Home /UOS — University of Sargodha /Information Security

Information Security BS 1/8 Semester/Term UOS — University of Sargodha 2025

University Of Sargodha (UOS) 2025 — page 1

Discussion

Ask a question about this paper, or help someone else with theirs. Answers are emailed to whoever asked.

Your email is only used to send you replies and occasional Ustadni updates. It is never shown publicly.

Log in to post under your name

No questions yet — be the first to ask.

More Information Security papers

See all

Paper text

Lnitvernity of Sargodha

US Nagester AM ester (S™

Lowi Allow wd: 92:18 Hours Maximum Marks: 60

Nate: Objective part is compulsory. Attempt any three questions from subjective part.

Objective Part (Compulsory)

Q.1. Write short answers of the following in 2-3 lines each on your answer sheet. (2*12)

~

i. Define availability.

#

ii. Define a malware.

«iii. What is hash function?

»

iv. What is symmetric encryption?

» V- Define a digital signature.

» Vi. What is stream cipher?

, = Vii. Define host attack.

Lntveentty of Sargodha

WS Nagester 4M ester (S™

Supe dad n -4

Lowa ABNow ody 92:18 Hours Maximum Marks:

60)

Note: Objective part is compulsory. Attempt any three questions from subjective part.

Q.1. Write short answers of the following in 2-3 lines each on your answer sheet. (2%12)

~ 1v. What is symmetric encryption?

v. Define a digital signature.

-~ vii, Define host attack.

#Viii. What is role based access control?

»

ix. Define an out-of-band attack.

« X. Define a passive sensor.

,« Xi. Name any two application layer attacks.

»~ Xi. What is injection attack?

Subjective Part (3*12)

Q.2. What are the main requirements of a cryptographic hash function, and how do these requirements

contribute to its security?

Q.3. Discuss various attack strategies that exploit password vulnerabilities and describe effective

countermeasures to mitigate these threats.

Q.4. Access control policies are generally grouped into several categories. Identify these categories and

briefly explain each.

Q.5. What are the main avenues of attack in an SQL Injection, and how can such vulnerabilities be exploited

by attackers?

Q.6. How is anomaly detection used in Intrusion Detection Systems (IDS)? Discuss its classification

mechanisms and the machine learning approaches commonly applied.

LK-6740, 9016/27-06-25

ustadni.com