TechNuggets Academy

Cryptography and PKI

Free GIAC Security Essentials practice — 6 questions on Cryptography and PKI, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Cryptography and PKI
A financial services firm is redesigning its TLS configuration after a regulator warns that captured traffic could be decrypted years later if the server's private key is ever compromised. The current configuration negotiates TLS_RSA_WITH_AES_256_CBC_SHA. Which change BEST addresses the regulator's concern?
ECDHE (or DHE) generates a fresh ephemeral key pair per session, so past session keys cannot be derived even if the server's long-term private key is later stolen. Static RSA key exchange lets an attacker who later obtains the private key decrypt all previously captured traffic — the exact 'harvest now, decrypt later' risk described.
Question 2 of 6 · Cryptography and PKI
A large e-commerce site wants to reduce the load on its CA's revocation infrastructure while still letting clients verify in real time that its certificate has not been revoked, without the CA learning which end users are visiting the site. Which mechanism BEST meets these requirements?
With OCSP stapling, the web server itself periodically queries the CA's OCSP responder and 'staples' the signed, time-stamped response to the TLS handshake. Clients get a real-time revocation status without contacting the CA directly, which removes the privacy leak of the CA seeing every client's browsing and offloads load from the OCSP responder to the web server.
Question 3 of 6 · Cryptography and PKI
A developer is choosing a block cipher mode for encrypting API payloads that must be protected against both eavesdropping and undetected tampering, with the integrity check built into the encryption operation itself rather than added as a separate step. Which mode should be selected?
GCM (Galois/Counter Mode) is an authenticated encryption mode: it produces ciphertext plus an authentication tag in a single operation, providing confidentiality and integrity/authenticity together without a separate MAC step. This is the standard exam answer for AEAD requirements.
Question 4 of 6 · Cryptography and PKI
During a code review of a custom document-signing utility, you find that it computes SHA-256 over the document, then encrypts the resulting hash with the signer's PUBLIC key and attaches it as the 'signature.' Which statement correctly identifies the flaw?
A digital signature must be created by encrypting (or more precisely, applying the private-key operation to) the hash with the SIGNER'S PRIVATE key. Verifiers then decrypt/verify using the signer's widely-known PUBLIC key. Using the public key to 'sign' means anyone could produce that same value, since the public key is not secret — it provides no authentication of the signer.
Question 5 of 6 · Cryptography and PKI
A web server presents a certificate whose Extended Key Usage (EKU) field is set to 'Code Signing' only, with no 'Server Authentication' EKU present. A browser refuses to establish a TLS connection and displays a certificate error. What is the MOST likely reason for this failure?
Browsers strictly validate the Extended Key Usage extension and require 'Server Authentication' (OID 1.3.6.1.5.5.7.3.1) for TLS server certificates. A certificate issued and constrained for Code Signing only is not authorized for TLS server authentication, regardless of trust chain or key strength, and the browser correctly rejects it.
Question 6 of 6 · Cryptography and PKI
A security architect is comparing hash algorithms for a new digital signature scheme and wants to understand the practical security margin against birthday-style collision attacks. For a hash function with an n-bit output, approximately how many hash operations are required to find a collision using a generic birthday attack?
The birthday paradox means collisions in an n-bit hash can generically be found in roughly 2^(n/2) operations rather than 2^n, because you only need to find any two matching outputs among a growing pool of hashes, not match a specific target. This is why SHA-256 (256-bit output) provides about 128 bits of collision resistance, and why SHA-1 (160-bit, ~80-bit collision resistance) is considered broken for collision-sensitive uses.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →