CYS401 Ch 1–5
CYS401 · Fundamentals of Cybersecurity

Chapters 1–5 exam cheat sheet

Every list, definition and difference from the chapter 1–5 slides, explained with the real questions the instructors asked. Built from the slides and every past paper on this site: Final 221 (Versions A and B), Quiz 1 (222), the chapter 1, 2 and 5 quizzes, and the chapters 1–2 practice exam.

88past-paper questions
7papers mined
36differences
42lists to recite
Past-paper cardsTry the question first, then open the answer. The tag says which paper it came from.
Exam trapsWhere the instructors swap a definition, borrow a list, or use a near-synonym.
Memory hooksShort mnemonics for the lists you have to write out in order.
Read it in orderStart with the exam patterns, then each chapter, then the differences table the night before.
00

How the instructors write the exam

The same nine question shapes come back on every paper. Learn to recognise the shape and you know what the question is really testing. Finals are 40 marks over 3 hours: 14 MCQs at 0.5 each, a 3-mark matching question, 15 marks of short answers and a 15-mark applied section. Quizzes are about 5 marks.

1 · "All of the following EXCEPT"

The wrong option is almost never random. It is taken from a neighbouring list, so it sounds right.

  • Pillars: People, Policies, Technologies, Data. Data is what the pillars protect. (Final 221 A, Q1)
  • Government classes: Top Secret, Critical, Secret, Unclassified. Critical belongs to the commercial scheme. (Final 221 A, Q4)
  • McCumber dimensions: Goals, States, Controls, Security Threats. (Ch1 Quiz)
  • Critical characteristics: Utility, Possession, Scalability, Authenticity. (Practice)
  • Threat-modelling steps: Visualize, Identify threats, Execute, Validate. (Final 221 B, Q5)
Name the list being tested, recite it from memory, then cross out the option that is not on it.

2 · True/False with a swapped definition

They take a correct definition and attach it to the wrong term, or reverse a one-way rule.

  • "Utility means information is genuine and original." False, that is Authenticity.
  • "A key fob is a software token that generates a PIN." False, a key fob is hardware; a soft token is software.
  • "Personnel security protects communications media." False, that is Communications security.
  • "A breach of possession always breaches confidentiality." False, the rule only works the other way.
  • "AAA refers to only three elements." False, there are five.
Find the one decisive word (hardware/software, recording/reviewing, always/not always) and check it against the slide definition.

3 · Superlatives

Several "most" and "-est" facts sit in the same chapter, so they mix them up on purpose.

  • Most difficult IS component to secure: Software
  • Most valuable asset: Data
  • Weakest component: People
  • Most common SDLC approach: Waterfall
  • Preferred threat-modelling approach: Proactive
  • Most secure media sanitization: Destruction
  • Only unbreakable cipher: One-time pad
  • Latest form of phishing: Angler phishing

4 · A scenario with one decisive word

Scenario questions hide a single clue. Underline it before you read the options.

  • "convince you specifically" → spear phishing (Final A Q14)
  • "unusable or unavailable" → interruption (Final A Q2)
  • "pay to unlock or decrypt" → ransomware (Final A Q3)
  • "no information exists, still investigating" → zero-day (Final A Q24)
  • "the victim called the technician" → reverse social engineering
  • "typed the correct URL" → pharming
  • "political DDoS on government sites" → hacktivists (Quiz 1)

5 · "Both (a) and (b)" options

When the paper offers "Both", check each half on its own. Sometimes both are right, sometimes one half is a trap.

  • "In case of data loss, ___ must be available to restore data": Backup, Redundancies, Checksum, Both (a) and (b). Both is right: the slide says "backups or redundancies". (Final 221 B, Q1)
  • A checksum only detects a change. It cannot restore anything.

6 · Order and direction

They test whether you know the sequence, not just the members.

  • 3DES decryption: D(K3) → E(K2) → D(K1) (Final A Q6)
  • AAA: Identification → Authentication → Authorization → Auditing → Accounting
  • SDLC: Planning → Analysis → Design → Implementation → Support
  • Defence in depth, outside in: Physical → Perimeter → Network → Host → Application → Data
  • Sanitization, weakest to strongest: Erasing → Formatting → Clearing → Purging → Destruction

7 · Calculations

Marks go to the method, so always write each step.

  • Availability % from downtime: MTTF ÷ (MTTF + MTTR) (Quiz 1, Q5)
  • Caesar, ROT13, keyword, Playfair, Vigenère and Hill encryption and decryption
  • Reading the brute-force table (DES at 10⁶ decryptions/µs ≈ 10 hours)

8 · "Differentiate between X and Y, with an example"

Usually 2–3 marks: one for each definition, one for the relationship or example.

  • Due care vs due diligence, and the relation (3 marks) (Final A Q21)
  • Hashing vs encryption, two differences (Final B Q17)
  • Best sanitization for reusing an HDD, and why (Final A Q19)
Answer in matched pairs: X is …, Y is …, the difference is …, for example ….

9 · The official key is sometimes wrong

The transcribed papers flag where the key slipped. Quiz 1's availability key used 90 weeks instead of 90 days (99.9% instead of 98.6%), and it lost half a mark. If your method is right, trust it and show every step so the marker can follow it.

CH 01

Introduction to Cybersecurity

The definitions, the seven characteristics of information, the McCumber Cube, the five IS components, defence in depth and the SDLC. This chapter is almost all "list it" and "which one is it" questions.

What cybersecurity is

Definition (slide wording)

Cyber security is the protection of internet-connected systems, including hardware, software and data, from cyberattacks.

"Protection of buildings" is physical security. "Encrypting all data" is one control. "A methodology for designing an IS" is the SDLC. None of these is the definition. (Practice)

The four related terms 4

  • Information security: protects information in any form, including paper and speech. The broadest term.
  • Computer security: protects computer systems and their components.
  • IT security: protects the IT infrastructure.
  • Cyber security: protects internet-connected systems.

Ch1 Quiz essay (13 marks): compare all four.

Cybersecurity pillars 3

  1. People: understand and follow security principles
  2. Policies: a framework for attempted and successful attacks
  3. Technologies: the tools that protect against attacks
PPT, like a slide deck: People, Policies, Technology.

Critical characteristics of information 7

Characteristic Slide definition Keyword to spot it Example
Confidentiality Preventing disclosure or exposure to unauthorized individuals or systems who can see it Credit cards, PII, health records
Integrity Being accurate, complete and authorised. Threatened by corruption, damage, destruction or disruption of its authentic state unchanged by unauthorised parties A file altered in transit
Availability Authorised users can access it without interference or obstruction, when and where needed and in the correct format reachable when needed Server down = loss of availability
Accuracy Free from mistakes or errors and having the value the end user expects error-free, matches expectation A wrong balance after any modification, intentional or not
Authenticity Genuine or original rather than a reproduction or fabrication genuine / original Same as when originally created, stored or transferred
Utility Having value for some purpose or end useful, meaningful format Available but unreadable format = no utility
Possession Having ownership or control of the item, independent of format holds a copy Stolen encrypted disk

The one-way rule (asked almost every time)

A breach of confidentiality always results in a breach of possession. A breach of possession does not always result in a breach of confidentiality.

Why: if someone reads your data, they now hold it. But if they steal an encrypted copy, they hold it without being able to read it.

Reading implies holding. Holding does not imply reading.

Accuracy vs Integrity vs Authenticity

  • Integrity: protected from unauthorised change (about who changed it).
  • Accuracy: the value is correct and what the user expects (about the value).
  • Authenticity: it is the original, not a copy or a fake (about origin).

Memorise the seven

CIA + AA + UP: Confidentiality, Integrity, Availability + Accuracy, Authenticity + Utility, Possession.

McCumber Cube 3 × 3

Security goals

  1. Confidentiality
  2. Integrity
  3. Availability

Information states

  1. Storage: data at rest (DAR), in memory, tape or disk
  2. Transmission: between systems, data in transit (DIT)
  3. Processing: operations performed on the data

Security measures / controls

  1. Policy and practices: administrative controls (plans, guidance)
  2. Education: users know their roles and responsibilities
  3. Technology: software and hardware solutions
Goals are CIA, States are STP (Storage, Transmission, Processing), Controls are PET (Policy, Education, Technology).

Five components of an information system 5

Component What it is The fact they test
Software Applications, operating systems, utilities Most difficult to secure: too many bugs, and security is left out of the first implementation, so version after version ships
Hardware Physical technology that houses and runs the software, stores and transmits data Secured with locks, keys and biometric access controls
Data What the organisation stores and processes Most valuable asset and main target of intentional attacks
People Users of the IS Weakest component, so policy, agreements, education and training matter
Procedures Written instructions for a specific task If an unauthorised user obtains them, the integrity of the information is threatened
Hard Software, Valuable Data, Weak People. Order: S-H-D-P-P, "She Hides Data from People's Procedures".

Two different "layers" lists (do not mix them)

Defence-in-depth diagram, outside in 6

  1. Physical: guards, locks, tracking devices
  2. Perimeter: firewalls, border routers, VPNs with quarantine procedures
  3. Network: network segments, NIDS
  4. Host / computer: OS hardening, authentication, security update management, antivirus updates, auditing
  5. Application: application hardening
  6. Data: strong passwords, ACLs, backup and restore strategy
"Please Protect Networks, Hosts, Apps and Data."

Organisation's security layers 6

  1. Physical security: physical items and objects
  2. Personnel security: the individuals authorised to access the organisation
  3. Operations security: the details of a particular operation or activity
  4. Communications security: communications media and technology
  5. Network security: network components and connections
  6. Data security: CIA of information in storage, processing and transmission

Quiz 1's seven-layer version

Quiz 1 used the extended onion, which adds an outer human layer:

  1. Policies and procedures (training, acceptable-use policy)
  2. Physical
  3. Perimeter
  4. Internal network (segmentation, auditing between departments)
  5. Host (OS patching, host antivirus)
  6. Application (input validation, secure coding)
  7. Data (encryption at rest, ACLs on records)
Auditing sits at the host layer in the six-layer diagram, not at the perimeter. (Practice T/F)

What defence in depth really means

Multiple independent controls in series. If one safeguard fails, the others still work. It is not about the number of devices, and it is not fail-over (that is redundancy, which protects availability).

SDLC and SecSDLC

SDLC phases 5

A methodology for designing and implementing an IS. Most common approach: waterfall.

  1. Planning: review and prioritise the project request, allocate resources, identify the team
  2. Analysis: study the current system, determine user requirements, recommend a solution
  3. Design: acquire hardware and software, develop the system details
  4. Implementation: develop the program, install and test, train users
  5. Support: identify errors and enhancements, monitor performance, update
PADIS: "Please Always Do It Securely".

SecSDLC phases 4

  1. Planning and analysis: potential impact of a breach; preliminary risk assessment → initial description of the basic security
  2. Design: risk assessments, security functional and assurance requirement analysis, security planning
  3. Implementation: inspection and acceptance, system integration bounded by the chosen controls
  4. Support: keep the security level when the environment changes, update, continuous monitoring

SDLC vs SecSDLC (the difference)

The SecSDLC follows the exact same phases as the SDLC. In addition it identifies specific threats and creates specific controls to counter them, in every phase.

"SecSDLC replaces the phases", "has fewer phases" or "adds security only at the end" are all false.

Past-paper questions · Chapter 1

Final 221 A · Q1

To achieve security we combine three key elements, the cybersecurity pillars. All of the following are pillars except ______.

  1. People
  2. Policies
  3. Technologies
  4. Data
Show answer
d) Data

Data is what the pillars protect. It is not one of them.

Practice exam · Ch1

Which of the following is NOT one of the critical characteristics of information?

  1. Utility
  2. Possession
  3. Scalability
  4. Authenticity
Show answer
c) Scalability

The seven are CIA + Accuracy, Authenticity, Utility, Possession. Scalability is a system-performance property.

Practice exam · Ch1

Information that is free from mistakes or errors and has the value the end user expects has which characteristic?

  1. Authenticity
  2. Accuracy
  3. Integrity
  4. Utility
Show answer
b) Accuracy

Integrity is the near-miss: it is about protection from unauthorised modification, not about matching the user's expectation.

Practice exam · Ch1

Data is stolen in encrypted form, so the attacker cannot read it. Which characteristic has been breached?

  1. Confidentiality only
  2. Possession only
  3. Both confidentiality and possession
  4. Neither, because the data is encrypted
Show answer
b) Possession only

They hold the data (possession), but nothing was disclosed (confidentiality intact).

Ch1 & Ch2 Quiz · T/F

A breach of ownership (possession) always results in a breach of confidentiality.

Show answer
False

Only the reverse is always true: a confidentiality breach always means a possession breach.

Practice exam · Ch1

Which component of an information system is described as the most difficult to secure?

  1. Hardware
  2. Software
  3. Data
  4. Procedures
Show answer
b) Software

Data is the most valuable; People are the weakest. Different superlatives, different components.

Ch1 Quiz · Q5

Which component of an Information System is considered the weakest link?

  1. Software
  2. Hardware
  3. Data
  4. People
Show answer
d) People

They fall for social engineering, make mistakes and skip policies.

Practice exam · Ch1

An unauthorised user obtains a copy of the organisation's written work instructions. Which IS component is compromised, and what is chiefly at risk?

  1. Data, availability
  2. Procedures, integrity of the information
  3. People, confidentiality
  4. Software, accuracy
Show answer
b) Procedures, integrity

The slide says leaked procedures threaten the integrity of the information.

Ch1 Quiz · Q7

Which of the following is NOT a dimension of the McCumber Cube?

  1. Security Goals
  2. Information States
  3. Security Controls
  4. Security Threats
Show answer
d) Security Threats

Also watch for "People, Policies, Technologies" (the pillars) or "Storage, Transmission, Processing" (only one axis) offered as "the three dimensions".

Practice exam · Ch1

In the McCumber Cube, "data at rest (DAR)" such as data stored on a disk corresponds to which information state?

  1. Transmission
  2. Processing
  3. Storage
  4. Retention
Show answer
c) Storage

Retention is not a McCumber state.

Practice exam · Ch1

In the defence-in-depth diagram, "network segments and NIDS" belong to which layer?

  1. Perimeter
  2. Network
  3. Host/Computer
  4. Physical
Show answer
b) Network

And "strong passwords, ACLs, backup and restore" is the Data layer.

Practice exam · Ch1

Which of the organisation's security layers protects the details of a particular operation or activity?

  1. Operations security
  2. Personnel security
  3. Communications security
  4. Physical security
Show answer
a) Operations security
Quiz 1 · 222 · Q1

What is a characteristic of a layered defence-in-depth security approach?

  1. Three or more devices are used.
  2. Routers are replaced with firewalls.
  3. One safeguard failure does not affect the effectiveness of other safeguards.
  4. When one device fails, another one takes over.
Show answer
c)

(d) is redundancy/fail-over, which is about availability. (b) is replacement, not layering. No device count makes it layered.

Past paper · T/F

Defence in depth is used to provide a protective multilayer barrier against various forms of attack.

Show answer
True
Quiz 1 · 222 · Q3

Which of the following is not a physical security measure to protect against physical hacking?

  1. Create a phishing policy.
  2. Updating the patches in the software on your office laptop.
  3. Add a front desk and restrict unknown access to the back room.
  4. Analyze how employees maintain their physical data and storage devices.
Show answer
b) Patching (keyed)

Patching is a technical control. The phishing policy (a) is administrative, so it is arguably also correct. If you get a similar question, pick the most clearly technical option and add a short note explaining why.

Quiz 1 · 222 · Q2 and Q4

In cybersecurity, ICT stands for ______. And: ______ limits the execution of files or handling of data by specific installed programs.

  1. Encryption programs
  2. Anti-virus programs
  3. Application firewall
  4. Routers
Show answer
Information and Communication Technology · c) Application firewall

An application firewall works at the application layer and decides what a named program may run or handle.

Practice exam · Ch1

In the SecSDLC, a preliminary risk assessment that produces an initial description of the basic security happens in which phase?

  1. Planning and Analysis
  2. Design
  3. Implementation
  4. Support
Show answer
a) Planning and Analysis

Design does risk assessments (plural, full). "Preliminary" is the clue for the first phase.

Practice exam · Ch1

"Study the current system, determine user requirements, recommend a solution" is which SDLC phase? And which phase identifies errors, monitors performance and updates?

Show answer
Analysis · Support
Ch1 Quiz · Q10

The main difference between SDLC and SecSDLC is:

  1. SecSDLC is faster to implement
  2. SecSDLC identifies threats and creates controls at every phase
  3. SecSDLC has fewer phases
  4. SecSDLC doesn't require testing
Show answer
b)

Older past-paper extras (asked before, not on the current slides)

Past paper · via Ch1 Quiz

What is layer 4 of the OSI model?

  1. Presentation
  2. Network
  3. Data Link
  4. Transport
Show answer
d) Transport

Physical 1, Data Link 2, Network 3, Transport 4, Session 5, Presentation 6, Application 7.

Past paper · via Ch1 Quiz

What is a TCP wrapper?

  1. An encapsulation protocol used by switches
  2. An application that can serve as a basic firewall by restricting access based on user IDs or system IDs
  3. A security protocol protecting TCP/IP over WAN links
  4. A mechanism to tunnel TCP/IP through non-IP networks
Show answer
b)
Past paper · via Ch1 Quiz

Which of the following is NOT true regarding firewalls?

  1. They are able to log traffic information
  2. They are able to block viruses
  3. They are able to issue alarms based on suspected attacks
  4. They are unable to prevent internal attacks
Show answer
b) Block viruses

That is the antivirus's job. Firewalls filter traffic by rules; they cannot stop internal attacks that never cross them.

Past paper · via Ch1 Quiz

What is encapsulation? And T/F: WEP uses a predefined shared secret key.

Show answer
Adding a header (and footer) to data as it moves down the OSI stack · True
CH 02

Security Foundations and Principles

The vocabulary (vulnerability, threat, control, risk), the threat landscape, malware, social engineering, the CIA triad in depth, AAA and the protection mechanisms. This chapter has the most scenario questions.

The basics

Three entities to protect 3

  1. Endpoint devices (computers, smart devices, routers)
  2. Networks
  3. The cloud and data centers

Common protection technology 5

  • Next-generation firewalls
  • DNS filtering
  • Malware protection
  • Antivirus software
  • Email security solutions

Vulnerability, threat, attack, control, risk

  • Vulnerability: a weakness in procedures, design or implementation that might be exploited.
  • Threat: a set of circumstances with the potential to cause loss or harm; a potential violation of security.
  • Attack: what a human commits when they exploit a vulnerability.
  • Control: an action, device, procedure or technique that removes or reduces a vulnerability.
  • Risk: exists when a threat meets a vulnerability in the system or in a control.
Risk = Threat + Vulnerability − Control. The vulnerability is the open window, the threat is the burglar, the control is the lock.

Threat damage: the four types 4

  • Interruption: asset unusable or unavailable → attacks Availability
  • Interception: unauthorised party gains access → attacks Confidentiality
  • Modification: unauthorised party changes the asset → attacks Integrity
  • Fabrication: unauthorised party creates counterfeit assets → attacks Authenticity
Interrupt = it stops. Intercept = someone sees. Modify = it changes. Fabricate = it's fake.

Modern threat landscape and threat vectors

Modern threat landscape 5

  1. Supply chain and third party: compromised vendors, insecure SaaS, malicious updates. External human threats with indirect access.
  2. AI-enabled: AI phishing, deepfake voice/video. More scale, speed and realism.
  3. Cloud and API: misconfiguration, insecure APIs, token theft
  4. Insider (intentional vs unintentional): malicious insider or negligent insider
  5. Hybrid: cyber + physical, or cyber + psychological (cyber attack + fake social media campaign)

Threat vectors and techniques 9

  • Malware: malicious software
  • Ransomware: encrypts files, demands ransom
  • Social engineering: tricks users into revealing information
  • Supply chain attacks: hit trusted vendors to reach many organisations
  • APTs: long-term, targeted, often state-sponsored, for espionage or data theft
  • Zero-day exploits: unknown or unpatched vulnerabilities
  • AI-powered attacks: automate attacks, bypass defences, deepfakes
  • IoT and OT attacks: connected devices, industrial systems
  • Cloud and API attacks: misconfigurations, insecure APIs

AI-driven threat vectors 5

  • AI-generated malware: adapts to avoid detection, creates polymorphic variants
  • AI-enhanced social engineering: personalised phishing using the target's style
  • AI-driven reconnaissance: automated scanning, prioritises high-value targets
  • AI deepfakes and impersonation: fake voice, video or text
  • AI-optimized exploit kits: selects the most effective attack per target
"Polymorphic" → AI-generated malware. "Selects the method" → exploit kits. "Finds targets" → reconnaissance.

Types of cyber attacker (Quiz 1)

Attacker Motive / signature Quiz 1 scenario
Hacktivists Political or social protest; disruption, not profit DDoS on Russian government sites during the Ukraine war
Organized crime Money; sustained, coordinated campaigns Carbanak and Cobalt malware robbing 100 banks in 40+ countries
Script kiddies Low skill, borrowed tools, known unpatched flaws; beaten by keeping systems updated "Lack knowledge and sophistication"
State-based attackers Government orders: espionage, surveillance NSA recording phone calls in the Bahamas
Hackers Generic skilled attacker exploiting technical flaws, no stated motive Exploiting plug-ins and browsers to install malware

Malware

Definition and types

Malware is any file or program used to harm a computer user.

  • Virus: attaches to a host file, needs it to run
  • Worm: spreads across networks by itself, no user action
  • Trojan horse: disguised as legitimate software
  • Spyware: secretly monitors activity
  • Keylogger: records keystrokes (beaten by an on-screen keyboard)
  • Backdoor: hidden unauthorised access
  • Ransomware: encrypts or locks, demands payment
  • Adware: unwanted advertising

Malware symptoms 9

  1. Increased CPU usage
  2. Slow computer or web browser
  3. Problems connecting to networks
  4. Freezing or crashing
  5. Modified or deleted files
  6. Strange files, programs or desktop icons appear
  7. Programs running, turning off or reconfiguring themselves
  8. Strange computer behaviour
  9. Emails/messages sent automatically without the user's knowledge
Distractors are always the opposite of slowdown: "more free disk space", "faster internet".

Malware countermeasures 5

  1. Install quality antivirus software
  2. Keep virus definitions regularly updated
  3. Never open an attachment from an untrusted source
  4. Take caution when surfing and downloading
  5. Back up data

Ransomware family (slide list)

WannaCry, Petya/NotPetya, Locky, Cerber, Jigsaw, Bad Rabbit, Ryuk, Dharma (CrySIS). The slide calls ransomware socially engineered malware.

Social engineering: spot it from the scenario

Social engineering relies on human interaction to trick users into breaking security procedures.

Technique Slide definition The clue in the question
Phishing Fraudulent emails that resemble reputable sources, to steal data mass email, "click this link"
Spear phishing / Whaling Targets a specific individual, group or organisation (whaling = a senior executive) "specifically", named target, "the CEO"
Angler phishing Latest form: social media, pretending to be customer service Twitter/Instagram support account
Vishing / Smishing Voice phishing / SMS phishing phone call / text message
Pharming Redirects to a fake site even when the correct URL is typed; poisons DNS or the local system "typed the right address"
Pretexting A fabricated story (pretext) to gain trust "pretending to be from IT / the bank"
Baiting Lures with attractive offers or rewards free USB, prize, free download
Tailgating Unauthorised person with a fake ID follows an authorised person through a door "followed through the secure door"
Shoulder surfing Spying on an ATM or device user to get a PIN or password (a confidentiality attack) "watched her type"
Reverse social engineering Attacker convinces the target they have a problem and offers to solve it the victim contacts the attacker
Doxing Publishing private, identifying information online with intent to harm "posted her address online"
Zero-day Unknown to those responsible for patching: no prior knowledge "no signature, no patch, nothing online"

Phishing vs pharming

Phishing is persuasive: the victim clicks a malicious link. Pharming is technical: DNS or the host is poisoned, so even the correct URL lands on the fake site. No click is needed.

Pretexting vs reverse social engineering

Pretexting: the attacker approaches with a made-up story. Reverse SE: the attacker causes or predicts a problem and the victim approaches the attacker for help. That is why the victim trusts them completely.

Social engineering countermeasures

  • Password policies: periodic change, no guessable passwords, account blocking after failed attempts, length and complexity, secrecy
  • Physical security policies: employee ID cards, area restrictions, shredding useless documents, security check before employment
  • Effective training programme
  • Operational guidelines
  • Classification of information: top secret, proprietary, for internal use only, for public use
  • Access privileges: administrator, user and guest accounts
  • Two-factor authentication

The CIA triad in depth

Confidentiality: "keeping secrets secret"

Measures that protect the secrecy of data, objects or resources. Controls: encryption, access control, steganography.

Attacks:

  • Stealing password files (public Wi-Fi, injected keylogger)
  • Port scanning: messages sent to learn which network services (well-known ports) are running
  • Shoulder surfing
  • Eavesdropping: intercepting communications not meant for you (man in the middle)
  • Sniffing: capturing network packets with a sniffer
  • Privilege escalation: programming errors or design flaws grant elevated access
  • Human errors (unintentional), intentional damage

Methods to ensure confidentiality

  • Data encryption: the common method
  • User IDs and passwords; two-factor is becoming the norm
  • Biometric verification: fingerprints, hand and earlobe geometry, retina/iris, voice, DNA, signatures
  • Security token: small hardware device carried to authorise network access
  • Soft token: software token that generates a single-use login PIN
  • Key fob: small programmable hardware device for access to a physical object needing 2FA/MFA
  • Extra measures for extremely sensitive documents: air-gapped computers (no external connection) and disconnected storage devices
Soft token is the only software one. Security token and key fob are both hardware.

Integrity: reliable and accurate

Attacks: viruses, logic bombs, unauthorised access, errors in coding, system back doors.

Methods:

  • File permissions and user access controls
  • Version control: stops erroneous changes or accidental deletion by authorised users
  • Checksums / hashing. Hash value = checksum. A cryptographic checksum is assigned to a file and used later to test that it has not been maliciously changed.

Restoring affected data: backups or redundancies. A checksum only detects a change.

Availability: accessible to authorised users at all times

Threats: device failure, software error, environmental issues (heat, flooding, power loss), DoS attacks, network intrusions.

To prevent data loss:

  • Backup copy in a geographically isolated location, perhaps a fireproof, waterproof safe
  • Firewalls and proxy servers against downtime
  • Web application firewall (Cloudflare)

Availability calculation (Quiz 1)

Availability = MTTF ÷ (MTTF + MTTR) × 100. MTTR is the downtime, MTTF the uptime. Use one consistent window.

Downtime per weekly test = 45 + 80 + 15 = 140 min
One week = 7 × 24 × 60     = 10,080 min
MTTF = 10,080 − 140        = 9,940
A = 9,940 ÷ 10,080 × 100   = 98.6%
Do not mix windows (the official key used 90 weeks of minutes and got 99.9%).

AAA services 5 elements

# Element Slide definition Banking example
1 Identification Claiming to be an identity Enter account number / username
2 Authentication Proving you are that identity Enter PIN, password, fingerprint
3 Authorization Defining the allow/deny permissions for that identity Which accounts you may see
4 Auditing Recording a log of events and activities The transaction is logged
5 Accounting / Accountability Reviewing log files for compliance and violations to hold subjects accountable The bank reviews the logs
"I Am Allowed, Audited, Accountable": Identify, Authenticate, Authorize, Audit, Account. Audit writes the log, Account reads it.

Protection mechanisms 4

Layering / defence in depth

Multiple controls in a series. Configurations: serial/parallel, mall, bank, airport.

Abstraction

Used for efficiency: similar elements put into groups, classes or roles that get controls or permissions as a collective.

Data hiding

Intentionally positioning data so it is not viewable or accessible to an unauthorised subject.

Encryption

The art and science of hiding the meaning or intent of a communication from unintended recipients.

LADE: Layering, Abstraction, Data hiding, Encryption. Data hiding hides the data; encryption hides the meaning.

Past-paper questions · Chapter 2

Final 221 A · Q2

______ is the attack that causes company assets to become unusable or unavailable on a temporary or permanent basis.

  1. Interruption
  2. Interception
  3. Modification
  4. Fabrication
Show answer
a) Interruption

Interception = confidentiality, Modification = integrity, Fabrication = authenticity.

Final 221 A · Q3

______ is social-engineering-based malware that asks the victim to pay in order to unlock or decrypt the system or the data.

  1. Worm
  2. Virus
  3. Ransomware
  4. Adware
Show answer
c) Ransomware
Final 221 A · Q14

Frequent emails from someone impersonating a bank, with a story about an account breach, trying to convince you specifically to disclose your credentials, is called ______.

  1. Phishing
  2. Spear phishing
  3. Whaling
  4. Pretexting
Show answer
b) Spear phishing

"Specifically" decides it. Whaling needs a senior executive. Pretexting is the story inside the attack, not the attack's name.

Final 221 A · Q24 (match)

Identify the attack: (1) ICMP replies flood the web server, and the requests' source IP was the server's own. (2) Three "free magazines" each ask for one personal detail. (3) Malware unseen for a week, nothing online, still investigating. (4) Credentials stolen from a lab PC even after logging out and clearing history. (5) Pop-ups appear; the victim calls the technician who warned him, hands over credentials, and the technician vanishes.

Show answer

1 Smurf attack (spoofed broadcast ping, amplified DoS) · 2 Salami theft (small slices that add up) · 3 Zero-day · 4 Keylogger (captured as typed) · 5 Reverse social engineering

Practice exam · Ch2

An unauthorised person wearing a fake ID follows an authorised employee through a secure door. This is:

  1. Tailgating
  2. Baiting
  3. Shoulder surfing
  4. Reverse social engineering
Show answer
a) Tailgating
Practice exam · Ch2

Which attack redirects a user to a fraudulent site even when the correct URL is typed?

  1. Phishing
  2. Pharming
  3. Pretexting
  4. Baiting
Show answer
b) Pharming
Practice exam · Ch2

Which phishing form targets people on social media by pretending to be customer service?

  1. Spear phishing
  2. Whaling
  3. Angler phishing
  4. Smishing
Show answer
c) Angler phishing
Practice exam · Ch2

An attacker convinces a target that they have (or will have) a problem, and offers to help solve it. This is:

  1. Pretexting
  2. Reverse social engineering
  3. Vishing
  4. Doxing
Show answer
b) Reverse social engineering
Practice exam · Ch2

A zero-day attack is best described as a threat that:

  1. Is unknown to the party responsible for patching the flaw
  2. Is launched one day after a patch
  3. Encrypts files and demands payment
  4. Publishes private information online
Show answer
a)

"Zero days" of warning for the defenders. (c) is ransomware, (d) is doxing.

Practice exam · Ch2

Long-term, targeted attacks, often state-sponsored, aimed at espionage or data theft are called:

  1. Zero-day exploits
  2. Advanced Persistent Threats
  3. Ransomware
  4. Hybrid threats
Show answer
b) APTs
Practice exam · Ch2

Supply chain and third-party threats are classified as:

  1. Internal human threats with direct access
  2. External human threats with indirect access
  3. Environmental threats
  4. Unintentional insider threats
Show answer
b) External, indirect
Practice exam · Ch2

A weakness in procedures, design or implementation that might be exploited to cause loss or harm is a:

  1. Threat
  2. Vulnerability
  3. Control
  4. Risk
Show answer
b) Vulnerability
Practice exam · Ch2

According to the slides, when does risk exist?

  1. Whenever a system is connected to the internet
  2. When a threat meets a vulnerability in the system or a control
  3. Only after a successful exploit
  4. When controls exist but users are untrained
Show answer
b)

(c) is an attack that already happened. Risk is about potential.

Ch2 Quiz · T/F

A threat is a weakness in the security system.

Show answer
False

That is a vulnerability.

Practice exam · Ch2

AAA is described in the lecture as referring to how many elements?

  1. Three
  2. Four
  3. Five
  4. Six
Show answer
c) Five

Identification and Auditing are the two people forget.

Practice exam · Ch2

Reviewing log files to check for compliance and violations, to hold subjects responsible, is:

  1. Auditing
  2. Accounting (accountability)
  3. Authorization
  4. Authentication
Show answer
b) Accounting

Auditing is the recording. Accounting is the reviewing.

Practice exam · Ch2

Claiming to be an identity when attempting to access a secured system is:

  1. Authentication
  2. Identification
  3. Authorization
  4. Accountability
Show answer
b) Identification
Practice exam · Ch2

Which method of ensuring confidentiality is a software-based security token that generates a single-use login PIN?

  1. Key fob
  2. Security token
  3. Soft token
  4. Biometric verification
Show answer
c) Soft token
Practice exam · Ch2

Isolating a computer or network so it cannot establish any external connection is called:

  1. Air gapping
  2. Steganography
  3. Sandboxing
  4. Data hiding
Show answer
a) Air gapping
Practice exam · Ch2

A series of messages sent to a machine to learn which network services are running is which confidentiality attack?

  1. Sniffing
  2. Port scanning
  3. Privilege escalation
  4. Eavesdropping
Show answer
b) Port scanning
Practice exam · Ch2

Which set of controls does the slide name as protecting confidentiality?

  1. Encryption, access control and steganography
  2. Hashing, checksums and version control
  3. Backups, redundancy and firewalls
  4. Auditing, accounting and authorisation
Show answer
a)

(b) is the integrity set, (c) is availability.

Practice exam · Ch2

Viruses, logic bombs, unauthorised access, coding errors and system backdoors are attacks that violate:

  1. Confidentiality
  2. Integrity
  3. Availability
  4. Authenticity
Show answer
b) Integrity
Final 221 B · Q1

In case of data loss, ______ must be available to restore the affected data to its correct state.

  1. Backup
  2. Redundancies
  3. Checksum
  4. Both (a) and (b)
Show answer
d) Both (a) and (b)

A checksum detects the change but cannot restore anything.

Practice exam · Ch2

Which of the following is listed as a threat to availability?

  1. Shoulder surfing
  2. Logic bombs
  3. Environmental issues such as heat, flooding and power loss
  4. Sniffing
Show answer
c)
Quiz 1 · 222 · Q5

An ethical hacker tests every week for 3 months. Each round takes 45 min (system) + 1 h 20 min (network) + 15 min (recover traces), with everything disconnected. Total availability, 1 decimal place?

Show answer
98.6%

140 min down out of 10,080 min per week: 9,940 ÷ 10,080 × 100.

Quiz 1 · 222 · Q7 (match)

Name the attacker: (1) DDoS on Russian government sites in the Ukraine war. (2) Carbanak and Cobalt hit 100 banks. (3) Low skill, uses well-known vulnerabilities. (4) NSA records nearly every call in the Bahamas. (5) Exploit plug-ins and browsers to install malware.

Show answer

1 Hacktivists · 2 Organized crime · 3 Script kiddies · 4 State-based attackers · 5 Hackers

Practice exam · Ch2

Which is NOT one of the malware countermeasures given in the lecture?

  1. Install quality antivirus
  2. Keep virus definitions updated
  3. Disable the firewall so the antivirus can scan traffic freely
  4. Never open an attachment from an untrusted source
Show answer
c)
Practice exam · Ch2

Which AI-driven vector is malware that adapts to avoid detection and creates polymorphic variants automatically?

  1. AI-driven reconnaissance
  2. AI-generated malware
  3. AI-optimized exploit kits
  4. AI deepfakes
Show answer
b) AI-generated malware
Practice exam · Ch2

Putting similar elements into groups, classes or roles that get security controls as a collective is:

  1. Abstraction
  2. Data hiding
  3. Layering
  4. Classification of information
Show answer
a) Abstraction
Practice exam · Ch2

Under the social engineering countermeasures, information should be classified as:

  1. Top secret, secret, confidential, unclassified
  2. Top secret, proprietary, for internal use only, for public use
  3. Public, private, restricted, sensitive
  4. Storage, transmission, processing
Show answer
b)

(a) is the government scheme from chapter 4. There are three classification lists in this course; see the Differences section.

Practice exam · Ch2

Which pair correctly names the two kinds of insider threat in the modern threat landscape?

  1. Malicious insider and negligent insider
  2. External insider and internal insider
  3. Physical insider and cyber insider
  4. State-sponsored and criminal insider
Show answer
a)
Ch2 Quiz · Q14

What is doxing?

  1. Creating fake documents
  2. Encrypting documents for ransom
  3. Publishing private information online with intent to harm
  4. Stealing documents from trash
Show answer
c)
CH 03

Threat Modeling

The vocabulary again (with slightly different wording from chapter 2), proactive vs reactive, the ways to identify threats, STRIDE, and the supply chain. STRIDE is the part most worth drilling.

What threat modeling is

Definition: a structured security process 4 steps

  1. Identify potential threats
  2. Analyze how those threats could exploit vulnerabilities
  3. Determine the impact on valuable assets
  4. Define appropriate security controls

It prevents security issues before they become real attacks.

The older papers used three key steps: Visualize → Identify threats → Validate. "Execute" is not a step. (Final B Q5)

The dictionary 7

  • Asset: any element with value to the organisation that must be protected
  • Threat: any potential event causing an unwanted impact
  • Attack: any actual event causing an unwanted impact
  • Vulnerability: the absence of a safeguard or a weakness a threat might use
  • Threat agent: the entity (person or process) that initiates the threat
  • Exploit: the vulnerability is found by a threat agent and the threat is initiated
  • Control / countermeasure / safeguard: any step that prevents the exploit, or minimises its damage
Threat = potential, attack = actual. A threat agent is the who.

Risk 4 elements

Risk is the possibility or likelihood that a threat will exploit a vulnerability, resulting in a loss such as harm to an asset.

Risk management reduces or eliminates vulnerabilities, or reduces the impact of threats, by implementing controls.

  1. Threat
  2. Vulnerability
  3. Asset
  4. Damage
TVAD: "The Vulnerable Asset Damaged".

Proactive vs reactive

Proactive Reactive
Also called Defensive approach Adversarial approach
When During system design and development After deployment, or after an incident
Based on Predicting threats; defences designed in while coding Observed attacks or failures; post-deployment patches
Result Security built in from the start Security added later
Verdict Proactive is the preferred and more effective approach.
Proactive = defensive (you defend before), Reactive = adversarial (you react to the adversary).

Identifying threats

Three key approaches 3

  • Focused on assets: uses asset valuation. "What is valuable?"
  • Focused on attackers: identifies potential attackers and their goals. "Who would harm us and why?"
  • Focused on software: threats against software the organisation develops. "Where are the weaknesses?"

Other modern approaches 5

  1. System / architecture-focused: components, interactions, trust boundaries (exposed internal APIs, lateral movement)
  2. Data-focused: how sensitive data is stored, sent, processed (breaches are the most common impact)
  3. Supply chain / third-party: vendors, libraries, APIs
  4. Environment / deployment-focused: cloud, on-prem, containers; misconfigurations are a top vector
  5. Emerging technology: agentic AI, IoT/OT

Three primary steps to identify threats 3

  1. Identify all of the technologies involved
  2. Identify attacks against each element of the diagram: logical/technical, physical and social
  3. Prevention measures

Threat models named on the slide

STRIDE, PASTA, LINDDUN, CVSS, Attack Trees, Persona non Grata, OCTAVE.

PASTA (Process for Attack Simulation and Threat Analysis) is risk-centric: countermeasures chosen against the value of the assets. (Final B Q2)

The university platform example (asset, actor, vulnerability, scenario)

Asset Threat actor Vulnerability Threat scenario
Student grades Student Weak authentication Student changes their own grade
Exam content Hacker SQL injection Extracts upcoming exam questions
Faculty login Hacker Phishing, no MFA Accesses faculty account to manipulate data
Platform uptime Insider Misconfigured permissions Staff deletes files causing downtime

STRIDE (Microsoft's threat categorisation)

Threat Meaning Property violated Example Countermeasures
Spoofing Access through a falsified identity Authentication Logging in with stolen credentials; pretending to be PayPal.com Digital signatures, Active Directory, LDAP, passwords, crypto tunnels
Tampering Unauthorised change or manipulation of data Integrity Changing form prices; modifying a transfer amount in transit Hashing, digital signatures, ACLs, crypto tunnels
Repudiation Ability to deny having performed an action Non-repudiation "I didn't send that email"; denying a transfer Digital signatures, logging
Information disclosure Private data revealed to unauthorised entities Confidentiality Balances exposed via API; customer list published Encryption, ACLs, PGP, SSL/TLS
Denial of service Prevent authorised use (connection overloading, traffic flooding) Availability Flooding the login page Load balancers, more capacity
Elevation of privilege Limited account gets greater privileges Authorization Regular user exploits a bug to become admin Isolation, input validation, firewalls, sandboxing
Read STRIDE against "A-I-N-C-A-A": Authentication, Integrity, Non-repudiation, Confidentiality, Availability, Authorization. STRIDE is mainly for applications but also works for network threats.

Supply chain

Definitions

A supply chain is the network between a company and its suppliers to produce and distribute a product to the final buyer. Most systems are not built by a single entity.

A secure supply chain: every vendor or link is reliable, trustworthy and reputable, and discloses its practices and security requirements to partners.

Goal of a secure supply chain

  • The finished product is of sufficient quality, meets performance and operational goals, and provides the stated security mechanisms
  • At no point was any element counterfeited or subjected to unauthorised or malicious manipulation or sabotage

How the security team inspects vendors 4

  1. On-site assessment: visit, interview, observe habits
  2. Document exchange and review: how data and documents are exchanged and reviewed
  3. Process/policy review: copies of policies, procedures, incident records
  4. Third-party audit: an independent auditor

Past-paper and exam-style questions · Chapter 3

Final 221 B · Q2

PASTA is a ______ that aims at selecting or developing countermeasures in relation to the value of the assets to be protected.

  1. Attacker-centric approach
  2. Risk-centric approach
  3. Software-centric approach
  4. Application-centric approach
Show answer
b) Risk-centric

"In relation to the value of the assets" is the clue.

Final 221 B · Q5

Which of the following is not a key step while doing threat modeling?

  1. Visualize
  2. Identify threats
  3. Execute
  4. Validate
Show answer
c) Execute
Exam-style · built from the slide

A banking app user makes a transfer and later claims they never made it. Which STRIDE threat, and which property is violated?

Show answer
Repudiation → Non-repudiation

Countermeasure: digital signatures and logging.

Exam-style · built from the slide

A regular user exploits a bug to open the admin panel. Which STRIDE threat, and which countermeasures?

Show answer
Elevation of privilege → Authorization

Isolation, input validation, firewalls, sandboxing.

Exam-style · built from the slide

Threat modeling performed after a product is deployed, based on observed attacks, is called ______ and is also known as the ______ approach.

Show answer
Reactive · adversarial

Proactive = defensive, and proactive is preferred.

Exam-style · built from the slide

Differentiate between a threat and an attack, and name the entity that initiates a threat.

Show answer

A threat is a potential event with an unwanted impact; an attack is an actual event. The initiating entity is the threat agent (a person or a process).

CH 04

Protection of Information Assets

Governance, due care, classification, data states, retention and destruction, privacy laws, ownership roles and the three security plans. Lots of "which role" and "which level" questions, and the short answers come from here.

Information assets

Definition

An information asset is any information that has value to an organisation, regardless of its form: student or customer records, financial data, intellectual property, research data.

Primary assets are the information itself. Supporting assets are the software, hardware, network, people and physical things that hold or process it (servers, LMS, routers, admins, data centers).

Why protect them

  • Information is a core business resource
  • Loss of confidentiality → privacy violations, legal penalties
  • Loss of integrity → wrong decisions, operational failures
  • Loss of availability → disrupted services and continuity
  • Breaches damage reputation and trust

So it is a strategic, legal and governance requirement, not only a technical one.

Information asset security domain

Collecting, handling and protecting information throughout its lifecycle. A primary step is classifying information by its value.

How: secure systems and environments, hardware and software controls, encryption and access control, monitoring and auditing.

Governance

Security governance

The collection of practices for supporting, defining and directing the security efforts of an organisation. It ensures clear accountability, consistent practices, compliance and oversight, enforced through policies, standards, procedures and audits.

Corporate governance: "doing the right things for the organisation and doing things the right way, independent of personal interests."

Security is a business operations issue, not an IT-only issue. Usually run by a governance committee or the board. Frameworks: NIST 800-53, 800-100 (government/military focus, usable by others).

Governance vs management

Governance Management
Level Strategic oversight Tactical, operational execution
Asks "Are we doing the right things?" "Are we doing things right?"
Who Senior leadership, board, committees CISO, managers, analysts, technical staff
Example Approving policies, defining acceptable risk Deploying firewalls, monitoring, vulnerability scans

Third party and cloud (ASP)

An Application Service Provider hosts and maintains software on its own servers and delivers it over the internet.

  • The organisation remains accountable for data protection
  • Due diligence before engagement
  • Contracts and SLAs define security responsibilities

Due care vs due diligence (Final 221 A, 3 marks)

Due care Due diligence
Current slides The reasonable steps an organisation takes to protect its assets by following accepted practices Goes further: actively identifying and analysing risks
Slide examples Strong password policies, applying patches, antivirus and firewalls Risk assessments, auditing third-party providers, reviewing incident history and vulnerabilities
Governance view Demonstrates responsible operation Demonstrates proactive risk management
Final 221 A key Doing the right thing: building the security structure (policy, standards, baselines, guidelines, procedures) Continuing to apply and maintain that structure
Relation Due care sets it up, due diligence keeps checking it works. Both are needed to avoid negligence and legal liability.
Due care = you do the right thing. Due diligence = you dig to check it is still right.

Classification: three lists you must not mix

Government / military 4

  1. Top Secret: "exceptionally grave damage" to national security
  2. Secret: "serious damage"
  3. Confidential: "damage"
  4. Unclassified: can go to the public with no threat to national interest
Damage words shrink as you go down: exceptionally grave → serious → damage → none.

Commercial (organisational) 4

  1. Restricted (sensitive / critical)
  2. Confidential
  3. Internal (private)
  4. Public (unclassified)

No standard: each company chooses its own and it is usually simpler than the government scheme. The more regulated the company, the more complex its scheme.

Social engineering countermeasure (Ch2) 4

  1. Top secret
  2. Proprietary
  3. For internal use only
  4. For public use
"Critical" is commercial, never government. (Final 221 A, Q4)

Classification criteria 4

  • Business value
  • Legal and regulatory impact (PDPL, GDPR)
  • Reputational damage
  • Operational impact

Guiding question: what is the worst possible impact if this is disclosed, altered or destroyed? Higher impact → higher level → stronger controls.

Restricted data examples

  • PII: identifies an individual (name, SSN, date and place of birth, mother's maiden name, biometrics)
  • PHI: health information tied to a person
  • Proprietary data: keeps a competitive edge (source code, product plans, internal processes), protected by copyrights, patents and trade secret law

Class exercise: sort into 4 categories

The slide leaves this as an exercise. A suggested sort, using the worst-impact question:

  • Cat 4 highly sensitive: credit card numbers (PCI), PHI, SSNs, financial account numbers, trade secrets, intellectual property
  • Cat 3 sensitive internal: student education records, customer personal data, employee records, employee pay cheques, supplier and vendor contracts
  • Cat 2 internal: internal emails, employee directory, IT service management information
  • Cat 1 public: public website content, marketing materials, newsletters, press releases, social media feeds

Marking, handling and data states

Marking (labelling)

So users can easily identify the classification of any data.

  • Physical labels on media and systems
  • Electronic labels: header/footer or watermark. Benefit: they also appear on printouts.

Asset classifications should match data classifications. A data breach is any event where an unauthorised entity can view or access classified data.

Protecting each state

  • At rest (drives, databases, backup tapes, USBs): encryption (AES-256), access controls, secure facilities, environmental controls (HVAC, fire suppression)
  • In transit: encrypted channels, secure protocols, network monitoring
  • In use: access control, endpoint security, memory protection

Retention

Keep information for as long as it is needed for business operations, legal and regulatory compliance, and audit. Periods come from policy, industry standards or law (3 years, 7 years, indefinitely). When the period expires, securely destroy it.

Secure destruction and sanitization

Two things destruction prevents

  • Data recovery: retrieving lost, deleted, corrupted or inaccessible data when normal access is no longer possible
  • Data remanence: the data that remains on media after it was supposedly erased

Paper: cross-shredding is recommended. Digital: the method depends on the media type.

Sanitization ladder, weakest to strongest

  1. Erasing: a plain delete. Everything is still recoverable.
  2. Formatting: delete plus a new file structure. Still recoverable in most cases.
  3. Clearing (overwriting): prepares media for reuse; not recoverable with traditional tools.
  4. Purging (multiple overwrites / degaussing): stronger clearing, for reuse in less secure environments.
  5. Destruction: end of the media's life. The most secure method.

Declassification: any process that purges media so it can be reused in an unclassified environment.

E-F-C-P-D: "Every File Can Probably Die".

Degaussing

A degausser generates a heavy magnetic field that realigns the magnetic domains of hard drives, tape and floppy disks, removing data remanence.

Degaussing an SSD does not remove data. SSDs are not magnetic.

Final 221 A Q19: to reuse an HDD with no recoverable bit, use degaussing, because the field destroys the stored magnetic pattern itself.

Data protection laws

Law Where What to remember
GDPR European Union Collection and processing of personal data of people living in the EU; applies wherever the website is based if it attracts EU visitors; heavy fines
CCPA / CPRA USA, California Consumers get more control over personal information businesses collect
HIPAA USA National standards protecting patient health information (PHI)
GLBA USA Financial institutions must explain information-sharing practices and safeguard data
PDPL Saudi Arabia In force 14 September 2023 by Royal Decree; regulator SDAIA; covers electronic and non-electronic data, including foreign entities processing Saudi residents' data; fines up to SAR 5 million (doubled for repeats); up to 2 years prison for unlawful disclosure of sensitive data with intent to harm

The US has no single federal law: it is sectoral and state-based, and generally more business-friendly than GDPR.

Ownership roles

Role Responsibility University Library
CISO Accountable for protecting organisational data; leads the security team, reports directly to senior management
Information owner Usually a business or department head. Decides classification, approves access rights, ensures protection Registrar's Office Library Director
Information steward Technical accountability for how information supports the business; data quality and business use Librarian
Information custodian Implements technical controls, keeps the data accessible as the owner and steward direct IT Department IT Admin
Information user Uses information according to its classification Faculty, advisors Borrowers
Owner decides, custodian does, steward keeps it tidy, user uses.

Data owner responsibilities (NIST SP 800-18)

  • Establishes rules for appropriate use and protection
  • Gives input to system owners on security requirements and controls
  • Decides who has access and with what privileges
  • Helps identify and assess common security controls

System (asset) owner responsibilities (NIST SP 800-18)

  • Develops the system security plan with information owners, admin and users
  • Maintains the plan and runs the system to its requirements
  • Ensures users and support staff get security training
  • Updates the plan after any significant change
  • Helps identify, implement and assess common controls

Business / mission owner and best practices

NIST calls the business/mission owner a program manager or information system owner; they ensure systems provide value. The role can overlap with the system owner.

Best practices: classify correctly, least privilege, strong authentication, encrypt sensitive data, monitor and log access, DLP, regular audits and awareness training.

Security management planning

Top-down approach

The main objective is to align security with the organisation's strategy, goals, mission and objectives. Senior management initiates policies, approves objectives and defines acceptable risk. The security team should be autonomous.

The security management plan includes: defining security roles, how security is managed, who is responsible, how effectiveness is tested, developing policies, risk analysis, and security education.

Three plans 3

Plan Horizon Answers Bank example
Strategic Long term, 3–5 yrs, reviewed yearly; includes a risk assessment Why secure? Which assets are critical Adopt ISO 27001, create the CISO role
Tactical Mid term, about 1 yr; can be ad hoc What controls to implement MFA, encryption, SIEM, IR plan; project, hiring, budget plans
Operational Short term, updated monthly or quarterly How controls are applied daily 24/7 log monitoring, weekly scans, monthly access reviews
Strategic = Why, Tactical = What, Operational = How. Longest to shortest.

Past-paper questions · Chapter 4

Final 221 A · Q4

In the governmental context, data should be classified rigidly into one of the following classes except ______.

  1. Top Secret
  2. Critical
  3. Secret
  4. Unclassified
Show answer
b) Critical

Government: Top Secret, Secret, Confidential, Unclassified. Critical is a commercial label.

Final 221 A · Q19 (2 marks)

You want to reuse a hard disk (HDD). What is the best sanitization technique to ensure no single bit can be recovered? Explain.

Show answer
Degaussing

A strong magnetic field resets the magnetic domains that store the bits, so no remanence is left. (Destruction is stronger but you could not reuse the disk.)

Final 221 A · Q21 (3 marks)

Using an example, differentiate between due care and due diligence, and show the relation between the two.

Show answer

Due care: the reasonable steps a prudent organisation takes to protect its assets, e.g. setting a password policy and patching. Due diligence: the continuing effort to check those steps still work and find new risks, e.g. regular risk assessments and auditing vendors. Relation: due care sets it up, due diligence keeps it effective. Together they prevent negligence.

Final 221 A · Q9

______ allows the systems admin to grant users the exact privileges they need to accomplish a task, with no additions.

  1. Least privilege
  2. Need to know
  3. Access control list
  4. Security clearance level
Show answer
a) Least privilege

Need to know is about information a person may see; least privilege is about actions.

Final 221 A · Q11 and Q23

An employee moves teams and keeps the old rights while gaining new ones. This is called ______.

  1. Default to Zero
  2. Need to Know
  3. Authorization Creep
  4. Declassification
Show answer
c) Authorization creep

It violates least privilege. Declassification is the chapter 4 media term, used here as a distractor.

Exam-style · built from the slide

The Registrar decides who may access student records; IT manages the servers and backups. Name both roles.

Show answer
Registrar = information owner · IT = custodian
Exam-style · built from the slide

A plan valid for about one year that includes a hiring plan for SOC analysts and an MFA project plan is a ______ plan.

Show answer
Tactical
Exam-style · built from the slide

Which sanitization level prepares media for reuse in a less secure environment, and which one prepares it for an unclassified environment?

Show answer
Purging · Declassification
CH 05

Cryptography

Vocabulary, Kerckhoffs, the three ways to classify ciphers, the classical ciphers (practise every worked example), block ciphers and their modes, and the attacks. Expect calculation questions here.

Vocabulary

Terms

  • Plaintext: original message. Ciphertext: coded message.
  • Cipher: the algorithm. Key: info known only to sender and receiver.
  • Encipher / encrypt: plaintext → ciphertext. Decipher / decrypt: ciphertext → plaintext.
  • Cryptography: making and using codes ("secret writing").
  • Cryptanalysis (codebreaking): deciphering without knowing the key.
  • Cryptology: the field of both.

Notation: EK(P) = C, DK(C) = P, and DK(EK(P)) = P. Plaintext and ciphertext are typically the same length.

Two facts they love

  • Cryptography can protect confidentiality and integrity, but not availability.
  • Kerckhoffs's principle: the algorithm is public; security depends only on the secrecy of the key. Assume Eve knows the algorithm.
  • Symmetric encryption is about 30,000 times faster than public-key encryption.
"The algorithm must be kept secret" is False.

Classify a cryptosystem 3 dimensions

  1. Number of keys: same key = symmetric (conventional); different keys = asymmetric (public key)
  2. Type of operation: substitution (each element mapped to another) or transposition/permutation (rearranged)
  3. Plaintext processing: block (a block at a time) or stream (an element at a time)

Cipher tree: Symmetric (classical: substitution, transposition; modern: block, stream), Asymmetric, Hash.

KOP: Keys, Operation, Processing. "Message length" is never a dimension.

Classical ciphers: the solving rules

Cipher You are given Encrypt Decrypt Remember
Caesar Shift n E(x) = (x + n) mod 26 D(x) = (x − n) mod 26 Build the shifted alphabet first
ROT13 Nothing (n = 13) Shift 13 Shift 13 again Applying it twice gives the plaintext back
Keyword Keyword Keyword without duplicates, then the rest of the alphabet in order; map top → bottom Map bottom → top Remove duplicates from the keyword, not the message. Still monoalphabetic.
Playfair Keyword → 5×5 matrix (I/J share) Pairs; same row → right; same column → below; else rectangle Same row → left; same column → above; rectangle Repeated letter in a pair → insert X. 676 digrams.
Vigenère Keyword + table Repeat keyword to message length; row = plaintext, column = key, intersection = cipher Row = key, find cipher letter, column = plaintext Polyalphabetic: a different Caesar shift per letter
One-time pad Random shift per letter Shift each letter by its own random key Reverse each shift The only absolutely unbreakable cipher (Mauborgne and Vernam, 1917)
Hill Invertible n×n matrix Letters → numbers (A = 0), blocks × K mod 26 Blocks × K−1 mod 26 Lester Hill 1929. Hides single-letter frequencies.
Transposition Column order key Write in a 2D table, swap columns by the key Undo the column order Letters keep their form, only positions change

Worked examples (verified)

Caesar and ROT13

a = 0, n = 14:  E(0) = (0 + 14) mod 26 = 14 → O
"CAT", n = 3:   C(2)→F  A(0)→D  T(19)→W  = FDW
"We love PSU", ROT13          = Jr ybir CFH

The slide writes E(a) = 1 + 14 = 15 = "o" with A = 1. Both give O; use A = 0 unless told otherwise.

Keyword cipher: "PSU IS MY CHOICE"

Keyword without repeats: P S U I M Y C H O E
Then the rest:           A B D F G J K L N Q R T V W X Z

Plain : A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
Cipher: P S U I M Y C H O E A B D F G J K L N Q R T V W X Z

HELLO     → HMBBG
SMART     → NDPLQ
STUDYHARD → NQRIXHPLI
BPZX      → LAZY (decrypt)

Keyword cipher: "ZEBRAS" (decrypt)

Plain : A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
Cipher: Z E B R A S C D F G H I J K L M N O P Q T U V W X Y

SIAA ZQ LKBA VA ZOA RFPBLUAOAR
FLEE AT ONCE WE ARE DISCOVERED

Playfair: keyword MONARCHY, plaintext HELLO

MONAR CHYBD EFGI/JK LPQST UVWXZ
HELLO → HE LX LO   (LL split with filler X)
HE: rectangle → C F
LX: rectangle → S U
LO: rectangle → P M
The slide prints LO → MP. By the rectangle rule (same row, other letter's column) L → P and O → M, so it is PM. If asked, follow the rule and show the matrix.

Vigenère: GEEKSFORGEEKS, keyword AYUSH

Plain : G E E K S F O R G E E K S
Key   : A Y U S H A Y U S H A Y U
Cipher: G C Y C Z F M L Y L E I M

Each letter: (plain + key) mod 26
E(4) + Y(24) = 28 mod 26 = 2 → C

Hill: "july", K = [11 8 ; 3 7]

j u = (9, 20)   l y = (11, 24)
(9, 20) · K  = (9·11 + 20·3, 9·8 + 20·7)
             = (159, 212) mod 26 = (3, 4)   → D E
(11, 24) · K = (121 + 72, 88 + 168)
             = (193, 256) mod 26 = (11, 22) → L W
"july" → DELW

Decrypt: det = 11·7 − 8·3 = 53 ≡ 1 (mod 26)
K⁻¹ = [7 −8 ; −3 11] = [7 18 ; 23 11] mod 26
(3, 4) · K⁻¹ = (113, 98) mod 26 = (9, 20) → j u

Attacking substitution: frequency analysis

Letters in natural language are not uniformly distributed, so letter (and pair, triple) frequencies break substitution ciphers. There are 26! (over 4 × 1026) substitution alphabets, but frequency analysis makes the key space irrelevant.

Why Playfair and Hill are stronger

Playfair (Wheatstone 1854, named after Baron Playfair) encrypts digrams: 26 × 26 = 676, so a 676-entry frequency table and much more ciphertext are needed. Used in WW1, but breakable with a few hundred letters.

Hill completely hides single-letter frequencies, so it resists ciphertext-only attacks.

Monoalphabetic vs polyalphabetic

Monoalphabetic (Caesar, keyword): one fixed substitution alphabet. Polyalphabetic (Vigenère): the alphabet changes with each key letter. Final A Q5 calls Vigenère "an advanced version of Caesar based on a keyword".

Modern block ciphers

Block cipher basics

Encrypts an n-bit block with a k-bit key. Plaintext is split into fixed-length blocks.

Padding: the plaintext length must be a multiple of the block size. Padding must be unambiguous (not just zeros), and the last block is always padded. Slide example, b = 64 bits (8 bytes): "Roberto" (7 bytes) → "Roberto9", where 9 denotes a number, not the character. The padding is a value the receiver can read and strip, which is why plain zeros are not allowed.

The algorithms

Cipher Block Key Fact
DES 64 56 IBM, NIST 1977; brute force feasible since the late 90s
3DES 64 168 Three DES keys, E-D-E; equals DES when KA = KB = KC
AES 128 128 / 192 / 256 NIST 2001, open competition
IDEA 128 Used in PGP email
RC5 Variable MIT
Blowfish Up to 448 Bruce Schneier, 1993

Triple DES order

Encrypt: C = E_KC( D_KB( E_KA(P) ) )
Decrypt: P = D_KA( E_KB( D_KC(C) ) )

Decryption undoes the last step first: decrypt with K3, encrypt with K2, decrypt with K1.

Nominal key length 168 bits. (In practice meet-in-the-middle gives about 112 bits, but answer 168 if the slide wording is asked.)

Block cipher modes 5

Mode Encryption How to recognise it
ECB, Electronic Code Book C[i] = EK(P[i]) Each block on its own; identical plaintext blocks give identical ciphertext
CBC, Cipher Block Chaining C[i] = EK(C[i−1] ⊕ P[i]) XOR then encrypt; first block XOR'd with the initialization vector
CFB, Cipher Feedback C[i] = EK(C[i−1]) ⊕ P[i] Encrypt the previous ciphertext then XOR
OFB, Output Feedback V[i] = EK(V[i−1]); C[i] = V[i] ⊕ P[i] Like a one-time pad made of generated blocks, starting from V0
CTR, Counter V[i] = EK(s + i − 1) Uses a seed; can run in parallel and recover from dropped blocks
CBC = XOR then encrypt. CFB = encrypt then XOR. CTR = Counts, so it can run in parallel.

Attacking conventional encryption

Objective and approaches

The objective is to recover the key, not just one message, so every past and future ciphertext is compromised. Two approaches: cryptanalysis and brute force. The algorithm is assumed known in every attack.

Cryptanalysis by what the attacker has 4

  1. Ciphertext only: only ciphertexts of several messages
  2. Known plaintext: some plaintext–ciphertext pairs, not chosen
  3. Chosen plaintext: can choose plaintexts to encrypt (has the encryption box)
  4. Chosen ciphertext: can choose ciphertexts to be decrypted (has the decryption box); goal is the key
Each step gives the attacker more power: see → know → choose to encrypt → choose to decrypt.

Brute force table

Key 1 decr/µs 10⁶ decr/µs
32 bit 35.8 min 2.15 ms
56 (DES) 1142 years 10.01 hours
128 (AES) 5.4 × 10²⁴ yrs 5.4 × 10¹⁸ yrs
168 (3DES) 5.9 × 10³⁶ yrs 5.9 × 10³⁰ yrs
26! perm. 6.4 × 10¹² yrs 6.4 × 10⁶ yrs

Hashing facts asked on the finals

Hashing vs encryption (Final 221 B, Q17)

  • A hash gives a fixed-size output whatever the input; ciphertext grows with the plaintext.
  • Hashing is one-way and irreversible (no key recovers the input); encryption is designed to be reversed with the key.

Hash algorithm facts

  • SHA-3: 256 and 512 bits (course wording), built on Keccak, structured differently from the rest of the SHA family (Final B Q3)
  • SHA-1 digest is 160 bits
  • MD4 is faster and less secure than MD5; MD5 was designed to fix MD4 (Final B Q4)

Past-paper questions · Chapter 5

Final 221 A · Q5

The ______ is an advanced version of the Caesar cipher in which the alphabetic text is encrypted by matching the plaintext with ciphertext based on a provided keyword.

  1. Vigenère cipher
  2. Keyword cipher
  3. One Time Pad
  4. Hill cipher
Show answer
a) Vigenère

The keyword cipher also uses a keyword, but it builds one fixed alphabet (monoalphabetic). "Advanced Caesar" = a Caesar shift per letter.

Final 221 A · Q6

Triple DES applies three phases of encryption with different keys. Which order is correct for decryption?

  1. Encrypt K1, decrypt K2, encrypt K3
  2. Encrypt K3, decrypt K2, encrypt K1
  3. Decrypt K1, encrypt K2, decrypt K3
  4. Decrypt K3, encrypt K2, decrypt K1
Show answer
d)

(a) is the encryption order. (c) has the operations right but the keys in the wrong direction.

Ch5 Quiz · Q1

Cryptography can protect which TWO of the three CIA properties?

  1. Confidentiality and Availability
  2. Integrity and Availability
  3. Confidentiality and Integrity
  4. All three
Show answer
c)

A DoS makes encrypted data unreachable however strong the encryption is.

Ch5 Quiz · Q3

T/F: According to Kerckhoffs's principle, the encryption algorithm must be kept secret; only the key is known publicly.

Show answer
False

The other way round: the algorithm is public, the key is secret.

Ch5 Quiz · Q6

Cryptosystems are classified along three independent dimensions. Which is NOT one of them?

  1. Number of keys used
  2. Type of operation
  3. Way the plaintext is processed
  4. Length of the plaintext message
Show answer
d)
Ch5 Quiz · Q7 and Q10

T/F: Symmetric encryption is about 30,000 times faster than asymmetric. T/F: ROT13 applied twice returns the original plaintext.

Show answer
True · True
Ch5 Quiz · Q8 and Q9

Caesar with n = 14: encrypt "a" (position 0). Then encrypt "CAT" with n = 3.

Show answer
O · FDW
Ch5 Quiz · Q11

In a keyword cipher with keyword "PSU IS MY CHOICE", what is the FIRST step before building the cipher alphabet?

  1. Reverse the keyword
  2. Remove repeated letters from the keyword
  3. Sort the keyword alphabetically
  4. Convert the keyword to numbers
Show answer
b)
Ch5 Quiz · Q12 to Q14

Which technique attacks substitution ciphers using letter frequencies? How many digrams does Playfair use? What do you insert between repeated letters in a pair (HELLO)?

Show answer
Frequency analysis · 676 · a filler such as X
Ch5 Quiz · Q15 and Q16

T/F: The one-time pad is the only theoretically unbreakable substitution cipher. And: in a transposition cipher, what happens to the plaintext characters?

Show answer
True · they keep their form but change positions
Ch5 Quiz · Q17 to Q19

DES block and key size? 3DES key length? T/F: AES uses 128-bit blocks with 128, 192 or 256-bit keys.

Show answer
64-bit block, 56-bit key · 168 bits · True
Ch5 Quiz · Q20 and Q21

If the last block of plaintext is too short, what must be done? In CBC, what is the first block XOR'd with?

Show answer
Pad it (unambiguously) · the initialization vector
Ch5 Quiz · Q22

Which block cipher mode can be performed in parallel and can recover from dropped blocks?

  1. ECB
  2. CBC
  3. CFB
  4. CTR
Show answer
d) CTR
Ch5 Quiz · Q23, Q24, Q26

The Hill cipher's main strength? How do you decrypt it? T/F: "july" with K = [11 8 / 3 7] gives "DELW".

Show answer
It hides single-letter frequencies · multiply by the inverse matrix mod 26 · True
Ch5 Quiz · Q25

In the Vigenère cipher, if the keyword is shorter than the plaintext, what happens?

  1. Encryption stops
  2. The keyword is repeated to match the plaintext length
  3. Remaining letters use shift 0
  4. A new random keyword is generated
Show answer
b)
Ch5 Quiz · Q27, Q28, Q30

What extra power does a chosen-plaintext attacker have over a known-plaintext one? An attacker holds only intercepted ciphertexts: which attack? In a chosen-ciphertext attack, what is the goal?

Show answer
Chooses their own plaintexts to encrypt · ciphertext-only · find the key
Ch5 Quiz · Q29

From the brute-force table, how long to break a 56-bit DES key at 1 million decryptions per microsecond?

  1. About 35 minutes
  2. About 2 milliseconds
  3. About 10 hours
  4. About 1,142 years
Show answer
c) About 10 hours

1,142 years is the same key at 1 decryption per µs.

Final 221 B · Q3, Q4, Q17

SHA-3 supports hash lengths of ___. MD4 is the ___ algorithm and ___ secure than MD5. Give two differences between hashing and encryption.

Show answer
256 and 512 bits · fast, less · fixed-length output; one-way/irreversible
Final 221 A · Q7 (key types)

You subscribe to a sports channel and get a licence to decrypt it. Which key does the decryption use?

  1. A private key of their server
  2. A private key generated in my device, used by me only
  3. A public key sent by their server to everyone
  4. My public key generated in my device
Show answer
b)

Public keys encrypt or verify; only your own private key decrypts what was sent to you. (This one leans into chapter 6.)

06

Tell the difference

Every pair the papers try to confuse, in one place. Cover the right column and explain each difference out loud.

Pair The difference in one line Ch
Pillars vs entities vs CIA vs components Pillars = People, Policies, Technology (what you combine). Entities = endpoints, networks, cloud (what you protect). CIA = the goals. Components = software, hardware, data, people, procedures (what an IS is made of). 1–2
Confidentiality vs possession Reading implies holding; holding (encrypted) does not imply reading. 1
Integrity vs accuracy vs authenticity Not changed by the unauthorised / the value is right / it is the original. 1
Defence-in-depth layers vs organisation's security layers Physical, Perimeter, Network, Host, Application, Data vs Physical, Personnel, Operations, Communications, Network, Data. 1
Defence in depth vs redundancy Independent controls in series vs a standby copy that takes over (availability). 1
SDLC vs SecSDLC Same phases; SecSDLC adds threat identification and specific controls in every phase. 1
Vulnerability vs threat vs attack vs risk vs control Weakness / potential harm / exploited for real / threat meets weakness / removes or reduces the weakness. 2–3
Interruption vs interception vs modification vs fabrication Availability / confidentiality / integrity / authenticity. 2
Virus vs worm vs Trojan Needs a host file / spreads alone over the network / pretends to be legitimate. 2
Phishing vs pharming Click a lure vs poisoned DNS, correct URL still lands on the fake site. 2
Spear phishing vs whaling vs angler Specific target / senior executive / social media "customer service". 2
Pretexting vs reverse social engineering Attacker approaches with a story vs victim approaches the attacker for help. 2
Baiting vs tailgating Tempting offer vs physically following someone through a door. 2
Eavesdropping vs sniffing vs port scanning Intercept a conversation (MITM) / capture packets with a sniffer / probe which services run. 2
Security token vs soft token vs key fob Hardware for network access / software, single-use PIN / hardware for a physical object. 2
Identification vs authentication vs authorization Claim / prove / permissions. 2
Auditing vs accounting Recording the log vs reviewing the log to hold people accountable. 2
Data hiding vs encryption Positioning data so it cannot be reached vs hiding its meaning. 2
Abstraction vs layering Grouping for efficiency vs multiple controls in series. 2
Proactive vs reactive Defensive, during design (preferred) vs adversarial, after deployment or an incident. 3
Threat vs threat agent The potential event vs the person or process that initiates it. 3
Governance vs management Doing the right things (strategic) vs doing things right (operational). 4
Due care vs due diligence Taking reasonable steps vs actively checking and analysing risk. 4
Government vs commercial classification TS, S, C, U vs Restricted, Confidential, Internal, Public. 4
Owner vs custodian vs steward vs user Decides / implements / data quality / uses per classification. 4
Data recovery vs data remanence Getting lost data back vs data left behind after "erasing". 4
Clearing vs purging vs destruction Overwrite for reuse / stronger, reuse in less secure places / end of life, most secure. 4
Strategic vs tactical vs operational Why, 3–5 yrs / what, ~1 yr / how, monthly or quarterly. 4
Cryptography vs cryptanalysis vs cryptology Making codes / breaking without the key / the field of both. 5
Substitution vs transposition Letters replaced vs letters keep their form but move. 5
Block vs stream A block at a time vs one element at a time. 5
Keyword vs Vigenère One fixed alphabet (mono) vs a shift per key letter (poly). 5
CBC vs CFB XOR then encrypt vs encrypt then XOR. 5
Known vs chosen plaintext Has pairs vs can pick the plaintexts to encrypt. 5
Chosen plaintext vs chosen ciphertext Encryption box vs decryption box. 5
Hashing vs encryption Fixed-length and one-way vs variable-length and reversible with a key. 5
07

Lists to recite before the exam

If you can write each of these from memory, with the count, you can answer every "list", "except" and "match" question above.