Document information
- University
- Politecnico di Milano
- Degree programme
- Computer Engineering
- Subject
- Computer Security
- Classification
- Exam · Full exam
- Content
- Exam paper only
- Original format
- Text
- Searchable text
Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Practicing with exam questions - Take 1 April 10, 2015 Question You are having a discussion with a friend about cryptography. Your friend makes a series of statements. Please tell us how you would respond (True or False). Note that you have to answer with an explanation to get
Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Practicing with exam questions - Take 1 April 10, 2015 Question You are having a discussion with a friend about cryptography. Your friend makes a series of statements. Please tell us how you would respond (True or False). Note that you have to answer with an explanation to get
Import quality: text was extracted directly from the original document.
Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.
Practicing with exam questions - Take 1 April 10, 2015 Question You are having a discussion with a friend about cryptography. Your friend makes a series of statements. Please tell us how you would respond (True or False). Note that you have to answer with an explanation to get any points. Example You should not run unknown programs: True. Reason: they may contain a Trojan horse or other types of malware. A. The reason why the 2048bit RSA is more robust to brute forcing that a 256bit AES, is because the key is longer. B. No encryption algorithm is perfect, as they are all vulnerable to brute forcing. C. An encryption algorithm is broken when there is at least one way to derive the key from a given amount of ciphertext. 1 of 10 Question We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? A. Passwords must be at least 12 characters long, with at least one lowercase, one uppercase, one number and one special character. Passwords must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 3 wrong attempts. B. Passwords must be at least 8 characters long, and not belong to a dictionary of common passwords. They must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 5 wrong attempts. C. 2 of 10 Question You are having a discussion about vulnerability, exploits and risk. Please say if you agree or not with the following statements (i.e. if they are true or false), and in each case explain why. A. When a vulnerability is found and reported to the vendor, risk for the users decreases. B. Release of a patch without vulnerability details lower risks, as opposed to full disclosure of patch and vulnerability…
First page of the document.