โ† All CCP Flashcard Decks

CCP Cryptography & PKI Flashcards

6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCP Cryptography & PKI flashcards as text
  1. What is a digital signature and how does it work?

    Answer: A hash of the message encrypted with the sender's private key, verifiable with the sender's public key

    A digital signature is created by hashing the message and encrypting the hash with the sender's private key; recipients decrypt it with the sender's public key and compare hashes to verify authenticity and integrity.

  2. Which key exchange protocol allows two parties to establish a shared secret over an insecure channel without transmitting the secret itself?

    Answer: Diffie-Hellman (DH) key exchange

    Diffie-Hellman key exchange enables two parties to independently compute the same shared secret using public values, without the secret ever being transmitted.

  3. What is the purpose of a Hardware Security Module (HSM) in a PKI deployment?

    Answer: To securely generate, store, and manage cryptographic keys in tamper-resistant hardware

    An HSM is a dedicated hardware device that provides tamper-resistant storage and cryptographic operations for private keys, protecting them from software-based attacks.

  4. Which attack involves an adversary intercepting encrypted traffic today with the intention of decrypting it in the future once quantum computers become capable?

    Answer: Harvest-now, decrypt-later (HNDL)

    HNDL attacks involve storing encrypted data captured today and decrypting it once sufficiently powerful quantum computers are available, motivating the transition to post-quantum cryptography.

  5. What is a Certificate Transparency (CT) log, and how does it improve PKI security?

    Answer: A publicly auditable append-only log of all issued certificates, enabling detection of misissued or rogue certificates

    CT logs are publicly accessible, append-only records of issued certificates that allow domain owners and security researchers to detect unauthorized or misissued certificates.

  6. Which NIST standard describes a suite of post-quantum cryptographic algorithms intended to replace RSA and ECC against quantum-capable adversaries?

    Answer: NIST IR 8413 / FIPS 203/204/205

    NIST finalized its first post-quantum cryptography standards in 2024 as FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), documented in NIST IR 8413.