CSS Cryptography & Data Protection Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CSS Cryptography & Data Protection flashcards as text
Which encryption mode of AES is considered most secure for bulk data encryption due to its use of an initialization vector and chaining?
Answer: AES-CBC (Cipher Block Chaining)
AES-CBC uses an initialization vector and chains each block to the previous ciphertext, preventing identical plaintext blocks from producing identical ciphertext.
What is the primary advantage of asymmetric encryption over symmetric encryption?
Answer: It eliminates the need to securely share a secret key between parties
Asymmetric encryption uses a public/private key pair, so parties can exchange encrypted data without first sharing a secret key.
What is a digital signature's primary function in data security?
Answer: Verifies the authenticity and integrity of a message or document
A digital signature uses asymmetric cryptography to prove the message originated from a specific sender and was not altered in transit.
Which hashing algorithm is currently recommended by NIST for secure cryptographic applications?
Answer: SHA-256
SHA-256 (part of the SHA-2 family) is NIST-recommended for cryptographic use, as MD5 and SHA-1 are vulnerable to collision attacks.
What is the purpose of a Public Key Infrastructure (PKI) in enterprise environments?
Answer: Manages the lifecycle of digital certificates to enable trusted encrypted communications
PKI provides the framework for issuing, managing, distributing, and revoking digital certificates used for authentication and encryption.
What does 'perfect forward secrecy' (PFS) ensure in TLS connections?
Answer: Compromise of the server's private key does not expose past session keys
PFS uses ephemeral key exchanges (like Diffie-Hellman) so each session generates a unique key that is discarded afterward, protecting past sessions.