ITN 260 MIDTERM EXAM QUESTIONS
WITH CORRECT ANSWERS
DEPRECATED ALGORITHM - Answer-A cryptographic algorithm that is still available
but should not be used because of known vulnerabilities
HASH - Answer-An algorithm that creates a unique digital fingerprint called a digest
RSA - Answer-The most common asymmetric cryptography algorithm
ALGORITHM - Answer-Procedures based on a mathematical formula used to encrypt
and decrypt that data
HIGH RESILIENCY - Answer-The ability to quickly recover from resource vs. security
constraints
CONFUSION - Answer-A means to thwart statistical analysis so that the key does not
relate in a simple way to the cipher text
COLLISION ATTACK - Answer-An attempt to find two input strings of a hash function
that produce the same hash result
CERTIFICATE CHAINING - Answer-Linking several certificates together to establish
trust between all the certificates involved
AUTHENTICATION HEADER - Answer-An IPsec protocol that authenticates that
packets received were sent from the source
TRANSPORT MODE - Answer-An IPsec mode that encrypts only the data portion
(payload) of each packet yet leaves the header unencrypted
OBJECT IDENTIFIER - Answer-A designator made up of a series of numbers
separated with a dot, which names an object or entity
CERTIFICATE AUTHORITY - Answer-The entity that is responsible for digital
certificates
INITIALIZATION VECTOR - Answer-A nonce that is selected in a non-predictable way
DIGITAL CERTIFICATE - Answer-A technology used to associate a user's identity to a
public key and that has been digitally signed by a trusted third party
KEY STRENGTH - Answer-The resiliency of a key to resist attacks
, CRYPTO MODULES - Answer-Cryptography modules that are invoked by crypto
service providers
SELF SIGNED - Answer-A signed digital certificate that does not depend upon any
higher-level authority for authentication
TUNNEL MODE - Answer-An IPsec mode that encrypts both the header and the data
portion
STAPLING - Answer-A process for verifying the status of a certificate by sending
queries at regular intervals to receive a signed time-stamped response
SECURE SHELL - Answer-An encrypted alternative to the Telnet protocol that is used
to access remote computers
PINNING - Answer-Hard-coding a digital certificate within a program that is using the
certificate
REPLAY - Answer-An attack that makes a copy of the transmission before sending it to
the recipient
IP SPOOFING - Answer-Imitating another computer by means of changing the IP
address
PRIVLEDGE ESCALATION - Answer-An attack that exploits vulnerability in software to
gain access to resources that the user normally would b restricted from accessing
CLICK JACKING - Answer-Hijacking a mouse click
MAC SPOOFING - Answer-Imitating another computer by means of changing the MAC
address
URL HIJACKING - Answer-Fake sites that are spelled similar
INJECTION ATTACK - Answer-An attack that introduces new input to exploit a
vulnerability
SESSION HIJACKING - Answer-An attack in which an attacker attempts to impersonate
the user by using the user's session token
DNS POISONING - Answer-An attack that substitutes DNS addresses so that the
computer is automatically redirected to an attacker's device
INTERNAL - Answer-The location within an enterprise in which some threat actors
perform
WITH CORRECT ANSWERS
DEPRECATED ALGORITHM - Answer-A cryptographic algorithm that is still available
but should not be used because of known vulnerabilities
HASH - Answer-An algorithm that creates a unique digital fingerprint called a digest
RSA - Answer-The most common asymmetric cryptography algorithm
ALGORITHM - Answer-Procedures based on a mathematical formula used to encrypt
and decrypt that data
HIGH RESILIENCY - Answer-The ability to quickly recover from resource vs. security
constraints
CONFUSION - Answer-A means to thwart statistical analysis so that the key does not
relate in a simple way to the cipher text
COLLISION ATTACK - Answer-An attempt to find two input strings of a hash function
that produce the same hash result
CERTIFICATE CHAINING - Answer-Linking several certificates together to establish
trust between all the certificates involved
AUTHENTICATION HEADER - Answer-An IPsec protocol that authenticates that
packets received were sent from the source
TRANSPORT MODE - Answer-An IPsec mode that encrypts only the data portion
(payload) of each packet yet leaves the header unencrypted
OBJECT IDENTIFIER - Answer-A designator made up of a series of numbers
separated with a dot, which names an object or entity
CERTIFICATE AUTHORITY - Answer-The entity that is responsible for digital
certificates
INITIALIZATION VECTOR - Answer-A nonce that is selected in a non-predictable way
DIGITAL CERTIFICATE - Answer-A technology used to associate a user's identity to a
public key and that has been digitally signed by a trusted third party
KEY STRENGTH - Answer-The resiliency of a key to resist attacks
, CRYPTO MODULES - Answer-Cryptography modules that are invoked by crypto
service providers
SELF SIGNED - Answer-A signed digital certificate that does not depend upon any
higher-level authority for authentication
TUNNEL MODE - Answer-An IPsec mode that encrypts both the header and the data
portion
STAPLING - Answer-A process for verifying the status of a certificate by sending
queries at regular intervals to receive a signed time-stamped response
SECURE SHELL - Answer-An encrypted alternative to the Telnet protocol that is used
to access remote computers
PINNING - Answer-Hard-coding a digital certificate within a program that is using the
certificate
REPLAY - Answer-An attack that makes a copy of the transmission before sending it to
the recipient
IP SPOOFING - Answer-Imitating another computer by means of changing the IP
address
PRIVLEDGE ESCALATION - Answer-An attack that exploits vulnerability in software to
gain access to resources that the user normally would b restricted from accessing
CLICK JACKING - Answer-Hijacking a mouse click
MAC SPOOFING - Answer-Imitating another computer by means of changing the MAC
address
URL HIJACKING - Answer-Fake sites that are spelled similar
INJECTION ATTACK - Answer-An attack that introduces new input to exploit a
vulnerability
SESSION HIJACKING - Answer-An attack in which an attacker attempts to impersonate
the user by using the user's session token
DNS POISONING - Answer-An attack that substitutes DNS addresses so that the
computer is automatically redirected to an attacker's device
INTERNAL - Answer-The location within an enterprise in which some threat actors
perform