0% found this document useful (0 votes)
60 views2 pages

Cyber Security and Forensics Exam Paper

Uploaded by

sivagar23685
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
60 views2 pages

Cyber Security and Forensics Exam Paper

Uploaded by

sivagar23685
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Reg. No.

Question Paper Code 12619


B.E. / [Link]. - DEGREE EXAMINATIONS, APRIL / MAY 2024
Sixth Semester
Information Technology
20ITEL603 - CYBER SECURITY AND FORENSICS
Regulations - 2020
Duration: 3 Hours Max. Marks: 100
PART - A (10  2 = 20 Marks) Marks
K–
CO
Answer ALL Questions Level

1. Define cyberspace. 2 K2 CO1

2. Mention the advanced patterns created by the Identity management 2 K2 CO1


community.
3. What do you mean by GDPR? 2 K1 CO2

4. What is the need for cyber law? 2 K2 CO2

5. Differentiate static acquisition and live acquisition. 2 K2 CO3

6. What is need of evidence custody form? 2 K2 CO3

7. Mention the scenarios when the firewalls will be less effective. 2 K2 CO4

8. Mention the key concepts of vulnerability management. 2 K2 CO4

9. Mention few tools in an initial-response toolkit. 2 K1 CO5

10. How are digital incidents secured? 2 K2 CO5

PART - B (5  13 = 65 Marks)
Answer ALL Questions
11. a) Justify the statement – “Security considerations are essential for 13 K2 CO1
managing the web asset”.
OR
b) Discuss about the impact of GDPR in various domain. 13 K2 CO1

12. a) Discuss on the significance of data encryption in business. 13 K2 CO2


OR
b) Elaborate on cyber security threats in detail. 13 K2 CO2

13. a) Explain the process of data acquisition from RAID drives. 13 K2 CO3
OR
b) Explain the steps in conducting an investigation for the 13 K2 CO3
Montgomery_72018 case.

K1 – Remember; K2 – Understand; K3 – Apply; K4 – Analyze; K5 – Evaluate; K6 – Create 12619


1
14. a) i) Explain the process involved in ethical hacking. 6 K2 CO4
ii) Discuss about the various types of hackers. 7 K2 CO4
OR
b) What is an Intrusion Detection System? Explain the types with 13 K2 CO4
suitable example.

15. a) Discuss about collecting evidence in private-sector incident scenes. 13 K3 CO5


OR
b) Elaborate the tasks performed by the digital forensic tools. 13 K3 CO5

PART - C (1  15 = 15 Marks)
16. a) Explain the investigation of E-mail crimes with suitable example. 15 K2 CO6
OR
b) Explain the acquisition procedures for mobile devices in cyber 15 K2 CO6
forensics.

K1 – Remember; K2 – Understand; K3 – Apply; K4 – Analyze; K5 – Evaluate; K6 – Create 12619


2

Common questions

Powered by AI

Cyber laws are critical in securing cyberspace by establishing norms and regulations that entities must follow to protect data integrity, privacy, and security. These laws impact global digital interactions by creating a framework for international cooperation in cybercrime investigation, facilitating information sharing, and promoting cyber resilience across borders. They also enhance consumer trust by ensuring companies adhere to privacy standards like GDPR, which mandates data protection for individuals within the EU, affecting global companies operating online .

Vulnerability management contributes to cybersecurity resilience by systematically identifying, evaluating, mitigating, and reporting security flaws. It involves continuous assessment to discover vulnerabilities, prioritization based on potential impact, and implementing remediations to address these issues before they can be exploited by attackers. This proactive approach minimizes risk exposure and enhances the ability to respond to incidents swiftly, thereby maintaining the security posture over time .

The implications of GDPR on businesses worldwide include stringent compliance requirements such as obtaining explicit consent for data use, implementing effective privacy measures, and ensuring data security. Businesses must appoint Data Protection Officers and conduct regular impact assessments to safeguard personal data. Non-compliance can lead to significant penalties, up to 4% of annual global turnover, compelling businesses to reconsider their data policies and operational strategies internationally .

Digital forensic tools are effective in automating the collection, preservation, and analysis of digital evidence, providing detailed reports that can withstand legal scrutiny. They facilitate keyword searches, data carving, and timeline analysis critical in investigations. However, limitations include the tools' inability to process encrypted data without decryption keys, varying capabilities across platforms, and the potential for overlooking context or intentions behind data due to reliance on automated processes .

Data encryption supports business security by converting information into a secure format requiring a decryption key to access, thus protecting data from unauthorized access during storage and transmission. Encryption ensures data integrity and confidentiality, key elements for compliance with regulations such as GDPR. However, it presents challenges such as key management complexity, potential impact on performance, and needing robust policies to prevent insider threats who might misuse encryption keys .

Ethical hacking involves authorized attempts to penetrate computer systems using the same tools and techniques as malicious hackers but aims to identify and remediate vulnerabilities. Unlike malicious hacking, which seeks to exploit systems for nefarious purposes, ethical hacking improves security defenses by preemptively discovering vulnerabilities, thus enabling organizations to protect against future attacks .

Static data acquisition involves collecting data from a powered-off device to prevent any modification, useful for preserving system integrity. Live data acquisition occurs with the system running to capture ephemeral data such as active network connections and real-time processes. Static acquisition is ideal for ensuring data is not altered, while live acquisition is used when volatile data and the current state of the system are crucial for the investigation .

Data acquisition from mobile devices involves securing the device, disabling connectivity to prevent remote wiping, and using specialized tools to extract data while preserving integrity. Challenges include handling various operating systems, bypassing device security features like passwords and encryption, and dealing with diverse data formats. Additionally, the rapid evolution of mobile technology and legal hurdles in protecting user privacy during evidence collection complicate the process .

Investigating email crimes involves steps such as identifying the email headers to trace the origin, analyzing content for malicious links or attachments, and determining the intent behind the email. Challenges include dealing with spoofed email addresses, encrypted content, and anonymized routing disguising the sender's location. Additionally, legal and privacy considerations can complicate evidence collection across jurisdictions .

Firewalls may become ineffective due to factors such as the complexity of cyber threats that can bypass traditional signature-based detection, insufficient updates leading to outdated rules, and incorrect assumptions about network security perimeters. Advanced techniques like tunneling, spoofing, or exploiting open ports and vulnerabilities within allowed traffic can also render firewalls insufficient without comprehensive security layers .

You might also like