← All CCP Flashcard Decks

CCP Cryptography & PKI Flashcards

6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CCP Cryptography & PKI flashcards as text
  1. Which cryptographic property ensures that a sender cannot later deny having sent a message?

    Answer: Non-repudiation

    Non-repudiation, typically achieved through digital signatures, provides cryptographic proof of origin that prevents a sender from denying their actions.

  2. What is the primary difference between symmetric and asymmetric encryption?

    Answer: Symmetric uses one key for encryption and decryption; asymmetric uses a public/private key pair

    Symmetric encryption uses a single shared secret key for both encryption and decryption, while asymmetric encryption uses a mathematically linked key pair — one public, one private.

  3. Which hashing algorithm is currently recommended by NIST for generating message digests due to its resistance to collision attacks?

    Answer: SHA-256

    SHA-256 (part of the SHA-2 family) is NIST-recommended for cryptographic hashing, as MD5 and SHA-1 have known collision vulnerabilities.

  4. In a Public Key Infrastructure (PKI), what is the role of a Certificate Authority (CA)?

    Answer: To issue, sign, and revoke digital certificates that bind public keys to identities

    A CA is a trusted third party that issues digitally signed certificates, binding a subject's identity to their public key and enabling other parties to trust that binding.

  5. What mechanism allows a relying party to check whether a digital certificate has been revoked before it reaches its expiration date?

    Answer: Online Certificate Status Protocol (OCSP)

    OCSP provides real-time certificate revocation status by querying an OCSP responder, offering a more efficient alternative to downloading full Certificate Revocation Lists (CRLs).

  6. Which cipher mode of operation provides both confidentiality and data integrity within a single operation, making it suitable for TLS 1.3?

    Answer: Galois/Counter Mode (GCM)

    GCM is an authenticated encryption mode that simultaneously provides confidentiality and message authentication, and is the preferred cipher mode in TLS 1.3.