CCP Cryptography & PKI Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCP Cryptography & PKI flashcards as text
What is a 'man-in-the-middle' (MitM) attack in the context of cryptography, and which PKI mechanism prevents it?
Answer: An attacker intercepts and possibly alters communications between two parties; prevented by certificate validation and pinning
In a MitM attack the adversary intercepts traffic between two parties; PKI certificate validation and certificate pinning prevent this by ensuring the presented certificate matches the expected trusted entity.
What is the function of a Registration Authority (RA) within a PKI hierarchy?
Answer: To validate the identity of certificate requestors and forward approved requests to the CA for issuance
An RA performs identity vetting and approves or rejects certificate requests, offloading validation tasks from the CA while the CA retains signing authority.
Which property of cryptographic hash functions ensures that it is computationally infeasible to find two different inputs that produce the same hash output?
Answer: Collision resistance
Collision resistance means it is computationally infeasible to find any two distinct inputs m1 ≠ m2 such that H(m1) = H(m2), which is critical for digital signature integrity.
In TLS handshake negotiation, what is the purpose of the 'cipher suite' agreed upon between client and server?
Answer: To specify the combination of key exchange, authentication, encryption, and MAC algorithms for the session
A cipher suite defines the specific algorithms used for each cryptographic operation in a TLS session: key exchange (e.g., ECDHE), authentication (e.g., RSA), bulk encryption (e.g., AES-256-GCM), and message authentication.
What is key escrow, and why is it controversial in cybersecurity policy?
Answer: A system where encryption keys are held by a trusted third party; controversial because it creates a high-value target and potential government backdoor
Key escrow stores copies of encryption keys with a third party (often government-mandated) to allow lawful access, but critics argue this creates a central vulnerability and undermines end-to-end encryption.
Which asymmetric algorithm is widely used for digital signatures in code signing and TLS certificates, and relies on the difficulty of factoring large integers?
Answer: RSA
RSA (Rivest–Shamir–Adleman) is the most widely deployed asymmetric algorithm for digital signatures and key exchange, deriving its security from the computational difficulty of factoring the product of two large primes.