Information Assurance & Security
Comprehensive Finals Test (Qns & Ans)
2025
1. Which of the following security models uses labels to enforce
access control and protect data confidentiality?
- A. Bell-LaPadula
- B. Biba
- C. Clark-Wilson
- D. Brewer-Nash
ANS: A. Bell-LaPadula
©/2025
, Rationale: The Bell-LaPadula model uses security labels to
enforce access control and ensure that information flows in a
manner that maintains data confidentiality.
2. Which encryption method is based on the difficulty of
factoring large prime numbers?
- A. AES
- B. RSA
- C. DES
- D. Blowfish
ANS: B. RSA
Rationale: RSA encryption relies on the mathematical
difficulty of factoring large prime numbers, making it a secure
method for public-key cryptography.
Fill-in-the-Blank Questions
3. The principle of __________ ensures that only authorized
individuals can access sensitive information.
ANS: confidentiality
©/2025
, Rationale: Confidentiality ensures that sensitive information
is accessible only to authorized individuals, protecting it from
unauthorized access and disclosure.
4. The __________ is the entity responsible for issuing and
managing digital certificates within a public key infrastructure.
ANS: Certificate Authority (CA)
Rationale: A Certificate Authority (CA) issues and manages
digital certificates, verifying the identities of entities and ensuring
secure communication.
True/False Questions
5. True or False: A zero-day vulnerability is a security flaw that
has been publicly disclosed but not yet patched by the software
vendor.
ANS: False
Rationale: A zero-day vulnerability is a security flaw that is
unknown to the software vendor and has not been publicly
disclosed or patched.
©/2025