Quiz: System Security Fundamentals — 29 questions

Detailed questions and answers

1. Which statement best describes the overall purpose of system security?

It protects systems and data from unauthorized access, damage, theft, and service disruption.
It ensures that users can access every resource without administrative restrictions.
It improves system performance by allocating more resources to high-priority applications.
It replaces operating-system functions with independent security software components.

It protects systems and data from unauthorized access, damage, theft, and service disruption.

Explanation

System security protects computers, software, networks, and data against threats such as unauthorized access, modification, malware, exploitation, and denial of service. Improving performance may be useful, but it is not the defining objective of system security.

2. A security policy prevents an unauthorized employee from viewing confidential files but permits authorized employees to read them. Which CIA Triad property does this policy primarily protect?

Confidentiality
Availability
Accountability
Integrity

Confidentiality

Explanation

Confidentiality limits information access to authorized users, which is the property addressed by restricting file viewing. Integrity concerns unauthorized modification, while availability concerns access to resources when needed.

3. After a user logs in successfully, which security function determines whether that user may delete a particular database record?

Authentication
Authorization
Accountability
Identification

Authorization

Explanation

Authorization determines which actions an authenticated user is permitted to perform. Authentication verifies identity, whereas accountability records actions performed by users.

4. What is the defining action in a control hijacking attack?

Compressing program data so the application uses less memory
Manipulating execution flow so unintended or attacker-controlled instructions run
Restricting network traffic so unauthorized packets cannot reach a host
Changing file permissions so legitimate users lose access to resources

Manipulating execution flow so unintended or attacker-controlled instructions run

Explanation

Control hijacking changes a program's execution flow so it runs unintended instructions or attacker-controlled code. Restricting traffic and changing permissions are security controls, not the defining mechanism of control hijacking.

5. When does a buffer overflow occur?

When a program rejects input because its length matches the buffer capacity
When a program reads data from a buffer without changing its contents
When a program stores data in a buffer that was dynamically allocated at runtime
When a program writes more data into a fixed-size buffer than it can hold

When a program writes more data into a fixed-size buffer than it can hold

Explanation

A buffer overflow occurs when writes exceed a fixed-size buffer's capacity, potentially overwriting adjacent memory. Dynamic allocation or reading without overwriting does not by itself constitute a buffer overflow.

6. How can a stack-based buffer overflow redirect execution after a function returns?

The operating system converts the overwritten buffer into a separate process
The function allocates a larger stack frame and resumes at its original caller
Excess data automatically encrypts the function's local variables before return
Excess data overwrites a nearby return address with an unintended target

Excess data overwrites a nearby return address with an unintended target

Explanation

Data written beyond a local stack buffer can overwrite nearby stack information, including the return address, causing the function to return to an unintended location. Encryption, stack growth, and process creation do not explain this control-flow transfer.

7. What value results from adding 1 to an unsigned 8-bit integer containing 255?

255 because the value is saturated
0 through wraparound
128 through range truncation
1 through signed conversion

0 through wraparound

Explanation

An unsigned 8-bit integer represents values from 0 through 255, so adding 1 to 255 wraps around to 0. The signed range and saturation behavior do not describe unsigned 8-bit arithmetic.

8. How can integer overflow contribute to a buffer overflow?

It can make every input string automatically exceed its destination buffer.
It can prevent all memory writes by converting the size into a protected pointer.
It can make a calculated size unexpectedly small, leading to insufficient allocation.
It can replace a program's control flow with browser isolation before allocation.

It can make a calculated size unexpectedly small, leading to insufficient allocation.

Explanation

Integer overflow can reduce a large calculated size to an unexpectedly small value, causing insufficient memory allocation and later writes beyond the allocated buffer. The overflow affects the size calculation; it does not automatically enlarge every input or directly provide browser isolation.

9. Which browser protection restricts a web document's ability to interact with resources from a different origin?

Process isolation
Data Execution Prevention
The Same-Origin Policy
Address Space Layout Randomization

The Same-Origin Policy

Explanation

The Same-Origin Policy restricts interactions between resources from different origins. ASLR randomizes memory locations, DEP/NX limits execution of non-executable memory, and process isolation separates execution contexts.

10. What does sandboxing primarily do to an application?

It analyzes the application without running its instructions
It separates the application from every other system component
It runs the application with restricted permissions and resource access
It verifies the identity of each user before execution

It runs the application with restricted permissions and resource access

Explanation

Sandboxing places an application in a restricted environment that limits access to resources such as files, networks, hardware, and system calls. Separating components from one another describes isolation rather than sandboxing.

11. A system places two applications in separate processes so that one cannot interfere with the other, even when their permissions are similar. Which security concept does this illustrate?

Isolation, because it creates a boundary between components
Authentication, because it distinguishes the two applications
Input validation, because it filters data before processing
Sandboxing, because it limits each application's available actions

Isolation, because it creates a boundary between components

Explanation

Isolation separates processes, users, applications, or resources to prevent unwanted interaction. Sandboxing instead focuses on restricting what an application may do through policies and limited permissions.

12. Which practice is a recognized technique for improving software robustness?

Granting broad permissions so unexpected operations can continue
Ignoring unusual input to reduce the amount of error handling
Disabling code review to accelerate the release process
Using secure defaults and testing the system for security weaknesses

Using secure defaults and testing the system for security weaknesses

Explanation

Secure defaults and security testing are among the techniques that improve robustness, along with input validation, safe error handling, and least privilege. Broad permissions and reduced review weaken the system rather than making it more robust.

13. Which analysis method combines concrete execution with symbolic reasoning to explore alternative program paths?

Static analysis
Manual code review
Concolic analysis
Dynamic analysis

Concolic analysis

Explanation

Concolic analysis executes a program with concrete values while using symbolic reasoning to derive additional path constraints. Static analysis does not execute the program, while dynamic analysis observes execution without this combined symbolic approach.

14. A concolic testing tool executes a program with one concrete input and then derives another input from symbolic constraints. What is the main limitation that can restrict this approach?

The program cannot be executed with concrete values
The technique examines source code without running it
The number of execution paths can grow explosively
The method cannot maintain constraints during execution

The number of execution paths can grow explosively

Explanation

Concolic execution can generate inputs for alternative paths, but path explosion makes systematic exploration difficult as the number of paths increases. The method does execute the program with concrete inputs and maintains symbolic constraints.

15. Which example best represents a privilege?

A rule that separates two applications into different processes
Permission for a process to modify a protected system configuration
A record describing the identity used to log into an account
A technique that detects flaws without executing a program

Permission for a process to modify a protected system configuration

Explanation

A privilege is permission granted to a user, process, or program to perform a particular operation, such as changing system configuration. Identity records, process separation, and program analysis describe different security concepts.

16. An attacker with an ordinary account accesses another ordinary user's files without gaining administrator capabilities. What type of privilege escalation is this?

Vertical escalation, because the attacker moves between different accounts
Authentication failure, because the attacker cannot identify the account
Role-based control, because permissions are assigned through roles
Horizontal escalation, because the accessed user has a similar privilege level

Horizontal escalation, because the accessed user has a similar privilege level

Explanation

Horizontal privilege escalation gives one user access to another user at a similar privilege level. Vertical escalation instead involves moving from a lower privilege level to a higher one.

17. What is the primary function of access control?

To determine which subjects may perform which operations on resources
To establish and verify the identity claimed by a subject
To encrypt every resource before any subject can access it
To detect software defects by examining program execution

To determine which subjects may perform which operations on resources

Explanation

Access control determines which subjects can access which resources and which operations they may perform. Establishing identity is authentication, while encryption and program analysis serve different security purposes.

18. Which access-control model assigns permissions to roles and then grants users access through those roles?

Attribute-based access control
Role-based access control
Discretionary access control
Mandatory access control

Role-based access control

Explanation

Role-based access control assigns permissions to roles, with users receiving permissions through their assigned roles. Discretionary control relies on resource owners, mandatory control uses centrally defined policies and labels, and attribute-based control evaluates attributes such as location or device.

19. What security property prevents one process from directly reading another process’s memory under normal conditions?

Shared access places related processes in a common address space.
File permissions restrict processes from opening executable files.
Privilege separation gives every process identical memory permissions.
Process isolation assigns each process a protected address space.

Process isolation assigns each process a protected address space.

Explanation

Process isolation separates address spaces so that a process cannot normally access another process’s memory directly. Shared access would permit processes to read memory in a common space, which is the opposite property.

20. A memory page marked R-X has which permissions?

It can be written and executed but not read.
It can be read and executed but not written.
It can be read and written but not executed.
It can be read, written, and executed.

It can be read and executed but not written.

Explanation

The R, W, and X flags represent read, write, and execute permissions, so R-X permits reading and execution without writing. An R-W page instead permits reading and writing but lacks execute permission.

21. Which set of resources falls within the protection responsibilities of operating system security?

Printers, keyboards, displays, applications, and removable media
Processes, memory, files, users, devices, and system calls
Passwords, encryption keys, browsers, networks, and cloud accounts
Source code, user interfaces, websites, databases, and documentation

Processes, memory, files, users, devices, and system calls

Explanation

Operating system security protects processes, memory, files, users, devices, system calls, the kernel, and network resources. The other sets contain related assets but do not represent the stated scope as completely.

22. What does exploitation mean in the context of software security?

Identifying a weakness without attempting to affect system behavior
Applying a security update to remove a weakness from software
Using a vulnerability to cause unintended system behavior
Monitoring normal program activity to detect unusual system behavior

Using a vulnerability to cause unintended system behavior

Explanation

Exploitation takes advantage of a vulnerability to produce unintended behavior. A vulnerability is the underlying weakness itself, so identifying one does not necessarily constitute exploitation.

23. What happens during a code injection attack?

An attacker reuses existing instruction sequences without adding commands.
Attacker-controlled input is interpreted or executed as code or commands.
A program stores valid input in memory after checking its data type.
A process accesses a released memory region after its allocation ends.

Attacker-controlled input is interpreted or executed as code or commands.

Explanation

Code injection occurs when input is caused to be interpreted or executed as code or commands, as in SQL, command, or script injection. Ordinary data remains data and does not trigger this behavior merely by being stored.

24. Which situation describes a use-after-free vulnerability?

A program executes input that has been interpreted as a shell command.
A process reads memory belonging to another isolated process.
A program uses existing instruction sequences to perform a task.
A program accesses memory after that memory has been released.

A program accesses memory after that memory has been released.

Explanation

A use-after-free occurs when software uses memory after releasing it, which can cause crashes, corruption, or further security consequences. Executing injected commands describes code injection, while reusing instruction sequences describes return-oriented programming.

25. What is the defining activity of fuzzing?

Restricting a program to a small set of carefully selected normal inputs
Manually examining a system to identify and exploit security weaknesses
Automatically supplying many unexpected inputs while monitoring program behavior
Reviewing source code to prove that every input-validation rule is correct

Automatically supplying many unexpected inputs while monitoring program behavior

Explanation

Fuzzing automatically generates or supplies large amounts of malformed, random, unexpected, or specially designed input and observes the results. Penetration testing is a broader investigation of exploitable weaknesses rather than this specific automated input-generation method.

26. Which sequence best represents a basic fuzzing workflow?

Create a specification, compile the target, optimize execution, and remove logs
Analyze source code, patch defects, deploy updates, and review user reports
Authenticate users, assign permissions, isolate processes, and audit access
Generate input, submit it, monitor behavior, save notable cases, and analyze results

Generate input, submit it, monitor behavior, save notable cases, and analyze results

Explanation

A basic fuzzing workflow generates test inputs, submits them, monitors for crashes or interesting behavior, saves notable inputs, and analyzes the findings. The other sequences describe security administration, software development, or unrelated analysis activities.

27. Which pairing correctly distinguishes black-box and white-box fuzzing?

Black-box fuzzing uses code coverage, while white-box fuzzing avoids implementation information.
Black-box fuzzing requires source code, while white-box fuzzing tests without implementation details.
Black-box fuzzing modifies valid inputs, while white-box fuzzing creates grammar-based inputs.
Black-box fuzzing uses little internal knowledge, while white-box fuzzing uses program structure.

Black-box fuzzing uses little internal knowledge, while white-box fuzzing uses program structure.

Explanation

Black-box fuzzing operates with little knowledge of the implementation, whereas white-box fuzzing uses internal program structure. Mutation versus generation describes how inputs are produced, not the distinction between black-box and white-box knowledge.

28. Which defense makes designated memory regions non-executable, helping prevent injected code from running there?

Stack canaries
Control-flow integrity
DEP/NX
ASLR

DEP/NX

Explanation

DEP/NX marks designated data regions as non-executable, blocking code execution from those areas. ASLR instead makes memory addresses harder to predict, so it does not provide the same protection.

29. Which sequence correctly distinguishes a vulnerability, an exploit, and an attack?

A malicious goal, a weakness that enables it, and a defensive technique against it
An unusual behavior, a complete assessment, and a technique for restricting permissions
A defensive control, an unexpected input, and a weakness discovered during testing
A weakness, a technique that uses it, and broader malicious activity pursuing a goal

A weakness, a technique that uses it, and broader malicious activity pursuing a goal

Explanation

A vulnerability is a weakness, an exploit is a technique, code, or input that takes advantage of it, and an attack is broader malicious activity aimed at achieving a goal. Treating the vulnerability itself as the exploit confuses the weakness with the means of using it.

Review with flashcards

Memorize the answers with 72 flashcards on System Security Fundamentals.

What does system security protect against?

Unauthorized access, modification, destruction, data theft, malware, vulnerability exploitation, and denial of service.

What are the three components of the CIA Triad?

Confidentiality, integrity, and availability.

What does confidentiality limit in the CIA Triad?

Information access to authorized users.

See flashcards →

Read the study sheet

Read the complete study sheet on System Security Fundamentals.

See study sheet →

Similar courses

Create your own quizzes

Import your course and AI generates quizzes with corrections in 30 seconds.

Quiz generator