Worksheetsfinal cnt3409c
Total questions: 109
Worksheet time: 55mins
A ________ is a legitimate user who accesses data, programs, or resources for which such access is not authorized, or who is authorized for such access but misuses his or her privileges.
emissary
masquerader
misfeasor
detection focuses on characterizing the past behavior of individual users or related groups of users and then detecting significant deviations.
Threshold
Profile-based anomaly
Statistical anomaly
Action condition
A backdoor is any mechanism that bypasses a normal security check.
True
False
_________ can result in pop-up ads or redirection of a browser to a commercial site
Adware
Flooders
Bots
RootKits
detection focuses on characterizing the past behavior of individual users or related groups of users and then detecting significant deviations.
Threshold
Statistical anomaly
Action condition
Profile-based anomaly
Unauthorized intrusion into a computer system or network is not one of the most serious threats to computer security
True
False
Statistical approaches attempt to define proper behavior and rule-based approaches attempt to define normal or expected behavior.
True
False
A _________ is an individual who is not authorized to use the computer and who penetrates a system's access controls to exploit a legitimate user's account.
clandestine user
masquerader
misfeasor
sniffer
is software that collects information from a computer and transmits it to another system
Trojan horse Spyware Exploit Flooder
Spyware
Exploit
Flooder
A ________ lies dormant until a predefined condition is met; the program then triggers an unauthorized act
logic-bomb
worm
IP security is a capability that can be added to either current version of the Internet Protocol by means of additional headers.
true
false
Typically housed in the user's computer, a _________ is referred to as a client e-mail program or a local network e-mail server
MUA
dns
pgp
The _________ payload allows peers to identify packet flows for processing by IPsec services.
EAP
flags
IAB
The __________ mechanism assures that a received packet was in fact transmitted by the party identified as the source in the packet header and assures that the packet has not been altered in transit.
key management
confidentiality
authenticationsecurity
Video content will be identified as _________ type.
MPEG.
pgp
(MIME)
The _________ accepts the message submitted by a Message User Agent and enforces the policies of the hosting domain and the requirements of Internet standards.
mail submission agent
message user agent
mail delivery agent
message transfer agent
The ________ MIME field is a text description of the object with the body which is useful when the object is not readable as in the case of audio data
Content-Description
Content-ID
Content-Transfer-Encoding
MIME-Version
Transport mode provides protection to the entire IP packet
true
false
S/MIME cryptographic algorithms use __________ to specify requirement level.
SHOULD and MUST
not
maybe
Authentication applied to all of the packet except for the IP header is _________ .
Transport mode
Tunnel Mode
ESP
In using cloud infrastructures, the client necessarily cedes control to the CP on a number of issues that may affect security
true
false
The ____________ knows the passwords of all users and stores these in a centralized database and also shares a unique secret key with each server
authentication server
EAP Transport Layer Security
EAP Tunneled TLS
Cloud computing gives you the ability to expand and reduce resources according to only to Cloud provider availability.
true
false
Public-key encryption is also referred to as conventional encryption, secret-key, or single-key encryption.
true
false
saves the complexity of software installation, maintenance, upgrades, and patches.
SaaS
SecaaS
IaaS
Verifying that users are who they say they are and that each input arriving at the system came from a trusted source
Authenticity
Accountability
The security goal that generates the requirement for actions of an entity to be traced uniquely to that entity
Accountability
Authenticity
_________ provides secure, remote logon and other secure client/server facilities.
SSH.
HTTPS
TLS
SLP
The strength of a hash function against brute-force attacks depends solely on the length of the hash code produced by the algorithm
true
false
If both sender and receiver use the same key the system is referred to as _________ encryption.
symmetric encryption
asymmetric
public-key
known as public-key cryptography, is a process that uses a pair of related keys -- one public key and one private key
Asymmetric
symmetric
The World Wide Web is fundamentally a client/server application running over the Internet and UDP/IP intranets.
true
false
Public key cryptography is __________ .
Asymmetric cryptography,
symmetric
The purpose of a ___________ is to produce a "fingerprint" of a file, message, or other block of data
cipher encryption
message authentication.
public key
hash function
The key used in conventional encryption is typically referred to as a _________ key
. secret
cipher
secondary
primary
_________ is the original message or data that is fed into the algorithm as input.
Plaintext
original
first text
__________ is a centralized, automated approach to provide enterprise-wide access to resources by employees and other authorized individuals, with a focus on defining an identity for each user, associating attributes with the identity, and enforcing a means by which a user can verify identity.
Identity management
Cloud broker
Cloud carrier
The protection of data from unauthorized disclosure is _________ .
Confidentiality
Integrity
Availability
Patient information stored in a database – inaccurate information could result in serious harm or death to a patient and expose the hospital to massive liability
Integrity
Availability
Confidentiality
The more critical a component or service, the higher the level of_______________required
Availability
Integrity
Confidentiality
The security goal that generates the requirement for actions of an entity to be traced uniquely to that entity is _________ .
Accountability
Authenticity
A __________ takes place when one entity pretends to be a different entity
masquerade
Accountability
Authenticity
____Involves the passive capture of a data unit and its subsequent retransmission to produce an unauthorized effect
Replay
Modification of messages
Denial of service
______Some portion of a legitimate message is altered, or messages are delayed or reordered to produce an unauthorized effect
Modification of messages
Masquerade
Denial of service
_______Prevents or inhibits the normal use or management of communications facilities
Denial of
service
Replay
Modification of messages
A _________ is a person, organization, or entity responsible for making a service available to interested parties.
Cloud Provider
cloud Carrier
cloud auditor
_____An independent entity that can assure that the CP conforms to a set of standards
Cloud auditor
Cloud broker
Cloud carrier
_____A networking facility that provides connectivity and transport of cloud services between cloud consumers and CPs
Cloud auditor
Cloud broker
Cloud carrier
_____• Useful when cloud services are too complex for a cloud consumer to easily manage • Three areas of support can be offered by a cloud broker: • Service intermediation • Value-added services such as identity management, performance reporting, and enhanced security • Service aggregation • The broker combines multiple cloud services to meet consumer needs not specifically addressed by a single CP, or to optimize performance or minimize cost • Service arbitrage • A broker has the flexibility to choose services from multiple agencies
Cloud auditor
Cloud broker
Cloud carrier
Wireless networks, and the wireless devices that use them, introduce a host of security problems over and above those found in wired networks.
true
false
____________ is an umbrella term for managing access to a network
Network access control (NAC)
EAP Transport Layer Security
EAP Generalized Pre-Shared Key
________Authenticates users logging into the network and determines what data they can access and actions they can perform
NAC
DHCP
Firewall
what are the Common NAC enforcement methods
Virtual local area networks (VLANs)
Firewall
DHCP management
IEEE 802.1X
all the above
What are the approaches to message authentication?
Symmetric encryption
authentication tag
includes an error detection code and a sequence number
timestamp
authentication function at the destination
One-way Hash
attacks include impersonating another user, altering messages in transit between client and server, and altering information on a Web site
passive
active
full force
What type of passive attacks?
eavesdropping
The release of message contents
Traffic analysis
all the above
Active Attacks
(a)
(b)
(c) (d)
Masquerade
Replay
Denial of service
Access control
all the above
X.800 Service Categories
Authentication • Access control • Data confidentiality • Data integrity
Nonrepudiation
Modification of messages
Denial of service
Replay
With a __________ infrastructure, the cloud infrastructure is made available to the general public or a large industry group and is owned by an organization selling cloud services.
public cloud
Intrusion management
gateway
The core of ___________ is the implementation of intrusion detection systems and intrusion prevention systems at entry points to the cloud and on servers in the cloud
Intrusion management
SIEM
security assessments
s Defined as "a model for enabling ubiquitous, convenient, on demandnetwork access to a shared pool of configurable computing resources that can be rapidlyprovisioned and released with minimal management effort or service providerinteraction
cloud computing
Infrastructure
hybrid
MAC spoofing occurs when an attacker is able to eavesdrop on network traffic and identify the MAC address of a computer with network privileges.
T
f
Sensors and robots, are not vulnerable to physical attacks
f
t
The actual method of key generation depends on the details of the authentication protocol used.
t
f
The layer of the IEEE 802 reference model that includes such functions as encoding/decoding of signals and bit transmission/reception is the _________
physical layer
physical layer
logical link layer
media access layer
In a(n) __________ situation, a wireless device is configured to appear to be a legitimate access point, enabling the operator to steal passwords from legitimate users and then penetrate a wired network through a legitimate wireless access point.
malicious association
identiy thef
network injection
ad hoc network
nd links, such as personal network Bluetooth devices, barcode readers, and handheld PDAs, pose a security risk in terms of both eavesdropping and spoofing
DoS
Accidental association
Nontraditional networks
Ad hoc networks
A signature is created by taking the hash of a message and encrypting it with the sender's
private key
Handshake Protocol
session identifier
all of the above
The SSL Internet standard version is called _________
SSH
SLP
HTTP
TLS
What are the uses of bots?
Distributed denial-of-service (DDoS) attacks • Spamming • Sniffing traffic • Keylogging • Spreading new malware • Installing advertisement add-ons and browser helper objects (BHOs) • Attacking Internet Relay Chat (IRC)
Keylogger
Spyware
Phishing
what are intruders ?
Masquerader
Misfeasor
Clandestine user
all the above
________An individual who is not authorized to use the computer and who penetrates a system’s access controls to exploit a legitimate user’s account
Masquerader
Misfeasor
Clandestine user
all the above
________A legitimate user who accesses data, programs, or resources for which such access is not authorized, or who is authorized for such access but misuses his or her privileges
Masquerader
Misfeasor
Clandestine user
all the above
________An individual who seizes supervisory control of the system and uses this control to evade auditing and access controls or to suppress audit collection
Masquerader
Misfeasor
Clandestine user
all the above
________Can be motivated by revenge or simply a feeling of entitlement
Masquerader
Misfeasor
Clandestine user
all the above
Insider Attacks
________Traditionally, those who hack into computers do so for the thrill of it or for status
Masquerader
Misfeasor
Clandestine user
all the above
Hackers
________Objective of the intruder is to gain access to a system or to increase the range of privileges accessible on a system • Most initial attacks use system or software vulnerabilities that allow a user to e
Masquerader
Misfeasor
Clandestine user
all the above
one way functionning
Access controlfunctioningcontrol functioning
________Objective of the intruder is to gain access to a system or to increase the range of privileges accessible on a system • Most initial attacks use system or software vulnerabilities that allow a user to e
Masquerader
Misfeasor
Clandestine user
all the above
Intrusion Techniques
________Ways to protect a password file:
Masquerader
Misfeasor
Clandestine user
all the above
One-way functioning
Access control
________The system stores only the value of a function based on the user’s password
Masquerader
Misfeasor
Clandestine user
all the above
One-way functioning
________Access to the password file is limited to one or a very few accounts
Masquerader
Misfeasor
Clandestine user
all the above
Access control
________involves the collection of data relating to the behavior of legitimate users over a period of time • Then statistical tests are applied to observed behavior to determine whether that behavior is not legitimate user behavior
Masquerader
Misfeasor
Clandestine user
all the above
Statistical anomaly detection
________This approach involves defining thresholds, independent of user, for the frequency of occurrence of various events
Masquerader
Misfeasor
Clandestine user
all the above
Threshold detection
profile based of the activity of each user is developed and used to detect changes in the behavior of individual accounts
t
f
Rule-based detection • Involves an attempt to define a set of rules or attack patterns that can be used to decide that a given behavior is that of an intruder • Often referred to as signature detection
t
f
Firewall limitations Cannot protect against attacks that bypass the firewall
t
f
Firewall limitations A laptop, PDA, or portable storage device may be used and infected outside the corporate network, and then attached and used internally
t
f
Firewall limitations May not protect fully against internal threats, such as a disgruntled employee or an employee who unwittingly cooperates with an external attacker
t
f
Firewall limitations Cannot guard against wireless communications between local systems on different sides of the internal firewall
t
f
firewalls Weaknesses
Because packet filter firewalls do not examine upper-layer data, they cannot prevent attacks that employ application-specific vulnerabilities or functions • Because of the limited information available to the firewall, the logging functionality present in packet filter firewalls is limited • Most packet filter firewalls do not support advanced user authentication schemes • Packet filter firewalls are generally vulnerable to attacks and exploits that take advantage of problems within the TCP/IP specification and protocol stack • Due to the small number of variables used in access control decisions, packet filter firewalls are susceptible to security breaches caused by improper configurations
Its simplicity • Transparent to users and are very fast
firewalls Strengths
Because packet filter firewalls do not examine upper-layer data, they cannot prevent attacks that employ application-specific vulnerabilities or functions • Because of the limited information available to the firewall, the logging functionality present in packet filter firewalls is limited • Most packet filter firewalls do not support advanced user authentication schemes • Packet filter firewalls are generally vulnerable to attacks and exploits that take advantage of problems within the TCP/IP specification and protocol stack • Due to the small number of variables used in access control decisions, packet filter firewalls are susceptible to security breaches caused by improper configurations
Its simplicity • Transparent to users and are very fast
Attacks
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
A suitabled countermeasures for __________ is to discard packets with an inside source address if the packet arrives on an external interface
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
A suitabled countermeasures for __________ is to discard all packets that use this option
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
A suitabled countermeasures for __________ is to enforce a rule that the first fragment of a packet must contain a predefined minimum amount of the transport header
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
__________The intruder transmits packets from the outside with a source IP address field containing an address of an internal host
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
__________The source station specifies the route that a packet should take as it crosses the internet, in the hopes that this will bypass security measures that do not analyze the source routing information
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
__________The intruder uses the IP fragmentation option to create extremely small fragments and force the TCP header information into a separate packet fragment
IP address spoofing
Source routing attacks
Tiny fragment attacks
all the above
__________Also called an application proxy • Acts as a relay of application-level traffic • If the gateway does not implement the proxy code for a specific application, the service is not supported and cannot be forwarded across the firewall • The gateway can be configured to support only specific features of an application that the network administrator considers acceptable while denying all other features • Tend to be more secure than packet filters • Disadvantage: • The additional processing overhead on each connection
IP address spoofing
Source routing attacks
Tiny fragment attacks
Level Gateway
__________A system identified by the firewall administrator as a critical strong point in the network’s security
IP address spoofing
Source routing attacks
Tiny fragment attacks
Bastion Host
__________A software module used to secure an individual host • Is available in many operating systems or can be provided as an add-on package • Filters and restricts the flow of packets • Common location is a server • Advantages: • Filtering rules can be tailored to the host environment • Protection is provided independent of topology • Used in conjunction with stand-alone
IP address spoofing
Source routing attacks
Tiny fragment attacks
Host-Based Firewall
Personal Firewall Controls the traffic between a personal computer or workstation on one side and the Internet or enterprise network on the other side
t
f
Host-resident firewall this category includes personal firewall software and firewall software on servers • Can be used alone or as part of an in-depth firewall deployment
t
f
Screening router • single router between internal and external networks with stateless or full packet filtering • This arrangement is typical for small office/home office (SOHO) applications
t
f
Single bastion inline • A single firewall device between an internal and external router • This is the typical firewall appliance configuration for small-to-medium sized organizations
t
f
Single bastion T • Similar to single bastion inline but has a third network interface on bastion to a DMZ where externally visible servers are placed
t
f
double bastion inline • DMZ is sandwiched between bastion firewalls
t
f
double bastion T • DMZ is on a separate network interface on the bastion firewall
t
f
distributed firewall configuration • Used by some large businesses and government organizations
t
f
