โ† All CAP Flashcard Decks

Cryptography & Encryption Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cryptography & Encryption flashcards as text
  1. Which elliptic curve cryptography standard is widely used in U.S. federal systems and recommended by NSA Suite B?

    Answer: ECDSA with P-256 or P-384

    NSA Suite B specifies ECDSA with NIST curves P-256 and P-384 for digital signatures in federal and classified systems.

  2. What is a 'salt' in the context of password hashing?

    Answer: A random value added to a password before hashing to prevent precomputed attacks

    A salt is a unique random value prepended or appended to each password before hashing, ensuring identical passwords produce different hash values and defeating rainbow table attacks.

  3. Which cryptographic primitive is the foundation of blockchain integrity?

    Answer: Cryptographic hash chaining

    Blockchains maintain integrity by chaining blocks together using cryptographic hashes, making any alteration of a prior block detectable.

  4. What is the key difference between TLS 1.2 and TLS 1.3 regarding cipher suites?

    Answer: TLS 1.3 removes support for static RSA and DHE key exchange, mandating forward secrecy

    TLS 1.3 eliminates cipher suites that lack forward secrecy (static RSA, DH) and removes weak algorithms, mandating ECDHE or DHE for key exchange.

  5. In the CAP authorization framework, which NIST document provides guidance on cryptographic key management?

    Answer: NIST SP 800-57

    NIST SP 800-57 (Recommendation for Key Management) provides comprehensive guidance on key generation, distribution, storage, and destruction.

  6. What type of attack targets the collision resistance property of a hash function?

    Answer: Birthday attack

    A birthday attack exploits the birthday paradox to find two different inputs that produce the same hash output, undermining collision resistance.

  7. Which encryption approach is most appropriate for protecting data at rest on government systems per FIPS 140-2 requirements?

    Answer: AES-256 in an approved mode

    FIPS 140-2 validated implementations of AES-256 in approved modes (such as CBC or GCM) are required for protecting sensitive federal data at rest.