CCP Cryptography & PKI Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCP Cryptography & PKI flashcards as text
What is a digital signature and how does it work?
Answer: A hash of the message encrypted with the sender's private key, verifiable with the sender's public key
A digital signature is created by hashing the message and encrypting the hash with the sender's private key; recipients decrypt it with the sender's public key and compare hashes to verify authenticity and integrity.
Which key exchange protocol allows two parties to establish a shared secret over an insecure channel without transmitting the secret itself?
Answer: Diffie-Hellman (DH) key exchange
Diffie-Hellman key exchange enables two parties to independently compute the same shared secret using public values, without the secret ever being transmitted.
What is the purpose of a Hardware Security Module (HSM) in a PKI deployment?
Answer: To securely generate, store, and manage cryptographic keys in tamper-resistant hardware
An HSM is a dedicated hardware device that provides tamper-resistant storage and cryptographic operations for private keys, protecting them from software-based attacks.
Which attack involves an adversary intercepting encrypted traffic today with the intention of decrypting it in the future once quantum computers become capable?
Answer: Harvest-now, decrypt-later (HNDL)
HNDL attacks involve storing encrypted data captured today and decrypting it once sufficiently powerful quantum computers are available, motivating the transition to post-quantum cryptography.
What is a Certificate Transparency (CT) log, and how does it improve PKI security?
Answer: A publicly auditable append-only log of all issued certificates, enabling detection of misissued or rogue certificates
CT logs are publicly accessible, append-only records of issued certificates that allow domain owners and security researchers to detect unauthorized or misissued certificates.
Which NIST standard describes a suite of post-quantum cryptographic algorithms intended to replace RSA and ECC against quantum-capable adversaries?
Answer: NIST IR 8413 / FIPS 203/204/205
NIST finalized its first post-quantum cryptography standards in 2024 as FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), documented in NIST IR 8413.