Font size
WorksheetsCIA Triad and Security Concepts Worksheet
Total questions: 100
Worksheet time: 53mins
The three concepts that form the CIA triad are:
confidentiality, integrity and availability
communication, integrity and authentication
confidentiality, integrity, access control
communication, information and authenticity
A loss of ________ is the unauthorized disclosure of information.
authenticity
confidentiality
reliability
integrity
Verifying that users are who they say they are is ________.
authenticity
credibility
accountability
integrity
Any action that compromises security is a:
security attack
security service
security alert
security mechanism
One entity pretends to be another:
replay
masquerade
service denial
passive attack
Protection of transmitted data from passive attacks is:
encryption
compression
fragmentation
multiplexing
A service protecting availability:
replay
availability
masquerade
integrity
Threats inhibiting legitimate users:
Information access
Reliability
Passive
Service
A potential for violation of security:
threat
attack
risk
attack vector
Protection against traffic analysis:
connectionless confidentiality
connection confidentiality
traffic-flow confidentiality
selective-field confidentiality
Data proving source and integrity:
A. Authentication
B. Authorization
C. Nonrepudiation
D. Encryption
Mapping plaintext to ciphertext:
Transposition
Substitution
Traditional
Symmetric
Original message & coded message:
decryption, encryption
plaintext, ciphertext
deciphering, enciphering
cipher, plaintext
Restoring plaintext:
deciphering
transposition
steganography
encryption
Trying every possible key:
brute-force
Caesar attack
ciphertext only
chosen plaintext
Deciphering without algorithm knowledge:
brute-force
Caesar attack
ciphertext only
chosen plaintext
Select the correct answer.
blind deciphering
steganography
cryptanalysis
transposition
Ciphertext + key → plaintext:
Voronoi algorithm
decryption algorithm
cryptanalysis
diagram algorithm
Same key used by both sides:
public-key encryption
two-key
asymmetric
conventional encryption
Algorithm-exploiting attacks:
Brute-force
Cryptanalytic
Block cipher
Transposition
Easiest attack to defend:
ciphertext-only
chosen ciphertext
known plaintext
chosen plaintext
22. A way to improve on the simple monoalphabetic technique is to use different monoalphabetic substitutions as one proceeds through the plaintext message. The general name for this approach is:
Polyalphabetic cipher
Transposition cipher
Caesar cipher
Stream cipher
A technique referred to as a __________ is a mapping achieved by performing some sort of permutation on the plaintext letters.
transposition cipher
polyalphabetic cipher
Caesar cipher
monoalphabetic cipher
The methods of __________ conceal the existence of the message in a graphic image.
steganography
decryptology
cryptology
cryptograph
DES exhibits the classic __________ block cipher structure, which consists of a number of identical rounds of processing.
Feistel
SAC
Shannon
Rendell
A sequence of plaintext elements is replaced by a __________ of that sequence.
permutation
diffusion
A _________ cipher encrypts data one bit or one byte at a time.
product
block
key
stream
The vast majority of network-based symmetric cryptographic applications use _________ ciphers.
linear
block
permutation
stream
A _________ cipher treats a block of plaintext as a whole and produces an equal-length ciphertext block.
bit
product
stream
block
_________ is when each plaintext element is uniquely replaced by a corresponding ciphertext element.
Substitution
Diffusion
Key sizes of _________ or less are now considered to be inadequate.
128 bits
32 bits
16 bits
64 bits
Feistel proposed the concept of a _________ cipher, which is the execution of multiple ciphers in sequence.
linear
permutation
differential
product
The criteria used in the design of the _________ focused on the design of the S-boxes and the P function.
Avalanche Attack
Data Encryption Standard
Product Cipher
Substitution Key
The greater the number of rounds, the _________ it is to perform cryptanalysis.
easier
less difficult
equally difficult
harder
The function F provides the element of __________ in a Feistel cipher.
clarification
alignment
confusion
stability
One of the most intense research areas in symmetric block ciphers is __________ design.
S-box
F-box
E-box
D-box
Mister and Adams proposed S-box columns should be __________ functions.
horizontal
angular
bent
vertical
The Nyberg approach with simple mathematics is __________.
human-made
random
math-made
random with testing
Allowing maximum encryption mappings is the __________.
Authentication applied to the entire original IP packet is ___________.
security mode
cipher mode
tunnel mode
transport mode
Asymmetric encryption is also known as:
public-key encryption
private-key encryption
optimal encryption
digital-key encryption
Public-key encryption is also known as:
digital-key encryption
asymmetric encryption
one-way time exchange encryption
optimal-key encryption
Asymmetric encryption can be used for:
both confidentiality and authentication
neither confidentiality nor authentication
confidentiality
authentication
The plaintext is recovered from the ciphertext using the paired key and a:
digital signature
recovery encryption
decryption algorithm
encryption algorithm
The most widely used public-key cryptosystem is:
optimal asymmetric encryption
asymmetric encryption
RSA
DES
Public-key algorithms are based on:
permutation
mathematical functions
substitution
symmetry
__________ are two related keys, a public key and a private key:
Asymmetric keys
Key exchanges
Symmetric keys
Cipher keys
The _________ indicates that the subscriber has sole control of the private key.
OAEP
Public Key Certificate
A cryptographic algorithm that uses a public key and private key is:
Private Key Cryptographic Algorithm
Key Exchange Cryptographic Algorithm
Public Key Cryptographic Algorithm
RSA Digital Cryptographic Algorithm
A public-key encryption scheme has _________ ingredients.
six
four
eight
two
The key used in symmetric encryption is called a:
public
secret
private
decryption
The readable message fed into the algorithm is:
ciphertext
exchange
plaintext
encryption
Two RSA computation issues: encryption/decryption and:
time complexity
trap-door functions
key generation
padding
__________ depend on the running time of decryption.
Mathematical attacks
Timing attacks
Chosen ciphertext attacks
Brute-force attacks
The __________ of an algorithm measures efficiency.
time complexity
one-way function
timing attack
OAEP
Authentication applied to all except IP header is:
tunnel mode
transport mode
association mode
security mode
Encapsulating header and trailer (RFC 4303) is:
SPI
ESP
Payload that identifies packet flows:
Configuration
Vendor ID
Traffic Selector
Extensible Authentication Protocol
Primary IPsec integrity method:
MD5
AES
RSA
DH
Source & destination of encrypted IPsec packet:
Original sender & receiver
Sender & outbound VPN gateway
Sending and receiving VPN gateways
VPN gateway & original destination
Private management traffic uses:
IPsec
IKE Phase 1
IKE Phase 2
IKE Phase 3
Negotiated during IKE Phase 1:
Hashing
DH group
Encryption
Authentication method
Establish shared secret over untrusted network:
AES
SHA
RSA
DH
Two peer authentication methods in IKE Phase 1:
RSA signatures
PSK
DH Group 2
TCP handshake
Encrypted management protocols (Choose three):
SNMPv2c
Telnet
SNMPv3
HTTPS
SSH
Valid Layer 2 security for 802.11ac:
(a)
Guest WLAN splash page authentication:
LDAP
RADIUS
local
WebAuth
PSK
Single sign-on wireless authentication (Choose two):
LDAP
RADIUS
Local
WEP
PSK
128-bit encryption with 802.11n speeds:
Static WEP
WPA-TKIP
WPA2-AES
CKIP
Trusted DHCP ports feature:
DHCP snooping
port security
True about named ACLs:
Support standard and extended ACLs
Filter usernames/passwords
Filter Layer 7
Standard only
Rate limit traffic
Valid extended ACL number:
99
1
64
299
100
ACL problem cause:
Permit entry inactive
Misconfigured ACL
Deny all active
Implicit deny
Verify which interfaces are affected by ACL:
show ip access-lists
show access-lists
show interface
Which command displays the IP interface information?
D. show ip interface
E. list ip interface
Permit only four networks (Choose two):
access-list 10 permit ip 192.168.146.0 0.0.1.255
access-list 10 permit ip 192.168.148.0 0.0.1.255
access-list 10 permit ip 192.168.146.0 0.0.0.255
access-list 10 permit ip 192.168.147.0 0.0.255.255
access-list 10 permit ip 192.168.149.0 0.0.255.255
Router ACL is used for:
filtering packets through a router
change admin distance
protect server
control route metric
IPsec protocol when confidentiality is required:
MD5
PSK
AH
ESP
Port security true statements:
Can apply to dynamic access ports
Apply to EtherChannels
Switch learns up to defined maximum MACs
Standard ACLs are based on:
destination + wildcard
destination + subnet
source + subnet
source + wildcard
VPN component ensuring data unaltered:
encryption
authentication
key exchange
data integrity
service password-encryption provides security by:
encrypting traffic
encrypting passwords in config file
requiring encrypted input
MD5 routing validation
auto-generate passwords
Packets processed by inbound ACL:
before they are routed
after routing
before and after
after routing but before queue
Wildcard mask for /29:
0.0.0.224
0.0.0.7
255.255.255.224
255.255.255.248
0.0.0.8
Valid reasons for VLANs (Choose three):
F. increase security
B. isolate broadcast traffic
C. increase collision
E. logically group hosts
A. VTP easier
Secure terminal protocol:
WEP
SSH
ARP
SNMPv1
Telnet
Extended ACL filters:
protocol
VLAN number
TCP/UDP ports
switch port
Permit SSH/Telnet on vty:
transport output all
transport preferred all
transport type all
transport input all
Protect the data plane (Choose three):
QoS
IPS
antispoofing
ACLs
policing
True about stateless firewall:
Operates at Layer 4
More secure than stateful
Tracks streams
Not vulnerable to spoofing
True of all firewalls:
Maintain state table
Hide source
Operate at Layer 7
Are multihomed devices
Validate address requests:
IP Source Guard
port security
DHCP snooping
dynamic ARP inspection
Result of port-security mac-address sticky:
Saved in startup-config
Saved in running-config
Saved in VLAN DB
Static saved in startup
Static saved in running
Port security true (Choose two):
Apply to dynamic access ports
Apply to EtherChannels
Learn MACs up to maximum
Sticky saved to startup-config
Configure in voice VLAN
Reasons for VPN instead of WAN:
broadband incompatibility
better throughput
scalability
increased security
reduced cost
Traffic replication feature:
copy run start
traceroute
ICMP SLA
SPAN
ACL wildcard substitutes:
all
any
host
range
subnet
IEEE authentication mechanism:
802.1x
802.11
802.2x
802.3x
DHCP snooping info stored in:
MAC table
CAM table
DHCP binding database
VLAN database
Command to save learned MACs:
switch port-security
switch port-security mac-address sticky
switch port-security maximum 10
switch mode access
