โ† All ACL Flashcard Decks

Cryptography & Encryption Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cryptography & Encryption flashcards as text
  1. Which type of encryption uses the same secret key for both encryption and decryption?

    Answer: Symmetric encryption

    Symmetric encryption uses a single shared secret key for both encrypting and decrypting data, making key distribution a key security challenge.

  2. In the context of TLS, what is the role of the 'certificate chain' or 'chain of trust'?

    Answer: Linking the server certificate back to a trusted root CA through intermediate CAs

    A certificate chain connects an end-entity certificate through one or more intermediate CAs up to a trusted root CA, allowing clients to verify the certificate's legitimacy.

  3. An ACL policy requires encrypting data with AES-256-GCM. What does the 'GCM' component provide beyond basic confidentiality?

    Answer: Authenticated encryption with integrity and authenticity verification

    GCM (Galois/Counter Mode) provides authenticated encryption, adding a message authentication tag that ensures both integrity and authenticity of the ciphertext.

  4. Which Diffie-Hellman variant provides stronger security per bit and is preferred in modern TLS implementations over classic DHE?

    Answer: ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)

    ECDHE achieves equivalent security to DHE with much smaller key sizes because elliptic curve discrete logarithm problems are harder to solve per bit than finite-field problems.

  5. A company's ACL requires that passwords stored in the database use 'key stretching.' Which algorithm is specifically designed for this purpose?

    Answer: bcrypt

    bcrypt is a password hashing function designed for key stretching; it incorporates a work factor that makes brute-force attacks computationally expensive.

  6. What distinguishes a 'digital signature' from a simple 'message authentication code (MAC)'?

    Answer: Digital signatures provide non-repudiation using asymmetric keys; MACs use a shared secret and cannot prove identity to third parties

    Digital signatures use the sender's private key, allowing any party with the public key to verify authenticity and providing non-repudiation, while MACs rely on a shared secret known to both parties.

  7. Which attack attempts to find two different inputs that produce the same hash output, potentially bypassing integrity checks?

    Answer: Birthday attack (collision attack)

    A collision attack (exploiting the birthday paradox) finds two distinct inputs with identical hash values, undermining hash-based integrity verification.