Search This Blog

Tuesday, 8 September 2026

Question Bank on Information Security

0 comments

Frequently Asked Questions (FAQ)

Unit-1 Questions

Topics Covered: 
  • Security Attacks (Interruption, Interception, Modification and Fabrication)
  • Security Services (Confidentiality, Integrity, Authentication, Non-repudiation, Access Contol)
  • Security Mecahanisms
    • A model for inter-network security
  • Classical Encryption Techniques
  • DES, Strength of DES
  • Differential and Linear Cryptanalysis
  • Design principles and Modes of Operation of Block ciphers
  • Blowfish
  • Placement of Encryption Function
  • Traffic Confidentiality
  • Key Distribution
  • Random Number Generation


Descriptive Questions (2 Marks):
  1. What does the CIA Triad stand for?
  2. What do you mean by Security Service?
  3. Define data confidentiality.
  4. What is Cryptanalysis?
  5. What are the ingredients of Symmetric Cipher model?
  6. List the security services available for securing a system from various attacks.
  7. Define stream ciphers.
  8. Differentiate Symmetric and Asymmetric cryptography.
  9. How many modes of operations are there for implementing a Block Cipher?  What are they?
  10. Give example for mono alphabetic and poly alphabetic ciphers.
  11. What is known as security attack?
  12. Brief the strengths of triple DES.


Descriptive Questions (5 Marks):
  1. With the help of a neat diagram, explain the model for network security.
  2. Differentiate active and passive security attack.
  3. Write short notes on Data Confidentiality.
  4. Explain symmetric cipher model with diagram.
  5. Compare and Contrast between Symmetric and Asymmetric key cryptography.
  6. Write about any two classical cryptosystems with suitable examples.
  7. Explain the Ceaser cipher and mono alphabetic cipher.
  8. Explain about Hill Cipher. Consider the plaintext "paymoremoney" and use the encryption key:

        Find the cipher text?
  9. For each of the following assets, assign a low, moderate or high impact level for the loss of confidentiality, availability and integrity respectively.  Justify your answer:
    • Financial organisation managing routine administrative information
    • Organisation managing public information on its web server
    • Law enforcement organisation managing extremely sensitive information.
  10. Draw a matrix that shows the relationship between security mechanisms and attacks.
  11. State the difference between block cipher and stream cipher.
  12. Discuss in details about cipher block modes of operation.
  13. Explain about security attacks
  14. Compare and contrast linear and differential cryptanalysis.
  15. Describe DES algorithm with neat diagram and explain the steps.
  16. List and explain the strength of DES.
  17. Explain in detail about Blowfish Algorithm.



Unit-2 Questions

Topics Covered: 
  • Principles of Public Key Cryptography
    • RSA Algorithm
  • Key Management
    • Diffie-Hellman Key Exchange
  • Elliptic Curve Cryptography
  • Message Authentication and Hash Functions
    • Authentication Requirements
    • Message authentication
    • Hash Functions and MACs
    • Hash and MAC Algorithms
    • SHA-512
    • HMAC


Descriptive Questions (2 Marks):
  1. Describe the use of Public Key cryptography.
  2. List the 6 ingredients of public key encryption.
  3. What are the advantages of key distribution in cryptography?
  4. Draw the diagram for Public-Key distribution scenario.
  5. What are the principles of Public-Key cryptosystems?
  6. What are the different approaches to Public-Key management?
  7. What is one-way authentication.
  8. What are the requirements for (message) authentication?
  9. Draw the general structure of Secure Hash Code.
  10. What are the requirements of MAC function?


Descriptive Questions (5 Marks):
  1. Briefly explain the working principle of Public Key Cryptography.
  2. In RSA, Given n=12091 and e=13, encrypt the message "THIS IS TOUGH" using the 00 to 26 encoding scheme.  Also decrypt the ciphertext to find the original message.
  3. Explain RSA algorithm, and perform encryption and decryption using RSA with p=7, q=11, e=17,  and M=8.
  4. Explain simple secret key distribution with diagram.
  5. Explain Diffie-Hellman key exchange algorithm in detail.
  6. Discuss about authentication requirement.
  7. Discuss about message authentication and Hash functions.
  8. Explain the SHA-512 algorithm.  Illustrate with an example.
  9. Explain message digest generation using SHA-512 algorithm.  
  10. What is the order of finding two messages having the same message digest using SHA-512?
  11. Define HMAC.  Write short notes on Security of HMAC.



Unit-3 Questions

Topics Covered: 
  • Digital Signatures
  • Authentication Protocols
  • Digital Signature Standard (DSS)
  • Authentication Applications
  • Kerberos
  • X.509 Directory Authentication Service (DAS)
  • E-Mail Security
    • Pretty Good Privacy (PGP)
    • S/MIME


Descriptive Questions (2 Marks):
  1. What is Digital Signature?
  2. Differentiate RSA and DES approach for digital signature.
  3. Why Kerberos is needed?
  4. List any two applications of X.509 certificates.


Descriptive Questions (5 Marks):
  1. State the properties and requirements of digital signatures.
  2. Mention three variations of digital signatures and state the purpose of each.
  3. Explain Digital Signature Standard (DSS) with necessary diagrams in detail.
  4. Explain in detail about Kerberos.
  5. What do you mean by the Kerberos Realm? Explain the working of Kerberos.
  6. Assume client C wants to communicate with a server S using Kerberos protocol.  How can it be achieved?
  7. Explain the X.509 certificate formats.
  8. Explain the X.509v3 certificate format.
  9. What do you mean by PGP?  Explain the working principle of PGP.
  10. How are the messages generated and transmitted in pretty good privacy (PGP) protocol? Explain with clear diagrams.
  11. Why does PGP compress the message?  What are the reasons for compressing the signature before encryption.
  12. List and explain the services provided by PGP and show how message generation is done using PGP with a neat diagram.
  13. In PGP, what is the probability that a user with N Public Keys will have at least one, duplicate key ID?
  14. Explain the significance of email security protocols like PGP and S/MIME in protecting email communication.



Unit-4 Questions

Topics Covered: 
  • IP Security
    • Overview
    • IP Security Architecture
    • Authentication Header (AH)
    • Encapsulating Security Payload (ESP) 
    • Combining Security Associations (SAs)
    • Key Management
  • Web Security
    • Web Security Requirements
    • Secure Socket Layer (SSL)
    • Transport Layer Security (TLS)
    • Secure Electronic Transaction (SET)


Descriptive Questions (2 Marks):
  1. Define Virtual Private Network (VPN).
  2. Define the term IP Security (IPSec).
  3. Write about Security Association (SA).
  4. What is Secure Socket Layer (SSL)?
  5. What is TLS?
  6. What are the different alert codes of TLS Protocol?


Descriptive Questions (5 Marks):
  1. What is IP Security?  Discuss in detail about IPSec Architecture.
  2. Explain in detail IP security architecture.
  3. What are the differences between transport mode and tunnel mode in IPsec?
  4. Explain the need for combining Security Associations (SAs) for network security.
  5. What are different services provided by the SSL Record Protocol?
  6. Describe in detail the working of SSL/TLS, including the handshake process and encryption techniques.
  7. List and briefly define the parameters that define an SSL session state.
  8. Explain in detail Secure Electronic Transaction (SET).
  9. Discuss the steps involved in Secure Electronic Transaction (SET).
  10. List out the participants of SET system, and explain in detail?




Unit-5 Questions

Topics Covered: 
  • Intruders
    • Viruses and Worms
    • Viruses and related threats
  • Firewall
    • Firewall Design Principles
    • Trusted Systems
    • Intrusion Detection System (IDS)


Descriptive Questions (2 Marks):
  1. What do you mean by Worms?
  2. Differentiate between worms and viruses.
  3. Write any two design goals of firewall.
  4. Define Firewall.
  5. List the three types of firewall.
  6. What is the role of firewall in Information Security (IS)?
  7. What is an intrusion detection system, and how does it work?

Descriptive Questions (5 Marks):
  1. Select any antivirus of your choice and explain it in detail.
  2. Write and explain the four phases that a typical virus goes through.
  3. Discuss about:
    • Intruders
    • Trusted System
  4. What is Intrusion? Explain in detail Intrusion Detection System (IDS) with diagram.
  5. Generalise the role of Intrusion Detection System? Point out the three benefits that can be provided by an intrusion detection system?
  6. Illustrate the working of an Intrusion Detection System with a real-world example.
  7. Justify the role of firewalls in protecting enterprise networks from cyber threats.
  8. Where would you place a web server in an organisation assuming that you can use a network firewall and why?
  9. Illustrate the three common types of firewalls with diagrams?
  10. Define firewall.  Explain its characteristics, types, services and limitations.

    Leave a Reply