CCP Cryptography & PKI Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCP Cryptography & PKI flashcards as text
Which cryptographic property ensures that a sender cannot later deny having sent a message?
Answer: Non-repudiation
Non-repudiation, typically achieved through digital signatures, provides cryptographic proof of origin that prevents a sender from denying their actions.
What is the primary difference between symmetric and asymmetric encryption?
Answer: Symmetric uses one key for encryption and decryption; asymmetric uses a public/private key pair
Symmetric encryption uses a single shared secret key for both encryption and decryption, while asymmetric encryption uses a mathematically linked key pair โ one public, one private.
Which hashing algorithm is currently recommended by NIST for generating message digests due to its resistance to collision attacks?
Answer: SHA-256
SHA-256 (part of the SHA-2 family) is NIST-recommended for cryptographic hashing, as MD5 and SHA-1 have known collision vulnerabilities.
In a Public Key Infrastructure (PKI), what is the role of a Certificate Authority (CA)?
Answer: To issue, sign, and revoke digital certificates that bind public keys to identities
A CA is a trusted third party that issues digitally signed certificates, binding a subject's identity to their public key and enabling other parties to trust that binding.
What mechanism allows a relying party to check whether a digital certificate has been revoked before it reaches its expiration date?
Answer: Online Certificate Status Protocol (OCSP)
OCSP provides real-time certificate revocation status by querying an OCSP responder, offering a more efficient alternative to downloading full Certificate Revocation Lists (CRLs).
Which cipher mode of operation provides both confidentiality and data integrity within a single operation, making it suitable for TLS 1.3?
Answer: Galois/Counter Mode (GCM)
GCM is an authenticated encryption mode that simultaneously provides confidentiality and message authentication, and is the preferred cipher mode in TLS 1.3.