Memra
academic · advanced

COMP 400 — Computer and Network Security

Both halves of the paper — 308 multiple-choice drills and 33 written answers

A full computer and network security course built to the shape of its own final: fifty multiple-choice questions and five written problems, rehearsed at their real weights. Part A covers the security concepts and the CIA model, the thirteen fundamental design principles with an example each, symmetric encryption and the modes of operation, hash functions and MACs and the three resistance properties, public-key cryptography with RSA and Diffie-Hellman worked end to end on real numbers, user authentication and the password-space arithmetic, access control from DAC through RBAC and ABAC plus database inference attacks, malicious software, denial of service and intrusion detection with the base-rate fallacy made concrete, firewalls and the IPv4 header a filter actually reads, software security and buffer overflow, operating-system and cloud security, and the management, risk, auditing, legal and privacy frame. Part B covers the internet security protocols — S/MIME and DKIM, the TLS stack and handshake and what TLS 1.3 changed, IPsec with the AH and ESP headers drawn to scale — then Kerberos, X.509 and PKI, wireless security from WEP through 802.11i, and the legacy topics the sample paper still tests that the current textbook has dropped. Definitions and discriminations are drilled as multiple choice, because that is what the paper asks; the questions the paper wants in prose are written, committed, then graded against the marking scheme; and the quantitative work is done in runnable Python you execute and watch come out right.

0 / 91 lessons
We'll stop scheduling reviews for after it.

Security Concepts, Assets, and the CIA Model

33 cards
  1. What "computer security" actually says 8 min ◈ 6
  2. The two goals the triad leaves out 8 min ◈ 7
  3. FIPS 199, and why the justification is the mark 11 min ◈ 5
  4. The words that get used interchangeably and must not be 10 min ◈ 7
  5. Three scopes, six services, eight mechanisms 10 min ◈ 8

Design Principles, Attack Surface, and Security Strategy

35 cards
  1. Saltzer and Schroeder: the first eight principles 11 min ◈ 11
  2. The five modern design principles 10 min ◈ 9
  3. Attack surfaces, attack trees, and security strategy 10 min ◈ 7
  4. The standards bodies: NIST, ISOC, ITU-T and ISO 7 min ◈ 8

Symmetric Encryption and Modes of Operation

51 cards
  1. The five ingredients of symmetric encryption 9 min ◈ 7
  2. Cryptanalytic attack models and brute-force effort 10 min ◈ 8
  3. Classical ciphers: composing and inverting them 11 min ◈ 7
  4. Feistel, DES, Triple DES and AES 11 min ◈ 7
  5. Stream ciphers: RC4, ChaCha20, and the rule you must never break 9 min ◈ 8
  6. ECB, CBC, and CBC padding arithmetic 11 min ◈ 6
  7. CFB, CTR, choosing a mode, and how the key gets there 11 min ◈ 8

Hash Functions, MACs, and Message Authentication

36 cards
  1. Why message authentication is not encryption 8 min ◈ 6
  2. Hash functions and the six requirements 10 min ◈ 7
  3. Preimage, second preimage, and collision resistance 11 min ◈ 8
  4. MACs, keyed hashes, and HMAC 10 min ◈ 8
  5. The SHA family, and the death of a hash function 9 min ◈ 7

Public-Key Cryptography, RSA, Diffie–Hellman, and Digital Signatures

40 cards
  1. Public-key encryption: two keys, two modes, six requirements 10 min ◈ 6
  2. RSA: generating a key pair and exponentiating by squaring 12 min ◈ 8
  3. Breaking RSA by factoring a small modulus 11 min ◈ 6
  4. Diffie–Hellman: agreeing on a secret with no secret 11 min ◈ 8
  5. Which algorithm does what — and why elliptic curves 9 min ◈ 7
  6. Digital signature versus MAC — four attacks, four different answers 12 min ◈ 5

User Authentication

44 cards
  1. The four means of authentication, and the e-authentication model 9 min ◈ 6
  2. Password attacks, hashing, and the three jobs of a salt 11 min ◈ 8
  3. Password-space combinatorics and cracking time 12 min ◈ 9
  4. Password selection strategies and proactive checking 10 min ◈ 8
  5. Tokens, smart cards, and one-time passwords 9 min ◈ 7
  6. Biometrics, remote authentication, and the attack matrix 12 min ◈ 6

Access Control and Database Security

40 cards
  1. Who decides, and the matrix that records it 12 min ◈ 9
  2. Nine bits, three more, and why a directory outranks a file 12 min ◈ 9
  3. RBAC₀ through RBAC₃ 11 min ◈ 4
  4. Read-only and read-write, per role, per column group 12 min ◈ 4
  5. Granting rights, and the injection that ignores them 11 min ◈ 8
  6. Learning the secret from the rows you are allowed to see 12 min ◈ 6

Malicious Software

39 cards
  1. Classifying malware by propagation and payload 10 min ◈ 8
  2. Viruses: three parts, four phases, and the concealment ladder 10 min ◈ 6
  3. Worms: propagation phases, scanning strategies, and the outbreaks 11 min ◈ 8
  4. Trojans, drive-by downloads, phishing and smishing 12 min ◈ 6
  5. Payloads: corruption, attack agents, information theft, stealthing 10 min ◈ 6
  6. Antivirus generations, and diagnosing an infected host 12 min ◈ 5

Denial of Service and Intrusion Detection

42 cards
  1. Denial of service, the TCP handshake, and SYN flooding 11 min ◈ 6
  2. DDoS, reflection, and amplification 10 min ◈ 7
  3. Defending against and responding to a DoS attack 10 min ◈ 6
  4. Intruder classes, the attack methodology, and what an IDS is 10 min ◈ 7
  5. The base-rate fallacy and NIDS alarm probability 12 min ◈ 6
  6. Anomaly detection, signature detection, sensors, and Snort 12 min ◈ 10

Firewalls and Intrusion Prevention

36 cards
  1. Five fields, and the header they live in 12 min ◈ 6
  2. Default deny, and the rule that breaks it 11 min ◈ 9
  3. What a stateless filter cannot do, and the rule that does it 12 min ◈ 8
  4. Where the firewall sits 10 min ◈ 6
  5. Deciding instead of reporting 9 min ◈ 7

Software Security and Buffer Overflow

44 cards
  1. Buffer overflow: the stack frame and the return address 12 min ◈ 12
  2. Shellcode, SetUID binaries, and privilege escalation 10 min ◈ 8
  3. Compile-time and run-time defences: canaries, NX, and ASLR 11 min ◈ 7
  4. Finding and rewriting a vulnerable C program 12 min ◈ 7
  5. The CWE/SANS Top 25, input validation, and safe coding 12 min ◈ 10

Operating System, Virtualization, Cloud, and IoT Security

33 cards
  1. OS hardening: four steps to secure it, five to keep it that way 10 min ◈ 6
  2. Local and remote exploits, chroot jails, and what assurance actually buys 12 min ◈ 8
  3. Virtualization and containers: where the isolation boundary sits 10 min ◈ 6
  4. Cloud: 5 / 3 / 4, the responsibility line, the risks, and the ten services 12 min ◈ 6
  5. IoT: the four tiers, and the patching vulnerability nobody is to blame for 10 min ◈ 7

Security Management, Risk, Auditing, and the Legal and Ethical Frame

47 cards
  1. IT security management — three questions, four approaches, five stages 12 min ◈ 7
  2. Likelihood, consequence, the risk matrix, and the five treatments 11 min ◈ 7
  3. Building a risk register for a home network 12 min ◈ 4
  4. Controls, plans, and change versus configuration management 10 min ◈ 7
  5. Physical security and threats from non-computing sources 11 min ◈ 4
  6. Human factors, awareness and training, and incident response 12 min ◈ 4
  7. Security auditing — what to record, and what kind of number it is 10 min ◈ 7
  8. Cybercrime, intellectual property, and professional ethics 12 min ◈ 3
  9. Privacy principles — GDPR, OECD, PIPEDA — and auditing a real policy 11 min ◈ 4

Internet Security Protocols: E-mail, TLS, HTTPS, and IPsec

57 cards
  1. The Internet mail architecture and the MIME multipart subtypes 10 min ◈ 7
  2. S/MIME’s four functions, and DKIM’s domain signature 11 min ◈ 7
  3. The TLS stack, sessions versus connections, and the six directional keys 11 min ◈ 7
  4. The Record Protocol’s five steps, and the two one-line protocols 10 min ◈ 7
  5. The four-phase handshake, and the three threats it does and does not counter 12 min ◈ 4
  6. TLS attacks, Heartbleed, HTTPS, and what TLS 1.3 changed 12 min ◈ 8
  7. IPsec: security associations and the ESP packet 12 min ◈ 9
  8. AH versus ESP, and transport versus tunnel mode 11 min ◈ 8

Internet Authentication, Wireless Security, and the Legacy Exam Layer

61 cards
  1. Kerberos: tickets, authenticators, and the three exchanges 12 min ◈ 8
  2. Realms, principals, and the interrealm scaling problem 10 min ◈ 7
  3. X.509: the certificate fields, version scoping, and revocation 11 min ◈ 7
  4. PKIX, certificate assurance classes, and identity federation 12 min ◈ 8
  5. Why radio is different: wireless threats and the 802.11 architecture 10 min ◈ 7
  6. WEP encapsulation, the CRC, and why a CRC is not a MAC 12 min ◈ 7
  7. 802.11i: five phases, the key hierarchy, and the four-way handshake 12 min ◈ 8
  8. WAP, WTLS, WML — and sitting an exam older than its textbook 11 min ◈ 9
NORMAL ~/memra/learn/comp-400 utf-8 LF