When & Where
The first exam will be held in our regular classroom on Monday, October 5, 2026.
It will take up about half the lecture, starting approximately during the second half of the class period. Please arrive on time and do not plan on coming in just to take the exam. If you arrive after the exam has started, you will not be allowed to take it.
Exam rules
Be sure to arrive on time. If you arrive after the exam starts, you will not be allowed to take it.
This will be a closed book, closed notes exam. Calculators, phones, augmented reality glasses, laptops, and tablets are neither needed nor permitted. If you have these devices, you must turn them off, put them out of sight, and not access them for the duration of the exam.
No other electronic devices are permitted except for hearing aids, pacemakers, electronic nerve stimulators, other implanted medical devices, or electronic watches that function only as timekeeping devices or chronographs.
Bring a couple of pens or pencils with you. Plan to use a pen only if you are supremely confident in not changing your mind about your answers. . Check here for information about pencils, sharpeners, and the craft of pencil sharpening.
Past exams
You can use my past exams as a guide to what this exam may look like, but realize there are differences in topics and in the sequencing of the topics. Expect around 25 multiple-choice questions. You won’t have to recite lists, do a frequency analysis, or present algorithms, so you should focus your studying to being able to recognize concepts. I do not refer to old exams when I come up with a new one, so it is likely that many of the topics that I considered important in past exams will show up on future exams. Some material may have changed, however, so do not worry about questions that appear to relate to topics we have not covered.
Study guide
You are responsible for the material from the first four lectures and recitations.

The study guide is a concatenation of the study guides from the past lectures. I expanded the lists of what you don’t need to study. My goal is to put most of the information you need to know in a concise format with fewer elaborations. The guide attempts to cover most of the material you should know. It is not a substitute for the lectures, lecture material, and other reading matter.
You can also prepare your own guide, which could be a better way to prepare for the exam!
Topics
Topics that you should know and may be on the exam include:
Introduction
Security properties and goals
-
Security properties: the CIA triad; confidentiality vs. privacy, anonymity, and secrecy; data, origin, and system integrity; availability, DoS, DDoS
-
Authenticity and accountability, and how authenticity differs from data integrity
-
Security system goals: prevention, detection, recovery, and why no one of them replaces the others; defense in depth
Policy, mechanism, and trust
-
Policy vs. mechanism; technical vs. procedural mechanisms; the assumptions a mechanism depends on
-
Assurance, security engineering, trusted computing base (TCB), trust boundary
-
Supply chain and supply chain security
-
Security theater and misaligned incentives
-
Human factors: why awareness training alone is not a sufficient control
Risk
-
Risk analysis: asset, threat, vulnerability, attack vector, security control, residual risk; what a threat model records
-
Risk responses: mitigate, avoid, transfer, accept, and what each one leaves behind
-
Attack surface, hardening, air gap; why patching removes a vulnerability without shrinking the attack surface
Attacks and adversaries
-
Bug, vulnerability, exploit, attack, security incident, data breach; exfiltration
-
Kinds of attack: ransomware, extortion, double extortion, wipers, denial of service, resource hijacking, impersonation, credential stuffing, social engineering
-
Threats vs. threat actors; the threat classes: disclosure, deception, disruption, usurpation
-
Why the Internet amplifies risk: action at a distance, anonymity, global reach, automation at scale, shared code, asymmetric effort, lack of distinction; botnets and command and control
-
Adversaries: goals, risk tolerance, resources, expertise, level of access; opportunistic vs. targeted; white, black, and gray hats; criminal groups, insiders, hacktivists, nation-states, script kiddies; advanced persistent threats (APTs)
-
Cyber espionage vs. cyber warfare; GPS jamming vs. spoofing; takedowns vs. hack-back; why attribution is uncertain and why analysts compare TTPs
Vulnerability tracking
- What CVE and CVSS are for, and why CVSS does not measure organizational risk; NVD and KEV; the general path from discovery to mitigation; zero-day vulnerabilities and attacks
You don’t need to know:
-
Dates, dollar amounts, victim counts, or the names and details of specific incidents, malware, groups, tools, or vendors
-
How Spectre, Meltdown, or Rowhammer work, or how injection attacks, ransomware, or AI attacks work
-
Which organization runs CVE, NVD, KEV, or CVSS; CVSS score ranges; EPSS and LEV
-
Vendor naming schemes for threat actors
Symmetric cryptography
Terms and principles
-
Terms: confidentiality, authentication, integrity, non-repudiation; plaintext, ciphertext, encryption, decryption; cipher, key, cryptosystem, keyspace; symmetric vs. asymmetric encryption; cryptography, cryptanalysis, brute-force attack
-
Kerckhoffs’s principle: security must not depend on the secrecy of the algorithm, and why
-
Schneier’s Law: why an unbroken cipher is not the same as a secure one
Classical ciphers
-
Substitution vs. transposition: what each hides and what each preserves
-
Caesar cipher, monoalphabetic substitution; why a huge keyspace does not save it
-
Frequency analysis: letter and bigram frequencies survive substitution
-
Polyalphabetic ciphers (Alberti, Vigenère): keyword, keystream, period; why they are stronger than monoalphabetic
-
Kasiski attack: repeated ciphertext reveals the period, then each stream is a Caesar cipher
-
Columnar transposition, padding
-
Why combining substitution and transposition is stronger than either alone
-
Lessons: a large keyspace is not enough; ciphertext must not preserve plaintext statistics; a repeating keystream leaves a pattern; the cipher is only one part of the system
-
Rotor machines: a polyalphabetic cipher whose substitution changes with every letter; Enigma had a huge keyspace and a known design and was broken anyway
Modern cryptography
-
Entropy (concept only) and redundancy; why English has low entropy and why that can help an attacker
-
Perfect secrecy: what it means and what it does not hide (length, sender, timing)
-
One-time pad: XOR, the three conditions, why key reuse is fatal, and why the pad is impractical
-
Computational security: bounded adversary, key length vs. structural shortcut, computational indistinguishability
-
Attack models: ciphertext-only, known-plaintext, chosen-plaintext, chosen-ciphertext
-
Confusion and diffusion, S-boxes, avalanche effect, rounds
-
Randomness: true random vs. pseudorandom (PRNG, seed) vs. CSPRNG; why keys and nonces come from the OS generator; predictable random values as the usual point of failure
-
Block ciphers: fixed-size block, rounds, round keys, key schedule
-
Substitution-permutation network (AES) vs. Feistel network (DES): the general idea of each
-
DES: why its key length and block size failed; 3DES and why double encryption gains little (meet-in-the-middle, concept only)
-
AES: block size, key sizes, the default choice
-
-
Modes of operation: ECB and why not to use it; CBC and the IV; CTR, the nonce, and the keystream; GCM as CTR plus an authentication tag; AEAD, authentication tag, associated data
-
Nonce and IV reuse: why a repeated nonce is the one-time pad failure again
-
Malleability: why a mode without authentication lets an attacker change plaintext by changing ciphertext
-
Stream ciphers and keystream generators; ChaCha20 (with Poly1305) as the current one
-
Cryptanalysis of modern ciphers: recognize differential, linear, and side-channel attacks; constant-time code as the side-channel defense; bits of security; why quantum computing motivates AES-256
-
Requirements for a secure cryptosystem; why most real failures of encrypted systems are in key handling, nonces, modes, and procedures rather than in the cipher itself
You don’t have to know:
-
Dates, names of people, the mechanics of Atbash, Playfair, ADFGVX, or the Vigenère square, or how to encrypt or decrypt anything by hand
-
How Enigma’s rotors, plugboard, or the bombe worked, the specific flaws that let it be broken, cribs, or traffic analysis
-
The entropy formula, the internals of the DES round, the AES key schedule, ChaCha20’s parameters, AES-NI, or RC4
-
The mechanics of the meet-in-the-middle, Sweet32, KRACK, and padding-oracle attacks, or the birthday-bound arithmetic
-
The randomness failure stories beyond the shared lesson, and anything in the appendix
Integrity, authentication, and public key cryptography
- Integrity vs. authenticity vs. confidentiality; why encryption alone does not provide integrity
Hash functions
-
Cryptographic hash function, digest, and the properties: fixed-length output, determinism, preimage resistance, second preimage resistance, collision resistance, avalanche
-
Why collisions must exist (pigeonhole principle); why finding a collision (about 2(n/2) tries, the birthday problem) is easier than finding a preimage (about 2n), and why a 256-bit digest gives 128 bits of collision resistance
-
Why a hash check is only as good as the trust in the expected digest
Message authentication codes
-
Message authentication code (MAC, authentication tag): a matching tag shows a key holder authenticated the message and the bytes are unchanged; it provides neither confidentiality nor non-repudiation
-
Length-extension attack: why hash(key || message) is a bad MAC and HMAC is the fix (no formula)
-
Encryption without authentication is malleable; AEAD; encrypt-then-MAC; reject a bad tag before using the plaintext
-
Limits of shared secrets: no non-repudiation, one key per pair of parties (n2 growth), a key embedded in every installation can be extracted
Public key cryptography
-
One-way function, trapdoor function, discrete logarithm problem
-
Public and private keys; what each public-key operation gives and lacks: encryption (confidential delivery, no sender identity), signature (public verifiability, message stays readable), key agreement (shared secret, no authentication)
-
RSA (product of two primes), ECC (smaller keys for equal security), Diffie-Hellman (key agreement, needs separate authentication); why public-key operations are reserved for keys and signatures while symmetric ciphers handle bulk data
-
Why textbook RSA is weak: deterministic encryption and predictable ciphertext changes
-
Quantum attacks: a capable quantum computer breaks RSA, ECC, and Diffie-Hellman; symmetric keys and hashes only need to be longer; harvest now, decrypt later; post-quantum and hybrid key establishment (concepts only)
Digital signatures
-
Digital signature: generate, sign, verify; sign the digest, not the message; which key signs and which verifies; why collision resistance matters for signatures
-
Non-repudiation and its limits: a stolen key, and a signature says nothing about whether the content is true or safe
-
Code signing and secure boot: what a valid signature proves and what it does not
-
Software supply chain attacks: stolen key or fraudulent certificate, compromised build system, malicious dependency
Certificates
-
Certificate authority as a trusted third party; what a certificate binds (subject, public key, validity period, issuer, CA signature); what domain validation does and does not establish
-
Certificate chain, trust anchor, trust store; why a self-signature establishes nothing; the server must prove possession of the private key
-
Revocation: why it is needed and why it is hard to do well; why shorter lifetimes help but do not replace it
You don’t have to know:
-
Names of people, incidents, malware, standards bodies, trust-store maintainers, quantum or post-quantum algorithms (including Shor’s and Grover’s), factoring algorithms, or code-signing systems
-
How any hash function, RSA, ECC, or Diffie-Hellman works internally, or any arithmetic beyond the digest-length and collision-resistance relationship
-
HMAC’s padding and constants, hash-based one-time signatures, key fingerprints, Certificate Transparency, certificate formats, the specific revocation delivery mechanisms, or exact key-size comparisons
-
Supply chain defenses (reproducible builds, provenance, SBOMs, and the rest)
-
CRCs, parity, check digits, and telegraph codebooks, beyond the difference between accidental corruption and deliberate change
Authentication and secure communication
Protocols, keys, and freshness
-
Security protocol; the adversary that controls the network (reads, replays, reorders, injects, takes part as a legitimate user) but cannot break the cryptography
-
Adversary in the middle (AiTM, man in the middle)
-
Key establishment and the four approaches: pre-shared key, trusted third party, public key transport, Diffie-Hellman key agreement; why pairwise keys do not scale (n(n-1)/2) and why Diffie-Hellman must be authenticated
-
Replay attack; freshness; the three freshness mechanisms and their costs: nonce (protects only the party that chose it), timestamp (needs synchronized clocks and a replay window), sequence number (both sides keep state)
-
A freshness nonce vs. an encryption nonce: different jobs, different rules
-
Challenge-response authentication; one-way vs. mutual authentication; why the key never crosses the network
-
Reflection attack and its fix (make the two directions distinguishable)
-
Session hijacking; why authenticating at the start does not protect later messages; authenticated key exchange
Trusted third parties and Kerberos
-
Key distribution center (KDC): reduces long-term keys from about n2/2 to n; what everyone must trust it for; why compromising it compromises everyone
-
Ticket: an encrypted credential one party forwards and cannot read or change
-
The protocol family and what each step added: basic protocol (no freshness, tickets replay forever), Needham-Schroeder (Alice’s nonce and a handshake), the Denning-Sacco attack (an old session key and old ticket replay to Bob), the Denning-Sacco fix (a timestamp inside the ticket, at the cost of clocks)
-
The lesson: evidence of freshness and key possession must be bound to the intended participant
-
Kerberos: authentication server (login, ticket-granting ticket) vs. ticket-granting server (service tickets, single sign-on); why the KDC is split; authenticator (client name and time under the session key) as proof of key possession and replay defense; the KDC as the center of trust; why service accounts need long random passwords
Public key authentication, forward secrecy, and TLS
-
Signing a fresh nonce proves possession of a private key; why a signature on a nonce alone can still be relayed
-
Public key transport (RSA key transport) and why a later key compromise exposes every recorded session
-
Why unauthenticated Diffie-Hellman falls to an adversary in the middle, and the fix: sign the exchange with a long-term key bound to an identity by a certificate
-
Hybrid cryptosystem: public keys to authenticate and establish a key, symmetric AEAD for the data
-
Long-term key, ephemeral key, session key; forward secrecy, why ephemeral Diffie-Hellman provides it, and why RSA key transport and reused Diffie-Hellman values do not
-
TLS: handshake vs. data transfer; what each handshake part contributes (algorithm negotiation, ephemeral Diffie-Hellman, certificate chain, signature over the transcript hash, HMAC over the transcript); how signing the transcript stops key substitution and downgrade attacks
-
TLS records, AEAD, and sequence numbers against replay and reordering; why early data is risky; TLS authenticates only the server unless mutual TLS is used
Authenticating people
-
Identification vs. authentication vs. authorization; the three factors; multi-factor authentication
-
PAP vs. CHAP: what each sends, what each protects, and what each forces the server to store
-
Salted password hashes: what a salt does (identical passwords differ, precomputed tables fail) and does not do (slow a single-account guess); slow password hashing functions
-
One-time passwords: HOTP (counter) and TOTP (time interval) as HMACs under a shared key; why the server’s OTP keys cannot be hashed
-
Match each attack to its defenses: eavesdropping, offline guessing, dictionary attack, rainbow tables, online guessing, password spraying, credential stuffing, OTP key theft, SIM swap, push fatigue (number matching), real-time phishing relay (passkeys)
-
NIST guidance: length over complexity, no forced changes, blocklists
-
Passkeys: key pair per site, challenge signed after a local unlock (biometric or PIN never leaves the device); why they resist phishing (the browser supplies the origin, the key is bound to the domain, the signature covers the origin); synced vs. device-bound passkeys and the remaining risks
Biometric authentication
-
Template, threshold, approximate matching; minutiae as the fingerprint example
-
False accept rate vs. false reject rate; how the threshold trades them off; the ROC curve and the operating point; what moves the curve vs. what moves along it
-
Verification vs. biometric identification, and why searching many templates raises the false-match risk
-
Presentation attack and liveness detection; why templates cannot be protected by hashing
-
Why biometrics cannot be revoked, and why they work best as a local check that unlocks a key on the device
You don’t have to know:
-
Incidents, dates, organizations, and people’s names (protocol and attack names such as Needham-Schroeder and Denning-Sacco are still required)
-
Protocol notation, exact message contents, Otway-Rees, the Needham-Schroeder public-key sidebar, and anything in the appendix
-
TLS message order, message names, and version history
-
Password-hashing parameters and benchmarks, PBKDF2, and the specific NIST requirements
-
S/Key and how hash-chain one-time passwords are computed
-
The FIDO2 and WebAuthn standards and how providers synchronize passkeys
-
Kerberos operational details and Kerberoasting
-
Biometric enrollment and feature-extraction steps, specific minutiae and ridge patterns, iris vs. fingerprint comparisons, cancelable templates, how liveness detection works, equal error rate, coercion, and accuracy differences across populations
Last update: Wed Sep 30 20:20:04 2026