Computer Security (Midterm) questions
with answers
Confidentiality, |Integrity, |Availability |- |correct |answers✔✔What |is |the |"CIA" |triad?
Reasons |that |successful |security |is |challenging. |- |correct |answers✔✔Security
|requirements |seem |easy, |but |the |mechanisms |are |complex; |there |are |many |different
|ways |to |attack; |attackers |only |need |to |find |one |weakness |and |defenders |must
|defend |against |everything; |Security |requires |regular |monitoring; |Often |security |is
|tacked |on |as |an |afterthought.
Integrity |- |correct |answers✔✔The |requirement |that |changes |to |data |must |be |done
|following |specific |rules; |modification |that |damages |something.
Availability |- |correct |answers✔✔The |requirement |that |a |system |must |respond
|promptly |to |legitimate |requests.
What |two |steps |can |authentication |be |broken |into? |- |correct
|answers✔✔Identification |and |then |verification.
Can |DES |be |used |with |any |size |encryption |key? |- |correct |answers✔✔No
Is |public-key |encryption |much |faster |than |private-key |encryption? |- |correct
|answers✔✔False
Data |Encryption |Standard |(DES) |- |correct |answers✔✔Block |cipher |and |must |be
|exactly |64 |bits |of |plaintext
Triple |Data |Encryption |Standard |(3DES) |- |correct |answers✔✔You |take |the |plaintext
|or |data |and |encrypt |it, |three |times, |with |a |56-bit |key |and |then |cipher. |Harder |to
|crack.
, Advanced |Encryption |Standard |(AES) |- |correct |answers✔✔The |message |that |goes
|into |this |is |now |128 |bits |instead |of |64 |bits. |Can't |really |reliably |tell |if |you |got |the
|right |key |or |not.
Block |chaining |- |correct |answers✔✔Making |a |chain |of |blocks |you |can |encrypt |using
|some |sort |of |strategy |that |uses |a |computer |algorithm |instead |to |translate |things.
|Matches |from |a |data |block |to |the |corresponding |cipher |block. |Encrypt |each |block
|identically.
Stream |cipher |- |correct |answers✔✔Like |a |block-cipher |with |incredibly |small |blocks
|— |we |have |a |whole |steam |of |data |coming |to |us |(not |at |once, |but |over), |called |a
|stream |of |data.
Pseudorandom |numbers |- |correct |answers✔✔Using |a |number |generator |and |and
|seeding |it |with |a |key; |used |as |an |encryption |method.
Which |kind |of |attack |is |denial? |- |correct |answers✔✔Repudiation
What |is |the |best |way |to |prevent |SQL |injection |attacks? |- |correct |answers✔✔Ensure
|that |every |time |a |dynamic |query |is |sent |to |the |database, |it |is |parameterized |with |'?'
|Placeholders.
Subject |- |correct |answers✔✔(Access |control |in |Authorization) |Who |has |permission;
|agents |who |can |access |the |resources |i.e. |person, |program |or |computer |system
Object |- |correct |answers✔✔(Access |control |in |Authorization) |Resources |we're
|protecting
Owner |- |correct |answers✔✔(Access |control |in |Authorization) |Subject |with |ultimate
|rights |to |the |object |i.e. |write |privilege, |read |privilege, |execute |privilege, |directories
|privilege.
Group |- |correct |answers✔✔A |set |of |subjects |who |have |special |rights |to |the |object
with answers
Confidentiality, |Integrity, |Availability |- |correct |answers✔✔What |is |the |"CIA" |triad?
Reasons |that |successful |security |is |challenging. |- |correct |answers✔✔Security
|requirements |seem |easy, |but |the |mechanisms |are |complex; |there |are |many |different
|ways |to |attack; |attackers |only |need |to |find |one |weakness |and |defenders |must
|defend |against |everything; |Security |requires |regular |monitoring; |Often |security |is
|tacked |on |as |an |afterthought.
Integrity |- |correct |answers✔✔The |requirement |that |changes |to |data |must |be |done
|following |specific |rules; |modification |that |damages |something.
Availability |- |correct |answers✔✔The |requirement |that |a |system |must |respond
|promptly |to |legitimate |requests.
What |two |steps |can |authentication |be |broken |into? |- |correct
|answers✔✔Identification |and |then |verification.
Can |DES |be |used |with |any |size |encryption |key? |- |correct |answers✔✔No
Is |public-key |encryption |much |faster |than |private-key |encryption? |- |correct
|answers✔✔False
Data |Encryption |Standard |(DES) |- |correct |answers✔✔Block |cipher |and |must |be
|exactly |64 |bits |of |plaintext
Triple |Data |Encryption |Standard |(3DES) |- |correct |answers✔✔You |take |the |plaintext
|or |data |and |encrypt |it, |three |times, |with |a |56-bit |key |and |then |cipher. |Harder |to
|crack.
, Advanced |Encryption |Standard |(AES) |- |correct |answers✔✔The |message |that |goes
|into |this |is |now |128 |bits |instead |of |64 |bits. |Can't |really |reliably |tell |if |you |got |the
|right |key |or |not.
Block |chaining |- |correct |answers✔✔Making |a |chain |of |blocks |you |can |encrypt |using
|some |sort |of |strategy |that |uses |a |computer |algorithm |instead |to |translate |things.
|Matches |from |a |data |block |to |the |corresponding |cipher |block. |Encrypt |each |block
|identically.
Stream |cipher |- |correct |answers✔✔Like |a |block-cipher |with |incredibly |small |blocks
|— |we |have |a |whole |steam |of |data |coming |to |us |(not |at |once, |but |over), |called |a
|stream |of |data.
Pseudorandom |numbers |- |correct |answers✔✔Using |a |number |generator |and |and
|seeding |it |with |a |key; |used |as |an |encryption |method.
Which |kind |of |attack |is |denial? |- |correct |answers✔✔Repudiation
What |is |the |best |way |to |prevent |SQL |injection |attacks? |- |correct |answers✔✔Ensure
|that |every |time |a |dynamic |query |is |sent |to |the |database, |it |is |parameterized |with |'?'
|Placeholders.
Subject |- |correct |answers✔✔(Access |control |in |Authorization) |Who |has |permission;
|agents |who |can |access |the |resources |i.e. |person, |program |or |computer |system
Object |- |correct |answers✔✔(Access |control |in |Authorization) |Resources |we're
|protecting
Owner |- |correct |answers✔✔(Access |control |in |Authorization) |Subject |with |ultimate
|rights |to |the |object |i.e. |write |privilege, |read |privilege, |execute |privilege, |directories
|privilege.
Group |- |correct |answers✔✔A |set |of |subjects |who |have |special |rights |to |the |object