• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 19 pages
Exam (elaborations)

Cybersecurity Exam 1 Questions With Accurate Answers (2025 Update).

Document preview thumbnail
Preview 3 out of 19 pages

CYBERSECURITY EXAM 1 QUESTIONS WITH ACCURATE ANSWERS (2025 UPDATE). Security Policy - what are we trying to protect? Confidentiality, Integrity, Availability, Privacy, Authenticity Threat Model - who are the attackers? Their motives, capabilities, level of access Risk assessment - what would a breach cost us? Direct costs, Indirect costs, How likely are costs Logic Bomb Has a payload (action to perform) and a trigger (boolean condition) self rep: no, pop growth: 0, parasitic: possibly Trojan horse Looks like a valid program - has a malicious purpose self rep: no, pop growth: 0, parasitic: yes Back door Any mechanism that allows bypassing of normal security checks self rep: no, pop growth: 0, parasitic: possibly Virus Code that modifies an executable program file and inserts itself into it (defining feature), often has destructive payload, does not propagate using a network, but infected files can be downloaded or emailed by a network self rep: yes, pop growth: positive; parasitic: yes Worm Standalone program that propagates via a network, does not modify an existing binary file self rep: yes, pop growth: positive, parasitic: no Rabbit Rapidly reproducing program, consumes all of the available computer resources, leaves lots of traces, doesn't accomplish much self rep: yes, pop growth: positive, parasitic: no Spyware Software that collects info from a computer, transmits to another self rep: no, pop growth: 0, parasitic: no Adware Gathers info no user, but more market/marketing focused self rep: no, pop growth: 0, parasitic: no Dropper Program that deposits malware on a computer, many viruses or worms contain dropper for larger piece of malware self rep: n/a, pop growth: n/a, parasitic: n/a Hybrids Uses multiple techniques self rep: n/a, pop growth: n/a, parasitic: n/a Zombie Computer that someone else can partially control, often windows machines, can send spam, perform DoS attacks, user often unaware of it self rep: ?, pop growth: ?, parasitic: yes (to a computer) Botnet number of zombies controlled by single source self rep: n/a, pop growth: n/a, parasitic: yes Ransomware Usually payload of another attack, pay to "release" resources, user behavior vulnerabilities: opening executable email attachments self rep: 0, pop growth: 0, parasitic: possibly Challenges in US cybersecurity policy Lack of congressional tech savvy, rapid change in the field, slow gov't response, well funded adversaries, state's rights, us gov't working against secure computing, who fixes this, lobbying and money in politics, retaining knowledgable people, repeated gov't shutdowns SOPA and PIPA Would have took down websites upon accusation of hosting pirated content, held users criminally liable SOPA and PIPA effect on DNSSEC Would have made it illegal, AG could sue anyone who provides a means for circumventing / bypassing removal of sites, DNSSEC requires browsers to continue searching DNS servers, even overseas, until untampered results are found SOPA and PIPA effect on https and tor Would have made it illegal, if IP address entered directly, ISP would have to inspect each packet, then potentially block that iP address (would also be computationally expensive) What is US National Security Strategy? President Trump's plan, four pillars 1) Protect the American people, homeland, American way of life 2) Promote American prosperity 3) Preserve peace through strength 4) Achieve American influence International Strategy for Cyberspace Obama-era policy, seven priorities 1) Economy 2) Protecting our networks 3) Law enforcement 4) Military 5) Internet governance 6) International development 7) Internet freedom Problem with presidential plans They need funding! and that comes from the legislative branch, which either fails to understand the need for the funding, has motive to lower spending, or has other political priorities Chelsea Manning Army intelligence analyst who leaked classified documents to Wikileaks, known as Iraqi war logs and Afghan war logs, lot of civilian death, abusive soldiers/police Edward Snowden Booz Allen Hamilton contractor, released info about NSA's global surveillance, foreign govts sending surveillance of their citizens Problems that led to Snowden insufficient background checks, no enforced policy against giving out login creds, insufficient compartmentalization of data, data can be removed from "secure sites" Shadow Brokers released NSA cyberweapons Reality Winner Released confidential report about Russian interference in 2016 election Caesar Cipher Substitution cipher, switches each char with char 3 spaces in front, pro: easy to encrypt and decrypt ConsL teach for classes Vigenere Cipher polyalphabetic substitution cipher, stronger than caesar cipher, weakness is repeating key One-time pad Substitution cipher, take a random string, use modular arithmetic, perfectly secret, good for short messages Route cipher Transposition cipher, written in a grid, secret is direction to read Rail fence cipher Transposition cipher, plain text written up and down, encrypted text read off in rows Navajo Code Talkers Native Americans from the Navajo tribe used their own language to make a code for the U.S. military that the Japanese could not decipher Rotor machines Implement poly-alphabetic substitution cipher, Enigma is a famous example Codes vs ciphers Codes change the meaning of words, ciphers encrypt them One- and two-part codes Contains one or two books that correlate coded words with their plaintext meanings One-time code A prearranged word or phrase intended to be used only once, and to convey a message Idiot code Any sentence with 'day' and 'night' means 'attack' the location in the sentence Should hiding the cryptographic system being used be our main form of security? No, the problem is eventually someone will figure it out, and if there are any weaknesses they will not be fixed, because it will not have been peer reviewed Block ciphers vs stream ciphers Block: encrypt a block at a time, stream: encrypt character by character, block is usually more secure Data Encryption Standard (DES) Block cipher, does a lot of bit shifting to encrypt/decrypt, 56 bits, susceptible to brute force attacks - use it 3 times (Triple DES) DES problems Key length (short), NSA kept details secret AES Successor to DES, longer keys (128, 192, 256), NSA kept open, many worry about security private key cryptography single key to encrypt and decrypt, key kept secret public key cryptography public key for encryption, private key for decryption public key cryptography goals key generation should be relatively easy, cracking should be very hard Fermat Primality Test If returns composite once, it is composite, else, it is probably not, each iteration halves the probability that the number is a composite, polynomial time Prime Number Theorem The number of prime numbers less than x is approximately x/ln(x), the chance of a number x being a prime number is roughly 1/ln(x) RSA Key Generation 1. Choose two random large prime number p and q (p does not equal q), compute n = p*q 2. Choose an integer 1 e n which is relatively prime to (p-1)(q-1) 3. Compute d such that d * e mod (p-1)(q-1) = 1 4. Destroy all records of p and q RSA encrypting a message 1. Encode the message m into a number 2. Split the number into smaller numbers m n 3. Use the formula c = m^e mod n (c is ciphertext, m is message) RSA decrypting messages 1. Use formula m = c^d mod n on each number 2. Split the number into individual ASCII character numbers 3. Decode the message into a string RSA cracking a message Must compute m = c^d mod n, n, c, and e are known, d is not, have to factor n into its component primes - no efficient way to do it RSA signing a message 1. Get the SHA2 hash of message 2. Encrypt it with your private key 3. Anyone can use your public key to decrypt it 4. The hash is then verified against the message Why RSA is considered secure 1. Factoring large composites into their prime factors is hard 2. Finding the eth roots modulo a composite number is hard RSA vulnerabilities Ciphertext can easily be decrypted if e and m are both small, if multiple receivers share the same e, but different p, q, and n, then the same clear text message encrypted for the multiple receivers can be cracked via Chinese remainder theorem, RSA is vulnerable to chosen plaintext attacks - solution: pad message to make it longer Man in the middle attack an attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. Can computers generate random numbers? No, by definition they produce the same output for the same input, can generate pseudo-random numbers Linear Congruential Generator Xn+1 = (a * Xn + c) mod m m is the modulus, must be positive a is the multiplier, 0 a m c is the increment, 0 c m X0 is the seed value Will cycle through all values less than m iff m and c are relatively prime, a-1 is divisible by all prime factors of m, a-1 is divisible by 4 iff m is divisible by 4 Need randomness extractor for the seed How to ensure download is correct Can provide hash code of file, provided hash should match hash of download Hash goals Changing even a single bit has a dramatic effect on the hash code Pigeonhole principle (in context of hash) For an n-bit hash, if we have n+1-bit files, there will be more possible files than possible hashes, multiple files will provide the same hash Hash vulnerabilities Want to be able to take an arbitrary text, make it match the desired hash code Can we go back from a hash? No, hashes are one way Collision resistant hash It is "hard" to find two inputs that hash to the same value (harder than brute force) CRC32: Cyclic Redundancy Check Hash value is a 32 bit integer, used for downloading files as a checksum, useful for checking for non-malicious alterations in file MD5: Message Digest 5 128-bit hash, number of collisions have been found, "should be considered cryptographically broken" SHA Secure Hashing Algorithm, flaws found in 0 and 1, not 2 but 2 is similar to 1, so they made 3 Dictionary attack Take every hashed password for a given system, take every word in the English language, find the intersection of those Rainbow tables Precomputed list of all hashed passwords Password salting Salt added to hash, prevents dictionary attacks, limits usefulness of rainbow tables Protocol stack: physical layer Charged with getting data from one end of the 'wire' to the other end ex. copper wire, fiber optic cable, wireless transmission Protocol stack: data link layer Charged with getting one packet of data from one host to another connected host ex. Ethernet Protocol stack: network layer Charged with getting a single packet of data from one computer to another (via the next layer down), 'routing' the computer between various nodes ex. IP, ICMP, IPsec Protocol stack: transport layer Charged with taking a large piece of data, splitting it into smaller packets, sending each packet to the destination (via the next layer down) and probably reassembling it at the destination ex. TCP, UDP Protocol stack: session and presentation layers Charged with such tasks as managing network sockets, compressing/encoding/encrypting the data, etc (does not exist in TCP/IP model) ex. TLS, SSL, NetBIOS Protocol stack: application layer The top level protocol used to communicate to the application on the other end ex. DHCP, DNS, FTP, HTTP, IMAP, NTP, POP, SMTP, SSH OSI Model The seven layers describing network functions Application, Presentation, Session, Transport, Network, Data Link, Physical What is a node any device on a network What is a switch A node that connects networks on the data link layer only What is a router A node that connects networks on the network layer What is a gateway A node that connects two networks that potentially use different protocols What is a firewall prevents unrequested network connections from outside hosts - isolates the 'inside' network and the 'outside' network, requested data is allowed to pass through, can 'poke a hole' in a firewall to allow access to a certain port (such as ssh) packet filter firewall removes packets based on the information in their TCP packet - can filter out individual hosts this way circuit level gateway forces all data to a given host or network to go through a single gateway, which manages security application level gateway only allows specific application level data through TCP Attacks Host can intercept packets, would have to know the TCP state, how to prevent: keep anybody from figuring out state of TCP connection IPsec protocol suite designed to allow encryption of IP packets at the network level TLS does something similar at the transport level, SSL is the predecessor to TLS allows for authentication, exchange of cryptographic keys, and encryption/decryption of IP data packets Virtual Private Network (VPN) makes potentially vastly separated IP addresses appear to be a single (virtual) private network, keeps one from having to construct one's own private network (expensive) Wi-Fi encryption Encrypts all data sent over a wireless network, two types, WEP and WPA/WPA2 Wired Equivalent Privacy (WEP) weaknesses Uses a stream cipher (RC4) to encrypt each packet, repeated keys can allow an RC4 message to be cracked Uses 24 bit IVs, 50% chance of key being repeated after 5k packets, on a busy network, this can happen in under 1 minute Wi-Fi Protected Access (WPA & WPA2) WPA uses RC4, WPA2 uses AES weaknesses: password cracking due to weak passwords, brute force attacks can crack moderate passwords denial of service attack Done via flooding the website or resource with network packets, using up its bandwidth, most often done from many sites (DDoS), zombie botnet ping flood A ping flood, also known as an ICMP flood attack, is when an attacker attempts to send many ICMP echo request packets (pings) to a host in an attempt to use up all available bandwidth. Combined bandwidth of the attacker must be greater than the combined bandwidth of the target SYN flood sends TCP SYN packet with forged 'from' field, each packet treated like a connection request, target site spans half-open connection, sends ACK, waits saturates number of connections the attacked server can make Reflected attack make the source be the target machine, when the target sends a reply, it goes back to the target, using up their bandwidth a second time Teardrop attack Sending mangled IP fragments with overlapping, over-sized payloads to the target Brute force DoS attack Just flood the machine with requests, probably via a zombie botnet TCP/IP Model Application, TCP, IP, Data Link, Physical

Content preview

CYBERSECURITY EXAM 1 QUESTIONS
WITH ACCURATE ANSWERS (2025
UPDATE).
Security Policy - what are we trying to protect?

Confidentiality, Integrity, Availability, Privacy, Authenticity




Threat Model - who are the attackers?

Their motives, capabilities, level of access




Risk assessment - what would a breach cost us?

Direct costs, Indirect costs, How likely are costs




Logic Bomb

Has a payload (action to perform) and a trigger (boolean condition)

self rep: no, pop growth: 0, parasitic: possibly




Trojan horse

Looks like a valid program - has a malicious purpose

self rep: no, pop growth: 0, parasitic: yes




1

,Back door

Any mechanism that allows bypassing of normal security checks

self rep: no, pop growth: 0, parasitic: possibly




Virus

Code that modifies an executable program file and inserts itself into it (defining feature), often
has destructive payload, does not propagate using a network, but infected files can be
downloaded or emailed by a network

self rep: yes, pop growth: positive; parasitic: yes




Worm

Standalone program that propagates via a network, does not modify an existing binary file

self rep: yes, pop growth: positive, parasitic: no




Rabbit

Rapidly reproducing program, consumes all of the available computer resources, leaves lots of
traces, doesn't accomplish much

self rep: yes, pop growth: positive, parasitic: no




Spyware

Software that collects info from a computer, transmits to another

self rep: no, pop growth: 0, parasitic: no

2

, Adware

Gathers info no user, but more market/marketing focused

self rep: no, pop growth: 0, parasitic: no




Dropper

Program that deposits malware on a computer, many viruses or worms contain dropper for
larger piece of malware

self rep: n/a, pop growth: n/a, parasitic: n/a




Hybrids

Uses multiple techniques

self rep: n/a, pop growth: n/a, parasitic: n/a




Zombie

Computer that someone else can partially control, often windows machines, can send spam,
perform DoS attacks, user often unaware of it

self rep: ?, pop growth: ?, parasitic: yes (to a computer)




Botnet

number of zombies controlled by single source

self rep: n/a, pop growth: n/a, parasitic: yes
3

Document information

Uploaded on
January 21, 2026
Number of pages
19
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$9.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
4
Followers
0
Items
371
Last sold
4 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions