/
Network Security and Cryptography Fundamentals
Save to my account
Sign up
Network Security and Cryptography Fundamentals
Network Security and Cryptography Fundamentals
Study
1
Question
What is defined as a hostile attempt to exploit a vulnerability in network security?
Page 1
Answer
Attack, such as SQL injection on a login form
2
Question
What characterizes a passive attack in network security?
Page 1
Answer
Learning from the system without affecting it, such as eavesdropping on unencrypted Wi-Fi
3
Question
How does an active attack differ from a passive attack?
Page 1
Answer
Active attack alters or disrupts system resources, such as modifying data in transit
4
Question
What is a threat in the context of network security?
Page 1
Answer
A circumstance with potential to cause harm, such as a known software vulnerability
5
Question
What constitutes a vulnerability in security systems?
Page 1
Answer
A weakness in a security system, such as unpatched OS or weak password
6
Question
What are controls in network security?
Page 1
Answer
Means and ways to block a threat, such as firewall rules or encryption
7
Question
What three elements form the attacker's triangle required for a successful attack?
Page 1
Answer
Tools (malware, exploits, scanners), Skills (technical knowledge, coding), Knowledge (target info, system architecture)
8
Question
Why does removing any one element from the attacker's triangle prevent an attack?
Page 2
Answer
Because an attacker needs all three: tools, skills, and knowledge for success
9
Question
How does a script kiddie differ from an advanced persistent threat actor?
Page 2
Answer
Script kiddie has tools but limited skills and knowledge, relying on pre-built tools; APT has all three
10
Question
What was the financial cost of the 2017 Equifax breach?
Page 2
Answer
$1.4 billion including ransom payments, fines, and recovery costs
11
Question
Name three consequences of a security breach besides financial loss.
Page 2
Answer
Reputational damage (loss of customer trust, negative press), legal consequences (GDPR fines, lawsuits), confidentiality breach (exposure of personal data)
12
Question
What is cryptography according to the notes?
Page 2
Answer
The art of securing communication
13
Question
What is cryptanalysis, and how does it relate to cryptography?
Page 2
Answer
Breaking ciphertext without knowing the key; together with cryptography forms cryptology
14
Question
What is a cryptographic algorithm?
Page 2
Answer
Well-defined function that transforms input to secure output, such as AES or SHA-256
15
Question
What risk arises from logging into unencrypted HTTP sites on public Wi-Fi?
Page 3
Answer
Attacker can intercept login credentials
16
Question
What is unauthorized access in network security?
Page 3
Answer
Gaining access to systems without proper authorization by external hackers or internal disgruntled employees
17
Question
What are the four pillars of the security ecosystem?
Page 3
Answer
Confidentiality, Integrity, Authentication, Non-repudiation
18
Question
What mechanisms ensure confidentiality in the security ecosystem?
Page 3
Answer
Symmetric or asymmetric encryption, such as HTTPS encrypting banking sessions
19
Question
How is integrity maintained in the security ecosystem?
Page 3
Answer
Hash functions plus MAC, such as software update verified by digital signature
20
Question
What provides authentication in the security pillars?
Page 3
Answer
PKI and digital certificates, such as SSL certificate proving website identity
21
Question
What ensures non-repudiation according to the security ecosystem?
Page 3
Answer
Digital signatures, such as E-signed contracts that cannot be denied
22
Question
What is the key requirement for symmetric encryption?
Page 4
Answer
One key used for both encryption and decryption, shared secretly
23
Question
How many unique keys are needed for n users in symmetric encryption?
Page 4
Answer
\( \frac{n(n-1)}{2} \)
24
Question
What challenge arises with 1000 users using symmetric encryption?
Page 4
Answer
Requires 499,500 unique keys, making it hard to scale
25
Question
What is the basic formula for symmetric encryption ciphertext?
Page 4
Answer
Ciphertext = Plaintext × Key
26
Question
How does asymmetric encryption use keys differently from symmetric?
Page 4
Answer
Public key shared for encryption, private key secret for decryption
27
Question
What is the security basis for asymmetric encryption?
Page 4
Answer
Hard mathematical problems like integer factorization
28
Question
In asymmetric encryption for digital signatures, which key verifies?
Page 4
Answer
Receiver verifies with sender's public key after decrypting signature
29
Question
Why is asymmetric encryption not used for large data volumes?
Page 5
Answer
Slow performance due to computational intensity; used for key exchange then symmetric
30
Question
Compare the key sizes and security of DES and AES.
Page 5
Answer
DES: 56 bits, insecure; AES: 128/192/256 bits, very secure