โ† All CCP Flashcard Decks

Cryptography & Information Security Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cryptography & Information Security flashcards as text
  1. In Public Key Infrastructure (PKI), what is the role of a Certificate Authority (CA)?

    Answer: To issue and sign digital certificates that bind public keys to identities

    A Certificate Authority issues digital certificates and digitally signs them to bind a public key to an entity's identity, establishing trust in the PKI.

  2. Which algorithm is the foundation of RSA encryption's security?

    Answer: The difficulty of factoring large prime numbers

    RSA's security relies on the computational difficulty of factoring the product of two large prime numbers back into its prime factors.

  3. What does the Diffie-Hellman key exchange protocol accomplish?

    Answer: It allows two parties to establish a shared secret over an insecure channel without prior contact

    Diffie-Hellman allows two parties to jointly derive a shared secret key over an unsecured channel without ever transmitting the secret itself.

  4. What is the purpose of a Message Authentication Code (MAC)?

    Answer: To verify both the integrity and authenticity of a message using a shared secret key

    A MAC is computed using both the message content and a shared secret key, allowing the recipient to verify that the message was not tampered with and came from a legitimate sender.

  5. In SSL/TLS, what does the handshake process primarily accomplish?

    Answer: It negotiates cipher suites and establishes session keys for secure communication

    The TLS handshake negotiates the protocol version and cipher suite, authenticates the server, and establishes a shared session key for encrypting subsequent communication.

  6. What is key escrow in cryptography?

    Answer: A system where encryption keys are held by a trusted third party for authorized recovery

    Key escrow is the practice of depositing encryption keys with a trusted third party so they can be recovered by authorized entities such as law enforcement or an employer.

  7. Which asymmetric key operation is used to create a digital signature?

    Answer: Encrypting a hash of the message with the sender's private key

    A digital signature is created by hashing the message and then encrypting that hash with the sender's private key, allowing anyone with the public key to verify authenticity.