CYBR 7400 Midterm Exam Questions with
Correct Answers
Security attacks are classified as either passive or aggressive
False - passive or active
Authentication protocols and encryption algorithms are examples of security
mechanisms
True
Symmetric encryption is used to conceal the contents of blocks or streams of data of any
size, including messages, files, encryption keys, and passwords
True
The data integrity service inserts bits into gaps in a data stream to frustrate traffic
analysis attempts
False - traffic padding
Data origin authentication does not provide protection against the modification of data
units
True
____ is the most common method used to conceal small blocks of data, such as
encryption keys and hash function values, which are used in digital signatures
asymmetric encryption
A common technique for masking contents of messages or other information traffic so
that opponents cannot extract the information from the message is ____
, encryption
A loss of ____ is the unauthorized disclosure of information
confidentiality
Verifying that users are who they say they are and that each input arriving at the
system came from a trusted source is ____
authenticity
A ____ is a potential for violation of security, which exists when there is a circumstance,
capability, action, or event that could breach security and cause harm
threat
A ____ attack attempts to alter system resources or affect their operation
active
A loss of ____ is the unauthorized modification of information
integrity
An attack tree is a branching, hierarchical data structure that represents a set of
potential techniques for exploiting security vulnerabilities
true
In the context of network security, access control is the ability to limit and control the
access to host systems and applications via communication links
true
Encryption prevents either sender or receiver from denying a transmitted message.
Thus, when a message is sent, the receiver can prove that the alleged sender in fact sent
Correct Answers
Security attacks are classified as either passive or aggressive
False - passive or active
Authentication protocols and encryption algorithms are examples of security
mechanisms
True
Symmetric encryption is used to conceal the contents of blocks or streams of data of any
size, including messages, files, encryption keys, and passwords
True
The data integrity service inserts bits into gaps in a data stream to frustrate traffic
analysis attempts
False - traffic padding
Data origin authentication does not provide protection against the modification of data
units
True
____ is the most common method used to conceal small blocks of data, such as
encryption keys and hash function values, which are used in digital signatures
asymmetric encryption
A common technique for masking contents of messages or other information traffic so
that opponents cannot extract the information from the message is ____
, encryption
A loss of ____ is the unauthorized disclosure of information
confidentiality
Verifying that users are who they say they are and that each input arriving at the
system came from a trusted source is ____
authenticity
A ____ is a potential for violation of security, which exists when there is a circumstance,
capability, action, or event that could breach security and cause harm
threat
A ____ attack attempts to alter system resources or affect their operation
active
A loss of ____ is the unauthorized modification of information
integrity
An attack tree is a branching, hierarchical data structure that represents a set of
potential techniques for exploiting security vulnerabilities
true
In the context of network security, access control is the ability to limit and control the
access to host systems and applications via communication links
true
Encryption prevents either sender or receiver from denying a transmitted message.
Thus, when a message is sent, the receiver can prove that the alleged sender in fact sent