Exem 2025 Paper Information Security (CMPC-303 /CMPC-4542) UOS
Discussion
Ask a question about this paper, or help someone else with theirs. Answers are emailed to whoever asked.
No questions yet — be the first to ask.
Paper text
LaneNty of Sargodha
H> y° Naigester / 1" Somester (50 Intake) Exem 2025
Paper: Information Security (CMPC-303 /СMPC-4542)
Maximum Marks: 60
Note: Objective part is compulsory. Attempt any three questions from subjective part.
Objective Part
(Compulsory)
Q.1. Write short answers of the following in 2-3 lines each on your answer sheet.
-
i.
Define availability.
Define a malware.
-iii.
What is hash function?
,
iv.
What is symmetric encryption?
V.
Define a digital signature.
•
vi.
What is stream cipher?
- -
vii.
Define host attack.
vili.
What is role based access control?
/
ix.
Define an out-of-band attack.
• x.
Define a passive sensor.
, xI.
Name any two application layer attacks.
•
xii. What is injection attack?
(2*12)
Subjective Part
(3*12)
Q.2. What are the main requirements of a cryptographic hash function, and how do these requirements
contribute to its security?
Q.3. Discuss various attack strategies that exploit password vulnerabilities and describe effective
countermeasures to mitigate these threats.
Q.4. Access control policies are generally grouped into several categories. Identify these categories and
briefly explain each.
Q.5.
What are the main avenues of attack in an SQL Injection, and how can such vulnerabilities be exploited
by attackers?
Q.6. How is anomaly detection used in Intrusion Detection Systems (IDS)? Discuss its classification
mechanisms and the machine learning approaches commonly applied.
- LK-6740, 9016/27-06-25
Subroil
LaneNty of Sargodha
HIS yin Negester /|" Nomester (50 Intake) Exem 2025
Paper Information Security (CMPC-303 /CMPC-4542)
.com
Maximum Marks: 60
Nade:
Objective part is compulsory. Attempt any three questions from subjective part.
Objective Part
(Compulsory)
ustadni
Q.1. Write short answers of the following in 2-3 lines each on your answer sheet.
i.
Define availability.
Define a malware.
-
iii.
What is hash function?
,
iv.
What is symmetric encryption?
V.
Define a digital signature.
•
vi.
What is stream cipher?
- -
vii.
Define host attack.
vili.
What is role based access control?
/
ix.
Define an out-of-band attack.
• x.
Define a passive sensor.
,1
xi.
Name any two application layer attacks.
•
xii. What is injection attack?
(2*12)
Subjective Part (3*12)
Q.2. What are the main requirements of a cryptographic hash function, and how do these requirements
contribute to its security?
Q.3. Discuss various attack strategies that exploit password vulnerabilities and describe effective
countermeasures to mitigate these threats.
Q.4. Access control policies are generally grouped into several categories. Identify these categories and
briefly explain each.
Q.5.
What are the main avenues of attack in an SQL Injection, and how can such vulnerabilities be exploited
by attackers?
Q.6. How is anomaly detection used in Intrusion Detection Systems (IDS)? Discuss its classification
mechanisms and the machine learning approaches commonly applied
- LK-6740, 9016/27-06-25
ustadni.com