← All CISSP Flashcard Decks

Cryptography Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cryptography flashcards as text
  1. Which key exchange protocol allows two parties to establish a shared secret over an insecure channel without transmitting the secret itself?

    Answer: Diffie-Hellman

    Diffie-Hellman enables two parties to derive a shared secret using public values without ever transmitting the secret itself.

  2. A digital signature provides which two security services?

    Answer: Authentication and non-repudiation

    Digital signatures verify the signer's identity (authentication) and prevent the signer from denying the action (non-repudiation).

  3. What is the primary weakness of a one-time pad if the same pad is used more than once?

    Answer: XORing two ciphertexts reveals information about plaintexts

    Reusing a one-time pad allows an attacker to XOR two ciphertexts together, canceling the key and exposing a combination of the two plaintexts.

  4. Which mode of operation for block ciphers produces the same ciphertext for identical plaintext blocks and is considered insecure for most uses?

    Answer: ECB

    Electronic Codebook (ECB) mode encrypts each block independently, so identical plaintext blocks produce identical ciphertext blocks, leaking data patterns.

  5. In PKI, what is the purpose of a Certificate Revocation List (CRL)?

    Answer: To enumerate certificates that have been invalidated before their expiry

    A CRL is a signed list published by the CA that identifies certificates that have been revoked and should no longer be trusted.

  6. What cryptographic property ensures that a small change in input produces a drastically different output hash?

    Answer: Avalanche effect

    The avalanche effect means flipping even a single bit in the input causes approximately half the output bits to change.

  7. Which of the following best describes a birthday attack against a hash function?

    Answer: Finding two different inputs that produce the same hash value

    A birthday attack exploits the birthday paradox to find two different messages with the same hash (a collision) far faster than brute force.