Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 16 pages
Exam (elaborations)

Final Exam 660 Study Guide Questions And Actual Answers.

Document preview thumbnail
Preview 3 out of 16 pages

Several security models exist, and all of them can help understand how security enters into computer architectures and operating system design - Answer -Trusted Computing Base (TCB) -State Machine Model -Information Flow & Noninterference Model -Take-Grant Model -Access Control Matrix -Bell-LaPadula Model -Biba Model -Clark-Wilson Model -Brewer and Nash Model (aka Chinese Wall) The foundation upon which security models are built is the - Answer Trusted Computing Base (TCB) An old U.S. Department of Defense standard known as the Orange Book describes a Trusted Computing Base (TCB) as - Answer "a combination of hardware, software, and controls that work together to form a trusted base to enforce your security policy" The TCB is a subset of a complete information system - Answer -It should be as small as possible so that a detailed analysis can ensure that the system meets design specifications and requirements -The TCB is the only portion of that system that can be trusted to enforce the security policy In general, TCB components in a system are responsible for - Answer controlling access to the system -It is the responsibility of TCB components to ensure that a system behaves properly and adheres to the security policy under all circumstances The security perimeter of a system is an imaginary boundary that separates the TCB from - Answer The rest of the system For the TCB to communicate with the rest of the system, it must create secure channels also called... - Answer Trusted Paths

Content preview

Final Exam 660 Study Guide Questions
And Actual Answers.
Several security models exist, and all of them can help understand how security enters into
computer architectures and operating system design - Answer -Trusted Computing Base (TCB)

-State Machine Model

-Information Flow & Noninterference Model

-Take-Grant Model

-Access Control Matrix

-Bell-LaPadula Model

-Biba Model

-Clark-Wilson Model

-Brewer and Nash Model (aka Chinese Wall)



The foundation upon which security models are built is the - Answer Trusted Computing Base
(TCB)



An old U.S. Department of Defense standard known as the Orange Book describes a Trusted
Computing Base (TCB) as - Answer "a combination of hardware, software, and controls that
work together to form a trusted base to enforce your security policy"



The TCB is a subset of a complete information system - Answer -It should be as small as
possible so that a detailed analysis can ensure that the system meets design specifications and
requirements



-The TCB is the only portion of that system that can be trusted to enforce the security policy



In general, TCB components in a system are responsible for - Answer controlling access to the
system



-It is the responsibility of TCB components to ensure that a system behaves properly and
adheres to the security policy under all circumstances

,The part of the TCB that validates access to every resource prior to granting access requests is
called the - Answer Reference Monitor



The reference monitor may be a conceptual part of the TCB - Answer -It doesn't need to be an
actual, stand-alone system component



-The collection of components in the TCB that work together to implement reference monitor
functions is called the security kernel



The reference monitor requires - Answer descriptive information about each resource that it
protects



-Such information normally includes its classification and designation



The Bell-LaPadula and Biba models are both - Answer Information flow models



What is the difference between the Bell-LaPadula and Biba models - Answer -Bell-LaPadula is
concerned with preventing information from flowing from a high security level to a low security
level



-Biba is concerned with preventing information from flowing from a low security level to a high
security level



Techniques for Ensuring CIA? - Answer 1. Confinement

2. Bounds

3. Isolation

4. Controls



What is the Confinement technique for ensuring CIA? - Answer Process confinement allows a
process to read from and write to only certain memory locations and resources

enforced by the operating system



•If a process attempts to initiate an action beyond its granted authority, that action is denied

, •The authority level tells the OS how to set the bounds for a process (e.g. , the memory
addresses and resources it can access)

•These bounds can be either logical or physical



What is Isolation technique for ensuring CIA? - Answer -When a process is confined through
enforcing access bounds, that process runs in isolation

•Process isolation ensures that any behavior will affect only the memory and resources
associated with the isolated process



What is Control technique for ensuring CIA? - Answer -Controls use access rules to limit the
access by a subject to an object



The Biba model is also built on a state machine concept, and is characterized by two basic
properties - Answer 1. -The Simple Integrity Property states that a subject cannot read an
object at a lower integrity level (no read down)

-When integrity is important, you do not want unvalidated data read into validated documents

•The potential for data contamination is too great to permit such access



2. -The * (star) Integrity Property states that a subject cannot modify an object at a higher
integrity level (no write up)

-A subject cannot write to an object at a higher integrity level



What are Closed Systems? - Answer -Designed to work with a narrow range of other systems,
generally all from the same manufacturer

Standards for closed systems are often proprietary and not normally disclosed



What is an Open System? - Answer -Designed using agreed-upon industry standards

•Much easier to integrate with systems from different manufacturers



There is also a distinction between open-source and closed-source systems - Answer -In open-
source solutions source code and internal logic are exposed to the public

•Dependent upon public inspection / review to improve the product over time



-In closed-source (or commercial) solutions source code and internal logic are hidden from the

Document information

Uploaded on
March 25, 2025
Number of pages
16
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TestSolver9
3.6
(175)
Sold
988
Followers
129
Items
31729
Last sold
23 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions