1/33
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a public key?
A cryptographic key that can be openly distributed. It is commonly used to encrypt data for the key owner or verify digital signatures.
What is a private key?
A secret cryptographic key that must be protected by its owner. It is commonly used to decrypt data encrypted with the corresponding public key or create digital signatures.
What is key escrow?
A process where encryption keys are securely stored by a trusted third party so they can be recovered when necessary.
Example: An employee leaves a company and their encrypted files need to be recovered.
Exam clue: Recovery of encryption keys
What is a Certificate Authority (CA)?
A trusted organization that issues and digitally signs certificates, verifying the identity associated with a public key.
What is a Certificate Revocation List (CRL)?
A published list of certificates that have been revoked before their expiration date.
What is OCSP?
Online Certificate Status Protocol. It allows a system to check the current status of a certificate with an online service.
What is a root of trust?
A trusted foundation used to establish the validity of certificates and cryptographic operations.
PKI example: A trusted root CA certificate serves as the starting point for validating a certificate chain.
What is a Certificate Signing Request (CSR)?
A request sent to a CA to obtain a digital certificate. It contains information about the requester and their public key.
What is a wildcard certificate?
A certificate that can secure multiple subdomains under the same domain.
Example: *.example.com could cover:
www.example.com
mail.example.com
shop.example.com
What is a self-signed certificate?
A certificate signed by the same entity that created it, rather than a trusted third-party CA.
Common use: Internal systems, testing, labs.
What is a third-party certificate?
A certificate issued and signed by a trusted external Certificate Authority.
Example: A public website certificate issued by a commercial CA.
What is symmetric encryption?
Encryption that uses the same key to encrypt and decrypt data.
Advantages: Fast and efficient.
Disadvantage: Securely sharing the key can be difficult.
Memory: Symmetric = Same key
What is asymmetric encryption?
Encryption that uses a public/private key pair.
Advantages: Secure key exchange and digital signatures.
Disadvantage: Slower than symmetric encryption.
Memory: Asymmetric = A pair
What is key exchange?
The process of securely establishing or sharing a cryptographic key between parties.
Example: Diffie-Hellman allows two parties to establish a shared secret over an insecure network.
Why is key length important?
Generally, longer keys provide greater resistance to brute-force attacks, although security also depends on the algorithm being used.
Example: AES-256 uses a 256-bit key.
Exam clue: Longer key ≠ automatically better if the algorithm itself is weak.
What is an encryption algorithm?
The mathematical process used to transform plaintext into ciphertext and, when applicable, back into plaintext.
Examples:
AES
RSA
3DES (legacy)
What is full-disk encryption (FDE)?
Encryption that protects the entire storage device, including the operating system, applications, and data.
Example: BitLocker.
What is partition encryption?
Encryption applied to applied to a specific partition of a storage device rather than the entire disk.
What is file encryption?
Encryption applied to individual files.
Advantage: You can encrypt specific sensitive files without encrypting the entire storage device.
What is volume encryption?
Encryption applied to an entire logical storage volume.
Think: Volume = a logical storage area that may span physical storage.
What is database encryption?
Encryption used to protect data stored within a database.
Purpose: Protect sensitive database information if unauthorized users gain access to the underlying data.
What is record-level encryption?
Encryption applied to individual database records rather than the entire database.
Example: Encrypting only records containing sensitive customer information.
What is transport/communication encryption?
Encryption that protects data while it is traveling across a network.
Examples:
TLS
HTTPS
VPN encryption
Memory: Data in transit → Transport encryption
What is a TPM (Trusted Platform Module)?
A hardware security component that securely stores cryptographic keys and can help verify the integrity of a device during startup.
Common use: BitLocker key protection.
What is an HSM?
A specialized hardware device designed to securely generate, store, and manage cryptographic keys and perform cryptographic operations.
Think: HSM = high-security key vault
What is a Key Management System (KMS)?
A system used to generate, store, distribute, rotate, and manage cryptographic keys.
What is a secure enclave?
A protected hardware or hardware-backed environment designed to securely store sensitive information such as cryptographic keys.
What is steganography?
he practice of hiding data inside another file or medium so the existence of the hidden data is concealed.
Example: Hiding a secret message inside an image.
What is tokenization?
Replacing sensitive data with a non-sensitive token that represents the original data.
Example: Replacing a credit card number with a randomly generated token.
What is data masking?
Hiding or obscuring sensitive information while keeping the data usable for authorized purposes.
Example:
5555-1234-5678-9012
becomes
****-****-****-9012
What is hashing?
A one-way mathematical function that converts data into a fixed-length value called a hash/digest.
Used for:
Password storage
Integrity verification
Digital signatures
What is salting?
Adding a unique random value to data, typically a password, before hashing.
Purpose: Helps defend against rainbow table attacks and makes identical passwords produce different hashes.
What is a digital signature?
A cryptographic mechanism used to provide authentication, integrity, and non-repudiation.
What is key stretching?
A technique that makes password-based keys harder to brute-force by repeatedly processing the password through a cryptographic function.