Cryptography Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography flashcards as text
Which cryptographic algorithm is specifically designed for key wrapping and protecting other cryptographic keys?
Answer: AES-KW (AES Key Wrap)
AES Key Wrap (AES-KW) is specifically designed to protect cryptographic keys by encrypting them with a key-encrypting key (KEK).
What is the main advantage of Elliptic Curve Cryptography (ECC) over RSA for the same security level?
Answer: ECC requires smaller key sizes for equivalent security
ECC provides equivalent security to RSA with much smaller key sizes; a 256-bit ECC key offers roughly the same security as a 3072-bit RSA key.
A message authentication code (MAC) differs from a digital signature primarily because a MAC:
Answer: Uses a shared secret key and does not provide non-repudiation
MACs use a shared symmetric key, so any party with the key could have generated it, meaning MACs cannot provide non-repudiation.
Which padding scheme is recommended for RSA encryption to prevent attacks such as Bleichenbacher's attack?
Answer: OAEP (Optimal Asymmetric Encryption Padding)
OAEP is the modern recommended padding for RSA encryption and is resistant to Bleichenbacher's chosen-ciphertext attack that affects PKCS#1 v1.5.
What does perfect forward secrecy (PFS) ensure in a TLS session?
Answer: Compromise of the long-term private key does not expose past session keys
PFS ensures that each session uses an ephemeral key pair, so compromising the server's private key cannot decrypt previously captured sessions.
In steganography, what distinguishes it from encryption?
Answer: Steganography hides the existence of data; encryption makes it unreadable
Steganography conceals the fact that a message exists at all (security through obscurity), while encryption scrambles content but doesn't hide the message's existence.
Which key management practice involves splitting a cryptographic key into multiple parts so that no single person holds the complete key?
Answer: Key splitting / M-of-N control
M-of-N key splitting (split knowledge) divides a key among N custodians, requiring M parts to reconstruct it, preventing single-person access.