• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

CS 6262 Network Security Exam Practice Questions And Correct Answers (Verified Answers) Plus Rationale 2027 Q&A| Instant Download Pdf.

Document preview thumbnail
Preview 4 out of 38 pages

CS 6262 Network Security Exam Practice Questions And Correct Answers (Verified Answers) Plus Rationale 2027 Q&A| Instant Download Pdf.

Content preview

CS 6262 Network Security Exam Practice
Questions And Correct Answers
(Verified Answers) Plus Rationale 2027
Q&A| Instant Download Pdf.



1. Which statement best characterizes the primary security objectives
that a network security architecture should preserve when designing
defenses against both passive and active adversaries?

A. Increasing bandwidth, reducing latency, and maximizing protocol
complexity
B. Preserving confidentiality, integrity, and availability while providing
appropriate authentication and accountability
C. Eliminating all network traffic that originates outside the organization
D. Ensuring that every application uses identical authentication and
encryption mechanisms

The fundamental security objectives are confidentiality, integrity, and
availability, commonly complemented by authentication, authorization,
accountability, and privacy. A secure architecture balances these objectives
against operational requirements rather than attempting to eliminate all
external communication.

2. An attacker observes encrypted network traffic between two hosts
but does not modify, inject, or delete any packets. Which type of
attack is most accurately represented by this behavior?

,A. Active interception
B. Replay attack
C. Passive eavesdropping
D. Man-in-the-middle modification

Passive eavesdropping involves observing communications without
altering them. Encryption is primarily used to protect confidentiality
against this class of attack, whereas authentication and integrity
mechanisms are needed to detect or prevent many active attacks.

3. A network administrator receives an authentication message
containing a cryptographic hash of a password. Why is storing an
unsalted password hash generally considered inadequate?

A. Hash functions cannot process passwords securely
B. Password hashes cannot be transmitted over networks
C. Identical passwords produce identical hashes, enabling precomputed
attacks such as rainbow-table attacks
D. Salting converts passwords into symmetric encryption keys

A salt introduces unique randomness into password derivation, making
identical passwords produce different stored values and substantially
reducing the effectiveness of precomputed lookup attacks.

4. Which property distinguishes a cryptographic hash function from a
conventional checksum?

A. A checksum always requires a secret key
B. A hash function guarantees that collisions are mathematically impossible
C. A cryptographic hash is designed to make preimage, second-preimage,
and collision attacks computationally difficult
D. A cryptographic hash necessarily provides confidentiality

Cryptographic hashes are designed with specific one-way and collision-
resistance properties. They provide integrity-related capabilities but do not
inherently provide confidentiality because the hash itself is not encryption.

, 5. A company wants to ensure that a message was generated by a
particular sender and was not modified while in transit. Which
mechanism provides the most appropriate solution when the sender
and receiver share a secret key?

A. Plaintext encoding
B. Digital certificate alone
C. Message Authentication Code (MAC)
D. Public-key encryption without authentication

A MAC uses a shared secret key to produce an authentication tag that
allows the receiver to verify both message integrity and possession of the
shared secret. It does not by itself provide nonrepudiation.

6. Which statement correctly distinguishes a digital signature from a
MAC?

A. A MAC uses public keys, whereas a digital signature uses one shared
secret
B. A digital signature cannot provide integrity
C. A digital signature uses asymmetric cryptography and can support public
verification and nonrepudiation properties
D. A MAC always provides stronger confidentiality than a digital signature

Digital signatures are generated with a private key and verified with the
corresponding public key. Because verification does not require sharing the
signing secret, signatures can provide stronger evidentiary and
nonrepudiation properties than MACs.

7. During a public-key exchange, an attacker substitutes the attacker's
public key for the legitimate recipient's key and later decrypts
messages before forwarding them. What attack has occurred?

A. Birthday attack
B. Replay attack
C. Man-in-the-middle attack
D. Denial-of-service attack

, A man-in-the-middle attacker positions itself between communicating
parties and manipulates the key-establishment process so that each
legitimate party unknowingly communicates through the attacker.

8. Why are digital certificates important in a public-key infrastructure?

A. They encrypt all Internet traffic automatically
B. They replace the need for private keys
C. They bind an identity to a public key through a trusted certification
authority
D. They guarantee that the certificate holder is trustworthy in every context

A certificate provides a digitally signed binding between an identity and a
public key. Trust in the binding depends on the certificate authority,
certificate validation procedures, and the applicable trust model.

9. Which characteristic of a properly designed nonce makes it
particularly useful for preventing replay attacks?

A. It remains constant for every session
B. It is publicly predictable before transmission
C. It is fresh and associated with a particular protocol execution
D. It is always derived from the user's password

A fresh nonce allows a protocol participant to distinguish a current
transaction from an earlier recorded transaction. Reusing predictable or
insufficiently unique values can undermine replay protection.

10. A network protocol accepts an authentication response
containing a previously captured valid message because it does not
verify freshness. Which security property has most directly failed?

A. Confidentiality
B. Availability
C. Replay resistance
D. Forward secrecy

Document information

Uploaded on
August 24, 2026
Number of pages
38
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$24.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
YouTubes
3.6
(37)
Sold
218
Followers
2
Items
5515
Last sold
13 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions