Information Security Fundamentals
A comprehensive quiz covering cryptography, network security, authentication protocols, and identity management concepts
Questions
The identity management component that acts as a repository for user ID and user profile information, that plays a key role in user authentication is
- Authentication services
- Authorization services
- Directory services
- Personalization services
A person has a total of 3 accounts - a LDAP based security system, Active Directory Server and a RADIUS server. An administrator will be responsible for adding the same user to multiple systems and maintaining those accounts. Identify the process that helps in automating the task of keeping the passwords same across various systems
- Password single sign on
- Password management
- Password self-help
- Password synchronization
In Security attacks how do you classify a SYN Flooding atack?
- DOS attacks
- Cryptanalysis
- Social Engineering
- repudiation attack
Which vulnerability is Exploited by TEAR DROP attack
- Microsoft IIS server vulnerability
- Vulnerability in the Google seach Engine
- Vulnerability in the reassembly mechanism of IP datagrams.
- Vulnerabilty in NETSCAPE
What is the Requirement for Kerberos to Work
- the clocks between the parties in communication must be in sync
- you need to have a system with linux installed
- you have to use RSA for encryption
- key length should be 128 bit or more
CHAP stands for
- Carrier Handshake Availability Protocol
- ChallengeHandover Authentication Protocol
- canonical Handshake Availability Protocol
- Challnge Handshake Authentication Protocol
The Science associated with Breaking A CIPHER is called as
- Cryptanalysis
- crptology
- cryptogram
- steganography
SYN FLOODING attack exploits a vulnerability in
- hole in IIS
- vulnerability in NETSCAPE
- TCP/IP three way Handshake
- SCTP fourway Handshake
CIA of security stand for
- Confidentiality,Integrity and Availability
- Confidentiality,Integrity and accessibility
- confidentiality Informativity Authentication
- Confidentiality Integrity Access Control
What is the best way they can do this?
- SYMMETRIC CRYPTOSYSTEM
- ASYMETTRIC CRYPTOSYSTEM
- HYBRID CRYPTOSYSTEM
- NONE
Passwords are usually stored in the systems
- Hashed form
- Encrypted Form
- Plain text form
- none
The Science associated with hiding text within text is known as (information can be hidden digitally also)
- Steganography
- Cryptography
- Cryptology
- none
Buffer overflows are most dangerous when they occur in programs
- Run by the administrator
- Run by normal user
- Run by the attacker
- Run by the remote user
DES IS STILL SECURE
- True
- False
Digital Signature does not provide protection from tampering.
- True
- False
signing the document is same as Signing the hash wrt to providing same level of data integrity
- True
- False
Given the necessary Time and necessary resources Which one of the following systems is 100% secure?
- DES
- TRIPLE DES
- ONE TIME PADS
- BLOW FISH
BLOWFISH is Designed BY
- WHITFIELD DIFFE
- LEONARD ADLEMAN
- RON RIVEST
- BRUCE SCHIENER
Which mobile storage devices can potentially store confidential information and should be protected at all times?
- Remote Access Memory (RAM)
- A mobile messaging device (i.e. Blackberry or Treo)
- Virtual Private Networks (VPNs)
- Digital Camera
Which of the following wireless technologies provides the most security?
- Bluetooth
- Wireless Encryption Protocol (WEP)
- Wi-Fi Protected Access (WPA)
- Microwave communications