โ† All SSCA Flashcard Decks

Cryptography & PKI Flashcards

7 cards from real SSCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cryptography & PKI flashcards as text
  1. Which encryption mode of operation turns a block cipher into a stream cipher by XOR-ing the plaintext with an encrypted keystream?

    Answer: Output Feedback (OFB)

    OFB mode pre-generates a keystream from the cipher's output and XORs it with plaintext, effectively operating as a synchronous stream cipher.

  2. What is the Diffie-Hellman key exchange primarily used for?

    Answer: Allowing two parties to establish a shared secret over an untrusted channel

    Diffie-Hellman enables two parties who have no prior shared secret to jointly derive a common symmetric key over an insecure channel without transmitting the key itself.

  3. An administrator discovers that the same RSA key pair is used for both encryption and digital signing. What is the primary security concern?

    Answer: Dual use increases attack surface and may violate key usage constraints in certificates

    Using the same key pair for both encryption and signing violates the principle of key separation; compromise of one use-case (e.g., decryption oracle) can expose the signing key.

  4. Which hashing algorithm is currently recommended by NIST for use in digital signatures and is part of the SHA-2 family?

    Answer: SHA-256

    SHA-256 is part of the NIST-approved SHA-2 family with a 256-bit output, providing strong collision resistance and currently recommended for digital signatures.

  5. What is a Certificate Signing Request (CSR)?

    Answer: A message sent to a CA containing the applicant's public key and identity information

    A CSR is a standardized message (typically PKCS#10 format) that an entity sends to a CA, containing its public key and identity details to request a signed certificate.

  6. In a PKI hierarchy, what is an Intermediate CA (also called a Subordinate CA)?

    Answer: A CA that issues end-entity certificates and is itself certified by a higher-level CA

    An Intermediate CA is signed by a Root CA (or another Intermediate CA) and issues certificates to end-entities, keeping the Root CA offline and protected.

  7. Which attack targets the weakest link in a cipher by trying every possible key value?

    Answer: Brute-force attack

    A brute-force attack systematically tries every possible key combination until the correct one is found, making key length the primary defense.