Chapter 17
Computer Science Illuminated · 46 exercises
Problem 1
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Information integrity ensures that data can be modified only by appropriate mechanisms.
4 step solution
Problem 2
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Pairing threats with vulnerabilities is a part of risk analysis.
4 step solution
Problem 4
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Biometrics is a type of user authentication that relies on the user having a smart card or a card with a readable magnetic strip.
4 step solution
Problem 5
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A password should not resemble anything that looks like a word or phrase in a language that humans speak.
4 step solution
Problem 6
For Exercises 1-27, mark the answers true or false as follows: A. True B. False CAPTCHA is a software mechanism that authenticates a particular user before allowing him or her to post a comment to a blog.
4 step solution
Problem 7
For Exercises 1-27, mark the answers true or false as follows: A. True B. False The reCAPTCHA project serves a secondary purpose-to help digitize books.
3 step solution
Problem 9
For Exercises 1-27, mark the answers true or false as follows: A. True B. False The Touch ID biometric system uses retinal scans for user validation.
5 step solution
Problem 10
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A computer virus "infects" another program by embedding itself into that program.
4 step solution
Problem 11
For Exercises 1-27, mark the answers true or false as follows: A. True B. False The terms "Trojan horse" and "worm" are used interchangeably to describe a particular category of malicious code.
4 step solution
Problem 12
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A logic bomb is set to go off when a particular system event occurs, such as a particular date and time.
4 step solution
Problem 13
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Antivirus software is not effective against non-virus types of malware.
4 step solution
Problem 14
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A password-guessing program uses dictionaries to try thousands of potential passwords each second.
3 step solution
Problem 15
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Phishing is a technique that uses deceptive emails and websites to obtain user information, such as usernames and passwords.
3 step solution
Problem 16
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A back door threat is implemented by a programmer of the system under attack.
4 step solution
Problem 17
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A denial-of-service attack does not directly corrupt data.
4 step solution
Problem 18
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Decryption is the process of converting plaintext into ciphertext.
3 step solution
Problem 19
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A cipher is an algorithm used to encrypt and decrypt text.
4 step solution
Problem 20
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A transposition cipher is an example of modern cryptography.
4 step solution
Problem 21
For Exercises 1-27, mark the answers true or false as follows: A. True B. False In public-key cryptography, each user has two related keys, one public and one private.
4 step solution
Problem 22
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A digital signature allows the recipient to verify that the message truly originates from the stated sender.
3 step solution
Problem 23
For Exercises 1-27, mark the answers true or false as follows: A. True B. False The Internet can create a false sense of anonymity.
4 step solution
Problem 25
For Exercises 1-27, mark the answers true or false as follows: A. True B. False A website's security policy describes the constraints and behaviors that an organization embraces regarding information management.
4 step solution
Problem 26
For Exercises 1-27, mark the answers true or false as follows: A. True B. False Many mobile phones collect and store location data that can then be read and used by third parties, such as law enforcement.
4 step solution
Problem 28
Exercises 28-55 are problems or shortanswer questions. What is the CIA triad of information security?
4 step solution
Problem 29
Exercises 28-55 are problems or shortanswer questions. Other than those presented in this chapter, give three examples of data integrity violations.
4 step solution
Problem 31
Exercises 28-55 are problems or shortanswer questions. List at least four guidelines related to password creation and management.
3 step solution
Problem 32
Exercises 28-55 are problems or shortanswer questions. Is "diningroom" a good password? Why or why not?
3 step solution
Problem 33
Exercises 28-55 are problems or shortanswer questions. Is "fatTony \(99^{\prime \prime}\) a good password? Why or why not?
5 step solution
Problem 34
Exercises 28-55 are problems or shortanswer questions. What is password management software?
4 step solution
Problem 35
Exercises 28-55 are problems or shortanswer questions. What is the goal of a CAPTCHA interaction?
3 step solution
Problem 37
Exercises 28-55 are problems or shortanswer questions. What is Apple's Touch ID technology used for?
4 step solution
Problem 38
Exercises 28-55 are problems or shortanswer questions. What do we mean when we say a computer virus is self-replicating?
4 step solution
Problem 39
Exercises 28-55 are problems or shortanswer questions. Describe the two techniques used by antivirus software to identify malware.
2 step solution
Problem 40
Exercises 28-55 are problems or shortanswer questions. Describe a hypothetical scenario, other than the one described in this chapter, of a phishing attack.
6 step solution
Problem 41
Exercises 28-55 are problems or shortanswer questions. Describe how a Trojan horse attacks a computer system.
5 step solution
Problem 42
Exercises 28-55 are problems or shortanswer questions. Describe a buffer overflow and how it might make a computer system vulnerable.
5 step solution
Problem 43
Exercises 28-55 are problems or shortanswer questions. How does a man-in-the-middle attack work?
4 step solution
Problem 44
Exercises 28-55 are problems or shortanswer questions. Using a Caesar cipher, shifting three letters to the right, encrypt the message "WE ESCAPE TONIGHT."
6 step solution
Problem 47
Exercises 28-55 are problems or shortanswer questions. Describe how Claire would send a message to David using public-key encryption.
5 step solution
Problem 48
Exercises 28-55 are problems or shortanswer questions. What is a digital signature?
4 step solution
Problem 49
Exercises 28-55 are problems or shortanswer questions. What does a website's security policy describe?
3 step solution
Problem 50
Exercises 28-55 are problems or shortanswer questions. What is GPS? How is it used to support cell phone applications?
4 step solution
Problem 51
Exercises 28-55 are problems or shortanswer questions. Which abuses are possible given the current state of cell phone data collection?
5 step solution
Problem 52
Exercises 28-55 are problems or shortanswer questions. What is a wiki?
3 step solution
Problem 53
Exercises 28-55 are problems or shortanswer questions. What is WikiLeaks? Is it a wiki?
3 step solution
Problem 54
Exercises 28-55 are problems or shortanswer questions. Who is Julian Assange?
3 step solution