SANS 401 GSEC EXAMINATION SET QUESTIONS
AND ANSWERS SET A+
✔✔Intrusion Prevention System (IPS) - ✔✔Stops attacks on systems and networks from
being effective which can be network or host-based
✔✔Network IPS (NIPS) - ✔✔Typically deployed at the perimeter in front and/or behind a
firewall. Ensure between internet and DMZ are safe, also checking VPN users
✔✔Cryptography - ✔✔Art and Science of hiding the meaning of a communication from
unintended recipients
✔✔Cryptology - ✔✔Encompasses cryptography and cryptanalysis
✔✔Encryption - ✔✔Coding a message so that its meaning is concealed
✔✔Decryption - ✔✔Process of transforming an encrypted message into it original form
✔✔Plaintext - ✔✔Message in its original form
✔✔Ciphertext - ✔✔Message in its encrypted form
✔✔The more bits of encryption - ✔✔The harder it is to break
✔✔COCOM - ✔✔1991, allowed export of encryption except to dangerous countries
✔✔Wassenaar Arrangement - ✔✔1995, 28 countries allowed free symmetric encryption
export, other crypto requires a license
✔✔European Union Controls - ✔✔Focused on export of encryption regulated by the
Concil Regulation (EC)
, ✔✔United States Controls - ✔✔No import restrictions, signed the Wassenaar
Arrangement but with strciter export controls
✔✔Symmetric Encryption (Confidentiality) - ✔✔Same key used to Encrypt as to
Decrypt. Fairly fast!
✔✔Symmetric Encryption Techniques - ✔✔Exclusive OR (XOR)
Arbitrary Substitution
Rotation
Permutation
✔✔Hashing (Integrity) - ✔✔One-way transformation which requires no key. Plaintext is
not recoverable (integrity)
✔✔Asymmetric Encryption (Authentication) - ✔✔Public key, dual-key encryption.
Whatever key encrypts, only the other key decrypts
✔✔If you send a message to someones Public Key - ✔✔Only their Private Key and
decrypt the message
✔✔If you send to private key - ✔✔Anyone can decrypt via the sender's public key
✔✔Digital Signature (Non-Repudiation) - ✔✔Use public key cryptography to "sign"
documents. Signatures are mostly authentic and nonrepudiable. Sign with hash of
private key
✔✔Stegonography - ✔✔Data hiding involving concealing the fact that you are sending
"sensitive" information
✔✔Types of Steganography - ✔✔Watermarking
Cryptography
Steganography
✔✔Confidentiality in Encryption - ✔✔Any Cryptography
✔✔Integrity in Encryption - ✔✔Hashing
✔✔Authentication in Encryption - ✔✔Asymmetric Encryption
✔✔Non-Repudiation in Encryption - ✔✔Asymmetric and Hashing
✔✔Data Encryption Standard (DES) - ✔✔Released May 17th, 1975. Symmetric 64-bit
block cipher algorithm. 56-bit key size
AND ANSWERS SET A+
✔✔Intrusion Prevention System (IPS) - ✔✔Stops attacks on systems and networks from
being effective which can be network or host-based
✔✔Network IPS (NIPS) - ✔✔Typically deployed at the perimeter in front and/or behind a
firewall. Ensure between internet and DMZ are safe, also checking VPN users
✔✔Cryptography - ✔✔Art and Science of hiding the meaning of a communication from
unintended recipients
✔✔Cryptology - ✔✔Encompasses cryptography and cryptanalysis
✔✔Encryption - ✔✔Coding a message so that its meaning is concealed
✔✔Decryption - ✔✔Process of transforming an encrypted message into it original form
✔✔Plaintext - ✔✔Message in its original form
✔✔Ciphertext - ✔✔Message in its encrypted form
✔✔The more bits of encryption - ✔✔The harder it is to break
✔✔COCOM - ✔✔1991, allowed export of encryption except to dangerous countries
✔✔Wassenaar Arrangement - ✔✔1995, 28 countries allowed free symmetric encryption
export, other crypto requires a license
✔✔European Union Controls - ✔✔Focused on export of encryption regulated by the
Concil Regulation (EC)
, ✔✔United States Controls - ✔✔No import restrictions, signed the Wassenaar
Arrangement but with strciter export controls
✔✔Symmetric Encryption (Confidentiality) - ✔✔Same key used to Encrypt as to
Decrypt. Fairly fast!
✔✔Symmetric Encryption Techniques - ✔✔Exclusive OR (XOR)
Arbitrary Substitution
Rotation
Permutation
✔✔Hashing (Integrity) - ✔✔One-way transformation which requires no key. Plaintext is
not recoverable (integrity)
✔✔Asymmetric Encryption (Authentication) - ✔✔Public key, dual-key encryption.
Whatever key encrypts, only the other key decrypts
✔✔If you send a message to someones Public Key - ✔✔Only their Private Key and
decrypt the message
✔✔If you send to private key - ✔✔Anyone can decrypt via the sender's public key
✔✔Digital Signature (Non-Repudiation) - ✔✔Use public key cryptography to "sign"
documents. Signatures are mostly authentic and nonrepudiable. Sign with hash of
private key
✔✔Stegonography - ✔✔Data hiding involving concealing the fact that you are sending
"sensitive" information
✔✔Types of Steganography - ✔✔Watermarking
Cryptography
Steganography
✔✔Confidentiality in Encryption - ✔✔Any Cryptography
✔✔Integrity in Encryption - ✔✔Hashing
✔✔Authentication in Encryption - ✔✔Asymmetric Encryption
✔✔Non-Repudiation in Encryption - ✔✔Asymmetric and Hashing
✔✔Data Encryption Standard (DES) - ✔✔Released May 17th, 1975. Symmetric 64-bit
block cipher algorithm. 56-bit key size