1 Fundamentals Of Information Security

Information Security · Unit 1

Fundamentals of Information Security

Exam-focused notes for Fundamentals of Information Security (Information Security, BIT303): what the TU syllabus asks and how it has actually been tested, with 8 solved past questions from this unit.

What this unit covers

  • Security concepts and terminology
  • Threats, attacks and assets
  • Security risk and risk assessment
  • Security policy and implementation
  • Security auditing architecture
  • Attack trees and threat modeling

Threats, attacks and assets

20825 marks

Explain about threats, attacks and assets. [5]

Assets are the valuable resources of a system or organization that need to be protected. They include: Type Examples --------------- Hardware Computers, servers, routers, storage devices Software Operating systems, application programs, utilities Data Datab...

Full solved answer →
20795 marks

What is Security threat and attack? Describe different types of attacks in brief. [5]

A security threat is any potential danger or circumstance that has the possibility of exploiting a vulnerability in a system to cause harm, loss, or unauthorized access to information or resources. It represents a possible violation of security. A security ...

Full solved answer →

Security auditing architecture

20825 marks

Explain the security auditing architecture. [5]

Note: The reference notes did not contain this topic. The following answer is based on standard, correct information from the security and operating systems domain, appropriate for BSc CSIT curriculum. --- Security auditing is the systematic process of coll...

Full solved answer →
05 marks

Describe security auditing architecture. [5]

Note: The reference notes did not contain material on this topic. The following answer is based on standard information security and operating systems security curriculum as taught in BSc CSIT programs. --- Security auditing is the systematic process of rec...

Full solved answer →

Attack trees and threat modeling

20825 marks

What is attack tree? Describe about password based authentication. [5]

--- An attack tree is a conceptual diagram that models the various ways an attacker can compromise a system or achieve a malicious goal. It provides a formal, structured methodology for describing the security of systems based on varying attacks. - The root...

Full solved answer →
05 marks

What is attack tree? Construct an attack tree for internet banking authentication. [5]

An attack tree is a conceptual diagram that models threats against a system in a tree structure. It was introduced by Bruce Schneier as a formal method for describing the security of systems based on varying attacks. - The root node represents the goal of t...

Full solved answer →

Security policy and implementation

20825 marks

Define security policy. How do you implement logging function? [5]

A security policy is a formal set of rules, guidelines, and procedures that defines how an organization manages, protects, and distributes sensitive information and resources. It specifies: - What assets need to be protected - Who is authorized to access th...

Full solved answer →

Security risk and risk assessment

20805 marks

What is risk assessment? Describe the security auditing architecture. [5]

Risk assessment is the process of identifying, analyzing, and evaluating potential threats and vulnerabilities to an information system in order to determine the likelihood and impact of security incidents. It helps organizations prioritize security measure...

Full solved answer →