Test your basic knowledge |

CISSP Crypto Domain

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Scrambled version of the alphabet






2. Broken






3. Has authority to remove keys from escrow;






4. Message hidden within larger context.






5. Set symbol size usually 64 bits






6. OCSP; OSPF- routing protocol; Online Vulnerability Assessment Language; Orthogonal Frequency Division Multiplexing


7. Based on Dif Hel; provides encrypt; dig sig; and key exchange; discrete logarithms-easy to reverse engineer; main drawback is performance- slower than other algorithms






8. Eliptical Curve Cryptography; encryption; dig signatures and key exchange;highest strength per bit of key length; most efficient;160 bit el gamal= 1024 RSA-used in wireless devices use






9. Public algorithm - private key.






10. 128 bit encryption; on 16 rounds of encryption; key size of 64 bits 8 parity; 56 bits long






11. Letters represented by numerical place in the alphabet






12. SHA - RSA - Eliptical Curve (ECDSA)






13. Similar to OFB-insteat of a static IV- a counter is incremented with each data block ;each block XORed with unique keystream value; no chaining; encryption of block s can happen in parallel used in IPSEc and implemented in 802.11i wireless






14. Pro's: key management cons: speed/file size






15. Based on probability with 23 people 50% chance 2 will have same birthday






16. Process of properly destroying keys at end of userful loife






17. 128 bit digest






18. Operates on bits - higher speed - usually implemented in hardware.






19. Caesar cipher - scytale - Blaise de vigenere - vernam cipher






20. Function that takes a variable length string; and compresses and transforms it into a fixed length- output called a hash or message digest






21. Stream based - errors do not propagate across blocks






22. Rives Shamir; adleman- based on factoring of large prime numbers-encrypt-dig sig- and key exchange variable key length 512 to 4096- strong but slow; 100 times slower than software; 1000-10000 slower than hardware encryption






23. Online Certificate Status Protocol- used to query the CA; useful in large; complex environments; responds to a query with status of valid; suspended; or revoked






24. variable block and key sizes 128; 192; 256; uses a variable number of rounds; has low memory requirements; easy to defend against timing attacks; implemented in software; hardware is costly.






25. Data Encryption Standard - 64 bit blocks - 56 bit key - 16 rounds - 4 modes






26. No plaintext exposure; encrypted at source; VPN; SSL ;SSH






27. Formula is public; used to creat checksums; message digests; or integrity check values






28. Secret; single; conventional; session; shared; private






29. Replaces bits characters and block s with differecnt values






30. Electronic Code Book Each block encrypted independently; 64 bits at a time; using same key; given message; always same ciphertext; susceptible to plaintext attack






31. Set of mathmatical rules used in encryption






32. Hash Mess Auth Code (512bit MD5; SHA-1); calculated using a hash function with secret key- shared key appended to data shared faster than DES CBC- used in IPSEC SSL/TLS and SSH






33. Keyword: integrity






34. Authenticity - integrity - digital signatures - storing passwords.






35. Different keys for encryption and decryption; two keys private and public Encrypt with private- unencrypt with privateor encrypt with public- decrypt with private. Use of private ensures non repudiation; without confidentiality-becomes the digital si






36. Cannot deny ownership / origination.






37. Hardware - software - and policies (security association) -






38. Block based - Previous block seeds next blocks key






39. 256 or 512-bit digest






40. Rearrances the bits characters or character blocks






41. Integrity Check Value-makes the hash with the hash algorithm






42. Symmetric for Bulk Encrypt; assym for key encapsulation- used in SSL; Email; key exchange






43. Output feedback; emulates stream cipher; similar to CFB except qty XORed; with each plaintext block; IV used as a seed; then keystream used as IV in continuing process






44. Large set of possible values used to construct keys






45. Integrity






46. Encryption - decryption - signing - verifying






47. Mathematical operation performed several times on the same message block






48. CIA plus non repudiation






49. NIST and NSA - 160 bit digest






50. Both parties have same key(kept secret) exchage keys before comms begins; faster than asymmetric crypto; best suited for bulk encryption; N(N-1)/2 is the number of keys needed; File Encryption Key (FEK)