1/113
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Which role does modular arithmetic play in cryptographic algorithms? | A. Generating random keys for encryption | B. Encrypting messages using complex algorithms | C. Performing calculations within a finite set of numbers | D. Decoding encrypted messages
C. Performing calculations within a finite set of numbers
How is lattice-based cryptography applied in modern encryption techniques? | A. Utilizing prime numbers for secure communication | B. Using geometric structures for cryptographic algorithms | C. Implementing substitution ciphers for data protection | D. Employing blockchain technology for encryption
B. Using geometric structures for cryptographic algorithms
What is encryption? | A. The process of decoding messages | B. The process of encoding messages | C. The study of secret codes | D. The practice of secure communication
B. The process of encoding messages
Which role do large prime numbers play in cryptographic algorithms? | A. They provide a visual representation of encrypted data. | B. They introduce randomness into the encryption process. | C. They ensure the security and strength of encryption. | D. They facilitate the transmission of encrypted messages.
C. They ensure the security and strength of encryption.
What is a cryptosystem? | A. Software application for auditing security | B. A method for compressing messages | C. A network performance monitor | D. A combination of cryptographic algorithms and protocols
D. A combination of cryptographic algorithms and protocols
How are digital signatures used in cryptographic protocols? | A. Encrypting messages for secure transmission | B. Verifying the authenticity and integrity of data | C. Generating random keys for encryption | D. Decoding encrypted messages
B. Verifying the authenticity and integrity of data
What is nonrepudiation? | A. The ability to deny sending a message | B. The ability to prove the origin of a message | C. The ability to verify the integrity of a message | D. The ability to prevent a sender from denying sending a message
D. The ability to prevent a sender from denying sending a message
Which encryption method is associated with symmetric encryption? | A. Advanced Encryption Standard (AES) | B. Elliptic-curve cryptography (ECC) | C. Rivest-Shamir-Adleman (RSA) | D. Diffie-Hellman
A. Advanced Encryption Standard (AES)
Which of the following is an example of asymmetric encryption? | A. Advanced Encryption Standard (AES) | B. Rivest-Shamir-Adleman (RSA) | C. Data Encryption Standard (DES) | D. Hash-based message authentication code (HMAC)
B. Rivest-Shamir-Adleman (RSA)
What are hash functions used for? | A. Data encryption | B. Message integrity | C. Key exchange | D. Password recovery
B. Message integrity
Which is a type of homomorphic encryption? | A. Asymmetric homomorphic encryption (AHE) | B. Semi homomorphic encryption (SHE) | C. Full homomorphic encryption (FHE) | D. Symmetric homomorphic encryption (SHE)
C. Full homomorphic encryption (FHE)
What is a characteristic of stream ciphers in a cryptographic system? | A. They operate on fixed-size blocks of data. | B. They generate a continuous stream of key material. | C. They require a different key for each encryption operation. | D. They use the same key for encryption and decryption.
B. They generate a continuous stream of key material.
What is ciphertext in a cryptographic system? | A. The original plaintext message before encryption | B. The encrypted form of the plaintext message | C. The key used for decryption | D. The process of generating random numbers for encryption
B. The encrypted form of the plaintext message
What distinguishes cipher block chaining (CBC) mode in a cryptographic system? | A. To prevent duplicate blocks from producing the same ciphertext | B. To provide one-time pad encryption | C. To ensure data integrity | D. To operate without an initialization vector (IV)
A. To prevent duplicate blocks from producing the same ciphertext
Which term refers to the blocks in a blockchain containing cryptographic proof of work? | A. Hash | B. Consensus mechanism | C. Proof-of-work | D. Digital signature
C. Proof-of-work
How is cryptography utilized in cryptocurrencies? | A. To compress transaction data for efficient storage | B. To secure transactions and protect the integrity of the blockchain | C. To generate random numbers for encryption | D. To authenticate users during data transmission
B. To secure transactions and protect the integrity of the blockchain
What is blockchain? | A. A centralized ledger | B. A chain of blocks linked by cryptographic hashes | C. A chain of encrypted messages | D. A data compression method
B. A chain of blocks linked by cryptographic hashes
What was the purpose of the National Institute of Standards and Technology's (NIST) selection of Ascon for lightweight cryptography? | A. To replace all current cryptographic algorithms | B. To secure data on IoT and small devices with limited resources | C. To create a new standard for blockchain encryption | D. To speed up encryption on high-power computers
B. To secure data on IoT and small devices with limited resources
Why is lightweight cryptography designed for modern systems? | A. To encrypt data at rest | B. To ensure compatibility with legacy encryption algorithms | C. To provide efficient and secure encryption solutions for devices with limited resources | D. To authenticate users during data transmission
C. To provide efficient and secure encryption solutions for devices with limited resources
In the case of a company that successfully aligned its cryptographic practices, what was likely a contributing factor? | A. Inconsistent application of encryption across departments | B. A dedicated security team that regularly communicates with all departments | C. Minimal investment in cryptographic solutions | D. Avoidance of new encryption technologies
B. A dedicated security team that regularly communicates with all departments
Which of the following is a reason to monitor cryptographic controls continuously? | A. To verify compliance with industry regulations | B. To eliminate the need for security policies | C. To create a backup of all encrypted data | D. To assess employee productivity
A. To verify compliance with industry regulations
Which of the following statements is true regarding the National Institute of Standards and Technology (NIST) standards? | A. NIST standards only apply to government organizations. | B. NIST provides guidelines for cryptographic standards and their implementation. | C. NIST standards are mandatory for all organizations in the U.S. | D. NIST only focuses on physical security measures.
B. NIST provides guidelines for cryptographic standards and their implementation.
In what way can cryptography support data integrity? | A. By preventing unauthorized access | B. By ensuring that data cannot be altered without detection | C. By providing anonymity to users | D. By eliminating the need for backups
B. By ensuring that data cannot be altered without detection
What is the primary purpose of aligning cryptography frameworks with organizational policies? | A. To ensure encryption is applied randomly | B. To maximize the effectiveness of data protection measures | C. To eliminate the need for internal audits | D. To focus solely on technological solutions
B. To maximize the effectiveness of data protection measures
What is a purpose of the International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27001? | A. To provide technical specifications for encryption algorithms | B. To establish guidelines for implementing an Information Security Management System | C. To regulate the use of cryptocurrencies | D. To specify a single encryption standard
B. To establish guidelines for implementing an Information Security Management System
What does the General Data Protection Regulation (GDPR) say about data encryption? | A. It is only recommended for large organizations. | B. It should be used as a measure to safeguard personal data. | C. It is irrelevant in the context of personal data protection. | D. It allows for the complete removal of personal data requirements.
B. It should be used as a measure to safeguard personal data.
In which area is lightweight cryptography most useful? | A. High-powered computers and servers | B. Internet of things (IoT) devices | C. Systems with extensive storage | D. Encrypted social media platforms only
B. Internet of things (IoT) devices
What is the first step in developing a cryptographic policy for an organization? | A. Choosing encryption algorithms | B. Assessing the organization's security objective | C. Implementing encryption across all systems | D. Training employees on cryptography
B. Assessing the organization's security objective
What is a potential ethical dilemma when using cryptography in an organization? | A. Ensuring employee privacy while using monitoring tools | B. The choice of encryption algorithms | C. The implementation of physical security measures | D. Regular updates to the cryptographic policy
A. Ensuring employee privacy while using monitoring tools
What does the term Nobody But Us (NOBUS) refer to? | A. Allowing only the National Security Agency (NSA) access to encrypted data | B. The idea that all encryption should be public | C. A method of distributing encryption keys | D. Limiting encryption to government use only
A. Allowing only the National Security Agency (NSA) access to encrypted data
Modular arithmetic
Mathematical operations performed within a finite set of numbers where values wrap around after reaching a modulus. It is fundamental to many cryptographic algorithms.
Modulus
The number that defines the finite range used in modular arithmetic.
Large prime numbers
Used in cryptography because mathematical problems involving large primes can be computationally difficult to reverse, helping provide cryptographic strength.
Lattice-based cryptography
A form of cryptography based on mathematical problems involving geometric lattice structures.
Why is lattice-based cryptography important?
It provides cryptographic techniques based on difficult mathematical lattice problems and is associated with modern cryptographic research.
Encryption
The process of transforming plaintext into an encoded form called ciphertext.
Plaintext
The original readable data before encryption.
Ciphertext
The encrypted and unreadable form of plaintext.
Decryption
The process of converting ciphertext back into plaintext using the appropriate cryptographic key or process.
Cryptosystem
A combination of cryptographic algorithms, protocols, keys, and related processes used to protect information.
Symmetric encryption
Encryption where the same shared secret key is used for encryption and decryption.
AES
Advanced Encryption Standard; a symmetric encryption algorithm.
DES
Data Encryption Standard; an older symmetric encryption algorithm.
Asymmetric encryption
Cryptography that uses a mathematically related public and private key pair.
RSA
Rivest-Shamir-Adleman; an asymmetric cryptographic algorithm.
ECC
Elliptic-curve cryptography; a form of public-key cryptography based on elliptic-curve mathematics.
Public key
The portion of an asymmetric key pair that can be distributed publicly.
Private key
The secret portion of an asymmetric key pair that must be protected by its owner.
Hash function
A one-way mathematical function that converts input data into a fixed-size hash or digest.
Primary cryptographic purpose of hashing
To support message and data integrity by making unauthorized modification detectable.
Hashing vs. encryption
Hashing is intended to be one-way and is primarily used for integrity; encryption is reversible with the appropriate key and is primarily used for confidentiality.
Data integrity
Assurance that information has not been modified or altered without detection.
Digital signature
A cryptographic mechanism used to verify authenticity and integrity and support nonrepudiation.
Digital signature provides
Authenticity, integrity, and support for nonrepudiation.
Digital signature does NOT primarily provide
Confidentiality. A digital signature verifies data and its origin rather than hiding the contents.
Authenticity
Assurance that data, a message, or a sender is genuine.
Nonrepudiation
Assurance that prevents a sender or signer from credibly denying having performed an action such as sending or signing a message.
Stream cipher
A cipher that encrypts data as a continuous stream rather than fixed-size blocks.
Key characteristic of a stream cipher
It generates or uses a continuous stream of key material.
Block cipher
A cipher that processes plaintext in fixed-size blocks.
CBC
Cipher Block Chaining; a block cipher mode where blocks are chained so identical plaintext blocks do not simply produce identical ciphertext blocks.
Why does CBC use chaining?
To prevent duplicate plaintext blocks from producing identical ciphertext patterns.
IV
Initialization Vector; a value used to introduce variation into cryptographic operations such as CBC.
CBC and IV relationship
CBC uses an initialization vector for the first block so encryption does not begin with a predictable identical state.
Homomorphic encryption
Encryption that allows certain computations to be performed on encrypted data without first decrypting it.
FHE
Fully Homomorphic Encryption; allows computations to be performed on encrypted data while the information remains encrypted.
Blockchain
A chain of blocks linked together using cryptographic hashes.
What links blockchain blocks?
Cryptographic hashes connect blocks and help make unauthorized changes detectable.
Blockchain is centralized or distributed?
Blockchain is generally associated with distributed or decentralized ledger architectures, not a traditional centralized ledger.
Cryptography in cryptocurrency
Cryptography helps secure transactions and protect the integrity of the blockchain.
Proof-of-work
A consensus mechanism in which participants perform computational work to satisfy a cryptographic requirement.
PoW memory hook
Proof-of-work = prove that computational WORK was performed.
Consensus mechanism
A process used by participants in a distributed system to agree on the valid state of the system.
Proof-of-work vs. digital signature
Proof-of-work supports consensus through computational work; a digital signature authenticates and protects the integrity of signed data.
Digital signature vs. hash
A hash primarily supports integrity; a digital signature uses cryptographic techniques to provide integrity plus authentication and nonrepudiation.
Lightweight cryptography
Cryptography designed to provide security efficiently on devices with limited processing power, memory, energy, or other resources.
Primary target for lightweight cryptography
Internet of Things (IoT) devices and other resource-constrained systems.
Ascon
A lightweight cryptography algorithm family selected by NIST for protecting data on resource-constrained devices.
Why did NIST select Ascon?
To provide cryptographic protection suitable for IoT and other small devices with limited resources.
IoT cryptography challenge
IoT devices may have limited CPU power, memory, storage, and energy, making traditional cryptographic implementations more resource intensive.
NIST
The National Institute of Standards and Technology, which publishes standards and guidelines related to cryptography and security.
Role of NIST cryptographic guidance
NIST provides guidelines for cryptographic standards and their implementation.
Are NIST standards mandatory for every U.S. organization?
No. NIST publishes widely used standards and guidance, but the preassessment does not state that all NIST standards are mandatory for every organization.
Continuous monitoring of cryptographic controls
Helps organizations verify that cryptographic controls remain effective and compliant with applicable requirements.
Why continuously monitor cryptographic controls?
To identify problems, verify effectiveness, and support compliance with industry or organizational requirements.
ISO/IEC 27001
A standard associated with establishing and maintaining an Information Security Management System (ISMS).
ISMS
Information Security Management System; a structured system for managing organizational information security risks and controls.
GDPR and encryption
GDPR recognizes encryption as a measure that can help safeguard personal data.
Cryptography and organizational policy
Cryptographic controls should align with organizational security objectives and policies to maximize the effectiveness of data protection.
First step in developing a cryptographic policy
Assess the organization's security objectives.
Why assess security objectives first?
Cryptographic controls should be selected based on what the organization actually needs to protect and accomplish.
Organizational cryptographic alignment
Coordinating cryptographic practices with business policies, security requirements, departments, and organizational objectives.
Factor supporting successful cryptographic alignment
A dedicated security team that regularly communicates with organizational departments.
Cryptographic governance
The policies, responsibilities, standards, monitoring, and decision-making processes surrounding an organization's use of cryptography.
Cryptographic policy
A formal set of organizational requirements governing how cryptography should be selected, implemented, managed, and monitored.
Cryptography and employee privacy
Organizations may face ethical issues when security monitoring or cryptographic controls conflict with employee privacy interests.
Ethical dilemma tested on the PA
Balancing employee privacy with the use of organizational monitoring tools.
NOBUS
Nobody But Us; the concept that a cryptographic capability or vulnerability is believed to be exploitable only by a particular intelligence organization.
NOBUS memory hook
NOBUS = Nobody But Us.
NOBUS on the WGU preassessment
The expected answer associates NOBUS with allowing only the National Security Agency (NSA) access to encrypted data.