NivaarExam PrepOfficial exam papers ↗

19-Soft-B3 Security: May 2014

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

  1. Question 1 Symmetric Ciphers — One-Time Pad vs. Block Cipher
  2. Question 2 Key Exchange, Public-Key Communication, and the Certificate Authority
  3. Question 3 Cryptographic Hashes, MACs, and Digital Signatures
  4. Question 4 Authentication Factors, Two-Factor Authentication, and Single-Sign-On
  5. Question 5 Firewalls, the DMZ, Intrusion Detection, and Honeypots
  6. Question 6 Stack Buffer Overflow in a C Program
  7. Question 7 Least Privilege, Defense in Depth, and Separation of Privilege

Start with Question 1 →

National Exams, May 2014 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.

Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control, Least Privilege), Ch. 1 & 9 (Defense in Depth, Separation of Duty).