Cryptography & Encryption Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography & Encryption flashcards as text
Which X.509 certificate extension restricts what a certificate may be used for, such as limiting it to 'Digital Signature' or 'Key Encipherment'?
Answer: Key Usage
The Key Usage extension defines the cryptographic operations for which the certificate's public key may be used, enforcing purpose restriction in PKI deployments.
An ACL permits only encrypted DNS traffic. Which protocol encrypts DNS queries to prevent eavesdropping and manipulation?
Answer: DNS over HTTPS (DoH)
DNS over HTTPS (DoH) encrypts DNS queries within HTTPS sessions, preventing ISPs or attackers from reading or modifying DNS traffic in transit.
What is 'certificate pinning' and why is it used in conjunction with ACL-enforced TLS policies?
Answer: Associating a host with its expected public key or certificate to prevent MITM using rogue CA-issued certificates
Certificate pinning hardcodes or pre-validates a specific public key or certificate, so even a validly CA-signed rogue certificate will be rejected, protecting against compromised CAs.
Which asymmetric key exchange algorithm's security relies on the difficulty of computing discrete logarithms in a finite field?
Answer: Diffie-Hellman (DH)
Diffie-Hellman key exchange derives its security from the discrete logarithm problem: given g^x mod p, it is computationally infeasible to determine x.
An encryption policy mandates 'authenticated encryption.' What additional guarantee does this provide over encryption-only modes?
Answer: Integrity and authenticity verification alongside confidentiality
Authenticated encryption (e.g., AES-GCM or ChaCha20-Poly1305) simultaneously provides confidentiality, integrity, and authenticity, detecting any ciphertext tampering.
Which mechanism allows a client to check whether a TLS certificate has been revoked without downloading a full Certificate Revocation List (CRL)?
Answer: OCSP (Online Certificate Status Protocol)
OCSP lets a client query the CA's OCSP responder in real time to check a specific certificate's revocation status, avoiding the need to download and process a full CRL.
In a zero-trust ACL architecture, data is encrypted both in transit and at rest. Which term describes encryption applied to data stored on disk or in databases?
Answer: Encryption at rest
Encryption at rest protects stored data (on disk, SSD, or in databases) so that physical theft or unauthorized storage access does not expose plaintext data.