PrepAway - Latest Free Exam Questions & Answers

Which of the following incorrectly describes steganography?

Which of the following incorrectly describes steganography?

PrepAway - Latest Free Exam Questions & Answers

A.
It is a type of security through obscurity.

B.
Modifying the most significant bit is the most common method used.

C.
Steganography does not draw attention to itself like encryption does.

D.
Media files are ideal for steganographic transmission because of their large size.

Explanation:
B: Steganography is the method of hiding data in another media type so that the very existence of the data is concealed. One of the most common methods of embedding the
message into some type of medium is using the least significant bit (LSB)not the most significant bit. Many types of files have some bits that can be modified and not affect the file
they are in, which is where secret data can be hidden without altering the file in a visible manner. In the LSB approach, graphics with a high resolution or an audio file that has many
different types of sounds (high bit rate) are the most successful in hiding information within. There is commonly no noticeable distortion, and the file is usually not increased to a size
that can be detected. A 24-bit bitmap file will have 8 bits representing each of the three color values, which are red, green, and blue. These 8 bits are within each pixel. If we consider
just the blue, there will be 28 different values of blue. The difference between 11111111 and 11111110 in the value for blue intensity is likely to be undetectable by the human eye.
A is incorrect because steganography is a type of security through obscurity. Security through obscurity means that instead of actually securing some-thing with a countermeasure,
someone uses secrecy as the way to protect the asset. An example of security through obscurity is if a network administrator changes his HTTP port from 80 to 8080 with the hopes
that no one will figure this out. Security through obscurity means that you are trying to fool the potential attacker and you assume that the attacker will not be clever enough to figure out
your trickery.
C is incorrect because it is true that steganography does not draw attention to itself as does encryption. An encrypted message can draw attention because it tells the bad guy that
the encrypted information is sensitive (otherwise, it wouldn’t be encrypted in the first place). An attacker may then be motivated to break the encryption and uncover the information.
The goal of steganography is that the attacker not even know that the sensitive information exists and thus will not attempt to capture it.
D is incorrect because it is true that larger media files are ideal for steganographic transmission because there are more bits to manipulate with a lower chance that anyone will
notice. As a simple example, a sender might start with an innocuous image file and adjust the color of every hundredth pixel to correspond to a letter in the alphabet, a change so
subtle that someone not specifically looking for it is unlikely to notice it. The larger the file, the more obscurity can be accomplished because there are more bits to work with and
manipulate.

One Comment on “Which of the following incorrectly describes steganography?


Leave a Reply