TLS, PKI & Encryption Standards Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 TLS, PKI & Encryption Standards flashcards as text
A CA issues a wildcard certificate for *.example.com. Which hostname would NOT be covered by this certificate?
Answer: sub.mail.example.com
Wildcard certificates cover only one level of subdomain depth; *.example.com matches mail.example.com but not sub.mail.example.com (two levels deep).
In TLS 1.3, application data encryption begins much earlier than in TLS 1.2. At which point does TLS 1.3 start encrypting handshake messages?
Answer: After the ServerHello and key_share, with the server's Certificate and CertificateVerify encrypted
TLS 1.3 derives handshake keys immediately after ServerHello/key_share exchange, encrypting the server's Certificate, CertificateVerify, and Finished messages, protecting certificate identity from passive observers.
Which key derivation function does TLS 1.3 use to derive all symmetric keys from the shared secret?
Answer: HKDF (HMAC-based Key Derivation Function)
TLS 1.3 uses HKDF (RFC 5869) exclusively for deriving handshake keys, traffic keys, and resumption secrets from the ECDHE shared secret and transcript hash.
An attacker performs a BGP hijack to redirect traffic for an OCSP responder's IP address. What is the likely goal of this attack in the context of PKI?
Answer: Cause OCSP responses to return 'good' for revoked certificates, enabling use of compromised credentials
By intercepting OCSP traffic, an attacker can return forged 'good' responses for revoked certificates, allowing continued use of compromised client or server certificates that should have been rejected.
Which cryptographic padding scheme used with RSA encryption was vulnerable to Bleichenbacher's oracle attack, and was removed in TLS 1.3?
Answer: PKCS#1 v1.5 padding
PKCS#1 v1.5 padding used for RSA key exchange allowed Bleichenbacher's adaptive chosen-ciphertext attack, which TLS 1.3 eliminated by removing RSA key exchange entirely.
What is the primary difference between a self-signed certificate and a certificate issued by a trusted CA for establishing a public TLS service?
Answer: Self-signed certificates are not trusted by browsers/OS trust stores, causing warnings for end users
Self-signed certificates are not chained to any CA in a client's trust store, so browsers display security warnings; CA-issued certificates inherit trust from a pre-installed root CA.
A penetration tester discovers a web server accepting TLS connections with export-grade cipher suites (40-bit or 56-bit encryption). Which attack can this enable even against a server that normally prefers strong ciphers?
Answer: FREAK — forcing downgrade to export RSA cipher suites to break the session key
FREAK (Factoring RSA Export Keys) exploited servers that still supported export-grade RSA cipher suites, enabling a MITM to force downgrade and then factor the weak 512-bit RSA key to decrypt traffic.