BIT303 Information Security

Information Security TU Board 2081 question paper

12 questionsSit this paper (timed)

Tribhuvan University

Bachelor of Information Technology

Semester 5 · TU Board 2081

Course Title: Information Security (BIT303)

Full Marks: 60Pass Marks: 24Time: 3 hours

Candidates are required to give their answers in their own words as far as practicable.

Group A

Attempt any Two questions.(2 × 10 = 20)

  1. 1.

    Consider p=11 and q=7 in a RSA cryptosystem. i. What is a public key pair (e, n)? ii. What is a private key pair (d, n)? iii. What is ciphertext for M=6?

    10
  2. 2.

    Discuss how encryption and decryption is done in the DES algorithm.

    10
  3. 3.

    Define subjects, objects and access rights in access control with suitable examples. How role based access control is different from attribute based access control?

    10

Group B

Attempt any Eight questions(8 × 5 = 40)

  1. 4.

    How online and offline dictionary attacks are done in password based authentication systems?

    5
  2. 5.

    Describe the roles of relying parties, attribute providers and identity providers in Open Identity Trust Framework.

    5
  3. 6.

    Define zombies, rootkits and Trojans.

    5
  4. 7.

    Briefly describe the status of cyber law in Nepal.

    5
  5. 8.

    Discuss various methods of risk treatment during security risk analysis.

    5
  6. 9.

    What is the use of S-box in DES? Illustrate S-box operation with an example.

    5
  7. 10.

    How hash value is generated by the SHA-2 hash function.

    5
  8. 11.

    Write Rabin Miller Algorithm for primality testing. Test whether 341 is prime or not using the algorithm.

    5
  9. 12.

    Define interception, repudiation and incapacitation with examples.

    5

— The End —