0,1,2,3,4,5,curie_correct,curie_choiceA_probs,curie_choiceB_probs,curie_choiceC_probs,curie_choiceD_probs
Which of the following styles of fuzzer is more likely to explore paths covering every line of code in the following program?,Generational,Blackbox,Whitebox,Mutation-based,C,False,0.13151152941354116,0.07225360954524652,0.10660096651414772,0.6896338945270646
"Assume that a TLS connection has been established successfully between a client and a server. Establishing the session included checking the server certificate and executing a DiffieHelmann exchange, but the client did not provide a client certificate. Further, assume that the client and server are honest, that the client and server don’t leak their keys, and that the cryptography is good. Which of the following attacks does TLS protect against?
1. An attacker replaying bytes that a client sent earlier.
2. An attacker impersonating the server.","True, True","False, False","True, False","False, True",A,False,0.25118873261272906,0.09597103010766503,0.2275779033019752,0.4252623339776307
MIT’s Kerberos KDC server has a maximum ticket lifetime of 24 hours (for most user principals). What ensures that an expired Kerberos ticket can no longer be used?,The Kerberos server (KDC) refuses to establish new connections between clients and servers for expired tickets.,"When a client connects to a server, the server sets a 24-hour timer to terminate the connection, which ensures a client cannot remain connected past the ticket’s maximum lifetime.","When a client connects to a server, the server compares the ticket’s expiration time to the server’s current clock, and refuses to authenticate the user if the ticket expiration time is in the past.","When a client connects to a server, the server sends a query to the KDC to check if the ticket is still valid with respect to the KDC’s clock, and refuses to authenticate the user if the KDC reports that the ticket is expired.",C,False,0.6411927302237348,0.029194285989334746,0.11243678819327539,0.2171761955936551
"In Message Condentiality, the transmitted message must make sense to only intended",Receiver,Sender,Modulor,Translator,A,False,0.1803565260312103,0.04982294741042468,0.14577412264058248,0.6240464039177827
Which of the following is a remote Trojan?,Troya,DaCryptic,BankerA,Game-Troj,A,False,0.15820207046117044,0.06746627288580945,0.1271176012961965,0.6472140553568235
______________ is a widespread app’s coding mistake made by developers which could be exploited by an attacker for gaining access or malfunctioning your system.,Memory leakage,Buffer-overrun,Less processing power,Inefficient programming,B,False,0.13304183548226603,0.03792306743230362,0.2600932989877594,0.568941798097671
"Consider the paper Native Client: A Sandbox for Portable, Untrusted x86 Native Code by Yee et al. Ben Bitdiddle notes that NaCl uses Intel x86 segmentation to ensure that the sandboxed module does not read or write memory outside its own data area, and does not execute instructions outside its own code. Ben thinks that with these restrictions alone, executing the sandboxed module must be safe; that is, he thinks validation is not needed. Ben is wrong. Circle the types of x86 machine instructions that the validator always forbids in sandboxed code. Please ignore trampoline and springboard code.",all instructions that modify segment state,all loads or stores to addresses that are not 0 mod 32,all indirect loads or stores (via an address in a register or variable),all indirect jumps (via an address in a register or variable),A,False,0.2525024109766104,0.05288479645602117,0.3476304922100823,0.3469823003572861
____________ is also a part of darknet that is employed for transferring files anonymously.,Freenet,ARPANET,Stuxnet,Internet,A,False,0.11664413985405021,0.045700549386323855,0.10753911924093978,0.7301161915186861
"Why apps developed in languages like C, C++ is prone to Buffer-overflow?",No string boundary checks in predefined functions,No storage check in the external memory,No processing power check,No database check,A,False,0.1149590309154342,0.029715438448875316,0.39282199032960535,0.46250354030608504
Man in the middle attack can endanger the security of Diffie Hellman method if two parties are not,Joined,Authenticated,Submitted,Shared,B,False,0.0790082795623073,0.03463945810080296,0.10464600847153493,0.7817062538653549
An integer overflow occurs when,"an integer expression's result ""wraps around""; instead of creating a very large number, a very small (or negative) number ends up getting created",an integer is used as if it was a pointer,an integer is used to access a buffer outside of the buffer's bounds,there is no more space to hold integers in the program,D,True,0.18166507217916494,0.02548134432481411,0.20549180473822662,0.5873617787577944
"Let HH be a Merkle-Damgard hash function is H:X^{\leq L} \to TH:X^≤L  →T. Construct a MAC from this HH as follows: \ \ S(k,m) = H(k \| m)  S(k,m)=H(k∥m). This mac is insecure because:",Given H(k \| m)H(k∥m) anyone can compute H(w \| k \| m \| \text{PB})H(w∥k∥m∥PB) for any ww,Given H(k \| m)H(k∥m) anyone can compute H(k \| m \| w)H(k∥m∥w) for any ww,Given H(k \| m)H(k∥m) anyone can compute H(k \| m \| \text{PB} \| w)H(k∥m∥PB∥w) for any ww,Anyone can compute H( k \| m )H(k∥m) for any mm,C,False,0.23323376321811146,0.16229050511946297,0.047032584354521255,0.5574431473079045
"Suppose that Alice and Bob sent confidential text messages to one another last month through an encrypted messaging system. Alice and Bob are worried that an adversary might compromise one of their computers today, while they are taking the 6.858 final exam, and would then be able to decrypt those messages. Which of the following security properties can address Alice and Bob’s concern?",Authentication.,Deniability.,Forward secrecy,Backward secrecy.,C,False,0.1933412208761538,0.08307330189910488,0.23129831458675018,0.49228716263799116
"The AH Protocol provides source authentication and data integrity, but not",Integrity,Privacy,Nonrepudiation,Both A & C,B,False,0.2500506257285111,0.08516286717161409,0.1717946812935994,0.49299182580627554
Which of the following is not a security exploit?,Eavesdropping,Cross-site scripting,Authentication,SQL Injection,C,False,0.11615630779440941,0.053657577219954164,0.17231661111379187,0.6578695038718445
_______________ is the central node of 802.11 wireless operations.,WPA,Access Point,WAP,Access Port,B,False,0.11365230389271447,0.047928118375096376,0.10871069735403548,0.7297088803781537
In MD-5 the length of the message digest is,160,128,64,54,B,False,0.2963780555937078,0.0640165285902856,0.14127685974491405,0.4983285560710925
What is Nmap?,"It is a scanner which works by injecting packets to a range of addresses, and inferring what hosts and services might be at those addresses, based on the responses",It is a network fuzz testing tool,It is a map of the Internet,"It is a suite of tools for scripting attacks: probe, construct, encode, inject, wait for response",A,False,0.238967247560286,0.028575782801537806,0.18617178556766334,0.5462851840705129
How do you prevent SQL injection?,Escape queries,Interrupt requests,Merge tables,All of the above,A,False,0.24728045600173393,0.044513940771667614,0.14198117779749259,0.5662244254291059
"What does it mean to ""be stealthy"" during a penetration test?",Performing the tests from an undisclosed location,Using encryption during tests to make the source of attacks impossible to determine,Performing penetration testing without the target organization knowing,"Taking care to avoid activities during a penetration test that might attract attention, e.g., by operators or IDS services",D,True,0.1295688507147139,0.02780961011262714,0.24577836798113314,0.5968431711915259
Which of the following is not a transport layer vulnerability?,"Mishandling of undefined, poorly defined variables",The Vulnerability that allows “fingerprinting” & other enumeration of host information,Overloading of transport-layer mechanisms,Unauthorized network access,D,True,0.13136425196821971,0.029717681640861894,0.150686863722267,0.6882312026686513
"In Brumley and Boneh’s paper on side-channel attacks, why does blinding prevent the timing attack from working?","Blinding prevents the server from using the CRT optimization, which is essential to the timing attack.","Blinding changes the p and q primes that are used, so an adversary cannot learn the server’s true p and q values.","Blinding randomizes the ciphertext being decrypted, thus obscuring the correlation between an adversary’s input and the timing differences.","Blinding adds a random amount of time to the decryption due to the multiplication and division by the blinding random value r, which obscures the timing differences used in the attack.",C,False,0.4134598646700689,0.07289736421574981,0.16565789511289833,0.347984876001283
"The openSSL implementation described in “Remote Timing Attacks are Practical” (by Brumley and Boneh) uses the following performance optimizations: Chinese Remainder (CR), Montgomery Representation (MR), Karatsuba Multiplication (KM), and Repeated squaring and Sliding windows (RS). Which of the following options would close the timing channel attack described in the paper if you turned the listed optimizations off?
1. RS and KM
2. RS and MR","True, True","False, False","True, False","False, True",D,True,0.20174022133097758,0.21428756122778161,0.2495608220868148,0.33441139535442604
Public key encryption is advantageous over Symmetric key Cryptography because of,Speed,Space,Key exchange,Key length,C,False,0.1712181158570829,0.036021865663345254,0.16881426714926379,0.623945751330308
The __________ was a huge marketplace of Dark Web specifically famous for selling of illegal drugs & narcotics as well as you can find a wide range of other goods for sale.,Silk Road,Cotton Road,Dark Road,Drug Road,A,False,0.09405894444021096,0.0451156449354339,0.13456409996548044,0.7262613106588748
The ______________ is categorized as an unknown segment of the Deep Web which has been purposely kept hidden & is inaccessible using standard web browsers.,Haunted web,World Wide Web,Dark web,Surface web,C,False,0.06539562480571477,0.024854067662695427,0.11221634010307667,0.7975339674285131
What does EXE do when the STP solver times out on a constraint query for a particular path?,Assume that the query is satisfiable and continue executing the path.,Assume that the query is not satisfiable and stop executing the path,"Restart STP and retry the query, up to a limited number of retries.",Remove a subset of the constraints and retry the query.,B,False,0.1322834203422678,0.06315527810243547,0.13171593298238912,0.6728453685729077
To verify a digital signature we need the,Sender’s Private key,Sender’s Public key,Receiver’s Private key,Receiver’s Public key,B,False,0.09593403541324656,0.0672097437865008,0.24058889560647567,0.596267325193777
Suppose you want to use fuzzing on a program to try to find memory errors; which of the following statements is true?,"You should not use a grammar-based fuzzer, because its adherence to the grammar means it will not find memory errors",Compiling the program with address sanitizer (ASAN) will make errors harder to reproduce,Compiling the program with address sanitizer (ASAN) will make the source of a memory error easier to find,"Fuzzing doesn't find memory errors, it finds crashes and hangs",C,True,0.23255340541545141,0.028942276215828636,0.3957651529847031,0.3427391653840169
"Based on the paper “SoK: SSL and HTTPS: Revisiting past challenges and evaluating certificates trust model enhancements”, which of the following statements are false?",Valid DV certificates provide more confidence to a user that she is connecting to the intended party than valid EV certificates.,OCSP stapling allows a server to prove to a browser that its certificate hasn’t been revoked.,DANE makes it difficult for an adversary to launch a SSL stripping attack.,Server key-pinning makes it harder for an adversary to convince a CA to mint a certificate for a site and launch an MITM attack on that site.,A,False,0.14999755844369886,0.024416681751589238,0.22222962016146214,0.6033561396432499
What tool can be used to perform SNMP enumeration?,DNSlookup,Whois,Nslookup,IP Network Browser,D,True,0.13782869200807324,0.06266036793027868,0.18373890364362705,0.615772036418021
Which among them has the strongest wireless security?,WEP,WPA,WPA2,WPA3,D,True,0.126412562755411,0.09306395472458619,0.14542561172156349,0.6350978707984393
"Suppose Unix did not provide a way of passing file descriptors between processes, but still allowed inheriting file descriptors from a parent on fork and exec. What aspects of the OKWS design would break without file descriptor passing?
1. It would be impossible for services to get a TCP connection to the client web browser.
2. It would be impossible for okd to run as a non-root user.","True, True","False, False","True, False","False, True",C,False,0.17473555335582108,0.10275083178919571,0.28860004998160776,0.4339135648733754
Failed sessions allow brute-force attacks on access credentials. This type of attacks are done in which layer of the OSI model?,Physical layer,Data-link Layer,Session layer,Presentation layer,C,False,0.07347041741066451,0.027394859822037404,0.15211901122832897,0.7470157115389691
Which of the following is an authentication method?,Secret question,Biometric,SMS code,All of the above,D,True,0.35748968690890887,0.08282081135102023,0.12818831049143817,0.4315011912486326
"When does a buffer overflow occur, generally speaking?",when writing to a pointer that has been freed,when copying a buffer from the stack to the heap,when a pointer is used to access memory not allocated to it,"when the program notices a buffer has filled up, and so starts to reject requests",C,False,0.09847753482897494,0.018609064344854157,0.20134873613066867,0.6815646646955021
A digital signature needs a,Private-key system,Shared-key system,Public-key system,All of them,C,False,0.2421225397059301,0.06716322462887825,0.1527642005274985,0.5379500351376931
A packet filter firewall filters at the,Application or transport,Data link layer,Physical Layer,Network or transport layer,D,True,0.1258854302976279,0.0575358080993709,0.1993776144576742,0.617201147145327
"Let I = (S,V)I=(S,V) be a MAC. Suppose S(k,m)S(k,m) is always 5 bits long. Can this MAC be secure?","No, an attacker can simply guess the tag for messages",It depends on the details of the MAC,"Yes, the attacker cannot generate a valid tag for any message","Yes, the PRG is pseudorandom",A,False,0.25797230270576404,0.07074227110560734,0.2801705316640615,0.3911148945245672
Which of the following deals with network intrusion detection and real-time traffic analysis?,John the Ripper,L0phtCrack,Snort,Nessus,C,False,0.0829454633999801,0.038324177694136555,0.1527531006204535,0.7259772582854299
The Message condentiality or privacy means that the sender and the receiver expect,Integrity,Condentiality,Authentication,Nonrepudiation,B,False,0.193350304100232,0.061901751478234276,0.15411305551670118,0.5906348889048325
"When a wireless user authenticates to any AP, both of them go in the course of four-step authentication progression which is called _____________",AP-handshaking,4-way handshake,4-way connection,wireless handshaking,B,False,0.21646680004596963,0.040199589679948425,0.198516111308804,0.5448174989652779
Message authentication is a service beyond,Message Condentiality,Message Integrity,Message Splashing,Message Sending,B,False,0.12736426120098204,0.03504916408112631,0.17832531978596752,0.6592612549319242
Which of the following are most vulnerable to injection attacks?,Session IDs,Registry keys,Network communications,SQL queries based on user input,D,True,0.09896423464563338,0.036667823694748095,0.16994659262540562,0.694421349034213
"Assume that a TLS connection has been established successfully between a client and a server. Establishing the session included checking the server certificate and executing a DiffieHelmann exchange, but the client did not provide a client certificate. Further, assume that the client and server are honest, that the client and server don’t leak their keys, and that the cryptography is good. Which of the following attacks does TLS protect against?
1. An attacker replacing bytes sent by a client with bytes of the attacker’s own choosing.
2. An attacker reading the plaintext bytes sent by a client.","True, True","False, False","True, False","False, True",A,False,0.23734383069599976,0.10112280229984266,0.22246942989082488,0.4390639371133327
Which of the following is a Wireless traffic Sniffing tool?,Maltego,BurpSuit,Nessus,Wireshark,D,True,0.16004433167860105,0.05652306855850391,0.10225522322044643,0.6811773765424487
A ___________ is a method in which a computer security mechanism is bypassed untraceable for accessing the computer or its information.,front-door,backdoor,clickjacking,key-logging,B,False,0.21791145094584352,0.03866140048269002,0.14501669562158107,0.5984104529498853
Which of the following is not a block cipher operating mode?,ECB,CFB,CBF,CBC,C,False,0.0892361383122572,0.09602196049461804,0.2695219789029901,0.5452199222901346
What is a web proxy?,A piece of software that intercepts and possibly modifies requests (and responses) between a web browser and web server,An agent that makes decisions on the client's behalf when interacting with web applications,"A piece of software that makes a web application look like a standalone application, making it easier to test","A simulator for the web, for use when off-line",A,False,0.23075622736083654,0.026806368819271714,0.12906839516659002,0.6133690086533018
Buffer-overflow may remain as a bug in apps if __________ are not done fully.,boundary hacks,memory checks,boundary checks,buffer checks,C,False,0.1032632658683676,0.028842777365314844,0.3814866562846706,0.4864073004816468
Applications developed by programming languages like ____ and ______ have this common buffer-overflow error.,"C, Ruby","Python, Ruby","C, C++","Tcl, C#",C,True,0.08851604559157346,0.03622330104803779,0.4845866136678783,0.39067403969251047
"Encryption and decryption provide secrecy, or condentiality, but not",Authentication,Integrity,Privacy,All of the above,B,False,0.23511760716066102,0.07268351963494733,0.16757681065877134,0.5246220625456204
A/an ___________ is a program that steals your logins & passwords for instant messaging applications.,IM – Trojans,Backdoor Trojans,Trojan-Downloader,Ransom Trojan,A,True,0.4600502484173027,0.04313785607896566,0.07259543780326266,0.4242164577004692
The sub key length at each round of DES is__________,32,56,48,64,B,False,0.17408005410383073,0.056199542885693045,0.1686144703812062,0.6011059326292701
Which of the following is true of mutation-based fuzzing?,It generates each different input by modifying a prior input,It works by making small mutations to the target program to induce faults,Each input is mutation that follows a given grammar,"It only makes sense for file-based fuzzing, not network-based fuzzing",A,False,0.16725940902635106,0.03155694491188434,0.1881306858661258,0.6130529601956388
What are the types of scanning?,"Port, network, and services","Network, vulnerability, and port ","Passive, active, and interactive","Server, client, and network",B,False,0.25742305194390136,0.035426013262589574,0.21580989642818102,0.49134103836532794
"A sender must not be able to deny sending a message that was sent, is known as",Message Nonrepudiation,Message Integrity,Message Condentiality,Message Sending,A,False,0.16451282450632015,0.047305510757306345,0.17761294604012612,0.6105687186962474
A proxy rewall lters at the,Physical layer,Application layer,Data link layer,Network layer,B,False,0.12210242824256018,0.05565308632215928,0.18279435519490153,0.639450130240379
Encapsulating Security Payload (ESP) belongs to which Internet Security Protocol?,Secure Socket Layer Protocol,Secure IP Protocol,Secure Http Protocol,Transport Layer Security Protocol,B,False,0.061454650345138175,0.050294480670650565,0.22377556404987212,0.6644753049343392
A special tool is necessary for entering the network which is _______________ that helps the anonymous internet users to access into the Tor’s network and use various Tor services.,Opera browser,Firefox,Chrome,Tor browser,D,True,0.12011041937338707,0.06805065659358824,0.11459606388655226,0.6972428601464725
How does a buffer overflow on the stack facilitate running attacker-injected code?,By overwriting the return address to point to the location of that code,By writing directly to the instruction pointer register the address of the code,By writing directly to %eax the address of the code,"By changing the name of the running executable, stored on the stack",A,False,0.0843443960756265,0.03100410706132704,0.27059535268692614,0.6140561441761203
The digest created by a hash function is normally called a,Modication detection code (MDC),Modify authentication connection,Message authentication control,Message authentication cipher,A,False,0.14924554439953197,0.05133634154591294,0.1179069914900368,0.6815111225645183
"Let F: K \times R \to MF:K×R→M be a secure PRF. For m \in Mm∈M define E(k,m) = \big[ r \gets R,\ \text{output } \big(r,\ F(k,r) \oplus m\big)\ \big]E(k,m)=[r←R, output (r, F(k,r)⊕m) ] Is EE symantically secure under CPA?","Yes, whenever F is a secure PRF","No, there is always a CPA attack on this system","Yes, but only if R is large enough so r never repeats (w.h.p)",It depends on what F is used,C,True,0.20241045115886075,0.04164788196485873,0.5454054650248595,0.2105362018514211
Old operating systems like _______ and NT-based systems have buffer-overflow attack a common vulnerability.,Windows 7,Chrome,IOS12,UNIX,D,True,0.14497754826516504,0.051851827784185255,0.23081625447292783,0.5723543694777219
What is a replay attack?,When the attacker replies to a message sent to it by the system,"An attack that continuously repeats, probing for a weakness",An attack that uses the system's own messages and so cannot be defended against,"The attacker resends a captured message, and the site accept its and responds in the attacker's favor",D,True,0.18334061529634177,0.025497168027586947,0.20399592365196076,0.5871662930241105
Statement 1| A U2F USB dongle prevents malware on the user’s computer from stealing the user’s second factor to authenticate as that user even when the user’s computer is turned off. Statement 2| A server using U2F can reliably determine that the user who is attempting to login is indeed behind the computer that sent the login request.,"True, True","False, False","True, False","False, True",C,False,0.2797580918534235,0.09600767763330531,0.20665065821419026,0.417583572299081
____________________ is the anticipation of unauthorized access or break to computers or data by means of wireless networks.,Wireless access,Wireless security,Wired Security,Wired device apps,B,False,0.12018547572983203,0.018139341021212153,0.06395542410603565,0.7977197591429201
Which of the following are benefits of penetration testing?,Results are often reproducible,Full evidence of security: a clean test means a secure system,Compositionality of security properties means tested components are secure even if others change,Makes an adversarial neural network converge more quickly,A,True,0.36366129841532807,0.022532283289960285,0.28051442713449154,0.33329199116022007
1. _________ framework made cracking of vulnerabilities easy like point and click.,.Net,Metasploit,Zeus,Ettercap,B,False,0.1376881056397725,0.06426816272842392,0.234545052935263,0.5634986786965406
You are given a message (m) and its OTP encryption (c). Can you compute the OTP key from m and c ?,"No, I cannot compute the key.","Yes, the key is k = m xor c.",I can only compute half the bits of the key.,"Yes, the key is k = m xor m.",B,False,0.23455343167392811,0.0695104335936986,0.23061947269559518,0.46531666203677813
"The openSSL implementation described in “Remote Timing Attacks are Practical” (by Brumley and Boneh) uses the following performance optimizations: Chinese Remainder (CR), Montgomery Representation (MR), Karatsuba Multiplication (KM), and Repeated squaring and Sliding windows (RS). Which of the following options would close the timing channel attack described in the paper if you turned the listed optimizations off?
1. CR and MR
2. CR","True, True","False, False","True, False","False, True",A,False,0.15505105618483794,0.16961601929121023,0.40763533799633467,0.26769758652761716
"When the data must arrive at the receiver exactly as they were sent, its called",Message Condentiality,Message Integrity,Message Splashing,Message Sending,B,False,0.18794036128688682,0.04152280158099453,0.18520121250692353,0.5853356246251952
What is the difference between a direct leak and a side channel?,"A direct leak creates a denial of service by failing to free memory, while a channel frees memory as a side effect","A direct leak is one that is intentional, rather than by unintentional","A direct leak comes via the software system's intended interaction mechanism, where as a side channel leak comes from measurements of other system features, like timing, power usage, or space usage",There is no difference,C,False,0.4505376478707335,0.013561364430491454,0.11469589745188563,0.4212050902468894
A session symmetric key between two parties is used,Only once,Twice,Multiple times,Conditions dependant,A,False,0.1781569140255512,0.028939915676154015,0.23019582085011206,0.5627073494481827
What is a nop sled,It is an anonymous version of a mop sled,"It is a sequence of nops preceding injected shellcode, useful when the return address is unknown",It is a method of removing zero bytes from shellcode,It is another name for a branch instruction at the end of sequence of nops,B,False,0.24549847705956776,0.027587042465635973,0.18344827537834865,0.5434662050964476
Which Nmap scan is does not completely open a TCP connection?,SYN stealth scan,TCP connect,XMAS tree scan,ACK scan,A,False,0.19248626538962768,0.06906420837920654,0.2716140957028894,0.4668354305282763
"Based on the paper “Click Trajectories: End-to-End Analysis of the Spam Value Chain”, which of the following statements are true? “Spammers” here refer to operators of various parts of the “spam value chain.”",Spammers run their spam-advertised web sites on compromised user machines that are part of a botnet.,Spammers need to register domain names in order for their spam-based advertisements to be effective.,There is a high cost for spammers to switch acquiring banks.,B and C,D,True,0.23055608890091553,0.14834985048127014,0.2411750106353112,0.3799190499825031
"In a _____________ attack, the extra data that holds some specific instructions in the memory for actions is projected by a cyber-criminal or penetration tester to crack the system.",Phishing,MiTM,Buffer-overflow,Clickjacking,C,False,0.3658659785310678,0.07137922851416276,0.17534731410286064,0.3874074788519088
_______________ is a popular tool used for network analysis in multiprotocol diverse network.,Snort,SuperScan,Burp Suit,EtterPeak,D,True,0.11817435179110669,0.05509166743997473,0.08065495133097118,0.7460790294379475
"___________________ is alike as that of Access Point (AP) from 802.11, & the mobile operators uses it for offering signal coverage.",Base Signal Station,Base Transmitter Station,Base Transceiver Station,Transceiver Station,C,False,0.08448048352125358,0.04513564651231973,0.187094545466801,0.6832893244996258
A __________ is a sequential segment of the memory location that is allocated for containing some data such as a character string or an array of integers.,stack,queue,external storage,buffer,D,True,0.1148206051928501,0.04517668580400279,0.20782048121140112,0.632182227791746
Which form of encryption does WPA use?,Shared key,LEAP,TKIP,AES,C,False,0.0886751249459798,0.0710776360156025,0.14686070715297042,0.6933865318854472
"Let suppose a search box of an application can take at most 200 words, and you’ve inserted more than that and pressed the search button; the system crashes. Usually this is because of limited __________",buffer,external storage,processing power,local storage,A,False,0.13521042126075397,0.04104271938363469,0.18492797674611744,0.6388188826094939
___________________ began to show up few years back on wireless access points as a new way of adding or connecting new devices.,WPA2,WPA,WPS,WEP,C,False,0.14694886987289768,0.05812392108561622,0.10823762991449179,0.6866895791269942
What are the port states determined by Nmap?,"Active, inactive, standby","Open, half-open, closed ","Open, filtered, unfiltered","Active, closed, unused",C,False,0.1742496313719111,0.06968087571056292,0.16800836209609954,0.5880611308214264
Which among the following is the least strong security encryption standard?,WEP,WPA,WPA2,WPA3,A,False,0.11963353482606763,0.10303942043142164,0.13717543617103553,0.6401516085714752
Why is it that the compiler does not know the absolute address of a local variable?,Programs are not allowed to reference memory using absolute addresses,The size of the address depends on the architecture the program will run on,"As a stack-allocated variable, it could have different addresses depending on when its containing function is called",Compiler writers are not very good at that sort of thing,C,True,0.1394335161691722,0.008201647053288965,0.5404109946265091,0.31195384215102984
The stack is memory for storing,Local variables,Program code,Dynamically linked libraries,Global variables,A,False,0.09078370395884916,0.02862529272088299,0.28911872529492033,0.5914722780253475
Can a stream cipher have perfect secrecy?,"Yes, if the PRG is really “secure”","No, there are no ciphers with perfect secrecy","Yes, every cipher has perfect secrecy","No, since the key is shorter than the message",D,True,0.10512821625453006,0.03576224164241183,0.2534809296603589,0.6056286124426993
Which of the following does authorization aim to accomplish?,Restrict what operations/data the user can access,Determine if the user is an attacker,Flag the user if he/she misbehaves,Determine who the user is,A,False,0.18561068124077773,0.05164560181055585,0.26648400769866515,0.49625970925000135
The message must be encrypted at the sender site and decrypted at the,Sender Site,Site,Receiver site,Conferencing,C,False,0.1917111782324432,0.05082001627644747,0.17213583258505352,0.5853329729060558
"A _________________ may be a hidden part of a program, a separate infected program a Trojan in disguise of an executable or code in the firmware of any system’s hardware.",crypter,virus,backdoor,key-logger,C,False,0.2056063303497068,0.034310558854855164,0.14691303453759572,0.6131700762578423
How is IP address spoofing detected?,Installing and configuring a IDS that can read the IP header,Comparing the TTL values of the actual and spoofed addresses,Implementing a firewall to the network,Identify all TCP sessions that are initiated but does not complete successfully,B,False,0.16370071889157936,0.022949174275412567,0.19019429789425854,0.6231558089387494
Which of the following is not an example of presentation layer issues?,Poor handling of unexpected input can lead to the execution of arbitrary instructions,Unintentional or ill-directed use of superficially supplied input,Cryptographic flaws in the system may get exploited to evade privacy,Weak or non-existent authentication mechanisms,D,True,0.18228497584430073,0.05515603990218916,0.31295204570434243,0.4496069385491677
"Suppose Unix did not provide a way of passing file descriptors between processes, but still allowed inheriting file descriptors from a parent on fork and exec. What aspects of the OKWS design would break without file descriptor passing?
1. It would be impossible for services to send messages to oklogd.
2. It would be impossible for services to get a TCP connection to a database proxy.","True, True","False, False","True, False","False, True",B,False,0.15417111882668638,0.09531072609032694,0.27391996947645014,0.4765981856065366
Why would a ping sweep be used?,To identify live systems,To locate live systems,To identify open ports,To locate firewalls,A,False,0.12295857526263429,0.036728591243701515,0.26658806221762793,0.5737247712760363
The four Primary Security Principles related to messages are,"Confidentiality, Integrity, Non repudiation and Authentication","Confidentiality, Access Control, Integrity, Non repudiation","Authentication, Authorization, Availability, Integrity","Availability, Authorization, Confidentiality, Integrity",A,False,0.12553029040964042,0.0626231145203455,0.2744028329737854,0.5374437620962286
What was the first buffer overflow attack?,Love Bug,SQL Slammer,Morris Worm,Code Red,C,False,0.13635471647686823,0.04186753728339449,0.31579249289665723,0.50598525334308
"The ______________ can cost you money, by sending text messages from your mobile phone numbers.",IM – Trojans,Backdoor Trojans,SMS Trojan,Ransom Trojan,C,False,0.40435956406330925,0.04938747083206943,0.08956298550921134,0.4566899795954099
Three of the following are classic security properties; which one is not?,Confidentiality,Availability,Correctness,Integrity,B,False,0.13163173943527953,0.04511651644124238,0.18750027917111772,0.6357514649523605
