โ† All CCP Flashcard Decks

TLS, PKI & Encryption Standards Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 TLS, PKI & Encryption Standards flashcards as text
  1. What is the function of the TLS Server Name Indication (SNI) extension?

    Answer: Allows the client to specify which hostname it is connecting to so the server can present the correct certificate

    SNI allows multiple TLS-enabled virtual hosts to share a single IP address by letting the client declare the target hostname in the ClientHello before the server selects which certificate to present.

  2. An organization uses a hardware security module (HSM) to protect its CA private key. What is the primary security benefit of this approach?

    Answer: The private key is generated and stored within tamper-resistant hardware and cannot be exported

    HSMs store cryptographic keys in tamper-resistant hardware that prevents key export, so even if the surrounding system is compromised, the CA private key itself remains protected inside the HSM.

  3. Which attack exploits weak Diffie-Hellman parameter reuse across many servers, allowing a passive attacker with significant precomputation to break the key exchange?

    Answer: Logjam attack

    The Logjam attack (2015) exploited export-grade 512-bit DH parameter reuse, enabling nation-state-level attackers with precomputed discrete logarithm tables to decrypt connections using those parameters.

  4. In X.509 certificates, what distinguishes the Subject Alternative Name (SAN) extension from the Common Name (CN) field for domain validation?

    Answer: Browsers rely on SAN for hostname validation and may ignore CN per RFC 2818 and CA/Browser Forum requirements

    Modern browsers and RFC 2818 require hostname matching against SAN entries; the CN field is deprecated for this purpose, so certificates must include SANs for all valid hostnames.

  5. A security engineer needs to ensure that a set of TLS certificates cannot be misused after their private keys are stolen, even retroactively for past captured traffic. Which property addresses this?

    Answer: Perfect Forward Secrecy (PFS)

    PFS, achieved via ephemeral key exchange (ECDHE/DHE), ensures that session keys are not derivable from the server's long-term private key, protecting past sessions even if that key is later compromised.

  6. What is the purpose of the 'critical' flag on an X.509 certificate extension?

    Answer: It mandates that a relying party must understand and process the extension or reject the certificate

    Marking an extension as critical means any system that does not recognize or process that extension must reject the certificate, preventing unsafe behavior from ignoring security-relevant constraints.

  7. Which protocol was specifically designed to replace SSL/TLS for IoT constrained devices, offering similar security guarantees over UDP?

    Answer: DTLS (Datagram TLS)

    DTLS (RFC 6347) adapts the TLS record layer for datagram transport (UDP), handling packet reordering and loss to provide TLS-equivalent security for IoT and real-time applications.