B-CS Cybersecurity Questions
Single-subject study programme
Technology and Security- Computing systems. Number systems, relationships between number systems, representation of integers in a computer, arithmetic. Codes: internal, external, detection and correction codes. Processors, their parameters and architectures. Internal and external memory and the principles of their operation. Computer input and output devices and their connection. ( PB151)
- Operating systems. Operating system architecture, kernel architecture, basic processor modes. Programming interfaces, libraries. Users, access rights, virtualisation. Virtual memory, processes and page tables. Threads, thread and process scheduling. Concurrency, deadlock, resource allocation. Process creation and programme execution in POSIX systems, copy-on-write. ( PB152, PV004)
- File systems. Block devices, block layer, I/O scheduler, RAID, disk encryption. Ordinary files, free space allocation, fragmentation. Directory structure and its representation on disk. Memory-mapped input and output. ( PB152, PV004)
- Networks. Computer network layer models (ISO/OSI, TCP/IP). Functionality and interaction of layers, addressing. Physical layer, signals and their encoding, media access control. Interconnection of computer networks. Network protocols, switching and routing, multicast. Secure data transmission, connection establishment and termination. Transport protocols. ( PB156, PB156cv)
- Network applications and security. Basic application protocols: email delivery, file transfer, the Web, directory service. Principles of service description and quality of service assurance, applications for multimedia. Network communication security, authentication and encryption, security at individual protocol layers. ( PB156, PB156)
- Principles of programming. Structured programming in an imperative language. The programme’s memory model; memory management, dynamic allocation, working with user data structures. Low-level memory management, pointers, arrays and pointer arithmetic. Methods of programme debugging. Secure programming and software development. ( PB071, PV080)
- Databases. The relational model, relational schema, keys in relational schemas, integrity constraints, relational algebra, join operations. The SQL query language (SELECT statement, join operations, aggregate functions). Query processing. Indexing. Transactions. Properties of transactional processing. ( PB154 || PB168)
- Software and Information Systems Development and operation of software systems. Use of UML in software development. Applied information systems. Architectures of large-scale information systems. Methods of managing large-scale projects. Information system operations management. ( PB007, PV028)
- Basic security functions and their assurance – confidentiality, integrity, availability, non-repudiation. Organisation and management of security, security policies and procedures. Cybersecurity governance structure, roles, responsibilities and competencies. ( PV080, PV017, PV210)
- Authentication and access control methods. Biometric authentication methods, their implications and challenges. Digital signatures and their use. Authentication of devices and applications. ( PV080, PV157)
- Risk analysis and management. Asset management, risk analysis, risk mitigation measures and their effectiveness. Identity and access management, ACLs, privileged users. Auditing, security standards, security assessments. ( PV080, PV157, PV017)
- Security architecture. Network security, network isolation and segmentation, firewalls. Monitoring, detection and logging. Operating system security, data security. ( PB156, PB156cv, PV004, PV175)
- Cybersecurity in Organisations. Cybersecurity events, incidents, attacks, vulnerabilities and weaknesses. The roles and activities of an organisation’s security team. Handling a cybersecurity incident. Security alerts. Practical examples of all the above. ( PB177, PV210)
- Cyberattacks. The cyberattack lifecycle. Advanced Persistent Threat. The MITRE ATT&CK® framework – tactics, techniques and procedures. Reconnaissance, initial access, exploitation of vulnerabilities, code execution, maintaining access, target actions. Defence options against attacks at host and network levels. Practical examples of all the above. ( PB177)
- Definition of security studies. The concepts of security, threat and risk, and their application in the field of cybersecurity. Internal and external security and sectors from a cybersecurity perspective. Definition of security policy and its analysis, with a focus on cybersecurity policy. ( BSSb1101)
- Security strategy. Documents of the Czech Republic and the significance of cybersecurity within them. The security system of the Czech Republic and the role of institutions in the field of cybersecurity. ( BSSb1103)
- Cyberwarfare. Definition, history, current trends. Identification of actors, problems with attributing cyberattacks, the possibility of deterrence in cyberspace. The concept of ‘netwars’ and its application in cyberconflict. ( BSSb1152)
- Critical Infrastructure Protection. Cyberattacks on critical infrastructure. Attribution and deterrence in cyberspace. ( BSSb1103)
- Legal framework for cyber security in the Czech Republic and the EU. Fundamental institutions, principles, competent authorities, and the cyber security assurance system. ( BVV03K)
- Cybercrime. Sources of law (national, European and international), typical criminal activities, classification of criminal offences, legal classification and related procedures and criteria, international cooperation. ( BVV03K)
- Electronic evidence and its preservation. Procedural institutions and their practical application; handling of electronic evidence; electronic documents. ( BVV03K)
- Data protection. Legal framework. Principles and rules governing the processing of personal data – definitions, fundamental principles, risk assessment, proportionality test. Purposes of processing. Legal bases. The Act on the Processing of Personal Data – the Office for Personal Data Protection (ÚOOÚ) and its role and status in the Czech Republic. ( BI301K)
- Electronic signatures and electronic seals. Legal framework and types. Data boxes – legal framework and practical use. ( BI301K)