CS/IS 196 Final Exam Review Final Exam: Wednesday, December 12
Final Exam Overview Chapters 13 through 25 Multiple Choice Similar to questions in the homework assignments. 50 questions You will have the full class time to complete
Chapter 13 Intrusion Detection Systems and Network Security IDS Components: Traffic collector Signature database User interface Host Based (active vs. passive) Advantages Disadvantages Network Based
Chapter 14 System Hardening & Baselines Baselining Sandboxing Antispam Egress Filtering Updates: Hotfix Patch Service pack
Chapter 15 Types of Attacks and Malicious Software Malware Spoofing War dialing War driving Trojan Logic Bomb Worm Buffer overflow
Chapter 16 E-mail and Instant Messaging Spam Email encryption PGP SMIME
Chapter 17 Web Components SSL Stripping Attack http and https FTP and SFTP SSL/TLS Cross-site scripting attack
Chapter 18 Secure Software Development Secure Development Lifecycle Phases Minimizing the attack surface (Design Phase) Database attacks SQL injection Spiral method Fuzz testing
Chapter 19 Disaster Recovery, Business Continuity, and Organizational Policies Alternate sites Hot Warm Cold RAID 1 (disk mirroring) 5 ( data spreading with parity ) Backups Full Differential Incremental Delta
Chapter 20 Risk Management Vulnerabilities Threat Vectors Qualitative risk assessment SLE, ARO, ALE Compute ALE given SLE and ARO ALE = SLE * ARO
Chapter 21 Change Management Least privilege Separation of duties Change management primary objective
Chapter 22 Incident Response Information Criticality Scanning Threats Remote Administration Trojan (Tool) (RAT) Data Minimization Quarantine
Chapter 23 Computer Forensics Software Bomb Disk/Drive Partition Free space Volatility of data CPU RAM Hard drive Kernel tables
Chapter 24 Legal Issues and Ethics Law Statutory Common Administrative Computer trespass CAN-SPAM Act Sarbanes-Oxley Act
Chapter 25 Privacy Freedom of Information Act (FOIA) Cookie cutter Country with poor privacy practices Family Education Records and Privacy Act of 1974 Data Destruction Shredding Degaussing Burning Wiping
The Final Exam Bring a #2 pencil and an eraser. Mr. Hodges will supply the scantron forms. Closed book, closed note, closed computer.
Questions Any Questions?