Past Exam Organisational Security
COMMONWEALTH OF AUSTRALIA Copyright Regulations 1969
Warning
This material has been reproduced and communicated to you by or on behalf of The Charles Darwin University pursuant to Part VB of the Copyright Act 1968 (the Act). The material in this communication may be subject to copyright under the Act. Any further reproduction or communication of this material by you may be the subject of copyright protection under the Act.
Do not remove this notice
Student ID
Surname Given Names
SEM-2, 2013 Final Examination Page 1 of 3 BIS243 - Organisational Security
EXAMINATIONS PAPERS ARE NOT PERMITTED TO BE REMOVED FROM THE EXAMINATION VENUE
Semester/Year: Semester 2, 2013
FINAL EXAMINATION COVER SHEET
Faculty / School: Engineering, Health, Science and the Environment / Engineering and Information Technology
Unit: BIS243 - Organisational Security Lecturer: Krishnan Kannoorpatti Examination Duration:
Reading: 10 minutes Writing: 120 minutes
1. INSTRUCTIONS TO CANDIDATES:
1.1 The examination has 2 sections. Both sections must be answered. The exam is worth 50 marks.
Section A Suggested time: 25 minutes
The section has one question. The section is worth 10 marks You must answer this question.
Section B Suggested time: 95 minutes
Answer any 5 of 7 questions. Each question is worth 8 marks. The section is worth 40 marks. In each question part A is worth 4 marks and Part B is worth 4 marks.
1.2 Note that questions ARE NOT of equal value. 1.3 Read ALL questions carefully. 1.4 Do not commence writing until instructed to do so.
2. ATTACHED MATERIALS: None
3. PERMITTED MATERIALS: No materials are permitted for this examination
4. EXAMINATION BOOKLETS: 1 20-pages Booklet(s) Answers on Exam Paper: NO
COMMONWEALTH OF AUSTRALIA Copyright Regulations 1969
Warning
This material has been reproduced and communicated to you by or on behalf of The Charles Darwin University pursuant to Part VB of the Copyright Act 1968 (the Act). The material in this communication may be subject to copyright under the Act. Any further reproduction or communication of this material by you may be the subject of copyright protection under the Act.
Do not remove this notice
SEM-2, 2013 Final Examination Page 2 of 3 BIS243 - Organisational Security
EXAMINATIONS PAPERS ARE NOT PERMITTED TO BE REMOVED FROM THE EXAMINATION VENUE
Section A
The section has one question. The section is worth 10 marks. You must answer this question.
Question A1
Assume you are the CISO of your organisation. You are asked by the CEO to plan for the security of your organisation’s ICT network. What technologies and concepts will you use to defend the network? Explain this using a schematic diagram of your network. Identify other aspects of security planning that you need to take in to account.
Section B
Answer any 5 of 7 questions. Each question is worth 8 marks. The section is worth 40 marks. In each question part A is worth 4 marks and Part B is worth 4 marks.
Question B1
A. Passwords are important as a defence against unauthorised access. This is usually done by making the users comply with a password policy. What are the key ingredients of a best practice password policy? Explain why these are considered best practice. What are the effects of changing some key aspects of the password policy?
B. Name four 2nd factor authentication methods. Compare in a tabular form the strengths and weaknesses of each of the methods.
Question B2
A. Describe the Australian Government’s Information classification system. What are the consequences of compromise of information for each classification?
B. Explain what actions you will take in your organisation to cover 85% of the problems faced due to the OS and application bugs on servers and workstations.
Question B3
A. Describe the need for IDPSs on your organisation network.
B. What considerations will you take into account before acquiring IDPSs for your organisation?
SEM-2, 2013 Final Examination Page 3 of 3 BIS243 - Organisational Security
EXAMINATIONS PAPERS ARE NOT PERMITTED TO BE REMOVED FROM THE EXAMINATION VENUE
Question B4
A. Explain with a schematic diagram a DoS attack.
B. Why is it difficult to stop a DDoS attack?
Question B5
A. Name some key policies an organisation needs to control actions of users on a network to ensure security.
B. Your organisation has asked you to write a policy to stop users from plugging USB and other peripheral devices in to the organisation’s computers. What considerations will you take into account before writing this policy?
Question B6
A. Many free services available on the internet for email and social networking use a single sign-on to provide their services. While providing the services, it has been found that these services make use of usage patterns and email content to target advertisements to users. What is your assessment of this situation?
B. Name four information privacy principles used for regulating information privacy in Australia.
Question B7
A. What are the steps in setting up PGP to encrypt emails? Use schematic diagrams to present your answers.
B. What are the issues to be considered in setting up PGP for your organisation?
- Copyright notice Part VB.pdf
- COMMONWEALTH OF AUSTRALIA
- Copyright Regulations 1969
- Warning
- Copyright notice Part VB.pdf
- COMMONWEALTH OF AUSTRALIA
- Copyright Regulations 1969
- Warning