Document information
- University
- Politecnico di Milano
- Degree programme
- Computer Engineering
- Subject
- Computer Security
- Academic year
- 2013-2014
- Classification
- Exam · Full exam
- Content
- Exam paper only
- Original format
- Text
- Searchable text
Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Computer Security 2013/2014 - Proff. Maggi & Zanero Premise In addition to the questions presented in this document, in this year exam there will be 2 types of exercises taken from previous years' exams: ● memory errors (e.g., buffer overflows) ● scenarios (e.g., description of
Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Computer Security 2013/2014 - Proff. Maggi & Zanero Premise In addition to the questions presented in this document, in this year exam there will be 2 types of exercises taken from previous years' exams: ● memory errors (e.g., buffer overflows) ● scenarios (e.g., description of
Import quality: text was extracted directly from the original document.
Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.
Computer Security 2013/2014 - Proff. Maggi & Zanero Premise In addition to the questions presented in this document, in this year exam there will be 2 types of exercises taken from previous years' exams: ● memory errors (e.g., buffer overflows) ● scenarios (e.g., description of a network layout and implementation of firewall rules), yet a bit more "guided" ● web application vulnerabilities (e.g., SQL injections, XSSs) The points assigned to each question depend on how many questions there will be at the exam. Focus on giving a concise yet complete answer in the space provided. Long answers will not be accepted because most of the time they are harder and more ambiguous to understand. Example Questions (answers given separately) Question 1 (2–4 pts) You are attending a hacking conference and you notice that a software vendor offers 10.000 Euro to whoever reports a previously unknown vulnerability to them, and an additional 20.000 Euro to whoever reports a working exploit for that vulnerability. Please tell us how you would respond (True or False). Note that you have to answer with an explanation to get any points: A. the company is basically asking to report zeroday vulnerabilities. True (by definition, a zeroday vulnerability is that the vulnerability is unknown until its disclosure). B. the existence of an undisclosed vulnerability implies a high level of risk for that vendor. False (the risk depends on other factors than the existence of a vulnerability). True (the vulnerability could be known to someone, who may have a zeroday exploit). Both true and false answers are accepted, if reasons are correctly explained. Question 2 (2-4 pts) Say if the following statements are True or False. Note that you have to answer with an explanation to get any points. Example You…
First page of the document.