What is the difference between mechanisms and policies? Why is the separation ne
ID: 3697029 • Letter: W
Question
What is the difference between mechanisms and policies? Why is the separation necessary?
Explain the principle of least privilege.
What is the difference between static and dynamic protection domain?
What are the possible implementations of access matrix?
Why is revocation of access important?
What is the difference between a threat and an attack?
What is the difference between authentication and authorization?
Briefly describe a man-in-the-middle attack.
What is the difference between a virus an a worm?
Briefly explain the dangers of a buffer overflow vulnerability.
What mechanisms can be used to prevent stack overflow attack?
Briefly explain the functionality of Morris's worm.
Why is it difficult to defend against DDOS attacks?
What protocols of the TCP/IP stack are responsible for security of communication?
What is the difference between symmetric and asymmetric encryption?
What is the difference between stream ciphers and block ciphers. Give an example of each.
What is a purpose of using "salt" along with passwords?
What is a digital certificate?
Why MD5 hashing algorithm is considered unsafe? How can it be exploited?
What are the top 3 antivirus programs? Explain your answer.
Explanation / Answer
What is the difference between mechanisms and policies? Why is the separation necessary?
Policies basically refer to the set of rules on the bases of which a perticular activitiy is choosen for execution. While mechanisms refer to the things we need to do to implement or to execute that policy. The separation is required because both have different meaning. Policy is to choose acitivity and mechanisms is the execution of that acitivity.
Explain the principle of least privilege
Principle of least privilege refer to the minimum privilege a user is required to complete its task on the computer. This principle deals with user privileges and promote the minimum privileges required for the user.
What is the difference between a threat and an attack?
Threat basically points to any harm to the asset, or point to any problem of the asses. Threat can be intentional as well as unintentiona. While attack is on intentional bases and its basically done to harm any asset.
What is the difference between authentication and authorization?
Authentication refer the verification of the user, if user is a valid and authentic or not. While authorization is basically to check if user have all the access rights and permissions to access the system or not.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.