0% found this document useful (0 votes)
20 views9 pages

Information Security Fundamentals Guide

The document outlines the fundamentals of information security, covering key concepts, methods, and threats to information systems. It includes open and multiple-choice questions from lectures on topics such as information security principles, network security, computer crimes, and cryptographic methods. The content is structured to facilitate understanding and assessment of information security principles and practices.

Uploaded by

Krosmoss M
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views9 pages

Information Security Fundamentals Guide

The document outlines the fundamentals of information security, covering key concepts, methods, and threats to information systems. It includes open and multiple-choice questions from lectures on topics such as information security principles, network security, computer crimes, and cryptographic methods. The content is structured to facilitate understanding and assessment of information security principles and practices.

Uploaded by

Krosmoss M
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Subject: Fundamentals of Information Security

Group: 875i
Student:
Teacher: Ahmadli Davudova Shukufa

Respond to each question using your own explanations

Lecture 1. Main conceptual issues of information security

Open Questions
1. What is the origin and meaning of the term information, and in what forms can it exist?
2. Which three key questions does information security answer?
3. Explain the difference between information hazard and information threat.
4. Describe the three main categories of information threats.
5. What is meant by information environment and information system lifecycle?
6. Compare information warfare and information terrorism.
7. Explain the principles of Confidentiality, Integrity, and Availability with real-life
examples.

Multiple Choice Questions


1. The term information comes from the Latin word meaning:
a) Collection b) Connection c) Expression d) Generation

2. Information security protects data from:


a) Only natural effects
b) Only human interference
c) Both natural and artificial effects
d) Only external hackers

3. Threats to information confidentiality aim at:


a) Unauthorized disclosure of information
b) Data modification
c) System crash
d) Access restriction

4. Which of the following is NOT a type of information threat?


a) Physical b) Organizational c) Software-mathematical d) Psychological

5. Which principle ensures that data remains accurate and complete?


a) Availability b) Integrity c) Confidentiality d) Reliability
Lecture 2 – Methods and Means of Ensuring Information Security

Open Questions
1. What is a vulnerability? Compare adversarial and non-adversarial threat sources.
2. What is an insider threat and how can it be prevented?
3. What is the difference between social engineering and Advanced Persistent Threat
(APT)?
4. Describe the main types of malicious code (virus, worm, trojan, logic bomb,
ransomware).
5. What kinds of information threats exist in mobile devices?
6. What are smishing and vishing? Explain with examples.

Multiple Choice Questions


1. A vulnerability is:
a) A system update b) A data backup c) A weakness exploitable by a threat source
d) A firewall

2. Which of the following is an adversarial threat?


a) Insider sabotage b) Flood c) Fire d) Power failure

3. The purpose of social engineering is to:


a) Manipulate people into revealing confidential information
b) Encrypt files c) Back up data d) Block operating system access

4. Which malware spreads automatically without user action?


a) Trojan b) Logic Bomb c) Worm d) Spyware

5. Smishing refers to:


a) Phishing through SMS b) Phishing via voice calls c) Network flooding d) Social
media scam
Lecture 3 – Information Security in Computer Systems and Networks

Open Questions
1. What is a computer network? List and explain its main components.
2. Explain the differences between LAN, WAN, MAN, and Corporate Networks.
3. What hardware, software, and organizational measures ensure network security?
4. Define protocol and packet in the context of computer networks.
5. Describe common network security risks and give examples.
6. What is the Client–Server architecture?

Multiple Choice Questions


1. Which of the following is NOT a network component?
a) Computers b) Communication channels c) Projector d) Network operating
system

2. The main function of a repeater is to:


a) Amplify and extend signal transmission
b) Encrypt data c) Store data d) Convert analog to digital

3. A modem performs:
a) Amplification b) Routing c) Modulation and demodulation d) Data storage

4. The Internet is:


a) The largest global computer-information network
b) A local system c) A closed LAN d) A single main server

5. LANs mainly use:


a) Cables for communication b) Satellites c) Wi-Fi only d) Radio only
Lecture 4 – The Dangers of Violating Information Security in Computer Systems and Networks

Open Questions
1. What does it mean to violate the confidentiality, integrity, or availability of information?
2. Explain the importance of information security in modern digital systems.
3. Describe the three main pillars of information security and their significance.
4. What are the most common causes of cybersecurity incidents according to IBM
research?
5. Summarize the Colonial Pipeline Attack (2021) and its consequences.
6. Define computer crime (cybercrime) in your own words.
7. List and explain at least five types of computer crimes.
8. How does phishing differ from social engineering?
9. Explain the main effects and consequences of computer crimes on individuals,
organizations, and governments.
10. What are the main reasons behind the rapid growth of computer crimes?
11. How can users prevent computer crimes in their daily digital activities?
12. Define falsification of computer information and give real-world examples.
13. What are the main methods used by criminals to falsify computer information?
14. What are the possible consequences of falsifying digital information?
15. Define theft of computer information and describe its main elements.
16. What types of data are usually targeted in cyber information theft?
17. Explain the difference between internal and external threats.
18. What are intentional and unintentional threats? Give examples.
19. Describe the difference between natural and human-made threats.
20. Why is security awareness among people considered more important than technology
itself?

Multiple Choice Questions (MCQs)


1. Which of the following is not one of the CIA principles of information security?
a) Confidentiality b) Integrity c) Transparency d) Availability

2. Violating any of the CIA principles may lead to:


a) Faster system performance b) Loss of trust and security breaches c) Free access
d) None of the above

3. According to IBM, what percentage of cybersecurity incidents are caused by human


error?
a) 50% b) 60% c) 95% d) 30%

4. The Colonial Pipeline Attack (2021) was an example of:


a) Phishing b) Ransomware attack c) Insider threat d) DoS
5. The term cybercrime refers to:
a) Illegal activities involving computers or networks
b) Legal data analysis c) Programming d) Technical maintenance

6. Which of the following is not a computer crime?


a) Data theft b) Hacking c) Data backup d) Phishing

7. Phishing aims to:


a) Trick users into revealing confidential data
b) Strengthen encryption c) Protect passwords d) Increase bandwidth

8. Denial of Service (DoS) attacks cause:


a) Faster network performance b) System or network unavailability
c) Data encryption d) Better communication

9. Identity theft involves:


a) Using another person’s digital identity without consent
b) Installing antivirus c) Using backup systems d) Creating new accounts legally

10. Cyberterrorism refers to:


a) Using digital technologies to cause fear or instability
b) Online gaming c) Social networking d) Regular hacking

11. A main reason for the growth of computer crimes is:


a) Low awareness and easy access to hacking tools
b) Overly strict laws c) Lack of computers d) Too much encryption

12. Falsification of computer information means:


a) Intentionally changing or inserting false data in a system
b) Copying files c) Encrypting data d) Deleting temporary files

13. Insider manipulation occurs when:


a) Authorized users deliberately alter information
b) Software is updated c) Systems are backed up d) Users forget passwords

14. The main legal consequence of falsification of digital data is:


a) Reward b) Promotion c) Criminal liability d) Network speed increase

15. Theft of computer information primarily violates which principle?


a) Confidentiality b) Integrity c) Availability d) Reliability

16. Health data theft is dangerous because:


a) It includes sensitive personal and medical details
b) It has no value c) It cannot be misused d) It’s only for education
17. Internal threats originate from:
a) Employees or authorized users b) Hackers c) Competitors d) Natural disasters

18. External threats come from:


a) Employees b) Hackers and outsiders c) Administrators d) None

19. Intentional threats are:


a) Deliberate harmful actions b) Accidents c) Natural disasters d) Mistakes

20. The use of KMSPico software is dangerous because:


a) It can include malware and violate system integrity
b) It’s an official Microsoft tool c) It increases speed d) It prevents attacks
Lecture 5 – Cryptographic Methods of Information Protection

Open Questions
1. Define cryptography and explain its main purpose in information security.
2. What is the difference between encryption and decryption?
3. List and briefly describe the four main goals of cryptography: confidentiality, integrity,
authentication, and non-repudiation.
4. Explain how cryptography ensures data confidentiality in three states: at rest, in transit,
and in use.
5. Describe the challenge–response authentication process between Alice and Bob.
6. Why can non-repudiation only be guaranteed by asymmetric cryptography?
7. What are the main differences between symmetric and asymmetric encryption
methods?
8. Explain what a cryptographic key is and how it is used.
9. Describe how hash functions work and give examples (e.g., SHA-256, MD5).
10. What is the role of digital signatures in maintaining data integrity?
11. Compare the Data Encryption Standard (DES) and Advanced Encryption Standard (AES)
algorithms.
12. What is the RSA algorithm, and how does it use public and private keys?
13. Explain the step-by-step process of encrypting and decrypting a message using RSA.
14. What is the difference between substitution and transposition ciphers? Give an example
of each.
15. Describe how the Caesar cipher works.
16. What is a Vigenère cipher, and why was it historically considered secure?
17. Explain the ROT13 cipher and how it is related to the Caesar cipher.
18. Identify at least four modern applications of cryptography in today’s digital world.
19. What is the function of SSL/TLS in secure web communication?
20. How is cryptography used in digital currencies like Bitcoin?

Multiple-Choice Questions (MCQs)


1. The word cryptography originates from Greek meaning:
a) “Secret communication” b) “Hidden writing” c) “Public message” d) “Data
encryption”

2. What is the main goal of cryptography?


a) Increase system speed b) Protect information from unauthorized access
c) Compress files d) Delete data

3. In cryptography, plain text refers to:


a) Readable data before encryption b) Encrypted message c) Secret key d) Hash
output
4. The process of converting ciphertext back to plaintext is called:
a) Encoding b) Decryption c) Hashing d) Transmission

5. Which of the following is not a cryptographic goal?


a) Confidentiality b) Integrity c) Interoperability d) Authentication

6. Which algorithm is used for both encryption and decryption with the same key?
a) Symmetric key encryption b) Asymmetric encryption c) Hashing d) Encoding

7. Which cryptographic algorithm is asymmetric?


a) DES b) AES c) RSA d) SHA-256

8. The main disadvantage of symmetric encryption is:


a) Key exchange problem b) Slow processing c) Weak algorithm
d) Expensive hardware

9. Which of the following is a hash function?


a) AES b) DES c) SHA-256 d) RSA

10. Hash functions are one-way because:


a) Original data cannot be derived from the hash value b) They use long keys c) They
are reversible d) They encrypt files

11. Which of the following provides non-repudiation?


a) Asymmetric encryption b) Symmetric encryption c) Hashing d) Encoding

12. The Caesar cipher shifts letters by a fixed number of positions, typically:
a) 3 b) 5 c) 10 d) 13

13. The Vigenère cipher is a type of:


a) Polyalphabetic substitution cipher b) Transposition cipher c) Hash function d)
Symmetric block cipher

14. The ROT13 cipher replaces each letter with the one:
a) 13 positions later in the alphabet b) 10 positions earlier c) Randomly chosen d)
26 positions later

15. Which algorithm replaced the older DES standard?


a) AES b) RSA c) MD5 d) SHA-1

16. In RSA, which key is used for encryption?


a) Public key b) Private key c) Secret key d) Hash key
17. What is the block size of AES?
a) 64 bits b) 128 bits c) 192 bits d) 256 bits

18. Digital signatures ensure:


a) Encryption only b) Data integrity and authentication c) Speed of data transfer d)
File compression

19. SSL/TLS protocols primarily use:


a) Public key cryptography b) Hashing c) Steganography d) Encoding

20. Cryptography in cryptocurrencies is mainly used to:


a) Secure transactions and prevent fraud b) Display data publicly c) Mine faster d)
Store data offline

You might also like