Cryptography & Encryption Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography & Encryption flashcards as text
What is the primary purpose of a Hash-based Message Authentication Code (HMAC)?
Answer: To provide both data integrity and authentication using a shared secret
HMAC combines a cryptographic hash function with a secret key to verify both the integrity and authenticity of a message.
Under NIST SP 800-57, what is the recommended minimum RSA key size for protecting data through 2030?
Answer: 2048 bits
NIST SP 800-57 recommends a minimum of 2048-bit RSA keys to provide adequate security through 2030.
Which attack exploits weaknesses in the CBC mode of operation by manipulating ciphertext blocks to alter decrypted plaintext?
Answer: Padding oracle attack
A padding oracle attack exploits CBC mode by sending modified ciphertexts and observing padding validation errors to decrypt data without the key.
What does 'perfect forward secrecy' (PFS) ensure in a cryptographic protocol?
Answer: Past session keys remain secure even if the long-term private key is later compromised
PFS ensures that compromise of a long-term private key does not expose previously recorded encrypted sessions, because ephemeral keys were used.
Which algorithm is commonly used for key derivation from passwords to slow down brute-force attacks?
Answer: PBKDF2
PBKDF2 (Password-Based Key Derivation Function 2) applies a pseudorandom function many times to stretch a password, making brute-force attacks computationally expensive.
In asymmetric encryption, which operation is typically performed with the recipient's public key?
Answer: Encrypting the plaintext
The sender encrypts a message using the recipient's public key so that only the recipient, who holds the corresponding private key, can decrypt it.
What is the primary vulnerability addressed by using authenticated encryption (e.g., AES-GCM) instead of AES-CBC?
Answer: Lack of ciphertext authentication, enabling tampering attacks
Authenticated encryption modes like AES-GCM combine confidentiality with an authentication tag that detects any tampering with the ciphertext.