Quiz: System Security Fundamentals — 11 questions

Detailed questions and answers

1. Which security objective ensures that information is accessible to authorized users when it is needed?

Availability
Integrity
Confidentiality
Accountability

Availability

Explanation

Availability concerns keeping systems and resources accessible when required. Confidentiality instead limits information access, while integrity addresses unauthorized modification or corruption.

2. A user successfully proves their identity and is then allowed to view but not alter a file. Which security functions are illustrated by these two steps?

Authentication followed by authorization
Authorization followed by authentication
Accountability followed by authentication
Integrity followed by confidentiality

Authentication followed by authorization

Explanation

Authentication verifies who the user is, and authorization determines what that authenticated user may do. Accountability records actions rather than granting permissions.

3. What condition directly defines a buffer overflow?

Redirecting execution to attacker-controlled instructions
Writing more data into a fixed-size buffer than it can hold
Exceeding the numeric range of an integer type
Deleting data from an adjacent memory region

Writing more data into a fixed-size buffer than it can hold

Explanation

A buffer overflow occurs when writes exceed the capacity of a fixed-size memory buffer. Exceeding an integer's numeric range is an integer overflow, while redirecting execution describes control hijacking.

4. How can a stack-based buffer overflow redirect a function's execution after the function returns?

It changes the numeric range supported by a local integer
It overwrites a nearby return address with an unintended value
It prevents the operating system from authenticating the caller
It increases the allocated capacity of the stack buffer

It overwrites a nearby return address with an unintended value

Explanation

A stack overflow can overwrite nearby stack data, including the return address, causing the return to transfer control to an unintended location. Changing an integer's range does not alter the function's return target.

5. What does the CIA triad in system security stand for?

Control, Integrity, Access
Confidentiality, Identity, Authorization
Control, Integrity, Authentication
Confidentiality, Integrity, Availability

Confidentiality, Integrity, Availability

Explanation

The CIA triad represents the core principles of system security: confidentiality, integrity, and availability. The other options mix related security concepts but do not match the standard triad.

6. What are the three core properties of the CIA triad in system security?

Control, Integrity, Accessibility
Confidentiality, Integrity, Availability
Control, Authentication, Availability
Confidentiality, Authentication, Authorization

Confidentiality, Integrity, Availability

Explanation

The CIA triad consists of Confidentiality, Integrity, and Availability, which are fundamental principles for protecting information systems. The distractor options mix unrelated security concepts or omit key properties.

7. What is the primary goal of control hijacking and buffer overflow attacks in software security?

To manipulate a program's execution flow to run unintended code or instructions.
To improve program performance by optimizing memory usage.
To prevent unauthorized access by encrypting data.
To detect and fix bugs in software before deployment.

To manipulate a program's execution flow to run unintended code or instructions.

Explanation

Control hijacking and buffer overflow attacks aim to manipulate the execution flow of a program, often by overwriting control data like return addresses. The other options relate to performance optimization, security measures, or bug fixing, which are not the primary goals of these attacks.

8. How does sandboxing differ from isolation in browser security?

Sandboxing and isolation are essentially the same, both preventing any external access to a program or process.
Sandboxing isolates processes to prevent interference, whereas isolation limits a program's access to hardware and network resources.
Sandboxing restricts a program's actions within a limited environment, while isolation separates processes or resources so that compromising one does not affect others.
Sandboxing involves separating processes at the hardware level, while isolation is a software-based security measure.

Sandboxing restricts a program's actions within a limited environment, while isolation separates processes or resources so that compromising one does not affect others.

Explanation

Sandboxing executes a program in a restricted environment, limiting its access to system resources, whereas isolation separates components to prevent one from affecting others. The key difference is that sandboxing focuses on restricting actions within an environment, while isolation emphasizes separation of components.

9. What is a primary consequence of a buffer overflow in software security?

It always results in system shutdown.
It guarantees the system's confidentiality.
It prevents any form of attack from succeeding.
It can lead to memory corruption and unintended code execution.

It can lead to memory corruption and unintended code execution.

Explanation

A buffer overflow can overwrite adjacent memory, leading to memory corruption and potentially allowing execution of malicious code. The other options are incorrect because buffer overflows do not inherently guarantee confidentiality, prevent attacks, or cause shutdowns.

10. How can robust software development practices be applied to minimize security vulnerabilities in a software project?

Implement thorough input validation, secure error handling, and regular testing including fuzzing and penetration testing.
Use only default security settings without additional security measures.
Rely solely on user reports to identify bugs and fix them after deployment.
Avoid code reviews to save time and focus on feature development.

Implement thorough input validation, secure error handling, and regular testing including fuzzing and penetration testing.

Explanation

Applying robust software development involves practices like input validation, secure defaults, and comprehensive testing to prevent vulnerabilities. Relying solely on user reports delays vulnerability detection and leaves the software exposed in the meantime.

11. Which key feature characterizes access control models in security systems?

They are only applicable in physical security environments.
They rely solely on user passwords for security decisions.
They primarily focus on encrypting data to prevent unauthorized access.
They determine which subjects can access which resources and what operations they may perform.

They determine which subjects can access which resources and what operations they may perform.

Explanation

Access control models define how permissions are granted to subjects for resources, specifying who can do what. The other options are incorrect because they either focus on encryption, are overly simplistic, or pertain to physical security, not access control models.

Review with flashcards

Memorize the answers with 11 flashcards on System Security Fundamentals.

What is system security?

Protection of computer systems and data from unauthorized access and threats.

What are the three components of the CIA triad?

Confidentiality, integrity, and availability.

What is a control hijacking attack?

It manipulates program flow to execute unintended or attacker-controlled code.

See flashcards →

Read the study sheet

Read the complete study sheet on System Security Fundamentals.

See study sheet →

Similar courses

Create your own quizzes

Import your course and AI generates quizzes with corrections in 30 seconds.

Quiz generator