Question Bank CSS Unit Test 2
Modules from Syllabus
MAC,HMAC, Digital signatures, RSA as digital signature, Kerberos, X.509 Directory
Authentication service, PKI, IDS & Firewall, SSL, IPSEC
2 marks questions
1. What is the final solution to the problem of key exchange?
2. What is the role of a CA & a RA?
3. Discuss any one mechanism used by a RA for checking the users proof of possession of
the private key.
4. What is the use of SSL?
5. SSL talks about security at the transport layer. What if we want to enforce security at the
lower layers?
6. How SSL handshake protocol is used for authentication?
7. Differentiate among encoding, encryption and hashing?
8. What is the difference between MAC and message digest?
9. What are the approaches are used for user authentication in standalone & distributed
environment? (Consider algorithm, protocol, methods)
10. In Kerberos protocol, what if two users have same passwords in generating session key
between client and Authentication server?
11. Why replay attack is not possible in Kerberos?
12. Discuss how does the encryption key is generated from password in Kerberos?
13. State the difference between eavesdropping and wiretapping?
14. What are replay attacks? Give an example of replay attack.
15. Which protocols are used for key management of IPSec?
16. Differentiate digital signature from digital certificate.
17. Discuss about the objectives of HMAC and its security features.
18. What is the difference between proxy, firewall, IDS and IPS (Intrusion Prevention
System)?
19. Mention the limitations of firewalls.
5 marks questions
1. How do you use RSA for both authentication and secrecy?
2. What is Digital Signature? Explain how it is created at the sender end and retrieved at
receiver end.
3. Describe the authentication protocol and list its limitations, how the limitations
overcome.
4. Assume a client C wants to communicate with a server S using Kerberos protocol. Infer
how can it be achieved?
5. Does a PKI use symmetric or asymmetric encryption? Explain your answer.
6. What is phishing? How is it related to authentication? How would you prevent possible
phishing attacks?