Introduction to Cryptography - D830

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/113

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:12 AM on 9/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

114 Terms

1
New cards

Which role does modular arithmetic play in cryptographic algorithms? | A. Generating random keys for encryption | B. Encrypting messages using complex algorithms | C. Performing calculations within a finite set of numbers | D. Decoding encrypted messages

C. Performing calculations within a finite set of numbers

2
New cards

How is lattice-based cryptography applied in modern encryption techniques? | A. Utilizing prime numbers for secure communication | B. Using geometric structures for cryptographic algorithms | C. Implementing substitution ciphers for data protection | D. Employing blockchain technology for encryption

B. Using geometric structures for cryptographic algorithms

3
New cards

What is encryption? | A. The process of decoding messages | B. The process of encoding messages | C. The study of secret codes | D. The practice of secure communication

B. The process of encoding messages

4
New cards

Which role do large prime numbers play in cryptographic algorithms? | A. They provide a visual representation of encrypted data. | B. They introduce randomness into the encryption process. | C. They ensure the security and strength of encryption. | D. They facilitate the transmission of encrypted messages.

C. They ensure the security and strength of encryption.

5
New cards

What is a cryptosystem? | A. Software application for auditing security | B. A method for compressing messages | C. A network performance monitor | D. A combination of cryptographic algorithms and protocols

D. A combination of cryptographic algorithms and protocols

6
New cards

How are digital signatures used in cryptographic protocols? | A. Encrypting messages for secure transmission | B. Verifying the authenticity and integrity of data | C. Generating random keys for encryption | D. Decoding encrypted messages

B. Verifying the authenticity and integrity of data

7
New cards

What is nonrepudiation? | A. The ability to deny sending a message | B. The ability to prove the origin of a message | C. The ability to verify the integrity of a message | D. The ability to prevent a sender from denying sending a message

D. The ability to prevent a sender from denying sending a message

8
New cards

Which encryption method is associated with symmetric encryption? | A. Advanced Encryption Standard (AES) | B. Elliptic-curve cryptography (ECC) | C. Rivest-Shamir-Adleman (RSA) | D. Diffie-Hellman

A. Advanced Encryption Standard (AES)

9
New cards

Which of the following is an example of asymmetric encryption? | A. Advanced Encryption Standard (AES) | B. Rivest-Shamir-Adleman (RSA) | C. Data Encryption Standard (DES) | D. Hash-based message authentication code (HMAC)

B. Rivest-Shamir-Adleman (RSA)

10
New cards

What are hash functions used for? | A. Data encryption | B. Message integrity | C. Key exchange | D. Password recovery

B. Message integrity

11
New cards

Which is a type of homomorphic encryption? | A. Asymmetric homomorphic encryption (AHE) | B. Semi homomorphic encryption (SHE) | C. Full homomorphic encryption (FHE) | D. Symmetric homomorphic encryption (SHE)

C. Full homomorphic encryption (FHE)

12
New cards

What is a characteristic of stream ciphers in a cryptographic system? | A. They operate on fixed-size blocks of data. | B. They generate a continuous stream of key material. | C. They require a different key for each encryption operation. | D. They use the same key for encryption and decryption.

B. They generate a continuous stream of key material.

13
New cards

What is ciphertext in a cryptographic system? | A. The original plaintext message before encryption | B. The encrypted form of the plaintext message | C. The key used for decryption | D. The process of generating random numbers for encryption

B. The encrypted form of the plaintext message

14
New cards

What distinguishes cipher block chaining (CBC) mode in a cryptographic system? | A. To prevent duplicate blocks from producing the same ciphertext | B. To provide one-time pad encryption | C. To ensure data integrity | D. To operate without an initialization vector (IV)

A. To prevent duplicate blocks from producing the same ciphertext

15
New cards

Which term refers to the blocks in a blockchain containing cryptographic proof of work? | A. Hash | B. Consensus mechanism | C. Proof-of-work | D. Digital signature

C. Proof-of-work

16
New cards

How is cryptography utilized in cryptocurrencies? | A. To compress transaction data for efficient storage | B. To secure transactions and protect the integrity of the blockchain | C. To generate random numbers for encryption | D. To authenticate users during data transmission

B. To secure transactions and protect the integrity of the blockchain

17
New cards

What is blockchain? | A. A centralized ledger | B. A chain of blocks linked by cryptographic hashes | C. A chain of encrypted messages | D. A data compression method

B. A chain of blocks linked by cryptographic hashes

18
New cards

What was the purpose of the National Institute of Standards and Technology's (NIST) selection of Ascon for lightweight cryptography? | A. To replace all current cryptographic algorithms | B. To secure data on IoT and small devices with limited resources | C. To create a new standard for blockchain encryption | D. To speed up encryption on high-power computers

B. To secure data on IoT and small devices with limited resources

19
New cards

Why is lightweight cryptography designed for modern systems? | A. To encrypt data at rest | B. To ensure compatibility with legacy encryption algorithms | C. To provide efficient and secure encryption solutions for devices with limited resources | D. To authenticate users during data transmission

C. To provide efficient and secure encryption solutions for devices with limited resources

20
New cards

In the case of a company that successfully aligned its cryptographic practices, what was likely a contributing factor? | A. Inconsistent application of encryption across departments | B. A dedicated security team that regularly communicates with all departments | C. Minimal investment in cryptographic solutions | D. Avoidance of new encryption technologies

B. A dedicated security team that regularly communicates with all departments

21
New cards

Which of the following is a reason to monitor cryptographic controls continuously? | A. To verify compliance with industry regulations | B. To eliminate the need for security policies | C. To create a backup of all encrypted data | D. To assess employee productivity

A. To verify compliance with industry regulations

22
New cards

Which of the following statements is true regarding the National Institute of Standards and Technology (NIST) standards? | A. NIST standards only apply to government organizations. | B. NIST provides guidelines for cryptographic standards and their implementation. | C. NIST standards are mandatory for all organizations in the U.S. | D. NIST only focuses on physical security measures.

B. NIST provides guidelines for cryptographic standards and their implementation.

23
New cards

In what way can cryptography support data integrity? | A. By preventing unauthorized access | B. By ensuring that data cannot be altered without detection | C. By providing anonymity to users | D. By eliminating the need for backups

B. By ensuring that data cannot be altered without detection

24
New cards

What is the primary purpose of aligning cryptography frameworks with organizational policies? | A. To ensure encryption is applied randomly | B. To maximize the effectiveness of data protection measures | C. To eliminate the need for internal audits | D. To focus solely on technological solutions

B. To maximize the effectiveness of data protection measures

25
New cards

What is a purpose of the International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27001? | A. To provide technical specifications for encryption algorithms | B. To establish guidelines for implementing an Information Security Management System | C. To regulate the use of cryptocurrencies | D. To specify a single encryption standard

B. To establish guidelines for implementing an Information Security Management System

26
New cards

What does the General Data Protection Regulation (GDPR) say about data encryption? | A. It is only recommended for large organizations. | B. It should be used as a measure to safeguard personal data. | C. It is irrelevant in the context of personal data protection. | D. It allows for the complete removal of personal data requirements.

B. It should be used as a measure to safeguard personal data.

27
New cards

In which area is lightweight cryptography most useful? | A. High-powered computers and servers | B. Internet of things (IoT) devices | C. Systems with extensive storage | D. Encrypted social media platforms only

B. Internet of things (IoT) devices

28
New cards

What is the first step in developing a cryptographic policy for an organization? | A. Choosing encryption algorithms | B. Assessing the organization's security objective | C. Implementing encryption across all systems | D. Training employees on cryptography

B. Assessing the organization's security objective

29
New cards

What is a potential ethical dilemma when using cryptography in an organization? | A. Ensuring employee privacy while using monitoring tools | B. The choice of encryption algorithms | C. The implementation of physical security measures | D. Regular updates to the cryptographic policy

A. Ensuring employee privacy while using monitoring tools

30
New cards

What does the term Nobody But Us (NOBUS) refer to? | A. Allowing only the National Security Agency (NSA) access to encrypted data | B. The idea that all encryption should be public | C. A method of distributing encryption keys | D. Limiting encryption to government use only

A. Allowing only the National Security Agency (NSA) access to encrypted data

31
New cards

Modular arithmetic

Mathematical operations performed within a finite set of numbers where values wrap around after reaching a modulus. It is fundamental to many cryptographic algorithms.

32
New cards

Modulus

The number that defines the finite range used in modular arithmetic.

33
New cards

Large prime numbers

Used in cryptography because mathematical problems involving large primes can be computationally difficult to reverse, helping provide cryptographic strength.

34
New cards

Lattice-based cryptography

A form of cryptography based on mathematical problems involving geometric lattice structures.

35
New cards

Why is lattice-based cryptography important?

It provides cryptographic techniques based on difficult mathematical lattice problems and is associated with modern cryptographic research.

36
New cards

Encryption

The process of transforming plaintext into an encoded form called ciphertext.

37
New cards

Plaintext

The original readable data before encryption.

38
New cards

Ciphertext

The encrypted and unreadable form of plaintext.

39
New cards

Decryption

The process of converting ciphertext back into plaintext using the appropriate cryptographic key or process.

40
New cards

Cryptosystem

A combination of cryptographic algorithms, protocols, keys, and related processes used to protect information.

41
New cards

Symmetric encryption

Encryption where the same shared secret key is used for encryption and decryption.

42
New cards

AES

Advanced Encryption Standard; a symmetric encryption algorithm.

43
New cards

DES

Data Encryption Standard; an older symmetric encryption algorithm.

44
New cards

Asymmetric encryption

Cryptography that uses a mathematically related public and private key pair.

45
New cards

RSA

Rivest-Shamir-Adleman; an asymmetric cryptographic algorithm.

46
New cards

ECC

Elliptic-curve cryptography; a form of public-key cryptography based on elliptic-curve mathematics.

47
New cards

Public key

The portion of an asymmetric key pair that can be distributed publicly.

48
New cards

Private key

The secret portion of an asymmetric key pair that must be protected by its owner.

49
New cards

Hash function

A one-way mathematical function that converts input data into a fixed-size hash or digest.

50
New cards

Primary cryptographic purpose of hashing

To support message and data integrity by making unauthorized modification detectable.

51
New cards

Hashing vs. encryption

Hashing is intended to be one-way and is primarily used for integrity; encryption is reversible with the appropriate key and is primarily used for confidentiality.

52
New cards

Data integrity

Assurance that information has not been modified or altered without detection.

53
New cards

Digital signature

A cryptographic mechanism used to verify authenticity and integrity and support nonrepudiation.

54
New cards

Digital signature provides

Authenticity, integrity, and support for nonrepudiation.

55
New cards

Digital signature does NOT primarily provide

Confidentiality. A digital signature verifies data and its origin rather than hiding the contents.

56
New cards

Authenticity

Assurance that data, a message, or a sender is genuine.

57
New cards

Nonrepudiation

Assurance that prevents a sender or signer from credibly denying having performed an action such as sending or signing a message.

58
New cards

Stream cipher

A cipher that encrypts data as a continuous stream rather than fixed-size blocks.

59
New cards

Key characteristic of a stream cipher

It generates or uses a continuous stream of key material.

60
New cards

Block cipher

A cipher that processes plaintext in fixed-size blocks.

61
New cards

CBC

Cipher Block Chaining; a block cipher mode where blocks are chained so identical plaintext blocks do not simply produce identical ciphertext blocks.

62
New cards

Why does CBC use chaining?

To prevent duplicate plaintext blocks from producing identical ciphertext patterns.

63
New cards

IV

Initialization Vector; a value used to introduce variation into cryptographic operations such as CBC.

64
New cards

CBC and IV relationship

CBC uses an initialization vector for the first block so encryption does not begin with a predictable identical state.

65
New cards

Homomorphic encryption

Encryption that allows certain computations to be performed on encrypted data without first decrypting it.

66
New cards

FHE

Fully Homomorphic Encryption; allows computations to be performed on encrypted data while the information remains encrypted.

67
New cards

Blockchain

A chain of blocks linked together using cryptographic hashes.

68
New cards

What links blockchain blocks?

Cryptographic hashes connect blocks and help make unauthorized changes detectable.

69
New cards

Blockchain is centralized or distributed?

Blockchain is generally associated with distributed or decentralized ledger architectures, not a traditional centralized ledger.

70
New cards

Cryptography in cryptocurrency

Cryptography helps secure transactions and protect the integrity of the blockchain.

71
New cards

Proof-of-work

A consensus mechanism in which participants perform computational work to satisfy a cryptographic requirement.

72
New cards

PoW memory hook

Proof-of-work = prove that computational WORK was performed.

73
New cards

Consensus mechanism

A process used by participants in a distributed system to agree on the valid state of the system.

74
New cards

Proof-of-work vs. digital signature

Proof-of-work supports consensus through computational work; a digital signature authenticates and protects the integrity of signed data.

75
New cards

Digital signature vs. hash

A hash primarily supports integrity; a digital signature uses cryptographic techniques to provide integrity plus authentication and nonrepudiation.

76
New cards

Lightweight cryptography

Cryptography designed to provide security efficiently on devices with limited processing power, memory, energy, or other resources.

77
New cards

Primary target for lightweight cryptography

Internet of Things (IoT) devices and other resource-constrained systems.

78
New cards

Ascon

A lightweight cryptography algorithm family selected by NIST for protecting data on resource-constrained devices.

79
New cards

Why did NIST select Ascon?

To provide cryptographic protection suitable for IoT and other small devices with limited resources.

80
New cards

IoT cryptography challenge

IoT devices may have limited CPU power, memory, storage, and energy, making traditional cryptographic implementations more resource intensive.

81
New cards

NIST

The National Institute of Standards and Technology, which publishes standards and guidelines related to cryptography and security.

82
New cards

Role of NIST cryptographic guidance

NIST provides guidelines for cryptographic standards and their implementation.

83
New cards

Are NIST standards mandatory for every U.S. organization?

No. NIST publishes widely used standards and guidance, but the preassessment does not state that all NIST standards are mandatory for every organization.

84
New cards

Continuous monitoring of cryptographic controls

Helps organizations verify that cryptographic controls remain effective and compliant with applicable requirements.

85
New cards

Why continuously monitor cryptographic controls?

To identify problems, verify effectiveness, and support compliance with industry or organizational requirements.

86
New cards

ISO/IEC 27001

A standard associated with establishing and maintaining an Information Security Management System (ISMS).

87
New cards

ISMS

Information Security Management System; a structured system for managing organizational information security risks and controls.

88
New cards

GDPR and encryption

GDPR recognizes encryption as a measure that can help safeguard personal data.

89
New cards

Cryptography and organizational policy

Cryptographic controls should align with organizational security objectives and policies to maximize the effectiveness of data protection.

90
New cards

First step in developing a cryptographic policy

Assess the organization's security objectives.

91
New cards

Why assess security objectives first?

Cryptographic controls should be selected based on what the organization actually needs to protect and accomplish.

92
New cards

Organizational cryptographic alignment

Coordinating cryptographic practices with business policies, security requirements, departments, and organizational objectives.

93
New cards

Factor supporting successful cryptographic alignment

A dedicated security team that regularly communicates with organizational departments.

94
New cards

Cryptographic governance

The policies, responsibilities, standards, monitoring, and decision-making processes surrounding an organization's use of cryptography.

95
New cards

Cryptographic policy

A formal set of organizational requirements governing how cryptography should be selected, implemented, managed, and monitored.

96
New cards

Cryptography and employee privacy

Organizations may face ethical issues when security monitoring or cryptographic controls conflict with employee privacy interests.

97
New cards

Ethical dilemma tested on the PA

Balancing employee privacy with the use of organizational monitoring tools.

98
New cards

NOBUS

Nobody But Us; the concept that a cryptographic capability or vulnerability is believed to be exploitable only by a particular intelligence organization.

99
New cards

NOBUS memory hook

NOBUS = Nobody But Us.

100
New cards

NOBUS on the WGU preassessment

The expected answer associates NOBUS with allowing only the National Security Agency (NSA) access to encrypted data.