- •15. Which type of encryption occurs between original source and final destination?
- •Verses 26 for a monoalphabetic
- •45. What key length does aes not support?
- •Internet Security
- •56. The Caesar Cipher is an example of what kind of cipher?
- •Violates computer security for little reason beyond maliciousness or for personal gain
- •90. What is Denial of Service in Threat Modeling?
- •78. Which of the following is a disadvantage of asymmetric cryptology?
- •83. Which of the following is a disadvantage of asymmetric cryptology?
- •89. Which of the following allows attackers to break passwords?
- •116. Centralized access control provides remote users with all of the following properties except
- •117. What are three principals of identification and authentication?
- •120. Which of the following is a knowledge-based authentication mechanism?
- •135. Exploits known flaws in network systems
- •Vigenere cipher
- •Vulnerability
- •192. Which term relates specifically to the art and science of code breaking?
- •194. Which of the following is a disadvantage of asymmetric cryptology?
- •Is a system in which a private key generated randomly is used only once to encrypt a message that is then decrypted by the receiver using a matching one-time pad and key.
45. What key length does aes not support?
512-bit.
46. The output of an encryption algorithm; the encrypted form of a message or data.
Ciphertext
47. Generic name for the collection of tools designed to protect data and to thwart hackers ?
Computer Security
48. Measures toprotect data during their transmission over a collection of interconnectednetworks
Internet Security
49. Anyaction that compromises the security of information owned by an organization.
Security attack:
50. The services are intended to counter security attacks, and they make use of one ormore security mechanisms to provide the service
Security service:
51. Types of passive attacks:
release of message contents
traffic analysis.
52. A worm is... pieces of malicious code that make copies of themselves and spread through computers without human interaction
53. If you receive an email claiming to need your username and/or password, what should you do?
report it as phishing/spam through your email provider
54. What is the best way to protect your information when you are away from your computer?
lock the computer with a password
55. What is a firewall?
A filter for an internet connection that monitors outgoing and incoming activity.
56. The Caesar Cipher is an example of what kind of cipher?
Substitution.
57. A strong password should contain:
58. Social engineering is:
scams distributed through email such as phishing, pharming and impersonation
59. Physical, remote, and system describe three types of what?
Physical Intrusions, Remote Intrusions, System Intrusions
60. What is social engineering?
scams distributed through email such as phishing, pharming and impersonation
Phishing
61. What is the first action you take once an intrusion is identified?
Evaluate -> Identify the intruder -> Identify the Vulnerability -> Return systems to operation
62. What is the definition of a black hat hacker?
Violates computer security for little reason beyond maliciousness or for personal gain
63.
What is takes place when one entity pretends to be a different entity
Masquerade
64. ensuring information has not been altered by unauthorised or unknown means.
Data integrity
65. Keeping information secret from all but those whoare authorised to see it.
Privacy or confidentiality
66. This is a set of related programs, usually located at a network gateway server, that protects the resources of a private network from other networks.
FIREWALL
67. Which algorithms are no longer recommended for use?
DES.
68. This is a class of programs that searches your hard drive for any known or potential viruses.
antivirus software.
69. This is a program in which malicious or harmful code is contained inside apparently harmless programming or data.
Trojan horse
70. This is the process of determining whether someone or something is, in fact, who or what it is declared to be.
authentication.
71. This is the conversion of data into a ciphertext that cannot be easily understood by unauthorized people
encryption
72. To be effective, this should ideally contain at least one digit and not match a natural language word
password
73. Which of the following is not a best practice for using tiered groups to control user access?
Apply policies to each layer individually
74. Widely used de facto secure email
Pretty Good Privacy (PGP)
75. This electronic "credit card" establishes a user's credentials when doing business or other transactions on the Web and is issued by a certification authority
digital certificate
76. This is an encryption/decryption key known only to the party or parties that exchange secret messages
private key
77. This is the name for the issuer of a PKI certificate
certificate authority.
