0% found this document useful (0 votes)
9 views17 pages

Computer and Network Security Assignment

The document is an assignment cover sheet for a coursework on Computer and Network Security at Knox Community College, submitted by student Anthony Granston. It outlines the importance of plagiarism, the CIA triad (Confidentiality, Integrity, Availability), and various security measures including physical and administrative controls. Additionally, it discusses concepts such as hashing, access control methods, and the principle of least privilege in cybersecurity.

Uploaded by

Anthony Granston
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views17 pages

Computer and Network Security Assignment

The document is an assignment cover sheet for a coursework on Computer and Network Security at Knox Community College, submitted by student Anthony Granston. It outlines the importance of plagiarism, the CIA triad (Confidentiality, Integrity, Availability), and various security measures including physical and administrative controls. Additionally, it discusses concepts such as hashing, access control methods, and the principle of least privilege in cybersecurity.

Uploaded by

Anthony Granston
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

THE COMMUNITY COLLEGES OF JAMAICA

EXAMINATIONS AND ASSESSMENT DEPARTMENT

ASSIGNMENT COVER SHEET

Knox Community
COLLEGE: CAMPUS: Spalding
College
STUDENT NAME: Anthony Granston
STUDENT ID
23010824
NUMBER:
PROGRAMME: Asc. Information Technology

COURSE: Computer and Network Security

LECTURER: Lincoln Foster


TYPE OF
Coursework
ASSESSMENT:
DATE
DUE DATE: 4/3/2025 4/3/2025
SUBMITTED:

Plagiarism

Plagiarism is the failure to properly acknowledge the use of another person’s work, or submitting
for assessment, material that is not a student’s own work. This is a form of academic misconduct
and is a serious offence which can lead to severe penalties, up to and including expulsion
(depending on the severity of the case). Please see your CCCJ student handbook for further
information.

Declaration of Authorship and authorisation to verify that it is original:


I Anthony Granston certify that the attached work is my own and that all material which is not
my own has been appropriately cited and referenced.
Signed: _________________________
Date: __________4/3/2025___________
What are the three components of the CIA triad?

Confidentiality
Maintaining sensitive information private and shielding it from unwanted access is the goal
of confidentiality. This entails restricting access to just authorized personnel inside an
organization and safeguarding data from malevolent actors (Staff, 2025).

Integrity
To ensure that data and business analysts are obtaining correct information, data integrity
must be maintained. Publicly displayed data must also be accurate in order for clients to have
faith in the company. A system with integrity protects data from unneeded modifications,
whether intentional or unintentional. When making adjustments, cybersecurity experts may
set up access levels, activate tracking, and safeguard data while it's being sent or stored
(Staff, 2025).

Availability
Availability represents the principle that individuals requiring access to data can obtain it

without compromising its confidentiality or integrity. You desire that the receivers of the

email you dispatched can access, display, and retain it for future reference. Ensuring

availability in data systems can be challenging due to potential conflicts with other elements

of the triangle. One of the most effective methods to safeguard data is to restrict access to it.

Individuals in information security positions may encounter resistance from clients or

colleagues on the accessibility of information (Staff, 2025).


Why might a CCTV camera be sited outside a building

without any film inside?

CCTV cameras can be installed outside a building without recording for various reasons,

including deterrence, cost reduction, maintenance, and future application. They can dissuade

potential intruders, minimize maintenance costs, and be installed in anticipation of upgrades or

activations, ensuring a comprehensive surveillance system is always in operation.

What does confidentiality mean?

Confidentiality pertains to the responsibilities of people and institutions to responsibly utilize

information that has been entrusted to them and is under their control. It entails safeguarding the

confidentiality of another individual or entity's information and is frequently mandated by law

for specific specialists. Confidentiality guarantees that critical information remains undisclosed

to unauthorized individuals (Cydni, 2015).

How can we protect a data center from people entering

it?

A data center's security is crucial for maintaining its integrity and safety. This involves a

comprehensive security strategy, including boundary protection, surveillance cameras, access

control systems, monitoring systems, security alarm systems, physical obstacles, staff

development, and visitor management (Howell, 2024). These measures include erecting high-

security fencing and barriers, deploying surveillance cameras, using biometric scanners for

authorized access, and implementing AI-enhanced cameras for identifying suspicious activities.
Security alarm systems monitor environmental conditions, and intrusion detection systems

activate upon detection of illegal access (Data Center Solutions, n.d.)

. Physical obstacles include reinforced entrances and high-security locks, and mantraps for one-

time entry. Staff development includes regular security training and strict visitor management

protocols. These measures ensure the security of the data center and prevent potential threats to

its operations (Shailaja, 2020).

What is the purpose of an airgap?

An air gap serves to enhance security by removing potential attack channels susceptible to

exploitation by hackers or viruses.

Name three administrative controls used to ensure

security.

Security Policies: Formulating exhaustive security rules that delineate permissible usage, data

safeguarding, and incident response protocols. These policies instruct staff on the management of

sensitive information and the response to security issues.

Access Management: Establishing protocols for user access management, encompassing role-

based access control (RBAC), periodic audits of access privileges, and guaranteeing that only

authorized individuals can access sensitive systems and data.

Security Training and Awareness Initiatives: Implementing frequent security training and

awareness initiatives to inform staff on best practices, phishing threats, and the identification and

reporting of suspicious activities.


Name three physical controls used to ensure security.

Lock and Key: The utilization of locks and keys to limit access to structures, data centers, and

storage units (Adcyber, 2023).

Surveillance: The employment of cameras to oversee the company's facilities and identify any

unauthorized entry (Adcyber, 2023).

Biometric scanners, including fingerprint, facial recognition, and iris scanning technologies, are

employed to limit access to offices, data centers, and information storage facilities (Adcyber,

2023).

Following an incident, what type of control will be used

when researching how the incident happened?

Post-incident assessments and analyses are essential for comprehending the events that

transpired and for averting future incidents. This research employs several prevalent control

measures:

Incident Evaluation: Performing a comprehensive assessment with personnel and responders to

analyze the efficacy of the response and pinpoint areas for enhancement (Hughes, 2022).

Incident Management Measurement Toolkit: Employing instruments such as questionnaires and

observational techniques to evaluate the efficacy of incident management (Nelson et al., 2024).

Cybersecurity Frameworks: Integrating advice and considerations from frameworks such as the

NIST Cybersecurity Framework to enhance incident response and management (A. Nelson,

2025).
How do I know if the integrity of my data is intact

Data Validation: Verify that data values adhere to the anticipated format, range, and type. This

encompasses field-level validation, record-level validation, and referential integrity assessments.

Verification of Consistency: Guarantee data consistency across several systems or inside a

singular system. This entails the comparison of data across various places or formats to

guarantee consistency.

Completeness: Ensure that your data is comprehensive. This entails verifying that all mandatory

fields are completed and that records exist for all monitored entities.

Accuracy: Verify that the data is precise and accurately reflects the real-world entities it

denotes. This entails verifying data entry inaccuracies, including typographical errors and

erroneous or absent values.

Timeliness: Ensure that data is gathered and revised expeditiously. Obsolete data may lack value

and reliability (Matillion, 2023).

Reliability: Ensure data integrity by maintaining its uncorrupted state and accessibility

throughout its existence (Matillion, 2023).


What is a corrective control

Corrective controls are essential components of internal control and risk management

frameworks within enterprises. Their objective is to address identified mistakes or issues

efficiently, with the intent of rectifying these problems and reinstating systems or processes to

their regular condition. This remedial step often transpires after the identification of an incident

or vulnerability by detective controls (Financial Crime Academy, 2025b).

What is the purpose of hashing?

Hashing is the process of assigning a numeric value to an alphanumeric string by transforming it

into another numeric value and storing it in an indexed database to enhance data retrieval speed

and/or to obscure the data for encryption, executed by a hash function (Hashing Working, Types,

and Functions | Spiceworks, 2025).

Hashing is a technique used to verify data integrity, secure password storage, and efficiently

retrieve data. It ensures data integrity by comparing the original data's hash value with the

received data, detecting unauthorized changes. It also aids in efficient data retrieval by creating

hash tables, linking keys to specific values, allowing quick access and storage. This method

protects users' passwords even in compromised storage databases ([Link], 2022).


If I hash the same data with different SHA1 applications,

what will the output be?

SHA1 is a deterministic algorithm. This indicates that hashing the identical input data with any
properly executed SHA1 application will yield the same 160-bit digest consistently. The SHA1
algorithm is precisely described, ensuring that all compliant implementations generate the
identical hash result for any given input.

What two things do HMAC provide?

Authenticity

HMAC guarantees that the message originates from an authentic sender. Utilizing

a shared secret key in the hashing process, HMAC verifies that only the sender,

who has the secret key, could have produced the HMAC for the specified message.

This mitigates impersonation and guarantees that the message is formally

acknowledged by the sender (Krishnamohan, 2020).

Integrity

HMAC ensures the integrity of the message during transmission. Any alteration to

the message—even a solitary bit—will yield a distinct HMAC value upon

recalculation by the recipient. Consequently, if the HMAC produced at the

recipient's end does not correspond with the sent HMAC, the recipient can deduce

that the message was altered during transmission (Schurman & Schurman, 2023).
What type of control is it when I change the firewall rules?

Firewall rules are a combination of technical and administrative controls that govern network

security and access management. Technical controls filter network traffic based on IP addresses,

ports, and protocols, while administrative controls establish policies and procedures for creating,

modifying, and managing rules (MEFMobile, 2025).

What is used to log into a system that works in

conjunction with a PIN

Two-Factor Authentication (2FA): This approach necessitates two distinct kinds of verification

for access. A PIN generally functions as the initial factor (something you know), whereas the

second factor may be something you possess (such as a smart card) or something intrinsic to you

(like a fingerprint). This security layer greatly improves defense against unwanted access.

Smart Cards: Distinct hardware devices such as Common Access Cards (CAC) or Personal

Identification Verification (PIV) cards are frequently utilized with PINs for user authentication.

The card must be inserted into a card reader, and the user must input their corresponding PIN to

obtain access. This method integrates an item possessed by the user (the card) with a piece of

knowledge (the PIN).


What is the name of the person who looks after classified

data and who is the person that gives people access to

the classified data?

A Data Custodian is tasked with the management and safeguarding of classified data. A Security

Officer is generally tasked with authorizing access to classified information.

The person responsible for overseeing and safeguarding classified information inside an

institution is typically known as a Data Custodian. The Data Custodian is tasked with adopting

security measures to protect data and ensuring the secure maintenance of confidential

information.

The responsibility of providing individuals access to classified data generally resides with a

Security Officer. The Security Officer ascertains access permission to specific data, contingent

upon the significance and security clearance of the personnel involved.

When you use a DAC model for access, who determines

who gains access to the data?

Discretionary Access Control (DAC) is a versatile access control framework that enables

resource proprietors to specify who may use their resources and the extent of that access (Access

Control Models: MAC, DAC, RBAC, & PAM Explained | Twingate, n.d.).
What is least privilege?

The principle of least privilege (PoLP) stipulates that people and systems must possess just the

essential access required to execute their functions, thereby mitigating potential risks and

bolstering overall security.

What access control method does SELinux utilize?

SELinux (Security-Enhanced Linux) employs Mandatory Access Control (MAC) to implement

security regulations on Linux systems, differentiating it from conventional discretionary access

techniques (Training, 2024).

What is the Linux permission of 777? What access does it

give you?

The Linux permission of 777 grants read, write, and execute permissions to all three user classes

which allows unrestricted access to everyone, but is not recommended due to security risks

(Bochis & Bochis, 2025).

What does the Linux permission execute allow me to do?

The execute permission in Linux enables the execution of a file as a program or script. It

ascertains the authorization to execute a file (What Does the “Execute” Permission Do?, n.d.).
The Sales Staff are allowed to log into the company

between 9 a.m. and 10 p.m. What type of access control

is being used?

With the use of Time-based access control allows the Sales Staff to log into the company

between 9 a.m and 10 p.m.

Two people from the finance team are only allowed to

authorize the payment of cheques; what type of access

control are they using?

The type of access control the finance team would be using to authorize the payment of cheques

is Role-Based Access Control (RBAC). This is because the RBAC is a security model that

restricts access to resources based on the roles assigned to users within an organization (8 Role-

Based Access Control (RBAC) Examples in Action — WorkOS, n.d.).

What is the purpose of the defense in depth model?

The defense in depth model in cybersecurity aims to implement layered security measures that

collectively safeguard an organization's data and systems against various threats, guaranteeing

that if one layer fails, subsequent layers continue to provide protection against attacks (What Is

Defense in Depth? Defined and Explained | Fortinet, n.d.).


When someone leaves the company what is the first

thing, we should do with their user account?

The first thing to do when an employee leaves the company is to immediately disable their

account to prevent unauthorized access.

Explain why a password would be salted

In cybersecurity, passwords are salted to substantially improve their security against attacks,

complicating the efforts of hackers to decipher them by precomputed hash databases or brute-

force techniques (Ricketts, 2024).


References

Staff, C. (2025, February 6). What is the CIA triad? Coursera.

[Link]

Cydni. (2015, October 16). Confidentiality - definition, examples, cases. Legal

Dictionary. [Link]

Howell, J. (2024, November 29). Data Center Physical Security: The Complete Guide

[2024]. ENCOR Advisors. [Link]

Shailaja, C. (2020, March 31). Physical security of a data center. [Link].

[Link]

center

Data center solutions. (n.d.). ASSA ABLOY DSS.

[Link]

Adcyber. (2023, June 17). What are the 3 types of security controls? Explained by an

expert - Cyber Insight. Cyber Insight. [Link]

controls/#:~:text=Some%20examples%20of%20physical%20control%20include%3A

%201%20Lock,to%20offices%2C%20data%20centres%20and%20information%20storage

%20rooms

Nelson, C. D., Clark-Ginsberg, A., Parks, V., Awan, J., Balagna, J., Fraade-Blanar, L., &

Hindmarch, G. (2024, March 26). Incident Management Measurement Toolkit. RAND.

[Link]
Hughes, J. (2022, January 8). 10 KEYS TO AN EFFECTIVE POST-INCIDENT

MANAGEMENT REVIEW & ANALYSIS. Jensen Hughes.

[Link]

review

Nelson, A. (2025). Incident Response Recommendations and Considerations for

cybersecurity Risk Management: [Link]

Matillion. (2023, June 15). 5 ways to measure data integrity. Matillion.

[Link]

Financial Crime Academy. (2025b, April 7). Risk control techniques: Preventive,

corrective, Directive, and Detective (PCDD). Financial Crime Academy.

[Link]

Hashing Working, Types, and Functions | Spiceworks. (2025, March 10). Spiceworks Inc.

[Link]

[Link]. (2022, August 22). What is hashing used for?

[Link]

Krishnamohan, T. (2020, April 20). What is HMAC and how does it work? The Armchair

Critic. [Link]

Schurman, K., & Schurman, K. (2023, October 8). What are message authentication

codes (MACs) and hash-based message authentication codes (HMACs)? Comparitech.

[Link]
MEFMobile. (2025, January 3). Firewall rules explained: From basics to best practices -

MEFMobile. MEFMobile. [Link]

practices/

Access control models: MAC, DAC, RBAC, & PAM Explained | Twingate. (n.d.).

[Link]

Training, I. O. I. (2024, February 28). SELinux for Enhanced Security: A Deep dive into

Mandatory Access Control - ITU Online IT Training. ITU Online IT Training.

[Link]

Bochis, N., & Bochis, N. (2025, January 31). Linux File Permissions – What is ChMOD

777 and how to use it. Help Desk Geek - Tech Tips from Trusted Tech Experts.

[Link]

8 Role-Based Access Control (RBAC) examples in action — WorkOS. (n.d.). WorkOS.

[Link]

What is Defense in Depth? Defined and Explained | Fortinet. (n.d.). Fortinet.

[Link]

Ricketts, N. (2024, October 11). What is Password Salting? A 4-Step Comprehensive

Guide. RickettsTech. [Link]

You might also like