Information Security and Audit 2071 Ashwin

Uploaded May 04, 2026 at 05:01 AM

Download
Document Metadata
Question Type:
University
University Name: Tribhuvan University
Institute: Institute of Engineering
Exam: Regular
Level: MSc
Programme: Computer Knowledge and System
Subject: Information Security and Audit
Full Marks: 60
Pass Marks: 30
Year: I
Part: II
Time: 3
Parsed Questions
10 Questions
1.
What is information security? Specify two security mechanisms each that can be used to enforce. (a) Confidentiality (b) Integrity (c) Availability. [1+5]
2.
Differentiate between symmetric key and asymmetric key cryptography. Explain how Deffie-Hellman algorithm can be used to negotiate a symmetric key over an un-secure channel. [2+4]
3.
What is a crypto-graphic checksum? State the properties of cryptographic checksum functions and briefly explain what they mean. [1+5]
4.
What is a security policy? Describe Bell La-padula model for confidentiality policy. [1+5]
5.
Explain about Clark-Wilson integrity model, on a context of your choice list a few CDIs and UDIs. [5+1]
6.
Define the following design principles. Also state which aspect of security does each of them address. [1.5×4]
(a) Principle of least privilege
(b) Principle of complete mediation
(c) Principle of open design
(d) Principle of separation of privilege
7.
What is an IT-Audit? List and briefly explain the major components in an IT Audit Report. [1+5]
8.
Suppose you have a corporate network with a distinct internal network and DMZ network with two firewalls, one facing the public network and another between the internal network and the DMZ. ii) Inner firewall configuration
(a) Explain the major things you would put on the
(b) Explain the parameters you would consider to decide whether to put a server on the internal network or the DMZ network. [3]
(i) Outer firewall configuration
9.
What is an IDS? List the characteristics of an IDS. Explain about the different components in a basic IDS architecture. [1+2+3]
10.
Mention any vulnerability scanning software you are aware of. Mention its feature and best a few things it can perform. You can base your explanation on any application or operating system of your choice. [6]
Original Document
Raw OCR Text
1. What is information security? Specify two security mechanisms each that can be used to enforce. (a) Confidentiality (b) Integrity (c) Availability. [1+5] 2. Differentiate between symmetric key and asymmetric key cryptography. Explain how Deffie-Hellman algorithm can be used to negotiate a symmetric key over an un-secure channel. [2+4] 3. What is a crypto-graphic checksum? State the properties of cryptographic checksum functions and briefly explain what they mean. [1+5] 4. What is a security policy? Describe Bell La-padula model for confidentiality policy. [1+5] 5. Explain about Clark-Wilson integrity model, on a context of your choice list a few CDIs and UDIs. [5+1] 6. Define the following design principles. Also state which aspect of security does each of them address. [1.5×4] a) Principle of least privilege b) Principle of complete mediation c) Principle of open design d) Principle of separation of privilege 7. What is an IT-Audit? List and briefly explain the major components in an IT Audit Report. [1+5] 8. Suppose you have a corporate network with a distinct internal network and DMZ network with two firewalls, one facing the public network and another between the internal network and the DMZ. a) Explain the major things you would put on the i) Outer firewall configuration ii) Inner firewall configuration b) Explain the parameters you would consider to decide whether to put a server on the internal network or the DMZ network. [3] 9. What is an IDS? List the characteristics of an IDS. Explain about the different components in a basic IDS architecture. [1+2+3] 10. Mention any vulnerability scanning software you are aware of. Mention its feature and best a few things it can perform. You can base your explanation on any application or operating system of your choice. [6]