotage
How the security team inspects vendors 4
- On-site assessment: visit, interview, observe habits
- Document exchange and review: how data and documents are exchanged and reviewed
- Process/policy review: copies of policies, procedures, incident records
- Third-party audit: an independent auditor
Past-paper and exam-style questions · Chapter 3
PASTA is a ______ that aims at selecting or developing countermeasures in relation to the value of the assets to be protected.
- Attacker-centric approach
- Risk-centric approach
- Software-centric approach
- Application-centric approach
Show answer
"In relation to the value of the assets" is the clue.
Which of the following is not a key step while doing threat modeling?
- Visualize
- Identify threats
- Execute
- Validate
Show answer
A banking app user makes a transfer and later claims they never made it. Which STRIDE threat, and which property is violated?
Show answer
Countermeasure: digital signatures and logging.
A regular user exploits a bug to open the admin panel. Which STRIDE threat, and which countermeasures?
Show answer
Isolation, input validation, firewalls, sandboxing.
Threat modeling performed after a product is deployed, based on observed attacks, is called ______ and is also known as the ______ approach.
Show answer
Proactive = defensive, and proactive is preferred.
Differentiate between a threat and an attack, and name the entity that initiates a threat.
Show answer
A threat is a potential event with an unwanted impact; an attack is an actual event. The initiating entity is the threat agent (a person or a process).
Protection of Information Assets
Governance, due care, classification, data states, retention and destruction, privacy laws, ownership roles and the three security plans. Lots of "which role" and "which level" questions, and the short answers come from here.
Information assets
Definition
An information asset is any information that has value to an organisation, regardless of its form: student or customer records, financial data, intellectual property, research data.
Primary assets are the information itself. Supporting assets are the software, hardware, network, people and physical things that hold or process it (servers, LMS, routers, admins, data centers).
Why protect them
- Information is a core business resource
- Loss of confidentiality → privacy violations, legal penalties
- Loss of integrity → wrong decisions, operational failures
- Loss of availability → disrupted services and continuity
- Breaches damage reputation and trust
So it is a strategic, legal and governance requirement, not only a technical one.
Information asset security domain
Collecting, handling and protecting information throughout its lifecycle. A primary step is classifying information by its value.
How: secure systems and environments, hardware and software controls, encryption and access control, monitoring and auditing.
Governance
Security governance
The collection of practices for supporting, defining and directing the security efforts of an organisation. It ensures clear accountability, consistent practices, compliance and oversight, enforced through policies, standards, procedures and audits.
Corporate governance: "doing the right things for the organisation and doing things the right way, independent of personal interests."
Security is a business operations issue, not an IT-only issue. Usually run by a governance committee or the board. Frameworks: NIST 800-53, 800-100 (government/military focus, usable by others).
Governance vs management
| Governance | Management | |
|---|---|---|
| Level | Strategic oversight | Tactical, operational execution |
| Asks | "Are we doing the right things?" | "Are we doing things right?" |
| Who | Senior leadership, board, committees | CISO, managers, analysts, technical staff |
| Example | Approving policies, defining acceptable risk | Deploying firewalls, monitoring, vulnerability scans |
Third party and cloud (ASP)
An Application Service Provider hosts and maintains software on its own servers and delivers it over the internet.
- The organisation remains accountable for data protection
- Due diligence before engagement
- Contracts and SLAs define security responsibilities
Due care vs due diligence (Final 221 A, 3 marks)
| Due care | Due diligence | |
|---|---|---|
| Current slides | The reasonable steps an organisation takes to protect its assets by following accepted practices | Goes further: actively identifying and analysing risks |
| Slide examples | Strong password policies, applying patches, antivirus and firewalls | Risk assessments, auditing third-party providers, reviewing incident history and vulnerabilities |
| Governance view | Demonstrates responsible operation | Demonstrates proactive risk management |
| Final 221 A key | Doing the right thing: building the security structure (policy, standards, baselines, guidelines, procedures) | Continuing to apply and maintain that structure |
| Relation | Due care sets it up, due diligence keeps checking it works. Both are needed to avoid negligence and legal liability. | |
Classification: three lists you must not mix
Government / military 4
- Top Secret: "exceptionally grave damage" to national security
- Secret: "serious damage"
- Confidential: "damage"
- Unclassified: can go to the public with no threat to national interest
Commercial (organisational) 4
- Restricted (sensitive / critical)
- Confidential
- Internal (private)
- Public (unclassified)
No standard: each company chooses its own and it is usually simpler than the government scheme. The more regulated the company, the more complex its scheme.
Social engineering countermeasure (Ch2) 4
- Top secret
- Proprietary
- For internal use only
- For public use
Classification criteria 4
- Business value
- Legal and regulatory impact (PDPL, GDPR)
- Reputational damage
- Operational impact
Guiding question: what is the worst possible impact if this is disclosed, altered or destroyed? Higher impact → higher level → stronger controls.
Restricted data examples
- PII: identifies an individual (name, SSN, date and place of birth, mother's maiden name, biometrics)
- PHI: health information tied to a person
- Proprietary data: keeps a competitive edge (source code, product plans, internal processes), protected by copyrights, patents and trade secret law
Class exercise: sort into 4 categories
The slide leaves this as an exercise. A suggested sort, using the worst-impact question:
- Cat 4 highly sensitive: credit card numbers (PCI), PHI, SSNs, financial account numbers, trade secrets, intellectual property
- Cat 3 sensitive internal: student education records, customer personal data, employee records, employee pay cheques, supplier and vendor contracts
- Cat 2 internal: internal emails, employee directory, IT service management information
- Cat 1 public: public website content, marketing materials, newsletters, press releases, social media feeds
Marking, handling and data states
Marking (labelling)
So users can easily identify the classification of any data.
- Physical labels on media and systems
- Electronic labels: header/footer or watermark. Benefit: they also appear on printouts.
Asset classifications should match data classifications. A data breach is any event where an unauthorised entity can view or access classified data.
Protecting each state
- At rest (drives, databases, backup tapes, USBs): encryption (AES-256), access controls, secure facilities, environmental controls (HVAC, fire suppression)
- In transit: encrypted channels, secure protocols, network monitoring
- In use: access control, endpoint security, memory protection
Retention
Keep information for as long as it is needed for business operations, legal and regulatory compliance, and audit. Periods come from policy, industry standards or law (3 years, 7 years, indefinitely). When the period expires, securely destroy it.
Secure destruction and sanitization
Two things destruction prevents
- Data recovery: retrieving lost, deleted, corrupted or inaccessible data when normal access is no longer possible
- Data remanence: the data that remains on media after it was supposedly erased
Paper: cross-shredding is recommended. Digital: the method depends on the media type.
Sanitization ladder, weakest to strongest
- Erasing: a plain delete. Everything is still recoverable.
- Formatting: delete plus a new file structure. Still recoverable in most cases.
- Clearing (overwriting): prepares media for reuse; not recoverable with traditional tools.
- Purging (multiple overwrites / degaussing): stronger clearing, for reuse in less secure environments.
- Destruction: end of the media's life. The most secure method.
Declassification: any process that purges media so it can be reused in an unclassified environment.
Degaussing
A degausser generates a heavy magnetic field that realigns the magnetic domains of hard drives, tape and floppy disks, removing data remanence.
Final 221 A Q19: to reuse an HDD with no recoverable bit, use degaussing, because the field destroys the stored magnetic pattern itself.
Data protection laws
| Law | Where | What to remember |
|---|---|---|
| GDPR | European Union | Collection and processing of personal data of people living in the EU; applies wherever the website is based if it attracts EU visitors; heavy fines |
| CCPA / CPRA | USA, California | Consumers get more control over personal information businesses collect |
| HIPAA | USA | National standards protecting patient health information (PHI) |
| GLBA | USA | Financial institutions must explain information-sharing practices and safeguard data |
| PDPL | Saudi Arabia | In force 14 September 2023 by Royal Decree; regulator SDAIA; covers electronic and non-electronic data, including foreign entities processing Saudi residents' data; fines up to SAR 5 million (doubled for repeats); up to 2 years prison for unlawful disclosure of sensitive data with intent to harm |
The US has no single federal law: it is sectoral and state-based, and generally more business-friendly than GDPR.
Ownership roles
| Role | Responsibility | University | Library |
|---|---|---|---|
| CISO | Accountable for protecting organisational data; leads the security team, reports directly to senior management | ||
| Information owner | Usually a business or department head. Decides classification, approves access rights, ensures protection | Registrar's Office | Library Director |
| Information steward | Technical accountability for how information supports the business; data quality and business use | Librarian | |
| Information custodian | Implements technical controls, keeps the data accessible as the owner and steward direct | IT Department | IT Admin |
| Information user | Uses information according to its classification | Faculty, advisors | Borrowers |
Data owner responsibilities (NIST SP 800-18)
- Establishes rules for appropriate use and protection
- Gives input to system owners on security requirements and controls
- Decides who has access and with what privileges
- Helps identify and assess common security controls
System (asset) owner responsibilities (NIST SP 800-18)
- Develops the system security plan with information owners, admin and users
- Maintains the plan and runs the system to its requirements
- Ensures users and support staff get security training
- Updates the plan after any significant change
- Helps identify, implement and assess common controls
Business / mission owner and best practices
NIST calls the business/mission owner a program manager or information system owner; they ensure systems provide value. The role can overlap with the system owner.
Best practices: classify correctly, least privilege, strong authentication, encrypt sensitive data, monitor and log access, DLP, regular audits and awareness training.
Security management planning
Top-down approach
The main objective is to align security with the organisation's strategy, goals, mission and objectives. Senior management initiates policies, approves objectives and defines acceptable risk. The security team should be autonomous.
The security management plan includes: defining security roles, how security is managed, who is responsible, how effectiveness is tested, developing policies, risk analysis, and security education.
Three plans 3
| Plan | Horizon | Answers | Bank example |
|---|---|---|---|
| Strategic | Long term, 3–5 yrs, reviewed yearly; includes a risk assessment | Why secure? Which assets are critical | Adopt ISO 27001, create the CISO role |
| Tactical | Mid term, about 1 yr; can be ad hoc | What controls to implement | MFA, encryption, SIEM, IR plan; project, hiring, budget plans |
| Operational | Short term, updated monthly or quarterly | How controls are applied daily | 24/7 log monitoring, weekly scans, monthly access reviews |
Past-paper questions · Chapter 4
In the governmental context, data should be classified rigidly into one of the following classes except ______.
- Top Secret
- Critical
- Secret
- Unclassified
Show answer
Government: Top Secret, Secret, Confidential, Unclassified. Critical is a commercial label.
You want to reuse a hard disk (HDD). What is the best sanitization technique to ensure no single bit can be recovered? Explain.
Show answer
A strong magnetic field resets the magnetic domains that store the bits, so no remanence is left. (Destruction is stronger but you could not reuse the disk.)
Using an example, differentiate between due care and due diligence, and show the relation between the two.
Show answer
Due care: the reasonable steps a prudent organisation takes to protect its assets, e.g. setting a password policy and patching. Due diligence: the continuing effort to check those steps still work and find new risks, e.g. regular risk assessments and auditing vendors. Relation: due care sets it up, due diligence keeps it effective. Together they prevent negligence.
______ allows the systems admin to grant users the exact privileges they need to accomplish a task, with no additions.
- Least privilege
- Need to know
- Access control list
- Security clearance level
Show answer
Need to know is about information a person may see; least privilege is about actions.
An employee moves teams and keeps the old rights while gaining new ones. This is called ______.
- Default to Zero
- Need to Know
- Authorization Creep
- Declassification
Show answer
It violates least privilege. Declassification is the chapter 4 media term, used here as a distractor.
The Registrar decides who may access student records; IT manages the servers and backups. Name both roles.
Show answer
A plan valid for about one year that includes a hiring plan for SOC analysts and an MFA project plan is a ______ plan.
Show answer
Which sanitization level prepares media for reuse in a less secure environment, and which one prepares it for an unclassified environment?
Show answer
Cryptography
Vocabulary, Kerckhoffs, the three ways to classify ciphers, the classical ciphers (practise every worked example), block ciphers and their modes, and the attacks. Expect calculation questions here.
Vocabulary
Terms
- Plaintext: original message. Ciphertext: coded message.
- Cipher: the algorithm. Key: info known only to sender and receiver.
- Encipher / encrypt: plaintext → ciphertext. Decipher / decrypt: ciphertext → plaintext.
- Cryptography: making and using codes ("secret writing").
- Cryptanalysis (codebreaking): deciphering without knowing the key.
- Cryptology: the field of both.
Notation: EK(P) = C, DK(C) = P, and DK(EK(P)) = P. Plaintext and ciphertext are typically the same length.
Two facts they love
- Cryptography can protect confidentiality and integrity, but not availability.
- Kerckhoffs's principle: the algorithm is public; security depends only on the secrecy of the key. Assume Eve knows the algorithm.
- Symmetric encryption is about 30,000 times faster than public-key encryption.
Classify a cryptosystem 3 dimensions
- Number of keys: same key = symmetric (conventional); different keys = asymmetric (public key)
- Type of operation: substitution (each element mapped to another) or transposition/permutation (rearranged)
- Plaintext processing: block (a block at a time) or stream (an element at a time)
Cipher tree: Symmetric (classical: substitution, transposition; modern: block, stream), Asymmetric, Hash.
Classical ciphers: the solving rules
| Cipher | You are given | Encrypt | Decrypt | Remember |
|---|---|---|---|---|
| Caesar | Shift n | E(x) = (x + n) mod 26 | D(x) = (x − n) mod 26 | Build the shifted alphabet first |
| ROT13 | Nothing (n = 13) | Shift 13 | Shift 13 again | Applying it twice gives the plaintext back |
| Keyword | Keyword | Keyword without duplicates, then the rest of the alphabet in order; map top → bottom | Map bottom → top | Remove duplicates from the keyword, not the message. Still monoalphabetic. |
| Playfair | Keyword → 5×5 matrix (I/J share) | Pairs; same row → right; same column → below; else rectangle | Same row → left; same column → above; rectangle | Repeated letter in a pair → insert X. 676 digrams. |
| Vigenère | Keyword + table | Repeat keyword to message length; row = plaintext, column = key, intersection = cipher | Row = key, find cipher letter, column = plaintext | Polyalphabetic: a different Caesar shift per letter |
| One-time pad | Random shift per letter | Shift each letter by its own random key | Reverse each shift | The only absolutely unbreakable cipher (Mauborgne and Vernam, 1917) |
| Hill | Invertible n×n matrix | Letters → numbers (A = 0), blocks × K mod 26 | Blocks × K−1 mod 26 | Lester Hill 1929. Hides single-letter frequencies. |
| Transposition | Column order key | Write in a 2D table, swap columns by the key | Undo the column order | Letters keep their form, only positions change |
Worked examples (verified)
Caesar and ROT13
a = 0, n = 14: E(0) = (0 + 14) mod 26 = 14 → O "CAT", n = 3: C(2)→F A(0)→D T(19)→W = FDW "We love PSU", ROT13 = Jr ybir CFH
The slide writes E(a) = 1 + 14 = 15 = "o" with A = 1. Both give O; use A = 0 unless told otherwise.
Keyword cipher: "PSU IS MY CHOICE"
Keyword without repeats: P S U I M Y C H O E Then the rest: A B D F G J K L N Q R T V W X Z Plain : A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Cipher: P S U I M Y C H O E A B D F G J K L N Q R T V W X Z HELLO → HMBBG SMART → NDPLQ STUDYHARD → NQRIXHPLI BPZX → LAZY (decrypt)
Keyword cipher: "ZEBRAS" (decrypt)
Plain : A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Cipher: Z E B R A S C D F G H I J K L M N O P Q T U V W X Y SIAA ZQ LKBA VA ZOA RFPBLUAOAR FLEE AT ONCE WE ARE DISCOVERED
Playfair: keyword MONARCHY, plaintext HELLO
HELLO → HE LX LO (LL split with filler X) HE: rectangle → C F LX: rectangle → S U LO: rectangle → P M
Vigenère: GEEKSFORGEEKS, keyword AYUSH
Plain : G E E K S F O R G E E K S Key : A Y U S H A Y U S H A Y U Cipher: G C Y C Z F M L Y L E I M Each letter: (plain + key) mod 26 E(4) + Y(24) = 28 mod 26 = 2 → C
Hill: "july", K = [11 8 ; 3 7]
j u = (9, 20) l y = (11, 24)
(9, 20) · K = (9·11 + 20·3, 9·8 + 20·7)
= (159, 212) mod 26 = (3, 4) → D E
(11, 24) · K = (121 + 72, 88 + 168)
= (193, 256) mod 26 = (11, 22) → L W
"july" → DELW
Decrypt: det = 11·7 − 8·3 = 53 ≡ 1 (mod 26)
K⁻¹ = [7 −8 ; −3 11] = [7 18 ; 23 11] mod 26
(3, 4) · K⁻¹ = (113, 98) mod 26 = (9, 20) → j u
Attacking substitution: frequency analysis
Letters in natural language are not uniformly distributed, so letter (and pair, triple) frequencies break substitution ciphers. There are 26! (over 4 × 1026) substitution alphabets, but frequency analysis makes the key space irrelevant.
Why Playfair and Hill are stronger
Playfair (Wheatstone 1854, named after Baron Playfair) encrypts digrams: 26 × 26 = 676, so a 676-entry frequency table and much more ciphertext are needed. Used in WW1, but breakable with a few hundred letters.
Hill completely hides single-letter frequencies, so it resists ciphertext-only attacks.
Monoalphabetic vs polyalphabetic
Monoalphabetic (Caesar, keyword): one fixed substitution alphabet. Polyalphabetic (Vigenère): the alphabet changes with each key letter. Final A Q5 calls Vigenère "an advanced version of Caesar based on a keyword".
Modern block ciphers
Block cipher basics
Encrypts an n-bit block with a k-bit key. Plaintext is split into fixed-length blocks.
Padding: the plaintext length must be a multiple of the block size. Padding must be unambiguous (not just zeros), and the last block is always padded. Slide example, b = 64 bits (8 bytes): "Roberto" (7 bytes) → "Roberto9", where 9 denotes a number, not the character. The padding is a value the receiver can read and strip, which is why plain zeros are not allowed.
The algorithms
| Cipher | Block | Key | Fact |
|---|---|---|---|
| DES | 64 | 56 | IBM, NIST 1977; brute force feasible since the late 90s |
| 3DES | 64 | 168 | Three DES keys, E-D-E; equals DES when KA = KB = KC |
| AES | 128 | 128 / 192 / 256 | NIST 2001, open competition |
| IDEA | 128 | Used in PGP email | |
| RC5 | Variable | MIT | |
| Blowfish | Up to 448 | Bruce Schneier, 1993 |
Triple DES order
Encrypt: C = E_KC( D_KB( E_KA(P) ) ) Decrypt: P = D_KA( E_KB( D_KC(C) ) )
Decryption undoes the last step first: decrypt with K3, encrypt with K2, decrypt with K1.
Nominal key length 168 bits. (In practice meet-in-the-middle gives about 112 bits, but answer 168 if the slide wording is asked.)
Block cipher modes 5
| Mode | Encryption | How to recognise it |
|---|---|---|
| ECB, Electronic Code Book | C[i] = EK(P[i]) | Each block on its own; identical plaintext blocks give identical ciphertext |
| CBC, Cipher Block Chaining | C[i] = EK(C[i−1] ⊕ P[i]) | XOR then encrypt; first block XOR'd with the initialization vector |
| CFB, Cipher Feedback | C[i] = EK(C[i−1]) ⊕ P[i] | Encrypt the previous ciphertext then XOR |
| OFB, Output Feedback | V[i] = EK(V[i−1]); C[i] = V[i] ⊕ P[i] | Like a one-time pad made of generated blocks, starting from V0 |
| CTR, Counter | V[i] = EK(s + i − 1) | Uses a seed; can run in parallel and recover from dropped blocks |
Attacking conventional encryption
Objective and approaches
The objective is to recover the key, not just one message, so every past and future ciphertext is compromised. Two approaches: cryptanalysis and brute force. The algorithm is assumed known in every attack.
Cryptanalysis by what the attacker has 4
- Ciphertext only: only ciphertexts of several messages
- Known plaintext: some plaintext–ciphertext pairs, not chosen
- Chosen plaintext: can choose plaintexts to encrypt (has the encryption box)
- Chosen ciphertext: can choose ciphertexts to be decrypted (has the decryption box); goal is the key
Brute force table
| Key | 1 decr/µs | 10⁶ decr/µs |
|---|---|---|
| 32 bit | 35.8 min | 2.15 ms |
| 56 (DES) | 1142 years | 10.01 hours |
| 128 (AES) | 5.4 × 10²⁴ yrs | 5.4 × 10¹⁸ yrs |
| 168 (3DES) | 5.9 × 10³⁶ yrs | 5.9 × 10³⁰ yrs |
| 26! perm. | 6.4 × 10¹² yrs | 6.4 × 10⁶ yrs |
Hashing facts asked on the finals
Hashing vs encryption (Final 221 B, Q17)
- A hash gives a fixed-size output whatever the input; ciphertext grows with the plaintext.
- Hashing is one-way and irreversible (no key recovers the input); encryption is designed to be reversed with the key.
Hash algorithm facts
- SHA-3: 256 and 512 bits (course wording), built on Keccak, structured differently from the rest of the SHA family (Final B Q3)
- SHA-1 digest is 160 bits
- MD4 is faster and less secure than MD5; MD5 was designed to fix MD4 (Final B Q4)
Past-paper questions · Chapter 5
The ______ is an advanced version of the Caesar cipher in which the alphabetic text is encrypted by matching the plaintext with ciphertext based on a provided keyword.
- Vigenère cipher
- Keyword cipher
- One Time Pad
- Hill cipher
Show answer
The keyword cipher also uses a keyword, but it builds one fixed alphabet (monoalphabetic). "Advanced Caesar" = a Caesar shift per letter.
Triple DES applies three phases of encryption with different keys. Which order is correct for decryption?
- Encrypt K1, decrypt K2, encrypt K3
- Encrypt K3, decrypt K2, encrypt K1
- Decrypt K1, encrypt K2, decrypt K3
- Decrypt K3, encrypt K2, decrypt K1
Show answer
(a) is the encryption order. (c) has the operations right but the keys in the wrong direction.
Cryptography can protect which TWO of the three CIA properties?
- Confidentiality and Availability
- Integrity and Availability
- Confidentiality and Integrity
- All three
Show answer
A DoS makes encrypted data unreachable however strong the encryption is.
T/F: According to Kerckhoffs's principle, the encryption algorithm must be kept secret; only the key is known publicly.
Show answer
The other way round: the algorithm is public, the key is secret.
Cryptosystems are classified along three independent dimensions. Which is NOT one of them?
- Number of keys used
- Type of operation
- Way the plaintext is processed
- Length of the plaintext message
Show answer
T/F: Symmetric encryption is about 30,000 times faster than asymmetric. T/F: ROT13 applied twice returns the original plaintext.
Show answer
Caesar with n = 14: encrypt "a" (position 0). Then encrypt "CAT" with n = 3.
Show answer
In a keyword cipher with keyword "PSU IS MY CHOICE", what is the FIRST step before building the cipher alphabet?
- Reverse the keyword
- Remove repeated letters from the keyword
- Sort the keyword alphabetically
- Convert the keyword to numbers
Show answer
Which technique attacks substitution ciphers using letter frequencies? How many digrams does Playfair use? What do you insert between repeated letters in a pair (HELLO)?
Show answer
T/F: The one-time pad is the only theoretically unbreakable substitution cipher. And: in a transposition cipher, what happens to the plaintext characters?
Show answer
DES block and key size? 3DES key length? T/F: AES uses 128-bit blocks with 128, 192 or 256-bit keys.
Show answer
If the last block of plaintext is too short, what must be done? In CBC, what is the first block XOR'd with?
Show answer
Which block cipher mode can be performed in parallel and can recover from dropped blocks?
- ECB
- CBC
- CFB
- CTR
Show answer
The Hill cipher's main strength? How do you decrypt it? T/F: "july" with K = [11 8 / 3 7] gives "DELW".
Show answer
In the Vigenère cipher, if the keyword is shorter than the plaintext, what happens?
- Encryption stops
- The keyword is repeated to match the plaintext length
- Remaining letters use shift 0
- A new random keyword is generated
Show answer
What extra power does a chosen-plaintext attacker have over a known-plaintext one? An attacker holds only intercepted ciphertexts: which attack? In a chosen-ciphertext attack, what is the goal?
Show answer
From the brute-force table, how long to break a 56-bit DES key at 1 million decryptions per microsecond?
- About 35 minutes
- About 2 milliseconds
- About 10 hours
- About 1,142 years
Show answer
1,142 years is the same key at 1 decryption per µs.
SHA-3 supports hash lengths of ___. MD4 is the ___ algorithm and ___ secure than MD5. Give two differences between hashing and encryption.
Show answer
You subscribe to a sports channel and get a licence to decrypt it. Which key does the decryption use?
- A private key of their server
- A private key generated in my device, used by me only
- A public key sent by their server to everyone
- My public key generated in my device
Show answer
Public keys encrypt or verify; only your own private key decrypts what was sent to you. (This one leans into chapter 6.)
Tell the difference
Every pair the papers try to confuse, in one place. Cover the right column and explain each difference out loud.
| Pair | The difference in one line | Ch |
|---|---|---|
| Pillars vs entities vs CIA vs components | Pillars = People, Policies, Technology (what you combine). Entities = endpoints, networks, cloud (what you protect). CIA = the goals. Components = software, hardware, data, people, procedures (what an IS is made of). | 1–2 |
| Confidentiality vs possession | Reading implies holding; holding (encrypted) does not imply reading. | 1 |
| Integrity vs accuracy vs authenticity | Not changed by the unauthorised / the value is right / it is the original. | 1 |
| Defence-in-depth layers vs organisation's security layers | Physical, Perimeter, Network, Host, Application, Data vs Physical, Personnel, Operations, Communications, Network, Data. | 1 |
| Defence in depth vs redundancy | Independent controls in series vs a standby copy that takes over (availability). | 1 |
| SDLC vs SecSDLC | Same phases; SecSDLC adds threat identification and specific controls in every phase. | 1 |
| Vulnerability vs threat vs attack vs risk vs control | Weakness / potential harm / exploited for real / threat meets weakness / removes or reduces the weakness. | 2–3 |
| Interruption vs interception vs modification vs fabrication | Availability / confidentiality / integrity / authenticity. | 2 |
| Virus vs worm vs Trojan | Needs a host file / spreads alone over the network / pretends to be legitimate. | 2 |
| Phishing vs pharming | Click a lure vs poisoned DNS, correct URL still lands on the fake site. | 2 |
| Spear phishing vs whaling vs angler | Specific target / senior executive / social media "customer service". | 2 |
| Pretexting vs reverse social engineering | Attacker approaches with a story vs victim approaches the attacker for help. | 2 |
| Baiting vs tailgating | Tempting offer vs physically following someone through a door. | 2 |
| Eavesdropping vs sniffing vs port scanning | Intercept a conversation (MITM) / capture packets with a sniffer / probe which services run. | 2 |
| Security token vs soft token vs key fob | Hardware for network access / software, single-use PIN / hardware for a physical object. | 2 |
| Identification vs authentication vs authorization | Claim / prove / permissions. | 2 |
| Auditing vs accounting | Recording the log vs reviewing the log to hold people accountable. | 2 |
| Data hiding vs encryption | Positioning data so it cannot be reached vs hiding its meaning. | 2 |
| Abstraction vs layering | Grouping for efficiency vs multiple controls in series. | 2 |
| Proactive vs reactive | Defensive, during design (preferred) vs adversarial, after deployment or an incident. | 3 |
| Threat vs threat agent | The potential event vs the person or process that initiates it. | 3 |
| Governance vs management | Doing the right things (strategic) vs doing things right (operational). | 4 |
| Due care vs due diligence | Taking reasonable steps vs actively checking and analysing risk. | 4 |
| Government vs commercial classification | TS, S, C, U vs Restricted, Confidential, Internal, Public. | 4 |
| Owner vs custodian vs steward vs user | Decides / implements / data quality / uses per classification. | 4 |
| Data recovery vs data remanence | Getting lost data back vs data left behind after "erasing". | 4 |
| Clearing vs purging vs destruction | Overwrite for reuse / stronger, reuse in less secure places / end of life, most secure. | 4 |
| Strategic vs tactical vs operational | Why, 3–5 yrs / what, ~1 yr / how, monthly or quarterly. | 4 |
| Cryptography vs cryptanalysis vs cryptology | Making codes / breaking without the key / the field of both. | 5 |
| Substitution vs transposition | Letters replaced vs letters keep their form but move. | 5 |
| Block vs stream | A block at a time vs one element at a time. | 5 |
| Keyword vs Vigenère | One fixed alphabet (mono) vs a shift per key letter (poly). | 5 |
| CBC vs CFB | XOR then encrypt vs encrypt then XOR. | 5 |
| Known vs chosen plaintext | Has pairs vs can pick the plaintexts to encrypt. | 5 |
| Chosen plaintext vs chosen ciphertext | Encryption box vs decryption box. | 5 |
| Hashing vs encryption | Fixed-length and one-way vs variable-length and reversible with a key. | 5 |
Lists to recite before the exam
If you can write each of these from memory, with the count, you can answer every "list", "except" and "match" question above.
- 3Pillars: People, Policies, Technologies
- 4Security terms: information, computer, IT, cyber security
- 7Characteristics: CIA + Accuracy, Authenticity, Utility, Possession
- 3×3McCumber: CIA · Storage, Transmission, Processing · Policy, Education, Technology
- 5IS components: Software, Hardware, Data, People, Procedures
- 6DiD layers: Physical, Perimeter, Network, Host, Application, Data
- 6Org layers: Physical, Personnel, Operations, Communications, Network, Data
- 5SDLC: Planning, Analysis, Design, Implementation, Support
- 4SecSDLC: Planning & Analysis, Design, Implementation, Support
- 3Entities: endpoints, networks, cloud and data centers
- 5Protection tech: NGFW, DNS filtering, malware protection, antivirus, email security
- 4Threat damage: interruption, interception, modification, fabrication
- 5Modern landscape: supply chain, AI-enabled, cloud & API, insider, hybrid
- 9Threat vectors: malware, ransomware, SE, supply chain, APT, zero-day, AI, IoT/OT, cloud/API
- 5AI vectors: generated malware, enhanced SE, reconnaissance, deepfakes, exploit kits
- 9Malware symptoms (CPU, slow, network, freezing, files, strange icons, programs, behaviour, auto emails)
- 5Malware countermeasures: AV, definitions, attachments, caution, backup
- 7SE countermeasures: password, physical, training, guidelines, classification, privileges, 2FA
- 6Confidentiality attacks: password theft, port scan, shoulder surfing, eavesdropping, sniffing, privilege escalation
- 5Integrity attacks: viruses, logic bombs, unauthorised access, coding errors, back doors
- 5Availability threats: device failure, software error, environment, DoS, network intrusion
- 5AAA: identification, authentication, authorization, auditing, accounting
- 4Protection mechanisms: layering, abstraction, data hiding, encryption
- 5Attacker types: hacktivists, organized crime, script kiddies, state-based, hackers
- 4Threat-modelling steps: identify, analyze, determine impact, define controls
- 7Ch3 dictionary: asset, threat, attack, vulnerability, threat agent, exploit, control
- 4Risk elements: threat, vulnerability, asset, damage
- 3 + 5Threat ID approaches: assets, attackers, software + architecture, data, supply chain, environment, emerging tech
- 6STRIDE: spoofing, tampering, repudiation, info disclosure, DoS, elevation of privilege
- 4Vendor inspection: on-site, document exchange, process/policy review, third-party audit
- 4Government classes: Top Secret, Secret, Confidential, Unclassified
- 4Commercial classes: Restricted, Confidential, Internal, Public
- 4Classification criteria: business value, legal, reputational, operational
- 5 + 1Sanitization: erasing, formatting, clearing, purging, destruction + declassification
- 5Roles: CISO, owner, steward, custodian, user
- 3Plans: strategic, tactical, operational
- 5Laws: GDPR, CCPA/CPRA, HIPAA, GLBA, PDPL
- 3Crypto dimensions: number of keys, type of operation, plaintext processing
- 8Classical ciphers: Caesar, ROT13, keyword, Playfair, Vigenère, OTP, Hill, transposition
- 6Block ciphers: DES, 3DES, AES, IDEA, RC5, Blowfish
- 5Modes: ECB, CBC, CFB, OFB, CTR
- 4Cryptanalysis: ciphertext only, known plaintext, chosen plaintext, chosen ciphertext