INTRODUCTION TO CRYPTOGRAPHY COMPREHENSIVE EXAM SCRIPT COMPLETE
QUESTIONS VERIFIED SOLUTIONS
● Active Attack. Answer: An attempt to alter system resources or affect
their operation.
Involve some modification of the data stream or the creation of a false
stream and can be subdivided into four categories: masquerade, replay,
modification of messages, and denial of service.
● Authentication. Answer: The assurance that the communicating entity
is the one that it claims to be
Assures that a communication is authentic. In the case of a single
message, such as a warning or alarm signal, the function of the
authentication service is to assure the recipient that the message is from
the source that it claims to be from
● Authenticity. Answer: Verifying that users are who they say they are
and that each input arriving at the system came from a trusted source.
, ● Availability. Answer: Ensuring timely and reliable access to and use of
information. A loss of availability is the disruption of access to or use of
information or an information system.
Consider a system that provides authentication services for critical
systems, applications, and devices. An interruption of service results in
the inability for customers to access computing resources and staff to
access the resources they need to perform critical tasks. The loss of the
service translates into a large financial loss in lost employee productivity
and potential customer loss.
● Data Confidentiality. Answer: Assures that private or confidential
information is not made available or disclosed to unauthorized
individuals.
● Data Integrity. Answer: Assures that information (both stored and in
transmitted packets) and programs are changed only in a specified and
authorized manner.
● Denial off service. Answer: prevents or inhibits the normal use or
management of communications facilities (path 3 active). This attack
may have a specific target; for example, an entity may suppress all
messages directed to a particular destination (e.g., the security audit
service). Another form of service denial is the disruption of an entire
network, either by disabling the network or by overloading it with
messages so as to degrade performance.
QUESTIONS VERIFIED SOLUTIONS
● Active Attack. Answer: An attempt to alter system resources or affect
their operation.
Involve some modification of the data stream or the creation of a false
stream and can be subdivided into four categories: masquerade, replay,
modification of messages, and denial of service.
● Authentication. Answer: The assurance that the communicating entity
is the one that it claims to be
Assures that a communication is authentic. In the case of a single
message, such as a warning or alarm signal, the function of the
authentication service is to assure the recipient that the message is from
the source that it claims to be from
● Authenticity. Answer: Verifying that users are who they say they are
and that each input arriving at the system came from a trusted source.
, ● Availability. Answer: Ensuring timely and reliable access to and use of
information. A loss of availability is the disruption of access to or use of
information or an information system.
Consider a system that provides authentication services for critical
systems, applications, and devices. An interruption of service results in
the inability for customers to access computing resources and staff to
access the resources they need to perform critical tasks. The loss of the
service translates into a large financial loss in lost employee productivity
and potential customer loss.
● Data Confidentiality. Answer: Assures that private or confidential
information is not made available or disclosed to unauthorized
individuals.
● Data Integrity. Answer: Assures that information (both stored and in
transmitted packets) and programs are changed only in a specified and
authorized manner.
● Denial off service. Answer: prevents or inhibits the normal use or
management of communications facilities (path 3 active). This attack
may have a specific target; for example, an entity may suppress all
messages directed to a particular destination (e.g., the security audit
service). Another form of service denial is the disruption of an entire
network, either by disabling the network or by overloading it with
messages so as to degrade performance.