← All CAP Flashcard Decks

Cryptography & Encryption Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cryptography & Encryption flashcards as text
  1. Which concept describes the process of wrapping an encryption key with another key for secure storage or transmission?

    Answer: Key encapsulation / key wrapping

    Key wrapping (encapsulation) uses one key to encrypt another key, protecting it during storage or transmission while keeping it usable by authorized parties.

  2. What is 'key escrow' and why is it controversial in government contexts?

    Answer: A process where encryption keys are deposited with a trusted third party for recovery, raising concerns about government surveillance

    Key escrow deposits copies of encryption keys with a trusted third party (often government), enabling lawful access but creating controversy over potential misuse and backdoors.

  3. Which attack leverages timing differences in cryptographic operations to infer secret key material?

    Answer: Side-channel attack

    A side-channel attack exploits physical implementation characteristics—such as timing, power consumption, or electromagnetic emissions—to extract cryptographic secrets.

  4. In a hybrid encryption scheme, what role does asymmetric cryptography typically play?

    Answer: It encrypts the symmetric session key used to protect the bulk data

    Hybrid encryption uses asymmetric cryptography to securely exchange a symmetric session key, which then encrypts the actual data for performance efficiency.

  5. Which property of a cryptographic hash function means that given a hash output, it is computationally infeasible to find the original input?

    Answer: Preimage resistance

    Preimage resistance means that given a hash value h, it is computationally infeasible to find any input m such that hash(m) = h.

  6. Under FISMA and NIST RMF, which security control family directly addresses the use of cryptography to protect federal information?

    Answer: SC – System and Communications Protection

    NIST SP 800-53's SC (System and Communications Protection) family includes controls such as SC-8 (Transmission Confidentiality and Integrity) and SC-28 (Protection of Information at Rest) that mandate cryptographic protections.

  7. What is the purpose of an initialization vector (IV) in symmetric encryption modes like CBC?

    Answer: To ensure identical plaintext blocks produce different ciphertext blocks across different encryptions

    An IV introduces randomness into the encryption process so that encrypting the same plaintext with the same key at different times produces different ciphertext, preventing pattern analysis.