IS4560 Hacking and Countermeasures


Credit hours: 4.5
Contact/Instructional hours: 60 (30 Theory, 30 Lab)
Prerequisite: NT2580 Introduction to Information Security or equivalent
Corequisite: None

1. Scope
This exam covers Units 1–5 and is based on the following content from the textbook:
Chapter 1, “Hacking: The Next Generation”
Chapter 2, “TCP/IP Review”
Chapter 3, “Cryptographic Concepts”
Chapter 4, “Physical Security”
6. If money is the motivation now, what was the motivation for previous generations of hackers?

a. Money
b. Fame
c. Source code access
d. Creation of botnets

7. Red teams, sneakers, and tiger teams are all examples of _________.

a. white hat hackers
b. hacktivists
c. social engineers
d. phreaks

8. Which fallacy is described by the quote “Accessing a system without authorization is okay, as long as nothing is stolen or damaged in the process”?

a. The computer game fallacy
b. The law-abiding citizen fallacy
c. The no-harm was done fallacy
d. The hacker fallacy

9. Attacking a company’s Web applications to prevent them from being vulnerable is an example of which of the following?

a. Ethical hacking if you are an employee
b. A legal activity if the application is one you use
c. Black hat hacking
d. Ethical hacking if you disclose the vulnerabilities

10. Which of the following sets the ethical standards?

a. Individuals
b. The government
c. Peer groups
d. Professional organizations and certifying bodies

11. What does hashing provide?

a. A guaranteed unique string for each file hashed
b. A quick way to check the author of a file
c. Cryptographic security
d. A fixed length string that represents the original file

12. Which capability of cryptography ensures that data can be verified as being valid and trusted?

a. Authenticity
b. Privacy
c. Integrity
d. Non-repudiation

13. What does losing the encryption key to stored data signify?

a. The passphrase must be re-created.
b. The data is typically lost.
c. The data can be recovered by hashing the stored file.
d. The data is no longer secure.

14. What can a digital signature provide?

a. Authentication
b. Integrity
c. Non-repudiation
d. Authentication, integrity, and non-repudiation

15. Symmetric encryption requires which of the following?

a. Both the parties should send the same length message.
b. Both the parties should use the same key.
c. Both the parties exchange messages only.
d. Both parties must exchange keys and handshakes.

16. Asymmetric encryption does not require ___________.

a. key exchange
b. secret keys
c. multiple keys
d. secure initial key exchange

17. Attacks against ciphers that feed information into a system and observe output are:

a. Ciphertext only
b. Known plaintext
c. Chosen plaintext
d. Chosen ciphertext

18. Symmetric encryption faces difficulty due to what issue?

a. Security
b. Key exchange
c. Bit length
d. Software expense

19. What attack is being used if two messages are found to have the same message digest?

a. Brute force
b. Known plaintext
c. Birthday attack
d. Collision

20. The encryption used for Web traffic is _________.

a. MD5
b. SHA1
c. SSL
d. SSH

21. What database of financial records should penetration testers review?

d. SECWeb

22. What technique should be used to secure DNS?


Penetration Test Plan Essay

584 words - 3 pages obtained from the network and any information regarding exploitation of vulnerabilities and the attempt to gain access to sensitive data. Overview: After the results have come back from the penetration testing and have been shared with The Fitness Club, Malcolm Testing Solutions will discuss security countermeasures that may need to be set in place to prevent exploitations in the future. The access control security countermeasures will depend on the

Identifying Potential Malicious Attacks Essay

1095 words - 5 pages software patches, reconfiguring devices, or deploying countermeasures such as firewalls and antivirus software.   Threat is when people take advantage of vulnerability and cause a negative impact on the network. If threat occurs it needs to be identified, and the associated vulnerabilities need to be addressed to minimize the risk.  As of today, most of the hackers are interested in hacking services such as HTTP (TCP Port 80) and HTTPS (TCP Port

Network Security Essay

1925 words - 8 pages ? Second, what relationship if any does the internet have under international law? Between the years of 2007 – 2009 several major incidents occurred that forever changed the way governments view internet cyberspace. The hacking attacks of Estonia in 2007, the Georgia cyber attacks during the Georgia-Russia War in 2008, and the release of the Stuxnet worm to hinder Iran’s nuclear program in 2009 all enhanced the support for military

Ciisp Exam Essay

4138 words - 17 pages . 87. Improving employee motivation and job satisfaction is a countermeasure against all but which of the following attacks? D: Fraud requires additional countermeasures, such as job rotation, mandatory vacations, audit trails, etc. 88. Trusted recovery is concerned with all but which of the following conditions? A: Trusted recovery is not concerned with the hot swapping of a failed RAID member drive. 89. The most important