CSS Cryptography & Data Protection Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CSS Cryptography & Data Protection flashcards as text
What is the difference between data masking and data encryption?
Answer: Masking replaces data with fictitious values while encryption scrambles data reversibly with a key
Data masking permanently replaces sensitive data with realistic but fake values, while encryption scrambles data that can be restored with the correct key.
Which key management practice ensures that encryption keys are protected from the data they encrypt?
Answer: Storing keys in a separate hardware security module (HSM)
An HSM is a dedicated hardware device that stores and processes cryptographic keys in a tamper-resistant environment, separate from the data.
What does tokenization do to protect sensitive data such as payment card numbers?
Answer: Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault
Tokenization substitutes sensitive data with a random token; the original value is stored in a secure token vault and can only be retrieved by authorized systems.
What is the main vulnerability addressed by salting a password hash?
Answer: Prevents rainbow table and precomputed hash lookup attacks
A salt is a random value added to a password before hashing, ensuring that identical passwords produce different hashes and defeating precomputed lookup tables.
Which US regulatory framework mandates encryption of cardholder data at rest and in transit?
Answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS Requirement 3 mandates protection of stored cardholder data and Requirement 4 mandates encryption of cardholder data in transit.
What is end-to-end encryption (E2EE) designed to prevent?
Answer: Interception and decryption of data by intermediaries, including service providers
E2EE ensures that only the communicating endpoints can decrypt the data, preventing even the service provider from reading message content.