0% found this document useful (0 votes)
25 views1 page

CSD in Cyber Security Course Overview

The document is an examination paper for a B.E. (Computer Engineering) course on Cyber Security & Digital Forensics. It contains four questions, from which students must answer one from each pair, covering topics such as threats to information systems, cybercrime, risk analysis, internet hacking, and data security. The exam is designed to assess students' understanding of various aspects of cyber security within a one-hour timeframe for a total of 30 marks.

Uploaded by

thontevijay
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views1 page

CSD in Cyber Security Course Overview

The document is an examination paper for a B.E. (Computer Engineering) course on Cyber Security & Digital Forensics. It contains four questions, from which students must answer one from each pair, covering topics such as threats to information systems, cybercrime, risk analysis, internet hacking, and data security. The exam is designed to assess students' understanding of various aspects of cyber security within a one-hour timeframe for a total of 30 marks.

Uploaded by

thontevijay
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Total No. of Questions : 4] SEAT No.

34
P5194 [Total No. of Pages : 1

ic-
[6188]-146

t
sta
B.E. (Computer Engineering) (Insem)

:41
CYBER SECURITY & DIGITAL FORENSICS

1
:33
(2019 Pattern) (Semester - VII) (Elective - III) (410244(C))

/20 52
13
1
23
Time : 1 Hour] [Max. Marks : 30
07 01
Instructions to the candidates:
.34 GP

1) Answer Q.1 or Q.2, Q.3 or Q.4.


/09

2) Neat diagrams must be drawn wherever necessary.


8.1 CE

3) Assume suitable data if necessary.

34
ic-
66

t
sta
Q1) a) What are different threats to information system? Explain any two in
details. [7]
.24

:41
49

1
b) List different types of cybercrime. Explain any two in detail.
:33 [8]
/20 52
13
OR
1
23
07 01

Q2) a) Elaborate the process of risk analysis in cyber security. [7]


.34 GP

b) Write short note on : [8]


/09

i) Cyber extortion
8.1 CE

-34
ii) Drug trafficking
66

tic
sta

Q3) a) What is mean by internet Hacking & Cracking? Explain types of cracking?
.24

:41

[7]
49

21
:33

b) What are different computer intrusion? Differentiate between virus &


13
15

Worms. [8]
23
01
/20

OR
GP
/09

Q4) a) Explain backups, archival storage & disposal of data in data security.[7]
07
CE

b) Describe firewall security technology with neat diagram. [8]


.34
66
8.1


.24
49

P.T.O.

Common questions

Powered by AI

Internet hacking refers to the unauthorized access to or manipulation of systems and networks for malicious purposes. Cracking, a subset of hacking, specifically involves breaking into systems to bypass security measures, often to access software or protected data. Types of cracking include software cracking, where copy protection is bypassed; password cracking, where user credentials are deciphered; and network cracking, which involves infiltrating networks to access sensitive information .

Viruses and worms are both malicious software that can result in computer intrusion, yet they operate differently. Viruses attach themselves to legitimate programs and require user action to propagate, often spreading through file sharing or email. In contrast, worms are standalone malware that can self-replicate and spread autonomously across networks, often exploiting vulnerabilities without requiring user interaction. This ability to spread independently makes worms potentially more widespread and damaging .

Backups provide a copy of data that can be restored in the event of data loss, ensuring continuity. Archival storage involves long-term data retention for reference or compliance purposes, often using less accessible storage methods to reduce costs. Data disposal is the process of permanently deleting data or physical media to prevent unauthorized access. Secure data disposal involves methods like shredding or digital wiping, essential for protecting sensitive information when no longer needed .

Risk analysis in cyber security involves identifying assets, assessing threats and vulnerabilities, calculating risk levels, and implementing measures to mitigate these risks. The process begins with inventorying essential assets and identifying potential threats such as hackers or insiders. Vulnerabilities are then assessed, often involving security audits. Risk levels are calculated by considering the likelihood and impact of potential incidents, leading to prioritization of risk mitigation efforts. Finally, strategies such as deploying security tools or establishing policies are implemented to reduce risks .

Cyber extortion involves threats to harm or disrupt systems unless a ransom is paid. This often manifests as ransomware attacks, where data is encrypted and decryption is withheld until a ransom is received. Prevention measures include regularly updating software, conducting employee training to recognize phishing attempts, maintaining secure backups, deploying advanced threat detection systems, and having an incident response plan ready to minimize impacts in case of an attack .

Firewall security technology works as a barrier between trusted internal networks and untrusted external networks, filtering incoming and outgoing traffic based on pre-established security rules. Key components include packet filtering, which inspects packets against rules; stateful inspection, maintaining context of active connections; and application-layer filtering, which enforces rules on specific applications or services. Diagrammatically, a firewall sits between the internet and internal network, controlling data flow to prevent unauthorized access .

Archival storage plays a crucial role in maintaining data integrity by preserving information for long-term access and ensuring compliance with legal or regulatory requirements. It involves using durable media and structured processes to prevent data corruption or loss. This continuity is vital for forensic investigations, historic reference, and ensuring information is consistently available over time, despite technological changes .

Information systems face numerous threats, including malware, phishing, denial of service (DoS) attacks, insider threats, and more. Malware, like viruses or ransomware, can disrupt operations or steal data by infecting systems. DoS attacks aim to make services unavailable by overwhelming them with traffic, potentially causing significant operational downtime and financial loss, as well as damage to reputation .

Cybercrime encompasses illegal activities conducted via computers or the internet, such as hacking, identity theft, cyberstalking, and phishing. Cyberstalking involves the use of the internet to harass an individual, often involving monitoring activities or sending threatening messages. Phishing is the fraudulent attempt to obtain sensitive information by disguising as a trustworthy entity, commonly through deceptive emails or websites .

Effective data disposal involves techniques that ensure data is unrecoverable. Strategies include physical destruction, such as shredding or incinerating media; overwriting data with random patterns multiple times; and degaussing, using magnetic fields to demagnetize storage media. These methods prevent data recovery and protect against unauthorized access to sensitive information once it is no longer needed .

You might also like