/
Security Fundamentals
Save to my account
Sign up
Security Fundamentals
WEEK 1 - Intro to Info sec concepts
Study
1
Question
What is the 'CIA' triad in computer security and what does each letter stand for?
Answer
The 'CIA' triad stands for Confidentiality, Integrity, and Availability. Confidentiality prevents unauthorized disclosure of information, Integrity prevents unauthorized modification, and Availability ensures authorized users can access information and resources when needed.
2
Question
How is confidentiality defined in information security?
Answer
Confidentiality is about preventing unauthorized users from reading information they are not entitled to, covering both data at rest (in a computer) and data in motion (in networks).
3
Question
What is the difference between data integrity and confidentiality?
Answer
Data integrity ensures that information is not modified by unauthorized users, focusing on the correctness and trustworthiness of data, whereas confidentiality focuses on preventing unauthorized access to read the data.
4
Question
What does availability mean in the context of security services?
Answer
Availability means ensuring that system services are accessible on demand to authorized entities. It includes preventing denial-of-service attacks and covers fault tolerance and high availability to avoid deliberate or accidental loss of service.
5
Question
Explain the role of data origin authentication in security.
Answer
Data origin authentication assures that data was created by a legitimate source and has not been altered. It includes verifying that the data’s integrity is intact but does not guarantee when the data was created.
6
Question
What is entity authentication and why is it important?
Answer
Entity authentication confirms the identity of the communicating party and verifies that this entity is actively participating in the communication, helping to prevent impersonation and unauthorized access.
7
Question
Describe the concept of non-repudiation in information security.
Answer
Non-repudiation prevents an entity from denying a previous action or communication. It often involves a third party to verify the action in case of a dispute.
8
Question
Why is accountability important in security, and how is it typically implemented?
Answer
Accountability ensures users are responsible for their actions, including misuse. It is implemented by securely identifying users, maintaining audit trails of security-relevant events, and keeping log files to track "who did what."
9
Question
How are reliability and security related in system design?
Answer
Reliability involves ensuring systems perform properly under adverse conditions, and it is related to security because both seek dependable system behavior. They often use similar evaluation methods and contribute to overall dependability.
10
Question
What is the modern understanding of privacy in the context of information security?
Answer
Privacy refers to the protection of personal data or Personally Identifiable Information (PII), including giving users control over their own data and imposing requirements on data holders to properly manage and protect PII.
11
Question
What historical examples illustrate ancient steganography methods?
Answer
Examples include Histiaeus shaving a messenger’s head, writing a message on the scalp, then letting hair grow back to conceal it, and Demaratus writing on wooden tablets scraped free of wax, then covering with wax again to hide the message.
12
Question
What is the difference between steganography and cryptography in message transmission?
Answer
Steganography hides the existence of the message so it is not detected, while cryptography disguises the message so it is unintelligible even if intercepted.
13
Question
What are the two key aspects that must be considered in security assessments?
Answer
Functionality, which is what security features the system provides, and Assurance, which is the guarantee that the security features perform as claimed.
14
Question
Why is minimizing complexity important when aiming for a high level of security assurance?
Answer
Because the effort needed to provide high assurance increases with complexity, minimizing complexity (e.g., using trusted kernels) makes it easier and more reliable to verify and maintain security features.
15
Question
How is a security threat defined according to ENISA?
Answer
A threat is any circumstance or event that can negatively impact an asset through unauthorized access, destruction, disclosure, modification of data, or denial of service.
16
Question
What is the significance of performing a threat analysis in defining security?
Answer
Threat analysis identifies potential threats relevant to a system, allowing security measures to be tailored to combat specific risks rather than attempting to counter every possible threat, considering cost versus benefit.
17
Question
What is the essence of risk analysis in information security?
Answer
Risk analysis involves assessing the importance of each threat, determining whether it should be combated, evaluating the likelihood of the threat being realized, and estimating the cost to the system if it happens. It also considers whether living with some threats may be less costly than preventing them.
18
Question
Why is designing security into a system from the start recommended compared to adding it afterward?
Answer
Designing security into a system from the start is better because security becomes an integral part of the system design and lifecycle, which results in more effective and thorough protection than adding security as an afterthought.
19
Question
What are some ways security can be integrated into the software development lifecycle?
Answer
Security can be integrated as a required feature, included in unit testing through security testing, or treated as an additional step in the development process.
20
Question
What are security controls and what do they typically focus on?
Answer
Security controls are techniques or rules that enforce protection of data in computer systems. They typically focus on limiting how data is handled, restricting which operations can be performed on data, and controlling which users can do certain actions. They can focus on data, operations, or users or a combination of these.
21
Question
What are the five layers of a typical IT system where security controls can be applied?
Answer
The five layers are: application programs, services, operating system, kernel of the operating system, and hardware.
22
Question
How do the characteristics of security controls differ depending on their location within the system layers?
Answer
Controls close to the hardware tend to be more generic and oriented toward the computer itself, while controls near the application layer tend to be more user-oriented.
23
Question
In addition to rules, what other types of security controls are important to consider?
Answer
Physical security is also crucial, and for protecting data communications, cryptography and cryptographic protocols are key tools.
24
Question
How can attackers bypass security controls? Give an example.
Answer
An attacker accessing a system layer below where a security control is applied can bypass it. For example, if someone gains system privilege on the operating system, they can bypass application-level controls by directly accessing protected files.
25
Question
What is a Security Policy and what are its main purposes?
Answer
A Security Policy is a set of rules specifying how security should be enforced within a specific domain like a department or company. It defines the security objectives, states what needs to be protected, how it will be protected, and plans actions when violations occur.
26
Question
What qualities should an effective Security Policy have?
Answer
It should be easy to read and remember, unambiguous, aligned with the organization's culture, supportive of productivity and innovation, and able to adapt to changes in the working environment.
27
Question
What is the UK Computer Misuse Act 1990 and what does it aim to protect?
Answer
It is the main UK legislation related to offences against computer systems. It provides provisions for securing computer material against unauthorized access or modification.
28
Question
List some offenses defined under the Computer Misuse Act 1990.
Answer
Offenses include causing a computer to perform a function with intent to secure unauthorized access, unauthorized acts impairing computer operation, and unauthorized acts causing or risking serious damage to human welfare, environment, economy, or national security.
29
Question
What does the UK Data Protection Act 2018 regulate?
Answer
It obliges holders of personal data to protect its accuracy and privacy. Personal data includes any information relating to an identified or identifiable living individual, such as name, ID number, or location data.
30
Question
What are some offenses under the UK Data Protection Act 2018?
Answer
Offenses include destroying or falsifying information or documents, unlawfully obtaining personal data, re-identifying de-identified personal data, and altering personal data to prevent disclosure to data subjects.