MODEL PAPER
SECOND SEMESTER, M. Sc INFORMATION TECHNOLOGY

Paper - VI (MIT - 206): INFORMATION SECURITY
First Semester
MIT - 101
MIT - 102
MIT - 103
MIT - 104
MIT - 105
MIT - 106
MIT - 107
MIT - 108
Second Semester
MIT - 201
MIT - 202
MIT - 203
MIT - 204
MIT - 205
MIT - 207
MIT - 208
Third Semester
MIT - 301
MIT - 302
MIT - 303
MIT - 304
MIT - 305
MIT - 306
MIT - 307
MIT - 308
Fourth Semester

Time: 3hrs Max. Marks: 75
Attempt any five questions.
All questions carry equal marks

  1. Question.

    1. How do changes in Technology affect the security of information of an organization?
    2. Describe the attributes Confidentiality, Accuracy and availability of information and why they should be protected at all costs.

  2. Question.

    1. What are the categories of resources of an organization that must be protected against any security incident? Describe the resources in brief.
    2. How is the value of a resource determined? What are the various costs involved?

  3. Question.

    1. What is meant by software security design flaw? How does it compromise information security?
    2. Discuss the issues pertaining to software security testing?

  4. Question.

    1. What is security polices? What is their role in overall security of an organization?
    2. Prepare a checklist for security awareness in an organization. Describe the entries of your checklist in brief.

  5. Question.

    1. Explain Private Key cryptography and Public Key cryptography
    2. Explain DES algorithm

  6. Question.

    1. What are discretionary and mandatory access policies?
    2. What is the purpose of Views? Explain with a suitable example
    3. What is resource profile in Oracle?

  7. Question.

    1. What is the purpose Authentication protocols,? Explain Diffie-Hellman key exchange protocol?
    2. What is Digital Signature? Explain its implementation using Public Key signature.
    3. Explain Message digest

  8. Question.

    1. What is Firewall? Explain Packet filtering technique.
    2. Explain n how VPN can be used for network security