Cryptography & Encryption Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography & Encryption flashcards as text
Which type of encryption uses the same secret key for both encryption and decryption?
Answer: Symmetric encryption
Symmetric encryption uses a single shared secret key for both encrypting and decrypting data, making key distribution a key security challenge.
In the context of TLS, what is the role of the 'certificate chain' or 'chain of trust'?
Answer: Linking the server certificate back to a trusted root CA through intermediate CAs
A certificate chain connects an end-entity certificate through one or more intermediate CAs up to a trusted root CA, allowing clients to verify the certificate's legitimacy.
An ACL policy requires encrypting data with AES-256-GCM. What does the 'GCM' component provide beyond basic confidentiality?
Answer: Authenticated encryption with integrity and authenticity verification
GCM (Galois/Counter Mode) provides authenticated encryption, adding a message authentication tag that ensures both integrity and authenticity of the ciphertext.
Which Diffie-Hellman variant provides stronger security per bit and is preferred in modern TLS implementations over classic DHE?
Answer: ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)
ECDHE achieves equivalent security to DHE with much smaller key sizes because elliptic curve discrete logarithm problems are harder to solve per bit than finite-field problems.
A company's ACL requires that passwords stored in the database use 'key stretching.' Which algorithm is specifically designed for this purpose?
Answer: bcrypt
bcrypt is a password hashing function designed for key stretching; it incorporates a work factor that makes brute-force attacks computationally expensive.
What distinguishes a 'digital signature' from a simple 'message authentication code (MAC)'?
Answer: Digital signatures provide non-repudiation using asymmetric keys; MACs use a shared secret and cannot prove identity to third parties
Digital signatures use the sender's private key, allowing any party with the public key to verify authenticity and providing non-repudiation, while MACs rely on a shared secret known to both parties.
Which attack attempts to find two different inputs that produce the same hash output, potentially bypassing integrity checks?
Answer: Birthday attack (collision attack)
A collision attack (exploiting the birthday paradox) finds two distinct inputs with identical hash values, undermining hash-based integrity verification.