Cryptography Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cryptography flashcards as text
Which key exchange protocol allows two parties to establish a shared secret over an insecure channel without transmitting the secret itself?
Answer: Diffie-Hellman
Diffie-Hellman enables two parties to derive a shared secret using public values without ever transmitting the secret itself.
A digital signature provides which two security services?
Answer: Authentication and non-repudiation
Digital signatures verify the signer's identity (authentication) and prevent the signer from denying the action (non-repudiation).
What is the primary weakness of a one-time pad if the same pad is used more than once?
Answer: XORing two ciphertexts reveals information about plaintexts
Reusing a one-time pad allows an attacker to XOR two ciphertexts together, canceling the key and exposing a combination of the two plaintexts.
Which mode of operation for block ciphers produces the same ciphertext for identical plaintext blocks and is considered insecure for most uses?
Answer: ECB
Electronic Codebook (ECB) mode encrypts each block independently, so identical plaintext blocks produce identical ciphertext blocks, leaking data patterns.
In PKI, what is the purpose of a Certificate Revocation List (CRL)?
Answer: To enumerate certificates that have been invalidated before their expiry
A CRL is a signed list published by the CA that identifies certificates that have been revoked and should no longer be trusted.
What cryptographic property ensures that a small change in input produces a drastically different output hash?
Answer: Avalanche effect
The avalanche effect means flipping even a single bit in the input causes approximately half the output bits to change.
Which of the following best describes a birthday attack against a hash function?
Answer: Finding two different inputs that produce the same hash value
A birthday attack exploits the birthday paradox to find two different messages with the same hash (a collision) far faster than brute force.