Chapter 22 (Internet Security Protocols and Standards) Flashcards

1
Q

MIME vs S/MIME

A

MIME is an email format, S/MIME is a security enhancement. provides ability to sign and/or encrypt email messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is DKIM

A

a spec for cryptographicly signing email messages permitting a signing domain to claim responsibility for a message

widely adopted by email providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

tls session vs tls connection

A

session = association between client and server, defines cryptographic security parameters

connection = a transport(in OSI) model that provides a suitable type of service, every conn associated w/ one session

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

when is the handshake part of TLS done

A

before any application data are transmitted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what does handshake protocol allow the server and client to do

A

authenticate each other, negotiate encryption, negotiate cryptographic keys to be used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is heartbeat protocol and what is it used for

A

a periodic signal generated by hardware or software to indicate normal operation or sync other parts of program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

2 purposes of heartbeats

A

assures sender that recipient is still alive

generates activity across connction during idle periods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

where are 2 spots ssl/tls attacks aimed at

A

the handshake protocol

application data protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is https

A

combination of http and ssl to implement secure communication between web browser and web server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what is IPSEC

A

various application security mechanisms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

3 main concepts of IPSEC

A

Authentication = are who you say you are

Confidentiality = prevent eavsedropping

Key managment = secure exchange of keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is a security accociation

A

a one way relationship between sender and reciever that affords security for traffic flow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

in a security association, what is transport mode

A

used for end to end communication for 2 hosts, like https

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

in a security association, what is tunnel mode

A

provides protection to the entire IP packet, like a VPN kinda

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly