Tuesday, 2 June 2020

5B Directed Graph

5B Directed Graph
Description:
This topic describes about the directed graphs of Advance Design and Analysis of algorithms.”

=====================================================================

Watch video tutorial for your assistant & for any question do not hesitate to type comment below:




=====================================================================

Here is the PDF version of your lesson to download please click on the button below:

=====================================================================

Here is the PowerPoint Slides are available for your lesson to download please click on the button below:
 
=====================================================================


Thank you for your visit at our educational blog.
Your suggestions are welcome.
Click below button to Subscribe:               





Stay Awesome
Have a Green Day!


Saturday, 30 May 2020

ICSI | Certified Network Security Specialist Answer Keys

ICSI

ICSI | Certified Network Security Specialist (CNSS)
Certified Network Security Specialist
Quiz 1:

1: Trivial File Transfer Protocol (TFTP) runs on which port?

69

2: Which of the following is NOT one of the three major classes of threats?

Online auction fraud

3: Malware is NOT a common threat for systems.

False

4: Class A IPs with range 0-126 are reserved for multicasting.

False

5: Subnetting is used to split a network into smaller portions.

True

6: The most desirable approach to security is one which is:

Layered and Dynamic

7: Server Message Block (SMB) protocol runs on which port?

445

8: Blocking attacks seek to accomplish what?


Prevent legitimate users from accessing a system

Quiz 2:

1: The most common session-hijacking is man in the middle attack

True

2: Smurf attack is a popular DoS attack

True

3: To be protected against Ping of death attacks ensure that all operating systems are patched.

True

4: Which of the following is the best definition for IP spoofing?

Sending a packet that appears to come from a trusted IP address

5: What is a Trojan horse? (2 Answers)

Sorry for this answer but you can pass 60% other answering

6: Which of the following is the best definition of a virus?

Software that self-replicates

7: What is the danger inherent in IP spoofing attacks?

Many firewalls do not examine packets that seems to come from within the network

8: The point of hijacking a connection is to exploit trust and gain access to a system.

True

9: Which of the following best describes session hacking?

Taking control of the communication link between two machines

10: The point of hijacking a connection is to exploit trust and gain access to a system.


True

Quiz 3:

1: What is the most important security advantage to NAT

It hides internal network addresses

1: A device that hides its internal IP addresses is called?

Proxy server

2: Why  a stateful packet inspection firewall is less susceptible to spoofing attacks?

It examines the source IP of all packets

3: What type of firewall requires client applications to be authorised to connect?

Application gateway

4: Which of the following is an advantage of the network host based configuration?

It is inexpensive or free

5: Which type of firewall is considered the most secure?

stateful packet inspection

6: Why might a proxy gateway be susceptible to a flood attack?

its authentication method takes time and resources XXX

7: Which of the following can be shipped preconfigured?

Network host-based firewalls XX

8: Which of the following are four basic types of Firewalls?

Packet filtering. app gateway, circuit level, stateful packet inspection

10: Which of the following is a combination of firewalls?


Screened firewalls

Quiz 4:

1: A profiling technique that monitors how applications use resources is called?

executable  profiling

2: What is another term for preemptive blocking?

Banishment vigilance

3: Specter is an advanced IDS system

False

4: Which of the following is NOT a profiling strategy used in anomaly detection?

System monitoring

5: What type of IDS is Snort?

Host-based

6: Attempting to attract intruders to a system setup for monitoring them is called?

intrusion detection

7: A system that is setup for attracting and monitoring intruders is called?

honeypot

8: Specter aggressive mode tries to trace the attacker and gain its identity

True

9: A series of ICMP packets sent to your ports in sequence might indicate what?

Sniffing

10: IDS is an acronym for:


Intrusion-detection system


Quiz 5:

1: What is a digital signature?

a piece of encrypted data added to other data to verify the sender

2: Which of the following is a symmetric key system using blocks?

DES

3: Secure Multipurpose Internet Mail Extensions (S/MIME) use X.509 certificates to secure e-mail communication

True

4: Which of the following is an encryption method developed by three mathematicians?

RSA

5: Which hashing algorithm do modern Windows systems use?

NLTM

6: Which of the following encryption algorithms is a block cipher and uses the Rijndael algorithm?

AES

7: What is the purpose of a certificate?

To validate the sender of a digital signature or software

8: Which of the following uses key sizes equal to 128, 192 and 256 bits?

AES

9: Blowfish is an asymmetric stream cipher

False

10: Which encryption algorithm uses a variable length symmetric key?


Blowfish

Quiz 6:

1: Which of the following is an important security feature in CHAP

It periodically re-authenticates

2: What does L2TP stand for?

Layer 2 Tunnelling protocol

3: PPTP is based on which protocol?

PPP

4: Which authentication protocols are available under PPTP?

EAP, CHAP

5: Which of the following is a weakness in PPTP?

No encryption

6: The ESP Protocol provides data confidentiality and authentication.

True

7: Which of the following is generally considered the least secure?

PAP

8: What is the purpose of IKE?

Key exchange

9: PPTP is an acronym for which of the following?

point-to-point tunneling protocol

10: Openswan is a VPN solution provided by CISCO.


False

Quiz 7:

1: What maximum password age does Microsoft reccomends?

42 Days

2: What operating system require periodic patches?

All

3: What is the rule for unused services on any computer?

Turn them off

4: What account lockout threshold does the NSA reccomends?

3 tries

5: What type of ecnryption does EFS utilize?

Public key encrption

6: What level of privileges all users must have?

Least possible

7: Which of the following best describes the registry

A database containing system settings

8: A Linux system has a repository of packages available to be installed on the system

True

9: The command sudo find / -perm -4000 checks for the location of suid binaries

True

10: What minimum password length does the NSA recommends?


12

Quiz 8:

1: The unfortunate side effect of heuristic scanning is that it can easily lead to false positives

True

2: What is heuristic scanning?

Scanning using a rule-based approach

3: What is active code scanning?

Scanning for active web elements (scripts, ActiveX, and so on)

4: What is the most common method of virus propagation?

Through e-mail attachments

5: In the context of viruses what is a .dat file?

A file with virus defination

6: Which of the following should be the least important consideration when purchasing antivirus software?

Cost of the software

7: In the event of a virus infection, the first priority is to contact the IT department.

False

8: Which of the below are famous Trojan Horses? (Choose two)

Netbus FinFisher

9: The first known ransomware was the 1995 PC Trojan

False

10: What malicious activity did the Rombertik virus attempt?


It overwrite the master boot record

Quiz 9:

1: Passwords must always be shared with any person for any reason.

False

2: What should an employee do if she believes her password has been revealed to another party?

Change her password immediately

3: Which of the following is NOT an example of a user password policy?

Users may share passwords only with their assistants

4: Instant messaging can be used not only for business communication but also for personall communication.

False

5: Always open email attachments coming from unknown sources.

Flase

6: Logon accounts, VPN, network and any other resources should NOT be disabled for leaving employees.

False

7: Which of the following should be recommended as acceptable e-mail attachments?

Attachments the user expected

8: Which of the following is NOT an area user policies need to cover.

If and when to share passwords

9: What is the best rule of thumb in access control?

Allow the least access job requirements allow

10: Which of the following is the best reason users should be prohibited from installing software?


If the user's account does not have privileges to install,

Quiz 10:

1: Ports 1 through 1024 are NOT assigned and used for well-known protocols

False

2: What is NOT a primary reason for documenting your security activity and audits?

To demonstrate how much work the network administrator usually do

3: All visitors to the building must be logged in and escorted by an employee at all times.

True

4: Open Web Application Security Project is the standard for risk assessment.

False

5: Which of the following is the least necessary security device/software

Encryption for all internal transmissions

6: Which of the following best describes risk assessment.

evaluating the security of a network

7: Virus attacks utilize uncommon ports to gain access to a system.

True

8: You should have a document that lists physical security is in place

True

9: Which of the following is the most fundamental aspect of security?

Patching the operating system

10: All employees within a company must have access to the server room.

False

Quiz 11: 

1: Which of the following describes ISO 27003?

ISMS Implementation

2: What standard should you consult for managing incident response?

ISO 27035

3: Which U.S. standard should you consult to guide you in developing security policies?

NIST SP 800-14

4: What is the acronym of GDPR?

General Data Protection regulation

5: NIST SP 800-30 Rev.1 is a standard for conducting risk assessments.

True

6: Which U.S. standard covers risk assessment?

NISt SP 800-30

7: PCI DSS is a proprietary information security standard for organisations that handle cardholder data.

True

8: Which standard defines Management System Auditing?

ISO 27007

9: ISO 27035 describes incident management.

True

10: What does the Step 3 in NIST 800-30 Rev.1 clarifies?

Vulnerability Identification

Quiz 12:

1: Which of the following is NOT considered a disaster?

Server maintenance

2: How should a company test the integrity of its backup data

restoring the backup

3: A common method of securing building access is to have a locked door or barrier requiring employee ID.

True

4: The disaster recovery plan has as a major goal to get the organisation back to full functionality.

True

5: Which RAID level offers dual parity

6

6: Which RAID level uses mirroring?

1

7: RAID 0 does not offer fault tolerance

True

8: The plan for recovering from an IT disaster and having the IT infrastructure back in operation is called?

DRP

9: What is a mantrap?

A duoble door facility used for physical access control

10: Cameras must be placed so that they have an unobstructed view of the areas you want to monitor.

True

Quiz 13: 

1: If you send a SYN to an open port what is the correct response?

SYN/ACK

2: If you send a SYN to an open port what is the correct response?

Connect

3: From a port scanning you identified that port 88 is open. What does this tell you?

The target system uses kerberos authentication

4: Julie has been hired to perform a penetration test on xyz.com. She begins by looking at IP address ranges owned by the company and details of domain name registration. She then goes to news groups and financial websites to see whether any of the company’s sensitive information or technical details are online. What is Julie doing?

Passive information gathering

5: Trying to identify machines on a target network is called?

Enumeration

6: Which of the following is the most reliable type of scan?


Connect

By Daniyal Younis
Copyrights © 2020 All rights Reserved

Saturday, 21 December 2019

Complete Guide Microsoft Office 2019

Complete Guide Microsoft Office 2019

This is complete guide to install Microsoft office 2019 pro+ 

Just follow instructions below to download and install and life time activate your office 2019 pro+

Download Files are linked at the end of this blog.

Here is the instructions with each step you only need to type and enter.

You can also watch video in which each step is shown.

Here are the instruction lines:

Installation guide for those who had Windows 7, 10, 8.1 & Server 2012

Note: You Must have windnows 10 program to install Office 2019

Start installation Microsoft Office 2019 file: 

Step1: Open File wotok_mdl using cmd as administrator
Step2: type 3 and press enter button
step3: Type 1 and press enter button
step4: Type 1 and press enter button
step5: Type 5 and press enter button
step6: copy serial key only [B61285DD-D9F7-41F2-9757-8F61CBA4E9C8] and paste and press enter
step7: copy this text [ProPlus2019Retail] and paste and press enter
step8: press enter button only
step9: Type 1 and press enter button (Be patience until installation will complete and take some time)
step10: Type Enter and you will login into main menu again
step11: Type [ - ] minus/dash button from keyboard and press enter


At the end of the installation, 

To activate Office Porgram follow steps below

from the Crack folder, 

Step12: start the OInstal file
Step13: From Drop down Menu Select [Microsoft Office 2019]
step14: Go to Utilities tab and Click [Office RETAIL => VL] It will process data below until completed
step15: Click on [Activate Office]
step16: Now Done and close window Enjoy registered version of Microsoft office 2019


=================


You can also Watch video To get rid of confusion.



Instruction file 1KB only. https://bit.ly/35IjUpT To download Setup Office 2019 Pro + Cick on link below:
x86/x32bit Operating System link :







x64bit Operating system








Follow me on: Facebook : https://goo.gl/Xt4Kk6 Linkedin : https://goo.gl/Ko9AFg Google+ : https://goo.gl/zrgwSj Twitter : https://goo.gl/hfKzef

www.daniyalyounis.blogspot.com
www.youtube.com\daniyalyounis

Stay Awesome, Have a Green Day!

Comparison Chat Data Sim Packages

Comparison Chat Data Sim Packages

Mostly people want to compare data packages and want to choose best package according to their desire and budget but always it is confusion while remembering all packages in all the tabs where this comparison chart will help you all to compare data sim packages in one graphical chart.

Here is the picture for you.

Kindly share your friends if you like this.


Thank you for your visit at my blog.

Regards,
Dany

Sunday, 8 September 2019

Typhoid Application for School

Typhoid Application for School

Given below is the Microsoft word Application format which can be just edit with your Father name and student name sign. Print and submit the Application.


Application in textual format Part-I:

09/Jul/2019

KBV CAA Model School 3,


Respected Principal,
With due respect, I am __________ father of _________ enroll as student of class 9D in your School. It has been stated that She is suffering down with typhoid since last few days. therefore, unable to come to school and attend her classes. She has been under the treatment of my family doctor, who has advised her, Almost 15 days’ bed rest.

It is, therefore, requested that I may be granted leave of her absence for 15 days with effect from July 03 to July 18 of 2019.
Medical Report is attached.

Thanking you.

__________________

father name
16/09/2019

Application in .docx format Part-II

Download on the link given below to download the microsoft word format.


Thank you for visiting and downloading from the blog.
Regards
Daniyal younis.

Tuesday, 9 July 2019

Transactions Not Allowed as workflow rule failed

                                            Image result for fbr

Those people, who are looking for FBR Tax return and after paying their fee or amount to anywhere with government tax applied and ready to request for returning that tax money with their filer registration on iris fbr.

Many people are worry when they go to filling forms and always error with selecting time period:2019 etc.

therefore, i am writing simple note after arguing with an FBR agent who advised me and i thought to share with you. those who search at google and yet not find error handle " Transaction not allowed  as workflow rule  failed".

Do not worry and there is always FBR agents day night work to make better public service via website and staying home you people can fix issues and deal concerning problems.

Updating website with Many functions is a bit tough job and keep updated with security.

Keep reading and stay relax because an answer has been posted according to  FBR service team.

When you get that error stated above can be just solve as wait and wait until 21 of August and then you try it again Declaration forms because there is so much work for the agent to be done of everyday regarding tax returns and resolving.

21 August 2019 system will updated for 2019 year and then again keep visiting Website to be updated and then you will not find an error when exact time you will again submit file and there will no such error again.

Also one more thing i would like to discuss with you readers, Do not hurry, there are one thousand people waiting like you to get their payment back. After proper screening you get your tax cash back in hand safe and sound with the wait of 9 months approximately. but time will be short as your submit application will  be in process and it takes months but not more than 9 months.

Never temper and these updates are for you to keep you relax after handling and saving your time.

Thank you for reading me with proper concentration and attention.
Stay updated and promote/Share article linked with you at social media pages and groups and Whatsapp so that everybody know this all story and be patience.

Stay awesome and blessed.

Best Regards,

Daniyal Younis

Monday, 27 May 2019

A survey on SDN Programming language: toward a Taxonomy


A survey on SDN Programming language: toward a Taxonomy

Error Prone: fixing errors with the help of X-programming language (already developed)
Modularity: make system module to program components separated and recombined
Topology:  Create a network graph how data will be interchange
Evolve: Develop gradually
Taxonomy: Classify languages according to their similarities and differences




Network: into two categories: 1, Deliver data.  2, Managing flow of Data
This paper is survey on programming languages for SDN, where before survey need look at what is SDN and its working methodology.

Introduction: SDN (Software Defined Networking) is newly emerging architecture for Networks controls from physical devices (embedded) to logical systems (Servers). Which could be easy to maintain and less expense on routers and wires etc. As well as with user requirement each network topology could be configured automatically using virtual SDN (Application interface). Where there is still lack of design and architecture for this System to be implement. Architecture divided into three categories:


SDN Architecture Diagram
                     

Northbound interface (NBI): which is used to share data between application layer and control layer.
Southband Interfaces (CDPI): used to share data between Controller and Data Layer (Forwarding devices).
Future Oriented Domain Analysis (FODA): is a method used to gather information about languages features and so on…


Data Plane:  also known as forwarding plane, used to forwarding devices such as; Switches, responsible forwarding packets through ports and links.
Control Plane (Controller): The controller is the part of network, which carries signal traffic and is responsible for routing. It also talks with application layer to which kind of services provided. Control plane functionality is to include system configuration and management.
Application Plane: Which provides the User facility to manage all the network activities on Data flow and manage security, virtualization, monitoring, Load balancing for each device and QoS using Application Plane Interface.
In the time of Physical installed devices all activities individually performed on each router installed control plane manually, where SDN has converted control plane into software installed that all time wasting and effort at a platform called SDN. All control and changes manage from Application Plane.


How to Change Author Name in Blogger Post

Thursday, 23 November 2017

SW-II

Software Engineering-II

Solved paper Section-B

Q4: Differentiate between LOC and FP?
A: Loc and FP both are used for measurement of program size. Line Of Code is used to measure the size of program by counting the Lines of Source code of the Program. Where Functional point used to measure the functional size.

Q5: Give solid reason for the actual benefits of documentation?
A:  Documentation is an important part of Software Engineering. It is a viable part of Software Development process and without it, it is hard to maintain any project and the developers have to re-invent the wheel.

Q6: When you feel that client don’t knot about their business environment in requirements gathering process. Which SDLC model you will preferred and why?
A: Agile SDLC will be preferred in this situation becuase;
     Customer satisfaction by rapid, continues delivery of useful software.
     Peoples and interactions are emphasized rather than process and tools.
     face to face communication and late requirements are welcome.

Q7: How extreme programming works for any given case of software development?
A: Extreme programming works in given case simply by placing two peoples together to work more faster than one person to overcome mistakes and errors. So in less time product is produced faster.

Q8: Is it possible that we can find the direct effort from FP analysis. If not give reason.
A: Yes this possible to find direct effort from functional points analysis as compare to other approach generation 2 that is known as COSMIC. That means it is worth to migrate from 1st generation method to 2nd generation.

Section-C
Q9: Following are the partial requirements written for a module “Online Banking debate  crad activation” of xyz marketing system.
The requirements listed above are a part of specification document. We want to calculate the lack of ambiguity for the requirements listed above in the “ Online Buying” module. The result will help us in gathering the data for maintaining the metrics for specification quality.
You have to analyze these requirements and then you have to find the value for lack of ambiguity in these requirements. For this you also have to mention the functional, Non-functional, total and ambiguous requirements in the given set of requirements.

Req-01 System shall allow user to enter 5 digit pin code number
Req-02 System shall allow user to enter national id card no
Req-03 System shall allow user to select type of user (current, pls and administrator) from combo
Req-04 System should have good user interface
Req-05 System should be user friendly
Req-06 System should be able to perform operations efficiently
Req-07 System shall confirm activation after getting correct info

A:
Metrics for specification quality,
 Software Requirements proposed by Davis in 1993
1. Functional requirements
2. Non-Functional requirements
Total Requirements (nr)= Functional req(nf) + Non-functional req(nnf)
Lack of ambiguity in requirements is calculated as;
Q = nui (ui = non-func req) / ur

Now calculate the un-ambiguity as follow;
check above table that how many are functional and non functional requirements in specification listed.

Req-01 (Functional) System shall allow user to enter 5 digit pin code number
Req-02 (Functional) System shall allow user to enter national id card no
Req-03 (Functional) System shall allow user to select type of user (current, pls & administrator)                                            from combo
Req-04 (Non-Fun)         System should have good user interface
Req-05 (Non-fun)         System should be user friendly
Req-06 (Non-fun)         System should be able to perform operations efficiently
Req-07 (Functional) System shall confirm activation after getting correct info

we  have Function req= 4, Non functional req= 3
Total Req= 4 ( Func_Req ) + 3 ( Non-Func_req)
Total Req= 7
Find Un-ambiguous efficiency:
Q = Non-Func_Req / Total Req
Q = 3 / 7
Q = .42%  (Un-ambiguous)

Q10: You are required to do functional point Analysis for these ease study given below.
This is real world example of FP Analysis. This will give you hand on experience of performing FP Analysis.
In the assignment you were provided with Library Information and Management system (LIMS). Consider only three tables from the same software (LIMS) named new_acc_no, Member and IssueHis.
1.  Newaccno: newacc keeps the record of books with all the details like title, Accession+, Author, Subauthor etx. max=40
2.  Member: member holds the data of the person who holds library membership Max=35
3.  IssueHis: This table holds the data of the books being issued. Max=14
The following operations are being performed on this system:


  • Add a book (with all it's details)
  • Delete the record of a book
  • Add a new member in the system
  • Generate a membership card for the library member
  • Generate a report that shows the number of books issued between two given dates
For this problem to do following:
a) Identify all ILF's, EIF's, DET's, EI's, EO's, and EQ's and calculate their complexities.
Calculate the understand FP count for the application.
Following support material for the problem.


EI


RET's
DET's
1 - 45 - 15> 16
<2LowLowAverage
2LowAverageHigh
> 2AverageHighHigh

EO, EQ
FTR's
DET's
1 - 56 - 19> 20
<2LowLowAverage
2 - 3LowAverageHigh
> 3AverageHighHigh

ILF, EIF

FTR's
DET's
1 - 1920-50> 51
1LowLowAverage
2-5LowAverageHigh
> 5AverageHighHigh

FP contribution of different Analysis Components
RatingValues
EOEQEIILFELF
Low43375
Average544107
High6561510

Solution: 
FTRDET
MaintainData_RefData_ProcTransactional
Add bookYesNoNoEI
Del bookYesNoNoEI
Add memYesNoNoEI
Gen_Card    YesNoYesEO
Book IssuedNoNoNoEQ

Complexities of the Functional POint Analysis
FTRDET
Transaction          FTR      DET Complexity  FP
Add bookEIbook>16Avg4
Del bookEIbook>16Avg4
Add memEImember>16Avg4

Gen_Card    EOmem. Lib>20high6
Book IssuedEQlib,mem,book>20high5

From above given tables we find Functional Points:FP= ILF + EIF + EI +EO+ EQ
FP= ILF + EIF + 23
FP= ILF +   0   + 23

FP= 3*7 +   0   + 23
FP= 21   +   0   + 23
FP= 44% out of 100%

You can also download Word file solution copy for more clearance , click
https://drive.google.com/open?id=1UL0GjSpR2wYTatZI36PbGbuGY5sy_2nx

23-nov-2017                                                          ALL-RIGHTS-RESERVED  ©DANIYALYOUNIS