Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 11 pages
Exam (elaborations)

CYBER SECURITY UPDATED EXAMS SCRIPT QUESTIONS AND ANSWERS SURE

Document preview thumbnail
Preview 2 out of 11 pages

CYBER SECURITY UPDATED EXAMS SCRIPT QUESTIONS AND ANSWERS SURE

Content preview

CYBER SECURITY UPDATED EXAMS SCRIPT
QUESTIONS AND ANSWERS SURE A+
✔✔Cognitive passwords - ✔✔Your mother's last name, 'matrix' or 'qwerty'. When a
person or password checker tries to guess the password, it will typically start with
common words.

✔✔CHAP - ✔✔The Challenge Handshake Authentication Protocol (CHAP) is an
authentication protocol that is primarily used for remote access PPP connections.
Replaced the Plain Authentication Protocol (PAP). CHAP uses a more secure method,
when a client wants to logon, the server sends a challenge request to the client, the
client replies with a challenge response which is a hashed (one-way encrypted) value
based on the username/password-combination and a random number. Vulnerable to
brute force and dictionary attacks.

✔✔Certificate - ✔✔An electronic document that typically contains a public key and
personal user information. Offer better security against brute-force or dictionary attacks
and password guessing than username/password-based authentication methods.

✔✔Certification Authority (CA) - ✔✔Issues certificates to entities such as users,
organizations, web sites and other CAs. As long as the CA can be considered a
trustworthy authority, the certificates (and the key and entity combination in it) issued by
it can be trusted as well.

, ✔✔EAP-TLS (Enhanced Authentication Protocol - Transport Layer Security) - ✔✔A
mutual authentication method, which means that both the client and the server prove
their identities to each other. During the EAP-TLS authentication process, the remote
access client sends its user certificate and the remote access server sends its computer
certificate.

✔✔Kerberos (Authentication) - ✔✔A fairly secure, but also complex and
comprehensive, authentication system, default in Windows, version 5.
There are three primary elements in a Kerberos system:
Client, which is the Kerberos client application representing a principal (computer or
user or software application).
Target server, provides the service the client wants to access.
Key Distribution Center (KDC), handles the distribution of keys and tickets.

✔✔Kerberos Process - ✔✔Authentication Service (AS) Exchange - When the client logs
on, the KDC issues a logon session key and a Ticket-Granting Ticket to the client, after
the KDC has verified the client's encrypted user credentials.
Ticket-Granting Service (TGS) Exchange - The client utilizes the TGT and the logon
session key to request a new session key and ticket to be used between the client and
the target server.
Client-Server (CS) Exchange - The client sends the new ticket, including the new
session key, to the target server to authenticate itself and to provide the target server
with the session key. Optionally, the target server uses the new session key to
authenticate itself to the client.

✔✔Single Sign On (SSO) - ✔✔Allows a user to logon only once and be able to access
all different resources in the network, such as e-mail, file servers, Intranet, etc. Attribute
of Kerberos.

✔✔Mutual authentication - ✔✔A client authenticates to a service, and the service
authenticates to the client, before any application traffic is exchanged. Can be
implemented using simple authentication protocols or more advanced solutions such as
Kerberos, commonly found in SSL (Secure Socket Layer) connections.

✔✔Biometrics - ✔✔Very secure type of authentication that uses anatomical and
physiological characteristics to authenticate a user, "something you are." Requires a lot
of storage, processing power, and appropriate conditions.
Ex: Finger print, voice, palm, retina, iris, facial, etc.

✔✔Tokens - ✔✔Software tokens are generated by the authenticating system when a
user logs on successfully, provide access to resources.
Hardware tokens, magnetic-strip cards and USB devices, contain a symmetric key that
is used for one-way hashing of a pin code or time stamp.

Document information

Uploaded on
July 16, 2026
Number of pages
11
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Pyramids
4.0
(2)
Sold
21
Followers
4
Items
7209
Last sold
3 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions