Name:
Class:
Date:
Page 1
1. Ubuntu and Debian Linux use what command to update and manage their RPM packages?
a.
yum
b.
get
c.
dir
d.
apt-get
ANSWER:
d
2. Which of the following is a common Linux rootkit?
a.
Back Orifice
b.
Kill Trojans
c.
Packet Storm Security
d.
Linux Rootkit 5
ANSWER:
d
3. Which of the following is an SELinux OS security mechanism that enforces access rules based on privileges
for interactions between processes, files, and users?
a.
Mandatory Access Control
b.
SE Access Control
c.
Access Control
d.
Mandatory Control
ANSWER:
a
4. What is the most serious shortcoming of Microsoft’s original File Allocation Table (FAT) file system?
a.
no ACL support
b.
no SUS support
c.
no SMTP support
d.
no Linux support
ANSWER:
a
5. What is the current file system that Windows utilizes that has strong security features?
a.
FAT
b.
ADS
c.
FAT32
d.
NTFS
ANSWER:
d
6. When using the Common Internet File System (CIFS), which security model will require network users to
have a user name and password to access a specific resource?
a.
NT level security
b.
Share-level security
c.
User-level security
Name:
Class:
Date:
ANSWER:
d.
CIF level security
ANSWER:
c
7. Which of the following is considered to be the most critical SQL vulnerability?
a.
null SA hash
b.
null SA password
c.
SQL password
d.
SQL scanning
ANSWER:
b
8. When using the Common Internet File System (CIFS), which security model does not require a password to
be set for the file share?
a.
NT level security
b.
Share-level security
c.
User-level security
d.
CIF level security
ANSWER:
b
9. What programming languages are vulnerable to buffer overflow attacks?
a.
C and Python
b.
C and C++
c.
Assembly and C++
d.
Perl and Python
ANSWER:
b
10. What functions do most Trojan programs perform?
ANSWER:
Most Trojan programs perform one or more of the following functions:
– Allow remote administration of the attacked system
– Create a file server on the attacked computer so files can be loaded and downloaded without the user’s
knowledge
– Steal passwords from the attacked system and e-mail them to the attacker
– Log all keystrokes a user enters and e-mail the results to the attacker or store them in a hidden file the
attacker can access remotely
– Encrypt all of the user’s files and hold them ransom
– Destroy all of the data on a victim system
11. What is the purpose of a file system?
ANSWER:
The purpose of any file system, regardless of the OS, is to store and manage information. The file system
organizes information that users create as well as the OS files needed to boot the system, so the file system is
the most vital part of any OS. In some cases, this critical component of the OS can be a vulnerability.
Name:
Class:
Date:
Name:
Class:
Date:
Name:
Class:
Date:
Page 5
27. In 2007 became Windows new standard to deploy and manage servers alongside updated patch-
management functionality
ANSWER:
h
28. An interprocess communication mechanism that allows a program running on one host to run code on a
remote host
ANSWER:
i
29. An open-source implementation of CIFS
ANSWER:
j
30. Embedded OSs are usually designed to be small and efficient so they do not have some of the functions that
general-purpose OSs have.
a.
True
b.
False
ANSWER:
True
31. Which one of the following, if compromised might allow attackers the ability to gain complete access to
network resources?
a.
host
b.
router
c.
driver
d.
rootkit
ANSWER:
b
32. A device that performs more than one function, such as printing and faxing is called which of the following?
a.
MILS
b.
ASA
c.
RTOS
d.
MFD
ANSWER:
d
33. Which of the following systems should be used when equipment monitoring and automation is critical?
a.
CAD
b.
GUI
c.
SCADA
d.
VoIP
ANSWER:
c
34. Rootkits that pose the biggest threat to any OS are those that infect what part of the targeted device?
a.
firmware
b.
testware
Name:
Class:
Date:
Page 6
c.
middleware
d.
fireware
ANSWER:
a
35. What type of malicious code could be installed in a system’s flash memory to allow an attacker to access the
system at a later date?
a.
BIOS-based rootkit
b.
embedded browser
c.
unclassified kernel
d.
patch
ANSWER:
a
36. SCADA systems controlling critical infrastructure are usually completely separated from the Internet by
which of the following?
a.
firewall
b.
air gap
c.
router
d.
Vlan
ANSWER:
b
37. What type of viruses and code has been created by security researchers and attackers that could infect
phones running Google’s Android, Windows Mobile, and the Apple iPhone OS?
a.
Python
b.
C++
c.
Perl
d.
Java-based
ANSWER:
d
38. Which of the following if often found within an embedded OS that can cause a potential vulnerability to an
attack?
a.
Web server
b.
USB port
c.
RAM
d.
PCB
ANSWER:
a
39. Which of the following source code is now available to the public and was considered a trimmed down
version of the Windows desktop OS?
a.
VxWorks
b.
Windows Embedded 8
c.
Windows CE
d.
Windows 10 IoT
Name:
Class:
Date:
(DDoS) or vulnerability exploitation attacks.
Supervisory control and data acquisition (SCADA) systems are used for equipment monitoring in large
industries, such as public works and utilities, power generators and dams, transportation systems (such as FAA
ANSWER:
c
40. List at least four best practices for protecting embedded OSs.
ANSWER:
The best practices for protecting embedded OSs include the following:
– Identify all embedded systems in an organization.
– Prioritize the systems or functions that depend on these embedded systems.
– Follow the least privileges principle for access to embedded systems.
– Use data transport encryption, when possible, for embedded system communication.
– Configure embedded systems as securely as possible.
– When possible, use cryptographic measures, such as TPM, for booting embedded systems.
– Install patches and updates, when available, to address vulnerabilities.
– Reduce the potential of vulnerabilities by restricting network access.
– Upgrade or replace embedded systems that can’t be fixed or pose an unacceptable risk.
41. What types of embedded systems are found in a typical corporate building?
ANSWER:
If you conduct a survey of a typical corporate building, you can find many embedded systems. These systems
include firewalls, switches, routers, Web-filtering appliances, network attached storage (NAS) devices,
networked power switches, printers, scanners, copy machines, video projectors, uninterruptible power supply
(UPS) consoles, Voice over IP (VoIP) phone and voicemail systems, thermostats, HVAC systems, fire
suppression systems, closed-circuit TV systems, elevator management systems, video teleconferencing
workstations and consoles, and intercom systems.
42. Why do many people dismiss the topic of embedded device security?
ANSWER:
Many dismiss the topic of embedded device security to focus on more popular security issues. Most of the
media emphasis is on threats that people can understand and relate to, such as the latest network worm, or the
most recent Facebook application attack. However, embedded systems are in all networks and perform
essential functions, such as routing network traffic and blocking suspicious packets.
43. What types of specific systems use VxWorks embedded real-time OS?
ANSWER:
Systems using VxWorks include:
– Clementine spacecraft
– Deep Impact space probe
– James Webb Space Telescope (in development)
– Mars exploration rovers Spirit and Opportunity
– Mars Phoenix Lander
– Mars Reconnaissance Orbiter
– Radvision 3G communication equipment
– Stardust spacecraft
– SAUVIM (a submersible spacecraft designed for deep-ocean operations)
44. What critical consumer product did the botnet worm psyb0t or the Network Bluepill target?
ANSWER:
Home router embedded systems, such as the Linksys WRT54G, were the target of the psyb0t worm. This
worm spread by exploiting outdated or poorly configured router OSs that contained easy–to-guess passwords.
After psyb0t had infected tens of thousands of systems, attackers used it to launch distributed denial-of-service
Name:
Class:
Date:
control towers), manufacturing-anywhere automation is critical. SCADA systems sometimes have many
embedded systems as components, which might be vulnerable through the data fed in and out of them or
through their embedded OSs. In any case, it’s no exaggeration to say the security of some SCADA systems is a
life or death proposition. For this reason, SCADA systems controlling critical infrastructure are usually
separated from the Internet by an “air gap.”
46. What principle can be used to help reduce insider threats to an organization?
ANSWER:
System administrators, network managers, and technicians often have unfettered, and unmonitored, access to a
company’s most critical IT components. They’re aware of any gaps in existing security processes and know
how to cover up illegal activities. Following the “least privileges principle” can help reduce the insider threat,
however. This principle specifies giving personnel only the access they need to perform their job duties and
revoking access as soon as they no longer need it.
47. Why are there problems with patching electronics such as heart rate monitors and MRI machines that run
embedded Windows OSs?
ANSWER:
Often these systems can’t be patched because they’re certified at a specific revision level, or the manufacturer
never provided a patch method. This problem was apparent when the Conficker worm infected numerous
medical systems around the world. Even in embedded systems that weren’t connected directly to the Internet,
versions of Conficker spread through removable media. A simple data transfer with USB drives, for example,
might be risky.
48. Why might attackers use social engineering techniques to masquerade as support technicians?
ANSWER:
Attackers might use social-engineering techniques to masquerade as support technicians so that they can get
physical access to MFDs and replace the printer’s hard drive or embedded OS with one containing malicious
code. Malicious insiders can also replace the firmware (embedded OS) with specially modified firmware.
49. Explain the BIOS-level rootkit SubVirt that was co-developed by Microsoft and the University of
Michigan?
ANSWER:
For demonstration purposes, SubVirt was developed for desktop computers that can survive hard disk
replacement and OS reinstallation. It modifies the boot sequence and loads itself before the OS so that it can
operate outside the OS and remain hidden from many rootkit-detection tools. By exploiting hardware
virtualization technology from CPU manufacturers, SubVirt can load the original OS as a virtual machine and
then intercept the OS’s calls to hardware.
Match each item with a statement below.
a.
Trusted Platform Module
b.
MILS
c.
RTLinux
d.
RTOS
e.
RTEMS
f.
embedded system
g.
firmware
h.
multifunction devices
i.
SCADA
j.
embedded operating system
Name:
Class:
Date:
Page 9
50. A cryptographic firmware boot-check processor installed on many new computer systems
ANSWER:
a
51. An embedded OS certified to run multiple levels of classification on the same CPU without leakage between
levels
ANSWER:
b
52. An OS microkernel extension developed for Linux
ANSWER:
c
53. A specialized embedded OS used in devices such as programmable thermostats, appliance controls, and
even spacecraft
ANSWER:
d
54. An open-source embedded OS used in space systems because it supports processors designed specifically to
operate in space
ANSWER:
e
55. Any computer system that is not a general-purpose PC or server
ANSWER:
f
56. Software residing on a chip
ANSWER:
g
57. Devices on an organization’s network performing more than one function, such as printers, scanners, and
copiers
ANSWER:
h
58. Systems used for equipment monitoring in large industries, such as public works and utilities, power
generators and dams
ANSWER:
i
59. A small program developed specifically for use with embedded systems
ANSWER:
j