Cryptography & Encryption Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cryptography & Encryption flashcards as text
In an ACL ruleset, traffic is permitted only over port 443. Which encryption protocol operates on this port by default?
Answer: HTTPS (TLS)
HTTPS uses TLS and operates on TCP port 443 by default, providing encrypted and authenticated web communications.
What is the function of a 'nonce' in cryptographic protocols?
Answer: A random or unique value used once to prevent replay attacks and ensure freshness
A nonce (number used once) is a random value included in cryptographic communications to ensure that old messages cannot be reused in replay attacks.
Which encryption standard replaced DES and uses key sizes of 128, 192, or 256 bits?
Answer: AES (Advanced Encryption Standard)
AES, selected by NIST in 2001, replaced DES and supports 128-, 192-, and 256-bit key lengths, and remains the dominant symmetric encryption standard today.
An access control policy requires 'mutual TLS (mTLS).' What does this mean compared to standard TLS?
Answer: Both the client and server present certificates to authenticate each other
In mTLS, both the client and the server present X.509 certificates, providing two-way authentication rather than just server-side authentication.
Which concept describes deriving multiple cryptographic keys from a single master secret using a key derivation function (KDF)?
Answer: Key derivation / key expansion
A key derivation function (KDF) takes a master secret and generates multiple distinct keys for different purposes (e.g., encryption key and MAC key) from a single secret.
Why is ECB (Electronic Codebook) mode considered insecure for encrypting structured or repetitive data?
Answer: Identical plaintext blocks always produce identical ciphertext blocks, revealing patterns
ECB encrypts each block independently, so identical plaintext blocks produce identical ciphertext blocks, leaking structural information — famously illustrated by the 'ECB penguin' image.
Which protocol uses cryptographic tunneling to protect IP packets at the network layer, commonly used in VPN implementations controlled by firewall ACLs?
Answer: IPsec
IPsec operates at the network (IP) layer and encrypts and authenticates IP packets, making it the foundation of many VPN solutions whose traffic is governed by firewall ACL rules.