0% found this document useful (0 votes)
3 views6 pages

Question Bank Format

This document is a question bank for the course 'Data and Information Security' at Arjun College of Technology, aimed at Computer Science and Business Systems students. It includes instructions for question formulation, course outcomes, and a variety of questions categorized into one-mark, two-mark, and fourteen-mark sections, covering topics such as information security principles, the NSTISSC Security Model, and the Software Development Life Cycle. The document emphasizes clarity, relevance, and alignment with Bloom's taxonomy in question design.

Uploaded by

dharini.raji
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views6 pages

Question Bank Format

This document is a question bank for the course 'Data and Information Security' at Arjun College of Technology, aimed at Computer Science and Business Systems students. It includes instructions for question formulation, course outcomes, and a variety of questions categorized into one-mark, two-mark, and fourteen-mark sections, covering topics such as information security principles, the NSTISSC Security Model, and the Software Development Life Cycle. The document emphasizes clarity, relevance, and alignment with Bloom's taxonomy in question design.

Uploaded by

dharini.raji
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

ARJUN COLLEGE OF TECHNOLOGY

An Autonomous Institution| Accredited with NAAC ‘A’


Approved by AICTE |Affiliated to Anna University, Chennai
Thamaraikulam, Coimbatore Pollachi Highway, Coimbatore- 642 120

QUESTION BANK

Name of the Department : COMPUTER SCIENCE AND BUSINESS SYSTEMS


Course Code : CW3551
Name of the Course : DATA AND INFORMATION SECURITY
Regulation : R2021
Semester / Year : V / III
Common To :AI & DS & CS & BS

Instructions

Questions must be clear, unambiguous and error free


Avoid repetitive and overlapping questions
Use appropriate diagrams/tables wherever required
Give complete data for numerical problems
Follow blooms taxonomy

Course Outcome
CO1: Understand the basics of data and information security
CO2: Understand the legal, ethical and professional issues in information security
UNIT– I
Introduction History of Information Security
Questions should be of
1. Gate preparatory questions

PART – A (One Mark Questions)

CO BT
Q. No Questions Mappe Level
d
1 The primary objective of information security is to protect the
confidentiality, integrity, and availability of ________
CO1
BTL1
A) Hardware B) Information C) Buildings D) Employees
2 The three fundamental security goals collectively referred to as the CIA
triad are:
CO1
BTL1
A) Confidentiality, Integrity, Availability B) Control, Identification,
Authentication C) Confidentiality, Identity, Authorization D)
Communication, Integrity, Access
3 Which one of the following is NOT a component of the CIA security
CO1
model? BTL2
A) Confidentiality B) Integrity C) Availability D) Authenticity
4 Which security property prevents unauthorized disclosure of sensitive
information? BTL2
CO1
A) Availability B) Confidentiality C) Integrity D) Authenticity
5 The NSTISSC Security Model is more commonly known as the ________
CO1 BTL1
A) Bell-LaPadula Model B) McCumber Cube C) Clark-Wilson Model D)
Biba Model
6 Routers and switches are primarily categorized under which component of
CO1 BTL2
an information system?
A) Software B) Hardware C) Procedures D) People
7 Which of the following is NOT considered a component of an information
CO1
system?
BTL1
A) Hardware B) Software C) Agriculture D) Data
8 Which of the following is NOT one of the three information states in the
CO1 BTL2
McCumber Cube?
A) Storage B) Processing C) Transmission D) Authentication
9 Humans are considered an integral part of an information system because
they ________
A) Develop road networks B) Manage and use information C) Manufacture CO1 BTL2
hardware D) Generate electricity
10 The information security principle that ensures authorized users can access
resources whenever required is known as ________
A) Integrity B) Confidentiality C) Availability D) Authenticity CO1 BTL2
11 In a secure organization, the document that defines security rules,
responsibilities, and acceptable practices is called the ________
CO1 BTL1
A) Test Plan B) User Manual C) Security Policy D) Project Report
12 In the Software Development Life Cycle (SDLC), the Design phase is
immediately followed by the ________
CO1 BTL1
A) Planning B) Coding (Implementation) C) Maintenance D) Disposal
13 People are considered a component of an information system because they
________
CO1 BTL2
A) Use and manage information B) Build roads C) Manufacture cars
D) Grow crops
14 Which of the following best describes the principle of balancing security
and usability?
CO1 BTL2
A) Eliminate all security controls B) Maximize restrictions irrespective of
usability C) Provide adequate protection while ensuring authorized access
D) Allow unrestricted access to all users
15 The information security principle that ensures authorized users can access
resources whenever required is known as ________
CO1 BTL2
A) Integrity B) Confidentiality C) Availability D) Authenticity
16 Which of the following is NOT a component of the CIA triad?
A) Confidentiality B) Integrity C) Availability D) Authenticity BTL2
CO1
17 The principle of balancing security and access means ________
A) No security B) Maximum restrictions only C) Appropriate protection BTL2
CO1
without affecting usability D) Unlimited access
18 Which SDLC phase involves writing the actual program?
A) Design B) Coding/Development C) Planning D) Maintenance CO1 BTL1
19 Which of the following is one dimension of the McCumber Cube?
A) Marketing B) Information States C) Sales D) Finance CO1 BTL1
20 Which SDLC phase involves writing the actual program?
A) Design B) Coding/Development C) Planning D) Maintenance CO1 BTL2
PART – A (Two Mark Questions)
Questions should be of
1. Basic concepts, definitions, laws and simple application
2. Lower order or intermediate type cognitive type
Q. No Questions CO BT
Mappe Level
d
1 Define Information Security. CO1 BTL1

2 State the objectives of Information Security. CO1 BTL1

3 List any four critical characteristics of information CO1 BTL1

4 Define Confidentiality in Information Security. CO1 BTL1

5 Define Integrity with an example. CO1 BTL2

6 Explain Authenticity as a characteristic of information. CO1 BTL2

7 Define Possession (or Control) in Information Security. CO1 BTL1

8 List the three dimensions of the NSTISSC Security Model. CO1 BTL1

9 Name the three states of information in the McCumber Cube CO1 BTL1

10 Mention the three categories of security measures in the NSTISSC model. CO1 BTL1

11 List the major components of an Information System. CO1 BTL1

12 State any four methods to secure information system components. CO1 BTL1

13 Define access control. CO1 BTL1

14 Expand SDLC. List its phases. CO1 BTL1

15 Mention any four phases of the Software Development Life Cycle. CO1 BTL1

16 List the phases of the Security SDLC. CO1 BTL1

17 State the importance of Security SDL CO1 BTL2

18 Mention any two benefits of implementing Information Security in an CO1 BTL2


organization.
19 What is meant by balancing security and access? CO1 BTL2

20 What is the purpose of the Planning phase in SDLC? CO1 BTL2

16 PART – B (Fourteen Mark Questions)


Questions should be of17
1. Higher Order (HO18) cognitive type.
2. Concept explanation, detailed reasoning, numerical problems, and derivations.
3. Understanding / Applying/ Analyzing/ Evaluating
4. Maximum number of Subdivisions is Two of seven marks each.
5. Formulate questions that align with the Evaluate and Create levels of higher-order thinking.
Q. No Questions CO BT
Mappe Level
d
Explain the history and evolution of Information Security. Discuss the major
milestones and emerging challenges in protecting information assets. CO1
BTL2
1
Describe the critical characteristics of information. Explain how
2 Confidentiality, Integrity, Availability, Authenticity, Accuracy, Possession, CO1
BTL2
Utility, and Privacy contribute to information protection.
Explain the NSTISSC (McCumber Cube) Security Model with a neat
3 diagram. Discuss its three dimensions and their significance in CO1
BTL2
implementing Information Security.
Analyze the role of Information Security in protecting organizational assets.
4 Discuss how security policies, procedures, and technologies help mitigate CO1
BTL4
cyber threats.
Evaluate the importance of integrating security throughout the Software
5 Development Life Cycle. Suggest best practices for developing secure
CO1 BTL5
information systems.
A company plans to implement a new information system. Explain how
6 Information Security concepts, Information System components, SDLC, and
BTL4
CO1
Security SDLC can be applied to ensure secure system development.
Discuss the concept of balancing security and access. Explain the challenges
BTL4
7 involved in providing adequate security while ensuring system usability CO1
with suitable examples.
8 Analyze the security risks associated with each component of an
Information System and propose appropriate countermeasures for CO1 BTL4
mitigating those risks.
Design a Security SDLC framework for a medium-sized organization.
9 Explain the activities performed in each phase and justify your CO1 BTL6
proposed framework.
Discuss various methods used to secure the components of an
10 Information System. Explain the security measures applicable to CO1 BTL3
hardware, software, data, networks, people, and procedures.
Evaluate the effectiveness of the NSTISSC Security Model in protecting
11 organizational information assets. Justify your answer with real-world CO1 BTL5
examples.

You might also like