โ† All CSS Flashcard Decks

CSS Cryptography & Data Protection Flashcards

6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSS Cryptography & Data Protection flashcards as text
  1. What is the role of a certificate revocation list (CRL) in PKI?

    Answer: Lists certificates that have been invalidated before their expiration date

    A CRL is a signed list published by a Certificate Authority of certificates that have been revoked due to compromise, policy violation, or other reasons.

  2. Which cryptographic concept ensures that a party cannot deny having performed an action?

    Answer: Non-repudiation

    Non-repudiation, typically achieved through digital signatures, provides proof of origin so that a sender cannot later deny sending a message.

  3. What type of encryption is used in TLS handshakes to securely exchange session keys?

    Answer: Asymmetric encryption (e.g., RSA or ECDH)

    TLS uses asymmetric cryptography during the handshake to securely establish a shared symmetric session key for bulk data encryption.

  4. What is the security risk of using weak or short RSA key lengths (e.g., 512-bit) in production systems?

    Answer: They can be factored using modern computing power, allowing private key recovery

    Short RSA keys can be broken through integer factorization attacks; NIST recommends at least 2048-bit keys for current applications.

  5. Which data protection technique allows computations to be performed on encrypted data without decrypting it first?

    Answer: Homomorphic encryption

    Homomorphic encryption allows mathematical operations to be performed on ciphertext such that the result, when decrypted, matches the result of operations on the plaintext.

  6. What is the primary purpose of key escrow in enterprise cryptography?

    Answer: Allows authorized parties to recover encrypted data if the original key is lost

    Key escrow stores a copy of encryption keys with a trusted third party, enabling data recovery in case of key loss or employee departure.