Distinguish between Authentication and Authorization.
Information Security Systems
22 questions
Define cryptanalysis.
What is a Denial of Service (DoS) attack?
Briefly explain the concept of Public Key Infrastructure (PKI).
What is Pretty Good Privacy (PGP) primarily used for?
Describe a Cross-Site Scripting (XSS) attack.
What is a botnet?
List two advantages of biometric authentication.
What is a logic bomb in malware?
Define a Key Distribution Center (KDC).
Explain the round structure in the Data Encryption Standard (DES).
Discuss the working principles of the SHA-1 algorithm.
Explain the concept of a Virtual Private Network (VPN) and its tunneling protocols.
Describe the Bell-LaPadula security model and its primary properties.
Compare and contrast DoS and DDoS attacks with examples.
Outline the Secure Electronic Transaction (SET) protocol for e-commerce.
Discuss role-based access control (RBAC) and its benefits.
Analyze the RSA cryptographic algorithm in detail. Provide a mathematical example of key generation, encryption, and decryption, followed by a security analysis.
Detail the architecture and modes (Transport and Tunnel) of IPSec. Discuss how it provides security at the network layer.
Elaborate on the working of Intrusion Detection Systems (IDS). Compare Network-based IDS (NIDS) and Host-based IDS (HIDS).
Discuss major Web Security threats including SQL Injection and Cross-Site Request Forgery (CSRF). Provide detailed countermeasures for each.
Explain the Digital Signature Standard (DSS) approach. Detail the algorithm used for generating and verifying digital signatures.