2022年11月信息安全工程师 上午试卷之二十四

摘要:对于【信息安全工程师】软考考试而言,真题无疑是最重要的学习资料之一。在软考备考过程中,吃透真题、掌握真题所考知识点、熟悉真题的出题思路,对我们提升分数的效果是最明显的,通过对真题的反复练习,还可以查漏补缺。今天,给大家带来【2022年11月信息安全工程师 上午试卷】部分真题的详解,一起来看看吧~1、网络设备的常见漏洞包括拒绝服务漏洞、旁路、代码执行、溢出、内存破坏等。C

1、网络设备的常见漏洞包括拒绝服务漏洞、旁路、代码执行、溢出、内存破坏等。CVE-2000-0945漏洞显示思科Catalyst 3500 XL交换机的Web配置接口允许远程攻击者不需要认证就执行命令,该漏洞属于(70)。
拒绝服务漏洞。拒绝服务漏洞将导致网络设备停止服务,危害网络服务可用性。例如,思科Catalyst交换机的HTTP服务器不当处理TCP Socket,允许远程攻击者通过将恶意数据包发送到80或443端口导致拒绝服务。
旁路(Bypass something)。旁路漏洞绕过网络设备的安全机制,使得安全措施没有效果。
代码执行(Code Execution)。该类漏洞使得攻击者可以控制网络设备,导致网络系统失去控制,危害性极大。CVE-2000-0945信息显示思科Catalyst3500XL交换机的Web配置接口允许远程攻击者不需要认证就执行任意命令。
内存破坏(Memory Corruption)。内存破坏漏洞利用常会对路由器形成拒绝服务攻击。
2、Perhaps the most obvious difference between private-key and public-key encryption is that the former assumes complete secrecy of all cryptographic keys,whereas the latter requires secrecy for only the private key.Although this may seem like a minor distinction,the ramifications are huge:in the private-key setting the communicating parties must somehow be able to share the (71) key without allowing any third party to learn it,whereas in the public-key setting the (72) key can be sent from one party to the other over a public channel without compromising security.For parties shouting across a room or,more realistically,communicating over a public network like a phone line or the Internet,public-key encryption is the only option.Another important distinction is that private-key encryption schemes use the (73) key for both encryption and decryption,whereas public-key encryption schemes use (74) keys for each operation.That is,public-key encryption is inherently asymmetric.This asymmetry in the public-key setting means that the roles of sender and receiver are not interchangeable as they are in the private-key setting;a single key-pair allows communication in one direction only.(Bidirectional communication can be achieved in a number of ways;the point is that a single invocation of a public-key encryption scheme forces a distinction between one user who acts as a receiver and other users who act as senders.)In addition,a single instance of a (75) encryption scheme enables multiple senders to communicate privately with a single receiver,in contrast to the private-key case where a secret key shared between two parties enables private communication only between those two parties.
3、Perhaps the most obvious difference between private-key and public-key encryption is that the former assumes complete secrecy of all cryptographic keys,whereas the latter requires secrecy for only the private key.Although this may seem like a minor distinction,the ramifications are huge:in the private-key setting the communicating parties must somehow be able to share the (71) key without allowing any third party to learn it,whereas in the public-key setting the (72) key can be sent from one party to the other over a public channel without compromising security.For parties shouting across a room or,more realistically,communicating over a public network like a phone line or the Internet,public-key encryption is the only option.Another important distinction is that private-key encryption schemes use the (73) key for both encryption and decryption,whereas public-key encryption schemes use (74) keys for each operation.That is,public-key encryption is inherently asymmetric.This asymmetry in the public-key setting means that the roles of sender and receiver are not interchangeable as they are in the private-key setting;a single key-pair allows communication in one direction only.(Bidirectional communication can be achieved in a number of ways;the point is that a single invocation of a public-key encryption scheme forces a distinction between one user who acts as a receiver and other users who act as senders.)In addition,a single instance of a (75) encryption scheme enables multiple senders to communicate privately with a single receiver,in contrast to the private-key case where a secret key shared between two parties enables private communication only between those two parties.
软考资料: 2024年软考论文范文> 软考考试核心重点难点汇总> 查看更多>
备考刷题:章节练习+每日一练> 软考历年试题+模拟题>查看更多>