[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-461801-105":59,"doc-detail-461801-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","cia-triad-practice-final","CIA Triad - Practice Final","","Practice final on computer and network security fundamentals, with questions covering the CIA triad and how specific attacks can violate confidentiality, integrity, and availability. Includes denial-of-service resource exhaustion examples, physical access limitations, wireless hardening through WPA2 and firmware updates, and SQL injection consequences. Also evaluates malware terminology (virus, worm, phishing, trojan, spyware, rootkit), least-privilege principles, W^X threat mitigation, endpoint defenses, and network protections like IDS, IPS, and firewalls. Concludes with reverse engineering and computer-crime law matching and a detailed social engineering scenario.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":20,"@type":76,"position":81},"https://docshare.wps.com/document/exam/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/cia-triad-practice-final/461801/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/cia-triad-practice-final/461801.png","ImageObject",300,407,{"name":92,"@type":93},"adawds","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-10-08","2026-09-30",true,{"@type":102,"interactionType":103,"userInteractionCount":19},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"How can an attacker violate confidentiality, integrity, or availability?","Question",{"text":112,"@type":113},"Confidentiality can be violated by an attack that steals or exposes protected data, integrity by an attack that alters data without authorization, and availability by an attack that prevents access to systems or services.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"What is the purpose of W^X in a threat model?",{"text":117,"@type":113},"W^X mitigates threats that rely on simultaneously writable and executable memory by enforcing a policy that prevents code from being both writable and executable, reducing exploit options.",{"name":119,"@type":110,"acceptedAnswer":120},"How does a wireless security mitigation improve protection?",{"text":121,"@type":113},"For example, enabling WPA2 encryption with a strong password reduces unauthorized access by protecting wireless communications from interception and unauthorized participation.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},461801,1791451679,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":19,"category_name":20,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":19,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":39,"language":139,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":140,"faqs":141,"seo_title":142,"seo_description":67,"update_tm":143,"read_time":46},3985747872983,"https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d","Signature:   Date:    \n\n| Part | Max points | Score |\n| --- | --- | --- |\n| 1 | 9 |  |\n| 2 | 8 |  |\n| 3 | 2 |  |\n| 4 | 2 |  |\n| 5 | 2 |  |\n| 6 | 12 |  |\n| 7 | 10 |  |\n| 8 | 10 |  |\n| 9 | 10 |  |\n| 10 | 10 |  |\n| 11 | 8 |  |\n| 12 | 8 |  |\n| 13 | 9 |  |\n| TOTAL | 100 |  |\n\nQ1. For each of the following principles of the CIA triad, give an example of an attack that violates it. [9pts]  \na. Confidentiality. [3]  \nb. Integrity. [3]  \nc. Availability. [3]  \nQ2 . Give two examples of resources an attacker may try to exhaust in a Denial of Service attack and, for each,  \ndescribe such an attack. [8] 1.  \n2.  \nQ3 . If given physical access to a computer, which of the follow will an attacker not necessarily be able to do?[2]  \n(a) Read the physical hard drive or SSD  \n(b) Delete all data  \n(c) Decrypt encrypted content  \n(d) Implant malicious software or hardware  \nQ4 . Which of the following mitigations is most helpful to wireless security? [2]  \n(a) Reducing transmit power to just cover the required area  \n(b) Enabling WPA2 encryption with a strong password  \n(c) Changing the SSID periodically  \n(d) Updating router firmware to the latest available  \nQ5 . SQL injection attacks could allow an attacker to   [2]  \n(a) Bypass authentication  \n(b) Access data without authorization  \n(c) Alter or destroy database content  \n(d) All of the above  \nQ6 . Imagine a piece of software with the following properties:  \n􀁸 When run manually on a Windows host, it stays resident on disk and in memory and performs the activities listed herein.  \n􀁸 It scans the internet for WordPress-based web servers on Linux with a particular vulnerable plugin and copies a Linux variant of itself to that web server, causing the server to run the software, whereupon it stays resident on disk and in memory and performs the activities listed herein.  \n􀁸 It locates any email addresses on the system (e.g. from user address books) and sends each one an email claiming to be a message from a would-be romantic partner sent from a dating site; the Windows variant of the software is attached as “mypic.jpg.exe”.  \n􀁸 After 30 days from the initial infection, it encrypts all user files with a random key, reveals itself to the user, and demands a Bitcoin payment to get this key and recover the files.  \nBelow are a number of malware terms. Some are valid descriptors of this software and some are not. For each one, either say “Yes” and explain why that term applies to this software or say “No” and explain why the term does not apply. As an example, the first is done for you. [12]  \na. Clickjacking attack  \nNo: A clickjacking attack attempts to divert the user’s mouse to authorize something he or she didn’t intend to. This malware does no such thing.  \nb. Virus [2]  \nc. Worm [2]  \nd. Phishing attack [2]  \ne. Trojan horse [2]  \nf. Spyware [2]  \ng. Rootkit [2]  \nQ7 . First, define the principle of least privilege. Second, give a concrete example of applying the principle (from a homework, a hypothetical situation, or your own experience) . Be sure to include an overview of the major technical steps involved. [10]  \nQ8 . Describe a threat model that is mitigated by W^X, and explain how the W^X defense achieves this. [10]  \nQ9 . Describe in detail two things you can do to an endpoint (a server, workstation, etc.; not the network) to  \nimprove security. For each defense you give, provide an example attack that the defense mitigates. [10] a.  \nb.  \nQ10. Answer the following questions regarding network defense technologies. [10]  \na. What is a network-based IDS? [2]  \nb. Given an example attack it can mitigate. [1]  \nc. Give an example attack it cannot mitigate. [1]  \nd. What is the difference between an IPS and an IDS? [2]  \ne. What is a network-based firewall? [2]  \nf. Given an example attack it can mitigate. [1]  \ng. Give an example attack it cannot mitigate. [1]  \nQ11. List two tools (or two categories of tools) useful in reverse engineering a compiled binary executable. Briefly define what ","cbCaincQr0vN8ZRr","https://ap.wps.com/l/cbCaincQr0vN8ZRr","pdf",627730,"English","# Q1 CIA triad examples of attacks that violate each principle\n# Q2 Denial of Service resource exhaustion examples\n# Q3 Physical access capabilities vs limits\n# Q4 Wireless security mitigations\n# Q5 SQL injection impacts\n# Q6 Malware term classification\n# Q7 Least privilege definition and application with technical steps\n# Q8 Threat model mitigated by W^X\n# Q9 Endpoint defenses and mitigated example attacks\n# Q10 Network defense technologies: IDS/IPS/firewalls\n# Q11 Reverse engineering tools for compiled binaries\n# Q12 Computer crime laws matching\n# Q13 Social engineering scenario analysis","[{\"question\":\"How can an attacker violate confidentiality, integrity, or availability?\",\"answer\":\"Confidentiality can be violated by an attack that steals or exposes protected data, integrity by an attack that alters data without authorization, and availability by an attack that prevents access to systems or services.\"},{\"question\":\"What is the purpose of W^X in a threat model?\",\"answer\":\"W^X mitigates threats that rely on simultaneously writable and executable memory by enforcing a policy that prevents code from being both writable and executable, reducing exploit options.\"},{\"question\":\"How does a wireless security mitigation improve protection?\",\"answer\":\"For example, enabling WPA2 encryption with a strong password reduces unauthorized access by protecting wireless communications from interception and unauthorized participation.\"}]","CIA Triad - Practice Final | PDF",1790762451]