CHAPTER 1 – OPERATING SYSTEMS SECURITY: KEEPING COMPUTERS
AND NETWORKS SECURE
TRUE/FALSE
1. In the world of computers and networks, the operating system provides both the lock and the key to
information.
2. The API is software that resides between the application software and the operating system kernel.
3. A MAN typically goes up to a distance of about 50 miles.
4. When new operating system software is purchased, it should be tested rigorously for security and
reliability.
5. NDS is a directory service used by Windows 2003 Server to provide a central listing of resources.
6. The Trojan horse program Trojan.Idly is designed to give the attacker command line access to the
remote operating system.
7. Source routing attacks are used to interfere with normal access to a network host, Web site, or service
by flooding a network with useless information.
8. Strobe and Nmap are two popular port-scanning programs that are used to find open ports on a remote
system.
9. In order to successfully use logon security, users must be taught to keep their passwords confidential
and to choose passwords that are difficult to guess.
10. WEP is a wireless communications authentication method.
MODIFIED TRUE/FALSE
1. Many systems use datasets to store data until it is ready to be used. _________________________
2. Ping is a utility that network users and administrators frequently use to test a network connection.
_________________________
3. In LinkState routing, the sender of a packet specifies the precise path that the packet will take to reach
its destination. _________________________
4. Using spoofing, an attacker can initiate access to a computer or can appear as just another transmission
to a computer from a legitimate source that is already connected. _________________________
5. A(n) socket is like a virtual circuit between two services or processes communicating between two
different computers or network devices. _________________________
6. Attacks on wireless networks are sometimes called auto-jacks, because the attacker may drive around
an area in a car, using a portable computer to attempt to pick up a wireless signal.
_________________________
7. Hardening involves taking specific actions to block or prevent attacks by means of operating system
and network security methods. _________________________
8. Remote access security involves requiring a user account and password to access a particular operating
system or to be validated to access a network through a directory service.
_________________________
9. Directories or folders and network printers are two important examples of resources that can be shared.
_________________________
10. Employing disaster recovery is vital when a hard disk is damaged or crashes and must be replaced.
_________________________
MULTIPLE CHOICE
1. A _____ is software or hardware placed between two or more networks that selectively allows or
denies access.
a.
gateway
c.
firewall
b.
filter
d.
DMZ
2. According to a recent survey performed by the CSI, what percentage of computer security
professionals have reported security breaches in their systems?
a.
50
c.
80
b.
65
d.
90
3. Operating system and network security is the ability to do which of the following reliably to
information?
a.
Store
d.
Grant access to
b.
Modify
e.
All of the above
c.
Protect
4. The _____ translates information from the kernel and device drivers so the application can use it.
a.
RPC
c.
BIOS
b.
API
d.
resource manager
5. Most of the first computer networks transmitted data over _____.
a.
telephone lines
c.
copper wires
b.
fiber optics
d.
frame relay
6. One WAN is composed of two or more LANs or MANs that are connected across a distance of more
than approximately _____ miles.
a.
10
c.
50
b.
30
d.
100
7. Statistics from the CSI suggest that the number of people working as computer security professionals
has been increasing by _____ percent a year since 1998.
a.
30
c.
75
b.
50
d.
100
8. Which of the following information about us should be kept private?
a.
Family information
d.
Both a and b
b.
Employment information
e.
a, b, and c
c.
Student information
9. _____ consists of a chain of activities that is necessary to complete a task, such as filling out and
transmitting forms, entering data, updating databases, and creating new files.
a.
Ensuring privacy
c.
Protecting information
b.
Workflow
d.
Compensating for human error
10. Which of the following is a reason for the failure to fully use the security features of an operating
system or network?
a.
Lack of time
b.
Inadequate training or knowledge of the features
c.
A history of doing things only in a specific way
d.
All of the above
11. At a minimum, how many groups does training involve within an organization?
a.
1
c.
3
b.
2
d.
4
12. Which of the following is a cost of deploying security within an organization?
a.
Testing security systems
d.
Both a and b
b.
Training users
e.
Both a and c
c.
Training consultants
13. Which of the following is part of the total cost of ownership of a computer network?
a.
Hardware
d.
Maintenance
b.
Software
e.
All of the above
c.
User support costs
14. What type of attack has occurred when a logged-on computer is used when that person is not present?
a.
Spoofing
c.
Buffer
b.
Denial of service
d.
Standalone workstation
15. What type of attack has occurred when an attacker gains access to a computer through the use of a
hidden program?
a.
Trojan horse
c.
Worm
b.
Buffer
d.
Source routing
16. A _____ attack is used to interfere with normal access to a network host, Web site, or service, by
flooding a network with useless information or with frames or packets containing errors that are not
identified by a particular network service.
a.
virus
c.
denial of service
b.
buffer
d.
port scanning
17. What type of attack occurs when the computer originating the attack causes several other computers to
send attack packets?
a.
Distributed denial of service
c.
Duplicated denial of service
b.
Dormant denial of service
d.
Distributed destruction of service
18. The traceroute troubleshooting utility can be used by which of the following operating systems?
a.
UNIX
d.
Windows
b.
Mac OS
e.
All of the above
c.
Netware
19. In a source routing attack, the attacker modifies the _____ and routing information to make a packet
appear to come from a different source, such as one that is already trusted for communications on a
network.
a.
destination address
c.
destination header
b.
source address
d.
source data
20. _____ can translate an IP address from a private network to a different address used on a public
network or the Internet.
a.
Routers
c.
Network address translation
b.
Proxy servers
d.
Packet filters
21. Attackers may get through a specific NAT device by using a form of source routing called _____.
a.
a macro
c.
loose source record route
b.
spoofing
d.
multiplexing
22. Using _____, an attacker can initiate access to a computer or can appear as just another transmission to
a computer from a legitimate source that is already connected.
a.
buffering
c.
worms
b.
denial of service
d.
spoofing
23. What type of port might be used during a port-scanning attack?
a.
Serial
c.
UDP
b.
Parallel
d.
USB
24. How many ports are there in UDP and TCP?
a.
6,550
c.
65,535
b.
63,353
d.
165,550
25. What port does DNS use?
a.
21
c.
53
b.
23
d.
110
26. What port do Telnet applications use for communication?
a.
20
c.
23
b.
21
d.
25
27. Which of the following is a key element used in a wireless attack?
a.
Omnidirectional antenna
d.
Only a and b
b.
Wireless NIC
e.
a, b, and c
c.
Passwords
28. Which organization offers training in security needs and hosts the Certified Protection Professional
certification?
a.
Computer Emergency Response Team Coordination Center
b.
InfraGard
c.
Information Systems Security Association
d.
American Society for Industrial Security
29. Which organization was started by Coopers and Lybrand as the European Security Forum?
a.
Forum of Incident Response and Security Teams
b.
SysAdmin, Audit, Network, Security Institute
c.
Information Security Forum
d.
National Security Institute
30. Callback security is an example of _____ security
a.
filtering
c.
object
b.
remote access
d.
user level
31. Which of the following components are found in section “A” in the figure above?
a.
Word processors
d.
Disk drives
b.
Device drivers
e.
APIs
c.
Resource managers
32. What is displayed in the figure above?
a.
Resources in a LAN
c.
Resources in a MAN
b.
Resources in a WAN
d.
Resources in an enterprise network
33. What application protocol is being used in the figure above?
a.
TCP
c.
Ping
b.
Telnet
d.
Traceroute
34. A _____ is a fundamental component or container that holds information about all network resources
that are grouped within it.
a.
workgroup
c.
domain
b.
directory service
d.
forest
35. In Linux, account security characteristics are controlled through the _____ file, which is normally
available only to the system administrator.
a.
/etc/shadow
c.
/etc/hosts
b.
/bin/shadow
d.
/etc/passwd
YES/NO
1. Is the goal of disaster recovery to enable you to restore systems and data without losing critical
information?
2. Is using the monitoring software that comes with an operating system one of the best places to start
when determining the performance and use of an operating system or network?
3. Do the operating system device drivers coordinate operating system functions such as control of
memory and storage?
4. Do all networks have vulnerable points that require security?
5. Should security or system patches be installed immediately upon their release?
6. Will a security policy help to overcome the human factors that diminish security in an organization?
7. Do users need training in the use of security tools to help limit human failure and neglect?
8. Is the cost of deploying security more expensive than the cost of not deploying security?
9. Does a locked computer operations room guarantee the protection of a network server?
10. Is a virus hoax a virus?
COMPLETION
1. A(n) ____________________ is ideal for providing security because it takes care of the computer’s
most basic input/output functions.
2. The ____________________ communicates with the BIOS, device drivers, and the API to perform
operating system functions such as control of memory and storage.
3. The ____________________ allows you to set a password that governs access to the hard disk drive.
4. A key characteristic of a(n) ____________________ network is the availability of different resources
that enable users to fulfill business, research, and educational tasks.
5. In operating systems, the built-in ____________________ account is typically deactivated or has a
password.
6. ____________________ security policies can often help to override politics that limit good security in
an organization.
7. One way to help reduce the _________________________ is to purchase systems that are designed to
work together in an environment that enables easier and faster configuration.
8. ____________________ is a TCP/IP protocol that provides terminal emulation services over a
network or the Internet.
9. A(n) ____________________ attack is typically intended to shut down a site or service but does not
usually damage information or systems.
10. Once an attacker has found available IP addresses, they may then run ____________________
software to find a system on which a key port is open or not in use.
MATCHING
Match the following terms to the appropriate definitions.
a.
Attribute
f.
LSRR
b.
Buffer
g.
Macro
c.
Buffer overflow
h.
Source routing
d.
DoS attack
i.
Spoofing
e.
DDos attack
j.
Worm
1. Occurs when there is more data to store in a buffer than the buffer can hold
2. The address of the source computer is changed
3. A computer causes other computers to launch attacks directed at one or more targets
4. The sender of a packet specifies the precise path that a packet will take
5. A form of source routing that specifies only one portion of a route
6. A characteristic associated with a directory, folder, or file
7. Flooding a network with frames or packets containing errors
8. A program that replicates and replicates on the same computer
9. A storage area in a device that temporarily saves information in memory
10. A set of instructions for an activity that is performed frequently
SHORT ANSWER
1. Which three NLMs enable a workstation to remotely access the Netware system console?
2. List five organizations that provide information, assistance, and training in types of system attacks and
how to prevent them.
3. List six features that operating systems provide for hardening a system.
4. List five types of VPN security that can be provided by operating systems.
5. List four hardening techniques that can be used with networks.
6. What six basic tasks does an operating system perform?
7. What are the five basic operating system components?
8. List three common password options that are offered in the BIOS.
9. List four mediums over which computer networks can transmit data.
10. List the five major groupings of reasons that operating system and network security is needed.