Midterm Study Guide

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/69

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:40 AM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

70 Terms

1
New cards

Which authentication factor category does a password represent?

            Something you know

2
New cards

In Iris-based authentication system, out of 1000 users, 50 users were rejected

when the system matched their fingerprint against their enrollment fingerprint

template. Also, 25 users were accepted by the system when the system matched

their fingerprint against other users’ fingerprint templates. What’s the False

Rejection Rate (FRR) of this system?

5% (50 ÷ 1,000). The text defines FRR as authorized access attempts not granted divided by total access attempts. The textbook's worked example gets 5.02% because it divides by 995, after 5 users failed to enroll; your question has no enrollment failures. 

3
New cards

Which security objective is most directly affected when authorized users cannot

access a service?

Availability

4
New cards

Which authentication factor category does a fingerprint represent?


something you are 

5
New cards

Are access tokens classified as "something you know"?

No, Access tokens are defined as “something you have” 

6
New cards

Which encryption method is based on the idea of two keys, one that is public

and one that is private?

Asymmetric encryption

7
New cards

Why is a unique random salt commonly added before hashing each stored

password?


To provide sufficient entropy (add randomness and increase complexity to make passwords harder to crack attackers)) 

8
New cards

Who acts to validate identities and bind them to cryptographic key pairs with

digital certificates?


Certificate authority (CA)

9
New cards

9. When material, called plaintext, needs to be protected from unauthorized

interception or alteration, it is encrypted into

Ciphertext

10
New cards

Which practice best helps an employee verify an unexpected request for

sensitive information?

internet usage policy and email usage policy

11
New cards

Which term refers to the science of encrypting, or hiding, information?

Cryptography 

12
New cards

Which network address class supports 253 hosts on each network with a

default subnet mask of 255.255.255.0?



Class C

13
New cards

What is Dynamic Host Configuration Protocol (DHCP)?


A method of assigning IP addresses dynamically. When a system boots or connects, it broadcasts a query for a DHCP server and receives its address assignment from the server that answers first. 

 

14
New cards

An audit log records who accessed a resource and when the access occurred.

Which AAA function does this most directly support?


Accounting.

15
New cards

Why might an insider be more successful in carrying out a social engineering

attack?


they would already have legitimate access and trying to obtain that would be significant deterent to unauthorized individuals

16
New cards

What does a public key infrastructure provide?


users and entities to be able to communicate securely 

 

17
New cards


What is non-repudiation?


 the ability to verify that aa message has been sent and received and that the sender can be identified and verified. 
 

18
New cards

Can a cryptographic hash value be reversed to recover the original input?


 No 

19
New cards

How can an attacker misuse ICMP to attack a network?


Denial of service attacks. Because icmp packets are very small and connectionless, thousands and thousands of ICMP packets can be generated by a single system in a very short period of time. Attackers have developed methods to trick many systems into generating thousands of ICMP packets with a common destination—the attacker’s tar- get. This creates a literal flood of traffic that the target—and in most cases the network the target sits on—is incapable of dealing with. 

 

20
New cards


When referring to the three steps in the establishment of proper privileges,

what does AAA stand for?

Authentication, authorization, and accounting.

21
New cards

Which device forms the backbone of the Internet, moving traffic from network to network, inspecting packets from every communication as it moves traffic in optimal paths? 

 


Routers

 

22
New cards

Which term refers to a unique alphanumeric identifier for a user of a computer system? 

User ID

23
New cards

A system checks a submitted password before allowing a user to sign in. Which process is being performed? 



Authentication

24
New cards

Before deploying a planned system change, which activity best supports controlled implementation? 

 


change management process

25
New cards

Does a CA sign a digital certificate using its own private key?


Yes

26
New cards
  1. Which statement describes symmetric encryption?



The same key is used for encryption and decryption

27
New cards

Which authentication factor category does gait represent?


Something you can do 

28
New cards

Which key should the owner of an asymmetric key pair keep secret?

The private key. It never leaves the owner's possession. 

29
New cards

Due to technological advances, which new category of shared “secrets” for authentication has emerged based on how users perform an action?

What users do.

30
New cards
  1. Which statement best describes a cryptographic hash collision?  

 

 

Occurs when an attacker finds two different messages that hash to the same value 

 

 

31
New cards

What does the * (star) property of the Bell-La Padula model describe?

 

 

top secret files should not be written to confidential storage

 

 

32
New cards

What is a digital certificate? 


A digital certificate is a digital file that is sent as an attachment to a message and is used to verify that the message did indeed come from the entity it claims to have come from. 

 

33
New cards

Do digital certificates use asymmetric key pairs for validation?

 

Yes. The certificate holds the public key, and the private key paired with it is stored separately. 

 

34
New cards

Are public keys components of digital certificates?  

Yes

35
New cards

Which principle gives users only the permissions needed to perform their assigned tasks? 



Least privilege. Limiting privileges limits the harm that can be caused. 

36
New cards

In Iris-based authentication system, out of 1000 users, 50 users were rejected when the system matched their fingerprint against their enrollment fingerprint template. Also, 25 users were accepted by the system when the system matched their fingerprint against other users’ fingerprint templates. What’s the False Acceptance Rate (FAR) of this system? 

calculates FAR as the number of unauthorized accesses granted divided by the total number of access attempts. Here, the 25 users accepted against other users' templates are the false acceptances, so 25 ÷ 1,000 × 100% = 2.5%.

37
New cards

An attacker enters a restricted building by closely following an authorized employee through a secured door. What is this technique called?

Tailgating (or piggybacking)

38
New cards

Does TCP necessarily have a faster transmission speed than UDP?

no. UDP is generally faster because it has less overhead: no connection setup, acknowledgments, or retransmissions.

39
New cards

Should policies generally be updated more frequently than the procedures that implement them? 

 


No.

 

40
New cards

Within an Ethernet LAN, which device normally forwards frames based on a table of learned MAC addresses?

 

Switch

 

41
New cards

How is shoulder surfing accomplished?

 

Shoulder surfing does not require direct contact • Example of information desired: PINs or gate codes  


42
New cards

What term refers to the combination of two or more types of authentication?  

 


Multifactor authentication. 

 

43
New cards

How do a security policy and a procedure differ in purpose and level of detail? 


Policies: high-level, broad statements of what the  

organization wants to accomplish 

• Procedures: step-by-step instructions on how to  

implement policies in the organization 
 

44
New cards

Which account is used to run processes that do not require human intervention to start/stop/administer? 



Service account, a special account used to provision permissions for services or non-human-initiated system activity. 



45
New cards


 What is Single sign-on (SSO)? 


Single sign-on (SSO) is a form of authentication that involves the transferring of credentials between systems. 

 

46
New cards

Is symmetric key encryption slower than asymmetric key encryption? 


No,  Symmetric encryption tends to be faster 

 

47
New cards

Which situation is an example of phishing?
 

 

It masquerades as a trusted entity. bulk email, supposedly from a bank, saying a security breach occurred and asking recipients to click a link to verify their account. The link leads to an attacker-controlled site that captures their account and password. 
 


48
New cards

What is the main difference between TCP and UDP? 



The most important difference between TCP and UDP is the concept of “guaranteed” reliability and delivery. UDP is known as a “connectionless” protocol as it has very few error recovery services and no guarantee of packet delivery.  

•With UDP, packets are created and sent on their way.  

•UDP is considered to be an unreliable protocol 

 

TCP is a “connection-oriented” protocol  

• TCP was also designed to ensure that packets are  

processed in the same order.  

•As part of the TCP protocol, each packet has a sequence  

number to show where that packet fits 

49
New cards

A file owner decides which other users may read or modify a file. Which access control model is being used? 

Discretionary access control (DAC)

50
New cards

A company assigns permissions to job categories such as accountant, manager, and technician. Which access control model best describes this arrangement? 

Role-based access control (RBAC)

51
New cards

Which network topology is the one where network components are connected to the same cable? 


Bus Topology


52
New cards

Which network topology is the one where network components are connected to central point?


Star Topology

53
New cards

Does disabling a user account necessarily delete all files owned by that user? 



No. Disabling is reversible and only prevents the account from being used. The text says disabling is preferred over removal because removal can cause permission and ownership problems. 

54
New cards

What is the primary purpose of the Domain Name System (DNS)?

DNS translates domain names into IP addresses.

55
New cards

Which access control type allows a company to restrict employee logon hours?  


 

Rule-based access control. 

56
New cards


Which security objective is most directly supported by encrypting confidential files to prevent unauthorized reading?

Confidentiality, the ability to keep data secret, which encryption excels at providing. 


57
New cards

What is the hardware address used to deliver traffic to a device on an office LAN called?

MAC Address


58
New cards

Why should an organization construct and implement a PKI? 

To establish a level of trust. A PKI verifies that a person's public key is bound to their identity, which prevents someone from substituting their own key (a man-in-the-middle attack). It also lets parties communicate securely without prior communication or a preexisting relationship

59
New cards

if the root CA’s private key were compromised, what would happen? 


compromising any CA component threatens the integrity of the certificates it produces, and that every certificate chain ends at the root CA certificate, with all signatures verified up to it. So a compromised root would undermine trust in every certificate in its chain

60
New cards

What does HMAC use to generate a message authentication code? 

a cryptographic hash function combined with a shared secret key.

61
New cards

What does PKI stand for?  



Public key infrastructure 

62
New cards

An attack in which an attacker attempts to lie and misrepresent himself in

order to gain access to information that can be useful in an attack is known as:

Social engineering, in which an unauthorized individual uses deceptive practices to convince an authorized individual to provide confidential information or access. 

63
New cards

An access control system uses security labels and centrally enforced clearance levels. Which model best describes this system?


Mandatory access control (MAC)

64
New cards

What are the three core properties of information security? 

Confidentiality, Integrity, Availability  


65
New cards

What characteristics help a password meet typical complexity requirements? 


Password complexity should include: 

• Minimum length 

• Uppercase 

• Lowercas 

• Numerals 

• Non-alphabetic characters 

66
New cards

What is change control? 


Change control is the process of how changes to  

anything are sourced, analyzed, and managed. 

67
New cards

Which term describes a network that is typically smaller in terms of size and geographic coverage and consists of two or more connected devices? 


Local area network (LAN). The text says a LAN is typically smaller in size and geographic coverage and consists of two or more connected devices. 

68
New cards

How is integrity provided?  



hash functions

69
New cards

After a user signs in, a system checks whether the user may edit a file. Which process is being performed? 


Authorization. Once a user is authenticated, the authorization step takes place, and access controls define what actions a user can perform. 


70
New cards

What type of cryptography do digital signatures use?

Based on hashing functions and asymmetric cryptography