Lesson 4.9.3.2
4.9.3.2 Internet security Quiz: AQA Computer Science, Unit 9
20 questions
In partnership with Revision Ninja
Lesson 4.9.3.2, Internet security: 20 multiple choice questions for the AQA Computer Science (7517), Unit 9: Fundamentals of communication and networking, written with Revision Ninja.
Host it live on the board and students join with a game code on their own devices, or revise alone with Free Play. The answers are revealed in the game.
The 20 questions
-
What does a packet-filtering firewall do?
- It stores a copy of every web page requested so that users can load pages faster
- It inspects each packet's header fields and allows or blocks it according to a set of rules
- It translates domain names into IP addresses for the devices on the local network
- It encrypts all outgoing traffic so that no one can read it in transit across the network
-
What is a proxy server in the context of a firewall?
- A server that assigns private IP addresses to devices as they join the network
- A server that keeps a permanent record of every connection state on the router
- A server that sits between clients and the Internet and makes requests on the clients' behalf, hiding them
- A server that checks the header of every packet against a list of allowed MAC addresses only
-
What does a stateful inspection firewall track?
- The number of users who are logged in to each web server on the network at any given moment
- The type of cable used by each device that is connected to the firewall, so that unknown cables can be blocked
- Only the size of each packet, so that oversized packets can be blocked before they reach the network segment
- The state of connections, so it allows return traffic only for connections that were started from inside
-
In symmetric encryption, what is used?
- A public key for encryption and a different private key for decryption
- A different key for every packet sent through the network
- The same key for both encryption and decryption
- No key at all, relying on a hash of the message instead
-
In asymmetric encryption, what is used?
- A key that is never stored and is generated afresh for every message
- Two private keys, one held by each party to the connection
- One shared secret key that is used for both encryption and decryption
- A public key to encrypt, and a related private key to decrypt
-
Why is key exchange a problem for symmetric encryption?
- Symmetric keys are too long to be transmitted across any network at all
- Symmetric encryption cannot be used for ordinary data traffic on the Internet
- Symmetric keys change after every packet, so they cannot be shared in advance
- The shared key must reach both parties securely, so that an eavesdropper cannot obtain it
-
How does asymmetric encryption help with key exchange?
- The key is embedded in the header of each packet so that routers can read it and then decrypt the payload
- A session key can be sent encrypted with the other party's public key, which only the owner of the private key can decrypt
- The private key is sent openly so that the other party can decrypt the message that is sent back to the sender
- Both parties use the same private key, so no key exchange is needed at all because the key is always known
-
What does a digital certificate do?
- It identifies the router that forwards each packet across the Internet, so that the route can be verified
- It binds a public key to an identity, and is issued and signed by a trusted certificate authority
- It stores the user's password in encrypted form on the server, so that the password can be checked on login
- It replaces the need for encryption by checking that the data is readable by the recipient at arrival time
-
What does a digital signature provide?
- A copy of the message stored on a trusted server for later audit
- Encryption of the message so that only the intended recipient can read it
- Evidence that the message came from the holder of a private key and has not been altered
- A list of IP addresses that have been allowed to access the message
-
A message is signed with the sender's private key. How does the recipient verify the signature?
- By using the sender's public key to check the signature against the message
- By comparing the message with a copy stored in a DNS record
- By decrypting the signature using the recipient's own private key
- By asking the sender's firewall to confirm the message's header
-
What is a worm?
- A program that encrypts a user's files and demands payment for the key
- Malware that replicates itself across networks without needing to attach to a host file
- A device driver that is copied into the operating system during installation
- Malware that disguises itself as legitimate software to trick the user into running it
-
What is a trojan?
- Software that records the user's keystrokes and sends them to the manufacturer only
- Malware disguised as legitimate software that the user installs, giving an attacker access
- A firewall rule that blocks all traffic from an unknown range of addresses
- Malware that spreads by copying itself across network connections without any user action
-
What is a virus?
- A firewall rule that blocks packets by port number to improve security
- A certificate that proves the identity of a website to its visitors
- Code that attaches itself to a host program or file, and spreads when that host is run or opened
- A separate program that runs automatically across a network without attaching to anything
-
Which vulnerability do worms commonly exploit?
- Strong encryption keys that are changed too often by the operating system
- Digital certificates that are signed by a trusted certificate authority
- Unpatched flaws in software or services that can be reached over the network
- Packets that are routed through several routers before they arrive
-
How can improved code quality help protect against worms, trojans and viruses?
- Fewer bugs and vulnerabilities leave fewer weaknesses for malware to exploit
- Better code encrypts malware so that it cannot spread across the network
- Better code allows firewalls to be removed without any loss of security at all
- Better code makes malware run more slowly, so that users can detect it easily
-
Which measure protects against malware by monitoring behaviour?
- Disabling the firewall to reduce the load placed on the processor
- Turning off all software updates so that the existing software remains stable
- Storing all passwords in plain text so that they can be checked quickly
- Monitoring running processes and network activity to detect unusual behaviour
-
A firewall allows return traffic only for connections that an internal host started. Which type of firewall is this?
- Stateful inspection
- Packet filtering, which checks each packet on its own
- An asymmetric key pair used to protect each connection
- A proxy server, which hides the client's address from the Internet
-
A message is encrypted using the recipient's public key. Who can decrypt it?
- Only the holder of the matching private key, which is the recipient
- Anyone who has the recipient's public key, which is freely available to all
- The sender, who holds the matching private key for the message
- Any firewall on the route, because it holds all of the public keys
-
Why is a digital certificate needed for a browser to trust a server's public key?
- It encrypts the public key so that no one can copy it while it is in transit
- It proves the public key belongs to the named server, as vouched for by a trusted authority
- It replaces the need for the server to have a private key at all
- It proves the server is fast enough to process the browser's requests quickly
-
A firewall uses packet filtering. Which attack is least likely to be stopped by packet filtering alone?
- Attempts to connect to a private port that the firewall is configured to block, using a spoofed address
- A malicious payload hidden inside an allowed application protocol that exploits a flaw in the application
- A flood of packets from an IP address range that is blocked by the firewall rules, arriving on allowed ports
- Connections to a port that has no service and is closed to all traffic, which the firewall would refuse
Related quizzes
- Data types Quiz · 4.1.1.1 · 20 questions
- Entity relationship modelling Quiz · 4.10.1.1 · 20 questions
- Big Data Quiz · 4.11.1.1 · 20 questions
- Function types and first-class objects Quiz · 4.12.1.1 · 20 questions
- Analysis Quiz · 4.13.1.1 · 20 questions
- Data structures and abstract data types Quiz · 4.2.1.1 · 20 questions
- Breadth-first and depth-first search Quiz · 4.3.1.1 · 20 questions
- Problem-solving and algorithms Quiz · 4.4.1.1 · 20 questions
- Natural, rational, irrational and real numbers Quiz · 4.5.1.1 · 20 questions
- Programming concepts: sequence, selection and iteration Quiz · 4.1.1.2 · 20 questions