WorksheetsSecurity Threats and Trust Boundaries
Total questions: 20
Worksheet time: 7mins
Businesses, Banks, Shops, Schools and Exam Boards all keep data on you and are required to keep it safe?
True
False
Qwerty123 is a Strong Password (i.e. not a cyber security risk)
True
False
Detecting Vulnerabilities in a computer system/network also includes employee behaviours and procedures?
True
False
If a website is using HTTPS it means that...
Data sent and received is encrypted
Data sent and received can be viewed by others
Data received is encrypted
Data sent is encrypted
An example of something NOT a security risk or threat to a computer is:
Malicious Code
Authorized Access
Theft
System Failure
Which node do we trust more?
Dataflow
Node 1
Node 3
Node 2
It indicates where to focus attention on where to validate data before we use it. (the answer should be in plural form, all small letters, and two words)
(a)
It simply means that you take steps to protect your software from known security threats, but also expect a malicious user to attack your system and take the appropriate measures to minimize the impact of a security vulnerability is exploited.
Security Threat
Security by Design
Security Trust
Security Control
Below are some of the factors in developing a secured information system, which is not?
understand potential threats
create a threat model
identify potential threats
tampering with data
A category used in understanding potential threats in systems development.
STRIPE
STRIDE
DEAD
DREAD
a STRIDE category occurs when a user makes a change or initiates some action in the system but later denies performing the action and the system lacks the necessary tracking or audit logs to prove otherwise.
Spoofing
Tampering
Elevation of Privelege
Repudiation
A method used in analyzing and prioritizing potential threats in systems development.
STRIPE
STRIDE
DEAD
DREAD
In DREAD method, it is prioritized by asking "Is the threat easy to discover?".
Exploitability
Damage
Discoverability
Functionality
In DREAD method, it is prioritized by asking "If the threat is exploited, how much damage will occur?".
Exploitability
Damage
Discoverability
Functionality
A visual representation that helps in visualizing components of your system and the interactions between them.
STRIDE
DREAD
Threat Model
Data Flow Diagram
Identifying and mitigating potential security threats early in your development process will save you countless hours.
Correct
Partly Correct
False
