Worksheets6001 Test 1
Total questions: 69
Worksheet time: 35mins
It is not necessary for a certification authority to maintain a list of certificates issued by that CA that were not expired but were revoked. ?
True
False
In order to solve the problem of minimizing the number of times that a user has to enter a password and the problem of a plaintext transmission of the password a server is used.
ticket granting
password ciphering
access code
authentication
User certificates generated by a CA need special efforts made by the directory to protect them from being forged.?
True
False
User certificates generated by a CA need special efforts made by the directory to protect them from being forged.?
True
False
User certificates generated by a CA need special efforts made by the directory to protect them from being forged.?
nonce
option
rtime
realm
___are entities that obtain and employ data maintained and provided by identity and attribute providers, which are often used to support authorization decisions and to collect audit information.
Federations
Principals
CAS
Data Consumers
__is a key used between entities for the purpose of distributing session keys.
permanent key
key distribution center
symmetric key
session relay key
If the sender and receiver each use a different key the system is referred to as encryption.
secret-key
conventional
single-key
asymmetric
The most common key length in modern algorithms is
64 bits
128 bits
32 bits
256 bits
The ciphertext-only attack is the easiest to defend against because the opponent has the least amount of information to work with.
True
False
The automated key distribution approach provides the flexibility and dynamic characteristics needed to allow a number of users to access a number of servers and for the servers to exchange data with each other.?
True
False
In order to prevent an opponent from capturing the login ticket and reusing it to spoof the TGS, the ticket includes a indicating the date and time at which the ticket was issued.
Ovalidation
certificate
timestamp
Orealm
Once the authentication server accepts the user as authentic it creates an encrypted sent back to the client. which is
password
key
access key
ticket
is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.
Traffic padding
Notarization
Authentication exchange
Routing control
In developing a particular security mechanism or algorithm one must always consider potential attacks on those security features. ?
True
False
Data origin authentication provides protection against the duplication or modification of data units. ?
True
False
The extension lists policies that the certificate is recognized as supporting, together with optional qualifier information.
policy mappings
directory attribute
certificate policies
authority key identifier
Kerberos version 4 did not fully address the need to be of general purpose.?
True
False
A session key is destroyed at the end of a session.
True
False
The ticket-granting ticket is encrypted with a secret key known only to the authentication server and the ticket granting server. ?
True
False
A approach involves trying every possible key until an intelligible translation of the ciphertext into plaintext is obtained.
triple DES
brute-force
block cipher
computational
The security of symmetric encryption depends on the secrecy of the algorithm, not the secrecy of the key.
True
False
Triple DES was first standardized for use in financial applications in ANSI standard X9.17 in 1985.
True
False
A ____ processes the input elements continuously, producing output one element at a time, as it goes along.
block sipher
cryptanalysis
keystream
Stream
With the introduction of the computer the need for automated tools for protecting files and other information stored on the computer became evident.
True
False
A connection-oriented integrity service deals with individual messages without regard to any larger context and generally provides protection against message modification only. ?
True
False
is a variety of mechanisms used to assure the integrity of a data unit or stream of data units.
Data integrity
Trusted functionality
Event detection
Authentication exchange
The protection of data from unauthorized disclosure is
Confidentiality
no options
There is a natural tendency on the part of users and system managers to perceive little benefit from security investment until a security failure occurs.
True
False
The prevention of unauthorized use of a resource is
access control
1000
data confidentiality
non repudiation
Cryptographic hash functions generally execute slower in software than conventional encryption algorithms such as DES. ?
True
False
____protects against passive attacks (eavesdropping).
Obfuscation
Encryption
Message authentication
SCR?
The purpose of the algorithm is to enable two users to exchange a secret key securely that then can be used for subsequent encryption of messages and depends on the difficulty of computing discrete logarithms for its effectiveness.
Diffie-Hellman
RSA
The private key is known only to its owner.
True
False
X.800 defines as a service that is provided by a protocol layer of communicating open systems and that ensures adequate security of the systems or of data transfers
replay
integrity
authenticity
security service
____is verifying that users are who they say they are and that each input arriving at the system came from a trusted source.
Confidentiality
Integrity
Accountability
Authenticity
The _____ extension lists policies that the certificate is recognized as supporting, together with optional qualifier information.
Certificate Policies extension
no options
is a procedure that allows communicating parties to verify that received messages are authentic. ?
ECB
Message authentication
Passive attack
Encryption
Because of the mathematical properties of the message authentication code function it is less vulnerable to being broken than encryption
True
False
Public key algorithms are indeed based on mathematical functions rather than on simple operations on bits.
True
False
The Feistel structure is a particular example of the more general structure used by all symmetric block ciphers.
True
False
If the message includes a the receiver is assured that the message has not been delayed beyond that normally expected for network transit.
Timestand
sequence number
shared key
error detection code
The Feistel structure is a particular example of the more general structure used by all symmetric block ciphers.
True
False
The property protects against a sophisticated class of attack known as the birthday attack.
preimage resistant
one-way
collision resistant
second preimage resistant
The algorithm performs various substitutions and transformations on the plaintext.
codebook
encryption
cipher
keystream
If the analyst is able to get the source system to insert into the system a message chosen by the analys attack is possible.
chosen ciphertext
chosen plaintext
known plaintext
ciphertext only
The Feistel structure is a particular example of the more general structure used by all symmetric block ciphers.
True
False
Random numbers play an important role in the use of encryption for various network security applications
True
False
The most commonly used symmetric encryption algorithms are stream ciphers.
True
False
A ___ takes as input a source that is effectively random and is often referred to as an entropy source.
PRNG
PRF
PSRN
TRNG
One desirable property of a stream cipher is that the ciphertext be longer in length than the plaintext.
True
False
The advantage of a block cipher is that you can reuse keys.
True
False
"It is easy to generate a code given a message, but virtually impossible to generate a message given a code" describes the hash function property.
collision resistant
strong collision resistant ?
preimage resistant
second preimage resistant
Public key algorithms are useful in the exchange of conventional encryption keys.
True
False
Public key algorithms are based on mathematical functions rather than on simple operations on bit patterns.
True
False
Secure Hash Algorithms with hash value lengths of 256, 384, and 512 bits are collectively known as
SHA-1
SHA-2
SHA-3
SHA-4
In addition to providing authentication, a message digest also provides data integrity and performs the same function as a frame check sequence.
True
False
The purpose of a is to produce a "fingerprint" of a file, message, or other block of data.
message authentication
public key
hash function
private key
Public-key encryption is also referred to as conventional encryption, secret-key, or single-key
True
False
The advantage of a block cipher is that you can reuse keys.
True
False
One desirable property of a stream cipher is that the ciphertext be longer in length than planetext.
True
False
__assures that systems work promptly and service is not denied to authorized users.
Integrity
Availability
System integrity
Data confidentiality
There are clear boundaries between network security and internet security.?
True
False
The security goal that generates the requirement for actions of an entity to be traced unique entity is
Integrity
Availability
Data confidentiality
Accountability
In developing a particular security mechanism or algorithm one must always consider potential a those security features. ?
True
False
The CIA triad embodies the fundamental security objectives for both data and for information an computing services.
Treu
False
The primary advantage of a stream cipher is that stream ciphers are almost always faster and more efficient than block ciphers.
True
False
is a professional membership society with worldwide organizational and individual m that provides leadership in addressing issues that confront the future of the Internet and is the home for the groups responsible for Internet infrastructure standards, including the IETF and
ITU-T
ISO
FIPS
ISOC
The emphasis in dealing with passive attacks is on prevention rather than detection. ?
True
False
