Cryptography & Information Security Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography & Information Security flashcards as text
What is a rainbow table attack?
Answer: A precomputed table of hash values used to reverse hash functions and recover passwords
A rainbow table is a precomputed lookup table that maps hash values back to their plaintext inputs, allowing rapid password recovery without brute-force computation.
How does adding a cryptographic salt to a password before hashing defend against rainbow table attacks?
Answer: It ensures each password produces a unique hash even if two users have the same password
A random salt is appended to the password before hashing, making precomputed rainbow tables useless because the same password with different salts produces entirely different hashes.
What is Perfect Forward Secrecy (PFS) in the context of TLS?
Answer: A property ensuring that compromise of long-term keys does not expose past session keys
PFS ensures that each session uses an ephemeral key derived independently, so that even if the server's long-term private key is later compromised, previously recorded sessions remain protected.
Which security protocol provides end-to-end encryption for email including digital signatures and encryption of message bodies?
Answer: S/MIME (Secure/Multipurpose Internet Mail Extensions)
S/MIME provides cryptographic security for email by supporting digital signing and encryption of message content, ensuring confidentiality and authenticity end-to-end.
What is the primary difference between stream ciphers and block ciphers?
Answer: Stream ciphers encrypt data one bit or byte at a time, while block ciphers encrypt fixed-size chunks of data
Stream ciphers process plaintext one bit or byte at a time using a keystream, while block ciphers operate on fixed-length groups of bits, making them suited for different use cases.
In cryptography, what does the term 'key derivation function (KDF)' refer to?
Answer: A function that derives one or more cryptographic keys from a master secret or password
A KDF takes a secret value such as a password or master key and derives one or more strong cryptographic keys using techniques like PBKDF2, bcrypt, or HKDF.
Which attack exploits the mathematical relationship between a public key and its certificate to impersonate a trusted entity?
Answer: Man-in-the-middle attack using a forged or rogue certificate
A man-in-the-middle attack using a rogue certificate intercepts communications by presenting a forged certificate trusted by the victim, allowing the attacker to impersonate the legitimate server.