100% found this document useful (2 votes)
511 views2 pages

Security Practices Exam Paper 2021

This document is a question paper for an exam on computer science and engineering security practices. It contains 3 parts with multiple choice and written response questions. Part A contains 10 short answer questions worth 2 marks each on topics like encryption, firewalls, intrusion detection systems, access control, cyber forensics, and physical security threats. Part B contains 5 longer answer questions worth 13 marks each on topics such as intrusion prevention, web application security, internet security threats, wireless sensor network attacks, and identity management. Part C contains 1 long answer question worth 15 marks involving designing a security management system or privacy policies for a banking/loan scenario.

Uploaded by

Ponraj Park
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (2 votes)
511 views2 pages

Security Practices Exam Paper 2021

This document is a question paper for an exam on computer science and engineering security practices. It contains 3 parts with multiple choice and written response questions. Part A contains 10 short answer questions worth 2 marks each on topics like encryption, firewalls, intrusion detection systems, access control, cyber forensics, and physical security threats. Part B contains 5 longer answer questions worth 13 marks each on topics such as intrusion prevention, web application security, internet security threats, wireless sensor network attacks, and identity management. Part C contains 1 long answer question worth 15 marks involving designing a security management system or privacy policies for a banking/loan scenario.

Uploaded by

Ponraj Park
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • PART B
  • PART A
  • PART C

*X86562* Reg. No.

Question Paper Code : X86562


M.E./[Link]. Degree Examinations, April/may 2021
Second Semester
Computer Science and Engineering
CP5291 – Security practices
(Common to M.E. Mobile and Pervasive Computing)
(Regulations 2017)

Time : Three Hours Maximum : 100 Marks

Answer all questions

Part – A (10×2=20 Marks)

1. What is the role of encryption in cryptography ?

2. Write down the purpose of fault tolerance and resilience in cloud computing
environment.

3. How does firewall ensure network security ?

4. Define availability in terms of network.

5. List down any four intrusion detection systems.

6. Write down the significance of access control in data security.

7. What is cyber forensics ?

8. State the significance of e-discovery.

9. Classify conflicts in policies.

10. Name any four physical security threats.

Part – B (5×13=65 Marks)

11. a) Explain in detail intrusion detection and prevention mechanisms.


(or)
b) Discuss in detail about the security issues in web applications and web services.
X86562 *X86562*

12. a) Explain with real-time examples possible internet security threats and
elaborate on internet security mechanisms.
(or)
b) List down various types of attacks in Wireless Sensor Networks and discuss
about various techniques to ensure security in WSN.

13. a) Illustrate how policy-driven system management is implemented.


(or)
b) Discuss in detail about how identity and user management system could
provide data security.

14. a) Write short notes on :


i) Satellite encryption. (7)
ii) Password based authentication system. (6)
(or)
b) Elaborate on how Cyber forensics is related to Incidence response.

15. a) How does privacy enhancing technologies provide privacy on internet ?


Discuss.
(or)
b) What is Storage Area Network ? Discuss in detail about SAN security and the
SAN security devices.

Part – C (1×15=15 Marks)

16. a) Consider a scenario where an IT manager of a company spread across locations


in the country with people or different roles spread across, is assigned a task
of implementing a security management system. As a security expert suggest
various alternatives for the implementation by considering factors such as
organization structure and the system architecture.
(or)
b) Design privacy policies to provide security pertaining to a banking firm and a
Loan processing agency which is supposed to recommend loans on verification
of the Customer information such as account details, transactions made and
loans availed. Consider the roles bank manager, Loan officer, Customer.
Provide necessary security system designs and architecture.

_________________

Common questions

Powered by AI

E-discovery is significant in legal contexts as it involves retrieving electronic data for use as evidence in legal cases. It impacts data management practices by necessitating robust data organization, retention policies, and retrieval processes to comply with legal requirements. Organizations must ensure that digital records are efficiently stored and can be retrieved accurately to meet legal standards during investigations and litigations .

Fault tolerance and resilience ensure that cloud computing systems can endure and recover from failures without significant disruption. Fault tolerance allows systems to continue operating gracefully even when components fail, thus minimizing the impact on users. Resilience involves the ability to recover quickly from failures, maintaining an acceptable level of service, which is crucial for the reliability and stability of cloud services .

Privacy-enhancing technologies (PETs) protect user privacy by minimizing data collection, storing only essential data, and securing it through encryption. Techniques like anonymity networks, secure communications, and data obfuscation are used to prevent unauthorized access to personal data, ensuring that users’ online interactions remain private and their personal information protected from surveillance and data breaches .

Cyber forensics and incident response intersect in the identification, analysis, and mitigation of cyber incidents. Cyber forensics involves collecting, preserving, and analyzing digital evidence, which aids incident response teams in understanding the nature and scope of threats. This integration is crucial as it allows organizations to respond effectively to breaches, recover systems, and prevent future attacks by learning from incidents .

Availability in network terms refers to the guarantee that users can access and use information and resources when needed. It is a critical aspect of network security because consistent, reliable access to network services is necessary for business operations and user satisfaction. High availability reduces downtime and ensures continuity of operations .

Intrusion Detection Systems (IDS) like Host-based IDS (HIDS) and Network-based IDS (NIDS) differ in deployment and scope. HIDS monitors individual host systems and detects threats based on activities, while NIDS monitors and analyzes traffic on the entire network. Both aim to identify suspicious activities and potential threats but differ in perspective—HIDS offers detailed logs at the host level, while NIDS provides a broader network-wide view. Despite differences, both share the goal of alerting administrators to potential threats .

Encryption converts plaintext into ciphertext to protect data from unauthorized access. It ensures data confidentiality, making it unintelligible to anyone who does not have the decryption key. This process helps maintain data integrity and authenticity, as only authorized parties can convert the data back to its original form, preventing unauthorized alterations .

A firewall acts as a barrier between a trusted internal network and untrusted external networks, such as the internet. It monitors and controls incoming and outgoing network traffic based on predetermined security rules. By enforcing these rules, firewalls prevent unauthorized access to or from private networks, hence protecting information systems from various attacks and threats like malware and intrusions .

Access control is pivotal in multi-user environments as it ensures that users only have access to the data and resources that are necessary for their roles, thereby enforcing the principle of least privilege. This prevents unauthorized access and potential breaches, ensuring data confidentiality and integrity. Effective access control mechanisms are essential for safeguarding sensitive information in both corporate networks and cloud computing environments .

Designing privacy policies for financial institutions involves challenges like regulatory compliance, balancing transparency with data protection, and ensuring secure data sharing among stakeholders. Considerations include defining clear access controls, implementing strong authentication mechanisms, and ensuring policies are adaptable to evolving regulatory landscapes. Privacy policies must prioritize protecting customer information from unauthorized access while allowing necessary data processing for loan assessments .

Reg. No. : 
*X86562*            
	
Question Paper Code : X86562
M.E./M.Tech. Degree Examinations, April/may 2021
Second Semes
X86562	
	
*X86562*
12.	 a)	 Explain with real-time examples possible internet security threats and 
elaborate on internet sec

You might also like