Frequently Asked Questions (FAQ)
Unit-1 Questions
Topics Covered:
- Security Attacks (Interruption, Interception, Modification and Fabrication)
- Security Services (Confidentiality, Integrity, Authentication, Non-repudiation, Access Contol)
- Security Mecahanisms
- A model for inter-network security
- Classical Encryption Techniques
- DES, Strength of DES
- Differential and Linear Cryptanalysis
- Design principles and Modes of Operation of Block ciphers
- Blowfish
- Placement of Encryption Function
- Traffic Confidentiality
- Key Distribution
- Random Number Generation
Descriptive Questions (2 Marks):
- What does the CIA Triad stand for?
- What do you mean by Security Service?
- Define data confidentiality.
- What is Cryptanalysis?
- What are the ingredients of Symmetric Cipher model?
- List the security services available for securing a system from various attacks.
- Define stream ciphers.
- Differentiate Symmetric and Asymmetric cryptography.
- How many modes of operations are there for implementing a Block Cipher? What are they?
- Give example for mono alphabetic and poly alphabetic ciphers.
- What is known as security attack?
- Brief the strengths of triple DES.
Descriptive Questions (5 Marks):
- With the help of a neat diagram, explain the model for network security.
- Differentiate active and passive security attack.
- Write short notes on Data Confidentiality.
- Explain symmetric cipher model with diagram.
- Compare and Contrast between Symmetric and Asymmetric key cryptography.
- Write about any two classical cryptosystems with suitable examples.
- Explain the Ceaser cipher and mono alphabetic cipher.
- Explain about Hill Cipher. Consider the plaintext "paymoremoney" and use the encryption key:

Find the cipher text? - For each of the following assets, assign a low, moderate or high impact level for the loss of confidentiality, availability and integrity respectively. Justify your answer:
- Financial organisation managing routine administrative information
- Organisation managing public information on its web server
- Law enforcement organisation managing extremely sensitive information.
- Draw a matrix that shows the relationship between security mechanisms and attacks.
- State the difference between block cipher and stream cipher.
- Discuss in details about cipher block modes of operation.
- Explain about security attacks
- Compare and contrast linear and differential cryptanalysis.
- Describe DES algorithm with neat diagram and explain the steps.
- List and explain the strength of DES.
- Explain in detail about Blowfish Algorithm.
Unit-2 Questions
Topics Covered:
- Principles of Public Key Cryptography
- RSA Algorithm
- Key Management
- Diffie-Hellman Key Exchange
- Elliptic Curve Cryptography
- Message Authentication and Hash Functions
- Authentication Requirements
- Message authentication
- Hash Functions and MACs
- Hash and MAC Algorithms
- SHA-512
- HMAC
Descriptive Questions (2 Marks):
- Describe the use of Public Key cryptography.
- List the 6 ingredients of public key encryption.
- What are the advantages of key distribution in cryptography?
- Draw the diagram for Public-Key distribution scenario.
- What are the principles of Public-Key cryptosystems?
- What are the different approaches to Public-Key management?
- What is one-way authentication.
- What are the requirements for (message) authentication?
- Draw the general structure of Secure Hash Code.
- What are the requirements of MAC function?
Descriptive Questions (5 Marks):
- Briefly explain the working principle of Public Key Cryptography.
- In RSA, Given n=12091 and e=13, encrypt the message "THIS IS TOUGH" using the 00 to 26 encoding scheme. Also decrypt the ciphertext to find the original message.
- Explain RSA algorithm, and perform encryption and decryption using RSA with p=7, q=11, e=17, and M=8.
- Explain simple secret key distribution with diagram.
- Explain Diffie-Hellman key exchange algorithm in detail.
- Discuss about authentication requirement.
- Discuss about message authentication and Hash functions.
- Explain the SHA-512 algorithm. Illustrate with an example.
- Explain message digest generation using SHA-512 algorithm.
- What is the order of finding two messages having the same message digest using SHA-512?
- Define HMAC. Write short notes on Security of HMAC.
Unit-3 Questions
Topics Covered:
- Digital Signatures
- Authentication Protocols
- Digital Signature Standard (DSS)
- Authentication Applications
- Kerberos
- X.509 Directory Authentication Service (DAS)
- E-Mail Security
- Pretty Good Privacy (PGP)
- S/MIME
Descriptive Questions (2 Marks):
- What is Digital Signature?
- Differentiate RSA and DES approach for digital signature.
- Why Kerberos is needed?
- List any two applications of X.509 certificates.
Descriptive Questions (5 Marks):
- State the properties and requirements of digital signatures.
- Mention three variations of digital signatures and state the purpose of each.
- Explain Digital Signature Standard (DSS) with necessary diagrams in detail.
- Explain in detail about Kerberos.
- What do you mean by the Kerberos Realm? Explain the working of Kerberos.
- Assume client C wants to communicate with a server S using Kerberos protocol. How can it be achieved?
- Explain the X.509 certificate formats.
- Explain the X.509v3 certificate format.
- What do you mean by PGP? Explain the working principle of PGP.
- How are the messages generated and transmitted in pretty good privacy (PGP) protocol? Explain with clear diagrams.
- Why does PGP compress the message? What are the reasons for compressing the signature before encryption.
- List and explain the services provided by PGP and show how message generation is done using PGP with a neat diagram.
- In PGP, what is the probability that a user with N Public Keys will have at least one, duplicate key ID?
- Explain the significance of email security protocols like PGP and S/MIME in protecting email communication.
Unit-4 Questions
Topics Covered:
- IP Security
- Overview
- IP Security Architecture
- Authentication Header (AH)
- Encapsulating Security Payload (ESP)
- Combining Security Associations (SAs)
- Key Management
- Web Security
- Web Security Requirements
- Secure Socket Layer (SSL)
- Transport Layer Security (TLS)
- Secure Electronic Transaction (SET)
Descriptive Questions (2 Marks):
- Define Virtual Private Network (VPN).
- Define the term IP Security (IPSec).
- Write about Security Association (SA).
- What is Secure Socket Layer (SSL)?
- What is TLS?
- What are the different alert codes of TLS Protocol?
Descriptive Questions (5 Marks):
- What is IP Security? Discuss in detail about IPSec Architecture.
- Explain in detail IP security architecture.
- What are the differences between transport mode and tunnel mode in IPsec?
- Explain the need for combining Security Associations (SAs) for network security.
- What are different services provided by the SSL Record Protocol?
- Describe in detail the working of SSL/TLS, including the handshake process and encryption techniques.
- List and briefly define the parameters that define an SSL session state.
- Explain in detail Secure Electronic Transaction (SET).
- Discuss the steps involved in Secure Electronic Transaction (SET).
- List out the participants of SET system, and explain in detail?
Unit-5 Questions
Topics Covered:
- Intruders
- Viruses and Worms
- Viruses and related threats
- Firewall
- Firewall Design Principles
- Trusted Systems
- Intrusion Detection System (IDS)
Descriptive Questions (2 Marks):
- What do you mean by Worms?
- Differentiate between worms and viruses.
- Write any two design goals of firewall.
- Define Firewall.
- List the three types of firewall.
- What is the role of firewall in Information Security (IS)?
- What is an intrusion detection system, and how does it work?
Descriptive Questions (5 Marks):
- Select any antivirus of your choice and explain it in detail.
- Write and explain the four phases that a typical virus goes through.
- Discuss about:
- Intruders
- Trusted System
- What is Intrusion? Explain in detail Intrusion Detection System (IDS) with diagram.
- Generalise the role of Intrusion Detection System? Point out the three benefits that can be provided by an intrusion detection system?
- Illustrate the working of an Intrusion Detection System with a real-world example.
- Justify the role of firewalls in protecting enterprise networks from cyber threats.
- Where would you place a web server in an organisation assuming that you can use a network firewall and why?
- Illustrate the three common types of firewalls with diagrams?
- Define firewall. Explain its characteristics, types, services and limitations.
