Test your basic knowledge |

CISSP Crypto Domain

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. OCSP; OSPF- routing protocol; Online Vulnerability Assessment Language; Orthogonal Frequency Division Multiplexing


2. Broken






3. key storage;escrow;archival;recovery agend;multiple key pairs






4. Integrity






5. Provided by mixing key values during repeated rounds of encryption






6. First public key exchange system - users exchange keys over insecure medium.






7. Message Authentication codes; aka message integrity code; modification detection code; cryptographic checksum; generated by running message through secret key(DES CBC) MAC is the last block generated by algorithm 64 bit






8. Data in readable format- red side






9. Based on Dif Hel; provides encrypt; dig sig; and key exchange; discrete logarithms-easy to reverse engineer; main drawback is performance- slower than other algorithms






10. Cannot deny ownership / origination.






11. Data Encryption Standard (DES) 5 Block Modes; Trple DES runs through it three times; Blowfish; IDEA; RC4; RC5






12. Relies on finding weaknesses in the hashing algorithm






13. MD5 - SHA1






14. Encryption - decryption - signing - verifying






15. Rivest-Shamir-Adleman - factorization - used for encryption - key exchange and digital signature.






16. characters are substituted or shifted






17. Advanced Encryption Standard






18. Provided by mixing up the location of plaintext throughout the cipher






19. Authenticity - integrity - digital signatures - storing passwords.






20. NIST and NSA - 160 bit digest






21. Single authority trust; heirarchal trust; web of trust; hybrid cross certificationusesd in businesses to trust each others CA's; and DISA Model Root; intermediate; leaf at the local levels






22. Keys needed to decrypt cyphertext so an authorized third party can gain access






23. Both parties have same key(kept secret) exchage keys before comms begins; faster than asymmetric crypto; best suited for bulk encryption; N(N-1)/2 is the number of keys needed; File Encryption Key (FEK)






24. Has authority to remove keys from escrow;






25. Integrity Check Value-makes the hash with the hash algorithm






26. Measar cipher






27. Storage of keys and certs for extended period of time-normally performed by CA a trusted third party; or key holder






28. Digital signature standard; performs integrity by SHA; uses DSA; RSA;Elyp CurveDSA






29. Large set of possible values used to construct keys






30. RC(x) - 32 - 64 - 128 bit blocks - key max at 2048 bits






31. NIST 1991 - outlines authorized algorithms






32. Function that takes a variable length string; and compresses and transforms it into a fixed length- output called a hash or message digest






33. Cipher Feedback Emulates stream cipher data encrypted in smaller units than block size; plaintext pattersn concealed in XOR; previous ciphertext block is encrypted and output produced is conbined with plaintext block using XOR-to produce next ciphert






34. Published document describing: howa CA is structured;which standards are used and how certs are managed






35. Easily transportable;cannot be initiated by something else; can be automatically time stamped;provides integrity by encrypting hash value;hash value generated with senders private key






36. Rives Shamir; adleman- based on factoring of large prime numbers-encrypt-dig sig- and key exchange variable key length 512 to 4096- strong but slow; 100 times slower than software; 1000-10000 slower than hardware encryption






37. Based on diffie-hellman - encryption - digital signatures and key exchange.






38. Science of breakin the code






39. Hides data in images - usually by LSB (least significant bit)






40. 64 bit blocks of data; variable key lengths






41. RSA






42. SHA - RSA - Eliptical Curve (ECDSA)






43. Pro's: key management cons: speed/file size






44. Modified md5 - v means "variable"






45. variable block and key sizes 128; 192; 256; uses a variable number of rounds; has low memory requirements; easy to defend against timing attacks; implemented in software; hardware is costly.






46. Stream based - errors do not propagate across blocks






47. Symmetric for Bulk Encrypt; assym for key encapsulation- used in SSL; Email; key exchange






48. One-way - difficult to solve - uses factorization - private key can compute the public key






49. Letters represented by numerical place in the alphabet






50. Authentication and integrity - needed when... At rest and in transit.