Test your basic knowledge |

CISSP Crypto Domain

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Online Certificate Status Protocol- used to query the CA; useful in large; complex environments; responds to a query with status of valid; suspended; or revoked






2. Rearranges bits or bytes






3. Data Encryption Standard - 64 bit blocks - 56 bit key - 16 rounds - 4 modes






4. RSA; El Gamal; ECC; Diffe Hellman; DSA






5. Scrambled version of the alphabet






6. Centralized key mgt key issuer; keeps copy of keys or decentralized key mgt; end user generates keys and submits to CA;does not provide for key escrow; no recovery possible






7. Science of breakin the code






8. Confidentiality - Authentication - Non-Repudiation






9. Electronic Code Book Each block encrypted independently; 64 bits at a time; using same key; given message; always same ciphertext; susceptible to plaintext attack






10. Keys needed to decrypt cyphertext so an authorized third party can gain access






11. Authentication and integrity - needed when... At rest and in transit.






12. International Data Enc Algorithm - 64 bit block - 128 bit key






13. Provided by mixing key values during repeated rounds of encryption






14. Spartans - wrapped around rod.






15. Measar cipher






16. Integrity






17. key storage;escrow;archival;recovery agend;multiple key pairs






18. Advanced Encryption Standard - replaced DES - Rijndael based - 128 - 192 - and 256 bit keys/blocks with 10 - 12 - 14 rounds resp.






19. Malled online encryption or traffic flow security- implemented in hardware' encrypts all traffic in a single path






20. NIST and NSA - 160 bit digest






21. 32 to 448 bit key - Schneier






22. Prove knowledge of a fact to a third party without revealing the fact itself






23. Similar to OFB-insteat of a static IV- a counter is incremented with each data block ;each block XORed with unique keystream value; no chaining; encryption of block s can happen in parallel used in IPSEc and implemented in 802.11i wireless






24. One key - only confidentiality






25. Study of both cryptography and cryptanalysis






26. Looks for patterns in ciphertext to discover the key.






27. Authenticity - integrity - digital signatures - storing passwords.






28. Mathematical operation performed several times on the same message block






29. Caesar cipher - scytale - Blaise de vigenere - vernam cipher






30. One-way - difficult to solve - uses factorization - private key can compute the public key






31. Based on diffie-hellman - encryption - digital signatures and key exchange.






32. Single authority trust; heirarchal trust; web of trust; hybrid cross certificationusesd in businesses to trust each others CA's; and DISA Model Root; intermediate; leaf at the local levels






33. variable block and key sizes 128; 192; 256; uses a variable number of rounds; has low memory requirements; easy to defend against timing attacks; implemented in software; hardware is costly.






34. Each pair of entities must receive in secure fashion; requires more overhead than worth; key distro challenging- sender recievermust be on the same sheet






35. Stream cipher; stream algorithm works one bit at a time usually done in Hardware; no memory required; very fast; block cipher; works on blocks of bits; transforms into fixed length blocks; encrypted block by block 64; 128; 256 uses substitution and t






36. Public algorithm - private key.






37. Public Key Infrastructure- Developed to provide standards for key generation; authentication; x.509 non used with Pretty Good Privacy; good private good "web of trust"






38. Uses asymmetric to figure out a key - symmetric used for large data encryption.






39. Hash Mess Auth Code (512bit MD5; SHA-1); calculated using a hash function with secret key- shared key appended to data shared faster than DES CBC- used in IPSEC SSL/TLS and SSH






40. Secret; single; conventional; session; shared; private






41. Pro's: key management cons: speed/file size






42. NIST 1991 - outlines authorized algorithms






43. Message Authentication Code - Symmetric enc + Hash






44. 256 or 512-bit digest






45. Advanced Encryption Standard






46. Setting policies; protecting keys; key recovery; responding to key compromise; keys long enough to prevent attack; cryptoperiod: key lifetimes






47. Carlisle Adams and Stafford Tavares; CAST 128 64 bit block cipher-uses keys between 48 and 128 bit lengths 12 to 16 rounds of operations CAST 256 uses 48 rounds; of 128; 192; 160; 224; 256






48. Link Encryption and end to end encryption






49. Process of properly destroying keys at end of userful loife






50. Science of protecting information by encoding it