NivaarExam PrepOfficial exam papers ↗

19-Soft-B3 Security: December 2016

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

  1. Question 1 Symmetric Ciphers — One-Time Pad vs. Stream Cipher
  2. Question 2 Public-Key Communication, the Certificate Authority, and Diffie–Hellman vs. RSA
  3. Question 3 Cryptographic Hashes, MACs, and Digital Signatures
  4. Question 4 Authentication Factors, Two-Factor Authentication, and Single-Sign-On
  5. Question 5 Firewalls, the DMZ, Intrusion Detection, and Honeypots
  6. Question 6 Stack Buffer Overflow in a C Program
  7. Question 7 The CIA Triad — Confidentiality, Integrity, and Availability

Start with Question 1 →

National Exams, December 2016 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.

Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Stream/Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 10 (Key Management, Diffie–Hellman, RSA), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow), Ch. 1 (Security Concepts — CIA Triad); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control), Ch. 1 (Security Concepts).