CYBERSECURITY EXAM 1 QUESTIONS WITH ACCURATE ANSWERS (2025 UPDATE).
Security Policy - what are we trying to protect?
Confidentiality, Integrity, Availability, Privacy, Authenticity
Threat Model - who are the attackers?
Their motives, capabilities, level of access
Risk assessment - what would a breach cost us?
Direct costs, Indirect costs, How likely are costs
Logic Bomb
Has a payload (action to perform) and a trigger (boolean condition)
self rep: no, pop growth: 0, parasitic: possibly
Trojan horse
Looks like a valid program - has a malicious purpose
self rep: no, pop growth: 0, parasitic: yes
Back door
Any mechanism that allows bypassing of normal security checks
self rep: no, pop growth: 0, parasitic: possibly
Virus
Code that modifies an executable program file and inserts itself into it (defining feature), often has destructive payload, does not propagate using a network, but infected files can be downloaded or emailed by a network
self rep: yes, pop growth: positive; parasitic: yes
Worm
Standalone program that propagates via a network, does not modify an existing binary file
self rep: yes, pop growth: positive, parasitic: no
Rabbit
Rapidly reproducing program, consumes all of the available computer resources, leaves lots of traces, doesn't accomplish much
self rep: yes, pop growth: positive, parasitic: no
Spyware
Software that collects info from a computer, transmits to another
self rep: no, pop growth: 0, parasitic: no
Adware
Gathers info no user, but more market/marketing focused
self rep: no, pop growth: 0, parasitic: no
Dropper
Program that deposits malware on a computer, many viruses or worms contain dropper for larger piece of malware
self rep: n/a, pop growth: n/a, parasitic: n/a
Hybrids
Uses multiple techniques
self rep: n/a, pop growth: n/a, parasitic: n/a
Zombie
Computer that someone else can partially control, often windows machines, can send spam, perform DoS attacks, user often unaware of it
self rep: ?, pop growth: ?, parasitic: yes (to a computer)
Botnet
number of zombies controlled by single source
self rep: n/a, pop growth: n/a, parasitic: yes
Ransomware
Usually payload of another attack, pay to "release" resources, user behavior vulnerabilities: opening executable email attachments
self rep: 0, pop growth: 0, parasitic: possibly
Challenges in US cybersecurity policy
Lack of congressional tech savvy, rapid change in the field, slow gov't response, well funded adversaries, state's rights, us gov't working against secure computing, who fixes this, lobbying and money in politics, retaining knowledgable people, repeated gov't shutdowns
SOPA and PIPA
Would have took down websites upon accusation of hosting pirated content, held users criminally liable
SOPA and PIPA effect on DNSSEC
Would have made it illegal, AG could sue anyone who provides a means for circumventing / bypassing removal of sites, DNSSEC requires browsers to continue searching DNS servers, even overseas, until untampered results are found
SOPA and PIPA effect on https and tor
Would have made it illegal, if IP address entered directly, ISP would have to inspect each packet, then potentially block that iP address (would also be computationally expensive)
What is US National Security Strategy?
President Trump's plan, four pillars 1) Protect the American people, homeland, American way of life 2) Promote American prosperity 3) Preserve peace through strength 4) Achieve American influence
International Strategy for Cyberspace
Obama-era policy, seven priorities 1) Economy 2) Protecting our networks 3) Law enforcement 4) Military 5) Internet governance 6) International development 7) Internet freedom
Problem with presidential plans
They need funding! and that comes from the legislative branch, which either fails to understand the need for the funding, has motive to lower spending, or has other political priorities
Chelsea Manning
Army intelligence analyst who leaked classified documents to Wikileaks, known as Iraqi war logs and Afghan war logs, lot of civilian death, abusive soldiers/police
Edward Snowden
Booz Allen Hamilton contractor, released info about NSA's global surveillance, foreign govts sending surveillance of their citizens
Problems that led to Snowden
insufficient background checks, no enforced policy against giving out login creds, insufficient compartmentalization of data, data can be removed from "secure sites"
Shadow Brokers
released NSA cyberweapons
Reality Winner
Released confidential report about Russian interference in 2016 election
Caesar Cipher
Substitution cipher, switches each char with char 3 spaces in front, pro: easy to encrypt and decrypt ConsL teach for classes
Vigenere Cipher
polyalphabetic substitution cipher, stronger than caesar cipher, weakness is repeating key
One-time pad
Substitution cipher, take a random string, use modular arithmetic, perfectly secret, good for short messages
Route cipher
Transposition cipher, written in a grid, secret is direction to read
Rail fence cipher
Transposition cipher, plain text written up and down, encrypted text read off in rows
Navajo Code Talkers
Native Americans from the Navajo tribe used their own language to make a code for the U.S. military that the Japanese could not decipher
Rotor machines
Implement poly-alphabetic substitution cipher, Enigma is a famous example
Codes vs ciphers
Codes change the meaning of words, ciphers encrypt them
One- and two-part codes
Contains one or two books that correlate coded words with their plaintext meanings
One-time code
A prearranged word or phrase intended to be used only once, and to convey a message
Idiot code
Any sentence with 'day' and 'night' means 'attack' the location in the sentence
Should hiding the cryptographic system being used be our main form of security?
No, the problem is eventually someone will figure it out, and if there are any weaknesses they will not be fixed, because it will not have been peer reviewed
Block ciphers vs stream ciphers
Block: encrypt a block at a time, stream: encrypt character by character, block is usually more secure
Data Encryption Standard (DES)
Block cipher, does a lot of bit shifting to encrypt/decrypt, 56 bits, susceptible to brute force attacks - use it 3 times (Triple DES)
DES problems
Key length (short), NSA kept details secret
AES
Successor to DES, longer keys (128, 192, 256), NSA kept open, many worry about security
private key cryptography
single key to encrypt and decrypt, key kept secret
public key cryptography
public key for encryption, private key for decryption
public key cryptography goals
key generation should be relatively easy, cracking should be very hard
Fermat Primality Test
If returns composite once, it is composite, else, it is probably not, each iteration halves the probability that the number is a composite, polynomial time
Prime Number Theorem
The number of prime numbers less than x is approximately x/ln(x), the chance of a number x being a prime number is roughly 1/ln(x)
RSA Key Generation
1. Choose two random large prime number p and q (p does not equal q), compute n = p*q
2. Choose an integer 1 e n which is relatively prime to (p-1)(q-1)
3. Compute d such that d * e mod (p-1)(q-1) = 1
4. Destroy all records of p and q
RSA encrypting a message
1. Encode the message m into a number
2. Split the number into smaller numbers m n
3. Use the formula c = m^e mod n (c is ciphertext, m is message)
RSA decrypting messages
1. Use formula m = c^d mod n on each number
2. Split the number into individual ASCII character numbers
3. Decode the message into a string
RSA cracking a message
Must compute m = c^d mod n, n, c, and e are known, d is not, have to factor n into its component primes - no efficient way to do it
RSA signing a message
1. Get the SHA2 hash of message
2. Encrypt it with your private key
3. Anyone can use your public key to decrypt it
4. The hash is then verified against the message
Why RSA is considered secure
1. Factoring large composites into their prime factors is hard
2. Finding the eth roots modulo a composite number is hard
RSA vulnerabilities
Ciphertext can easily be decrypted if e and m are both small, if multiple receivers share the same e, but different p, q, and n, then the same clear text message encrypted for the multiple receivers can be cracked via Chinese remainder theorem, RSA is vulnerable to chosen plaintext attacks - solution: pad message to make it longer
Man in the middle attack
an attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other.
Can computers generate random numbers?
No, by definition they produce the same output for the same input, can generate pseudo-random numbers
Linear Congruential Generator
Xn+1 = (a * Xn + c) mod m
m is the modulus, must be positive
a is the multiplier, 0 a m
c is the increment, 0 c m
X0 is the seed value
Will cycle through all values less than m iff m and c are relatively prime, a-1 is divisible by all prime factors of m, a-1 is divisible by 4 iff m is divisible by 4
Need randomness extractor for the seed
How to ensure download is correct
Can provide hash code of file, provided hash should match hash of download
Hash goals
Changing even a single bit has a dramatic effect on the hash code
Pigeonhole principle (in context of hash)
For an n-bit hash, if we have n+1-bit files, there will be more possible files than possible hashes, multiple files will provide the same hash
Hash vulnerabilities
Want to be able to take an arbitrary text, make it match the desired hash code
Can we go back from a hash?
No, hashes are one way
Collision resistant hash
It is "hard" to find two inputs that hash to the same value (harder than brute force)
CRC32: Cyclic Redundancy Check
Hash value is a 32 bit integer, used for downloading files as a checksum, useful for checking for non-malicious alterations in file
MD5: Message Digest 5
128-bit hash, number of collisions have been found, "should be considered cryptographically broken"
SHA
Secure Hashing Algorithm, flaws found in 0 and 1, not 2 but 2 is similar to 1, so they made 3
Dictionary attack
Take every hashed password for a given system, take every word in the English language, find the intersection of those
Rainbow tables
Precomputed list of all hashed passwords
Password salting
Salt added to hash, prevents dictionary attacks, limits usefulness of rainbow tables
Protocol stack: physical layer
Charged with getting data from one end of the 'wire' to the other end
ex. copper wire, fiber optic cable, wireless transmission
Protocol stack: data link layer
Charged with getting one packet of data from one host to another connected host
ex. Ethernet
Protocol stack: network layer
Charged with getting a single packet of data from one computer to another (via the next layer down), 'routing' the computer between various nodes
ex. IP, ICMP, IPsec
Protocol stack: transport layer
Charged with taking a large piece of data, splitting it into smaller packets, sending each packet to the destination (via the next layer down) and probably reassembling it at the destination
ex. TCP, UDP
Protocol stack: session and presentation layers
Charged with such tasks as managing network sockets, compressing/encoding/encrypting the data, etc (does not exist in TCP/IP model)
ex. TLS, SSL, NetBIOS
Protocol stack: application layer
The top level protocol used to communicate to the application on the other end
ex. DHCP, DNS, FTP, HTTP, IMAP, NTP, POP, SMTP, SSH
OSI Model
The seven layers describing network functions
Application, Presentation, Session, Transport, Network, Data Link, Physical
What is a node
any device on a network
What is a switch
A node that connects networks on the data link layer only
What is a router
A node that connects networks on the network layer
What is a gateway
A node that connects two networks that potentially use different protocols
What is a firewall
prevents unrequested network connections from outside hosts - isolates the 'inside' network and the 'outside' network, requested data is allowed to pass through, can 'poke a hole' in a firewall to allow access to a certain port (such as ssh)
packet filter firewall
removes packets based on the information in their TCP packet - can filter out individual hosts this way
circuit level gateway
forces all data to a given host or network to go through a single gateway, which manages security
application level gateway
only allows specific application level data through
TCP Attacks
Host can intercept packets, would have to know the TCP state, how to prevent: keep anybody from figuring out state of TCP connection
IPsec
protocol suite designed to allow encryption of IP packets at the network level
TLS does something similar at the transport level, SSL is the predecessor to TLS
allows for authentication, exchange of cryptographic keys, and encryption/decryption of IP data packets
Virtual Private Network (VPN)
makes potentially vastly separated IP addresses appear to be a single (virtual) private network, keeps one from having to construct one's own private network (expensive)
Wi-Fi encryption
Encrypts all data sent over a wireless network, two types, WEP and WPA/WPA2
Wired Equivalent Privacy (WEP) weaknesses
Uses a stream cipher (RC4) to encrypt each packet, repeated keys can allow an RC4 message to be cracked
Uses 24 bit IVs, 50% chance of key being repeated after 5k packets, on a busy network, this can happen in under 1 minute
Wi-Fi Protected Access (WPA & WPA2)
WPA uses RC4, WPA2 uses AES
weaknesses: password cracking due to weak passwords, brute force attacks can crack moderate passwords
denial of service attack
Done via flooding the website or resource with network packets, using up its bandwidth, most often done from many sites (DDoS), zombie botnet
ping flood
A ping flood, also known as an ICMP flood attack, is when an attacker attempts to send many ICMP echo request packets (pings) to a host in an attempt to use up all available bandwidth.
Combined bandwidth of the attacker must be greater than the combined bandwidth of the target
SYN flood
sends TCP SYN packet with forged 'from' field, each packet treated like a connection request, target site spans half-open connection, sends ACK, waits
saturates number of connections the attacked server can make
Reflected attack
make the source be the target machine, when the target sends a reply, it goes back to the target, using up their bandwidth a second time
Teardrop attack
Sending mangled IP fragments with overlapping, over-sized payloads to the target
Brute force DoS attack
Just flood the machine with requests, probably via a zombie botnet
TCP/IP Model
Application, TCP, IP, Data Link, Physical
Content preview
CYBERSECURITY EXAM 1 QUESTIONS
WITH ACCURATE ANSWERS (2025
UPDATE).
Security Policy - what are we trying to protect?
Confidentiality, Integrity, Availability, Privacy, Authenticity
Threat Model - who are the attackers?
Their motives, capabilities, level of access
Risk assessment - what would a breach cost us?
Direct costs, Indirect costs, How likely are costs
Logic Bomb
Has a payload (action to perform) and a trigger (boolean condition)
self rep: no, pop growth: 0, parasitic: possibly
Trojan horse
Looks like a valid program - has a malicious purpose
self rep: no, pop growth: 0, parasitic: yes
1
,Back door
Any mechanism that allows bypassing of normal security checks
self rep: no, pop growth: 0, parasitic: possibly
Virus
Code that modifies an executable program file and inserts itself into it (defining feature), often
has destructive payload, does not propagate using a network, but infected files can be
downloaded or emailed by a network
self rep: yes, pop growth: positive; parasitic: yes
Worm
Standalone program that propagates via a network, does not modify an existing binary file
self rep: yes, pop growth: positive, parasitic: no
Rabbit
Rapidly reproducing program, consumes all of the available computer resources, leaves lots of
traces, doesn't accomplish much
self rep: yes, pop growth: positive, parasitic: no
Spyware
Software that collects info from a computer, transmits to another
self rep: no, pop growth: 0, parasitic: no
2
, Adware
Gathers info no user, but more market/marketing focused
self rep: no, pop growth: 0, parasitic: no
Dropper
Program that deposits malware on a computer, many viruses or worms contain dropper for
larger piece of malware
self rep: n/a, pop growth: n/a, parasitic: n/a
Hybrids
Uses multiple techniques
self rep: n/a, pop growth: n/a, parasitic: n/a
Zombie
Computer that someone else can partially control, often windows machines, can send spam,
perform DoS attacks, user often unaware of it
self rep: ?, pop growth: ?, parasitic: yes (to a computer)
Botnet
number of zombies controlled by single source
self rep: n/a, pop growth: n/a, parasitic: yes
3