BIT303 · TU past paper
Information Security 2080 question paper
The complete TU 2080 exam paper for Information Security (BIT303), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksSHA-1 algorithm and paddingHideAnswer
Describe the role of hash functions in authenticating message? How SHA-1 algorithm is used to produce hash value of a message? Explain.[10]
A hash function H is a mathematical function that maps a variable-length input message M to a fixed-length output called the message digest or hash value. The basic authentication process works as follows: At the Sender Side: 1. Sender c...
- 210 marksNumericalEuler totient functionHideAnswer
Define Euler totient function with an example. Find the GCD of 12 and 32 using Extended Euclidean algorithm.[10]
- Euler totient function: define with an example - Numbers for GCD: $a = 12$, $b = 32$ - Method: Extended Euclidean Algorithm --- The Euler Totient Function $\phi(n)$ counts the number of positive integers from $1$ to $n$ that are relati...
- 310 marksNumericalDiffie-Hellman key exchange protocolHideAnswer
Distinguish between threats and attack. Discuss some computer security strategy. Assume a prime number 23 and 9 as its primitive root. Alice select a private key 5 and Bob select the private key 6. Now find the secret key value that Alice and Bob shared using Diffie - Hellman protocol.[10]
Parameter Value ------ Prime number $p$ 23 Primitive root $g$ 9 Alice's private key $a$ 5 Bob's private key $b$ 6 All required data is present. --- Aspect Threat Attack --------- Definition A potential danger that could exploit a vulnera...
- 45 marksTwo-factor authenticationHideAnswer
Discuss about two factor authentication with an example. [5]
Two-Factor Authentication (2FA) is a security mechanism that requires a user to provide two distinct forms of verification from two different categories before granting access to a system or account. It adds an extra layer of security be...
- 55 marksAccess control principles and modelsHideAnswer
Explain the different types of access control principles. [5]
Note: The reference notes did not contain this topic directly. The following answer is based on standard Information Security / Operating Systems curriculum as taught in BSc CSIT programs. --- Access control is a security mechanism that ...
- 65 marksMalicious software definition and typesHideAnswer
Describe any two types of malicious software. [5]
--- A computer virus is a malicious program that attaches itself to a legitimate host file or program and replicates when that file is executed. It requires human action (such as running an infected program) to spread. - It self-replicat...
- 75 marksSecurity risk and risk assessmentHideAnswer
What is risk assessment? Describe the security auditing architecture. [5]
Risk assessment is the process of identifying, analyzing, and evaluating potential threats and vulnerabilities to an information system in order to determine the likelihood and impact of security incidents. It helps organizations priorit...
- 85 marksCybercrime and computer crimeHideAnswer
Do cybercrime and computer crimes refers to same? Justify with relevant scenarios. [5]
No, cybercrime and computer crime do not refer to exactly the same thing, although they are closely related and often used interchangeably in casual conversation. They overlap significantly but have distinct meanings. --- Computer crime ...
- 95 marksCountermeasures for malwareHideAnswer
What do you mean by countermeasures for malwares? Discuss about audit trail analysis. [5]
Countermeasures for malwares refer to the set of techniques, tools, and practices used to prevent, detect, and respond to malicious software (malware) attacks on computer systems and networks. Category Description ------ Prevention Stopp...
- 105 marksAuthentication systems and componentsHideAnswer
List some issues for user authentication. What is trust framework? [5]
--- User authentication faces several practical and security-related challenges: 1. Password Management Problems - Users tend to choose weak, easily guessable passwords - Password reuse across multiple systems increases vulnerability - F...
- 115 marksDigital signatures for authenticationHideAnswer
What is the role of digital signature in message authentication? List any two natures of zombies. [5]
--- A digital signature is a cryptographic mechanism that provides a way to verify the authenticity and integrity of a digital message or document. It plays the following key roles in message authentication: A digital signature confirms ...
- 125 marksRSA algorithm and key generationHideAnswer
Write the algorithm for RSA key generation with encryption and decryption. [5]
Note: No specific reference notes were found for this topic. The following answer is based on standard RSA cryptography as taught in BSc CSIT curriculum. --- RSA (Rivest-Shamir-Adleman) is a public-key (asymmetric) cryptosystem based on ...