Flashcards: System Security Fundamentals — 72 cards

All cards

1Question

What does system security protect against?

Answer

Unauthorized access, modification, destruction, data theft, malware, vulnerability exploitation, and denial of service.

2Question

What are the three components of the CIA Triad?

Answer

Confidentiality, integrity, and availability.

3Question

What does confidentiality limit in the CIA Triad?

Answer

Information access to authorized users.

4Question

What does integrity prevent in the CIA Triad?

Answer

Unauthorized modification or corruption.

5Question

What does availability ensure in the CIA Triad?

Answer

Systems and resources remain accessible when required.

6Question

What does authentication verify?

Answer

Who a user is.

7Question

What does authorization determine?

Answer

What an authenticated user may do.

8Question

What does accountability track?

Answer

Actions performed by users.

9Question

What is a control hijacking attack?

Answer

It manipulates a program's execution flow to run unintended or attacker-controlled code.

10Question

Which program elements are commonly targeted in control hijacking?

Answer

Return addresses, function pointers, jump addresses, exception handlers, and stack control information.

11Question

What causes a buffer overflow?

Answer

Writing more data into a fixed-size buffer than it can hold, overwriting adjacent memory.

12Question

What happens in a stack-based buffer overflow?

Answer

Data beyond a local buffer overwrites nearby stack data, including the return address.

13Question

What can happen when a function returns after a stack-based buffer overflow?

Answer

Execution may transfer to an unintended location.

14Question

Name common causes of buffer overflow.

Answer

Lack of bounds checking, unsafe string operations, incorrect memory management, improper input validation, and programming errors.

15Question

Which C functions are historically unsafe and can cause buffer overflows?

Answer

gets(), strcpy(), strcat(), and sprintf().

16Question

What value range does an unsigned 8-bit integer represent?

Answer

From 0 to 255.

17Question

What happens when you add 1 to 255 in an unsigned 8-bit integer?

Answer

It wraps around to 0.

18Question

What is the range of a 32-bit signed integer?

Answer

From −231-2^{31} to 231−12^{31}-1.

19Question

How can integer overflow cause buffer overflow vulnerabilities?

Answer

By turning large sizes into small values causing insufficient memory allocation.

20Question

Which programming aspects can integer overflow affect?

Answer

Memory allocation, array sizes, buffer sizes, loop conditions, file sizes, and length calculations.

21Question

Name some browser protections against attacks.

Answer

Sandboxing, ASLR, DEP/NX, site isolation, process isolation, and the Same-Origin Policy.

22Question

Can attackers bypass browser protections?

Answer

Yes, by exploiting additional vulnerabilities.

23Question

What is sandboxing in software execution?

Answer

Executing a program inside a restricted environment with limited access.

24Question

How does sandboxing restrict an application?

Answer

By enforcing policies and limited permissions on its actions.

25Question

What is the purpose of isolation in computing?

Answer

To separate processes or resources to prevent unwanted interaction.

26Question

What defines robust software behavior?

Answer

Continuing to behave safely and correctly under unexpected input or abnormal conditions.

27Question

Name one key technique to improve software robustness.

Answer

Input validation.

28Question

Name another key technique to improve software robustness.

Answer

Least privilege.

29Question

Name a third key technique to improve software robustness.

Answer

Secure memory management.

30Question

What does static analysis examine in program analysis?

Answer

A program without executing it.

31Question

What does dynamic analysis examine in program analysis?

Answer

A program during execution.

32Question

What does concolic analysis combine in program analysis?

Answer

Concrete execution with symbolic reasoning.

33Question

What vulnerabilities can static analysis detect?

Answer

Possible buffer overflows, uninitialized variables, dead code, memory problems, dangerous functions, some injection vulnerabilities, and incorrect data flows.

34Question

What are the limitations of static analysis?

Answer

It may produce false positives and miss runtime-dependent vulnerabilities.

35Question

What issues can dynamic analysis detect?

Answer

Memory violations, crashes, invalid memory accesses, runtime behavior, and resource problems.

36Question

What is the limitation of dynamic analysis?

Answer

It only explores executed paths.

37Question

What is the main limitation of concolic execution?

Answer

Path explosion.

38Question

What is a privilege in computer security?

Answer

Permission to perform a specific operation by a user, process, or program.

39Question

What does vertical privilege escalation involve?

Answer

Moving from a low-privileged user to a high-privileged user.

40Question

What does horizontal privilege escalation involve?

Answer

Accessing another user at a similar privilege level.

41Question

What is the purpose of access control?

Answer

To determine which subjects can access which resources and operations.

42Question

What question does authentication answer?

Answer

Who are you?

43Question

What question does authorization answer?

Answer

What are you allowed to do?

44Question

What does DAC allow in access control?

Answer

Resource owners decide access permissions.

45Question

On what basis does ABAC make access decisions?

Answer

Attributes like user, role, device, location, resource, time, and environment.

46Question

What does operating system security protect?

Answer

Processes, memory, files, users, devices, system calls, the kernel, and network resources.

47Question

What is process isolation in operating systems?

Answer

Each process has its own protected address space preventing direct memory access by others.

48Question

Which permissions can memory pages have in an OS?

Answer

Read, write, and execute permissions represented by R, W, and X.

49Question

What does an R-X memory page allow?

Answer

It is readable and executable but not writable.

50Question

Name some major operating-system security mechanisms.

Answer

Authentication, authorization, access control, process isolation, memory protection, privilege separation, secure boot, file permissions, auditing and logging, and security updates.

51Question

What is exploitation in software security?

Answer

It is the process of taking advantage of a software or system vulnerability to cause unintended behavior.

52Question

What happens during code injection attacks?

Answer

An attacker causes unintended code or commands to be executed.

53Question

What is a use-after-free vulnerability?

Answer

It occurs when a program uses memory after it has been released.

54Question

What risks can use-after-free vulnerabilities cause?

Answer

They can cause crashes, data corruption, unexpected behavior, or code-execution vulnerabilities.

55Question

What does return-oriented programming use to perform actions?

Answer

It uses existing instruction sequences called gadgets.

56Question

How does return-oriented programming achieve desired behavior?

Answer

By chaining gadgets without injecting a new program.

57Question

What is fuzzing in software testing?

Answer

An automated testing technique supplying unexpected or malformed inputs to a program.

58Question

What are the main steps in a basic fuzzing process?

Answer

Generate input, submit to application, monitor behavior, save notable inputs, analyze results.

59Question

What types of bugs can fuzzing discover?

Answer

Crashes, buffer overflows, integer bugs, memory corruption, parser vulnerabilities, and input-validation errors.

60Question

How does mutation-based fuzzing generate inputs?

Answer

By modifying valid inputs.

61Question

How does generation-based fuzzing create inputs?

Answer

From a specification or grammar.

62Question

What characterizes black-box fuzzing?

Answer

It has little internal knowledge of the program.

63Question

What distinguishes white-box fuzzing?

Answer

It uses the internal structure of the program.

64Question

What feedback does grey-box fuzzing use?

Answer

Limited feedback such as code coverage.

65Question

What does ASLR do in security defenses?

Answer

ASLR randomizes memory locations.

66Question

What is the difference between a vulnerability and an exploit?

Answer

A vulnerability is a system weakness; an exploit takes advantage of it.

67Question

What are the main program-analysis approaches?

Answer

Static, dynamic, and concolic analysis.

68Question

How does fuzzing differ from penetration testing?

Answer

Fuzzing tests inputs automatically; penetration testing assesses full attack paths.

69Question

What security defense prevents execution from data regions?

Answer

DEP/NX prevents execution from designated data regions.

70Question

What is the role of stack canaries in security?

Answer

Stack canaries detect certain stack overflows.

71Question

What does Control-Flow Integrity (CFI) enforce?

Answer

CFI restricts execution to valid control-flow paths.

72Question

What does sandboxing do in application security?

Answer

Sandboxing restricts compromised applications.

Test yourself with the quiz

Test your knowledge with 29 questions on System Security Fundamentals.

1. Which statement best describes the overall purpose of system security?

2. A security policy prevents an unauthorized employee from viewing confidential files but permits authorized employees to read them. Which CIA Triad property does this policy primarily protect?

Take the quiz →

Read the study sheet

Review the complete course in the study sheet for System Security Fundamentals.

See study sheet →

Similar courses

Create your own flashcards

Import your course and AI generates flashcards in 30 seconds.

Flashcard generator