Cryptography Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cryptography flashcards as text
Which attack exploits the mathematical relationship between related RSA keys when the same plaintext is encrypted with multiple public keys sharing the same exponent?
Answer: Håstad's broadcast attack
Håstad's broadcast attack uses the Chinese Remainder Theorem to recover plaintext when the same message is encrypted with multiple RSA public keys using a small exponent like e=3.
What is the role of a Key Derivation Function (KDF) in cryptographic systems?
Answer: To derive cryptographic keys from a master secret or password
A KDF derives one or more cryptographic keys from a source secret (like a password or master key), often adding salt and iterations to resist brute force.
In a hybrid encryption scheme, what is the typical role of asymmetric cryptography?
Answer: Encrypting the symmetric session key used for data encryption
Hybrid schemes use fast symmetric encryption for bulk data and asymmetric encryption only to securely transmit the symmetric session key.
Which of the following is an example of a stream cipher?
Answer: RC4
RC4 is a stream cipher that generates a pseudorandom keystream XORed with plaintext one byte at a time, unlike block ciphers like AES and Blowfish.
What cryptographic concept does the Diffie-Hellman problem rely on for its security?
Answer: The difficulty of computing discrete logarithms
Diffie-Hellman security relies on the computational difficulty of the discrete logarithm problem: given g^x mod p, finding x is computationally infeasible.
When using AES in GCM mode, what additional security property does it provide beyond encryption?
Answer: Authenticated encryption with associated data (AEAD)
AES-GCM provides AEAD, combining encryption with an authentication tag that detects any tampering with the ciphertext or associated unencrypted data.
What is the purpose of key escrow in an enterprise cryptographic environment?
Answer: To allow authorized recovery of encrypted data if the original key is lost
Key escrow stores copies of cryptographic keys with a trusted third party so encrypted data can be recovered if the original key holder is unavailable.