Cryptography & PKI Flashcards
7 cards from real SSCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptography & PKI flashcards as text
What is the purpose of a Hardware Security Module (HSM) in a cryptographic infrastructure?
Answer: To securely generate, store, and manage cryptographic keys in tamper-resistant hardware
An HSM is a dedicated physical device that protects cryptographic key material and performs cryptographic operations in a tamper-resistant environment, preventing key extraction.
Which concept describes the practice of keeping a copy of an encryption key with a trusted third party so it can be recovered if lost?
Answer: Key escrow
Key escrow involves depositing a copy of a cryptographic key with a trusted third party (often a government authority or enterprise agent) for lawful recovery purposes.
During a TLS 1.3 handshake, which step establishes the shared session key?
Answer: Both parties use an ephemeral Diffie-Hellman exchange to derive a shared secret
TLS 1.3 mandates ephemeral Diffie-Hellman (ECDHE) for key establishment, providing forward secrecy and removing older RSA key exchange methods.
What does a Message Authentication Code (MAC) provide that a simple hash function does not?
Answer: Both integrity and data origin authentication using a shared secret key
A MAC uses a shared secret key in addition to the message content, ensuring that only parties with the key can generate or verify the code, adding authentication to integrity.
Which cipher suite component provides forward secrecy by ensuring that past session keys cannot be recovered even if the server's long-term private key is compromised?
Answer: Ephemeral ECDHE key exchange
Ephemeral ECDHE generates a new key pair for each session; since session keys are never derived from the long-term private key, their compromise does not expose past sessions.
An organization wants to ensure email authenticity and prevent repudiation. Which technology should be implemented?
Answer: S/MIME digital signatures using sender's private key
S/MIME digital signatures use the sender's private key to sign emails, allowing recipients to verify the sender's identity and providing non-repudiation.
What is the purpose of certificate pinning in application security?
Answer: Hardcoding expected certificate or public key values in the application to reject unexpected certificates
Certificate pinning embeds the expected certificate or public key hash in the application, so it rejects connections presenting any other certificate, mitigating rogue CA attacks.