Courseiva

CCNA Cryptography Application Questions

10 questions · Cryptography Application · All types, answers revealed

1
Multi-Selectmedium

Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?

Select 2 answers
A.Centralized distribution of symmetric keys.
B.Issuance of digital certificates to verify identity.
C.Revocation of compromised or invalid certificates.
D.Hardware-level encryption for disk storage.
E.Real-time traffic flow monitoring and alerting.
AnswersB, C

Issuing digital certificates is a core function of the Certificate Authority (CA) within a PKI. These certificates bind a public key to a specific entity, allowing other parties to verify that the entity is who they claim to be, which is fundamental to establishing trust online.

Why this answer

PKI is vital for managing the lifecycle of digital certificates, ensuring trust in identity. By providing mechanisms for issuance and revocation, PKI allows entities to communicate securely without pre-existing trust. Understanding these functions is essential for GSEC professionals to manage authentication and secure communication channels effectively within an enterprise architecture, preventing the use of expired or fraudulent credentials that could be exploited by malicious actors during network sessions.

Exam trap

Candidates often select 'encryption' or 'hashing' as primary PKI functions. While PKI uses these technologies, its primary purpose is the management of identity through certificate issuance and revocation.

2
MCQmedium

A security analyst is hardening a web server to ensure that only modern, secure protocols are used for HTTPS traffic. Which configuration best aligns with GSEC security standards for data in transit?

A.Support TLS 1.0, 1.1, and 1.2 to maintain maximum backward compatibility.
B.Enable SSLv3 for clients who cannot support newer TLS versions.
C.Disable SSL and TLS 1.0/1.1, allowing only TLS 1.2 and 1.3.
D.Use RC4 for all connections to ensure high performance over low-bandwidth links.
AnswerC

Restricting traffic to TLS 1.2 and 1.3 eliminates the usage of deprecated, insecure ciphers and handshake methods. This configuration adheres to current industry best practices and compliance frameworks, effectively closing the window on several classes of protocol downgrade attacks that plague older implementations of the HTTPS stack.

Why this answer

Disabling legacy protocols like SSLv3 and TLS 1.0 is essential to prevent downgrade attacks like POODLE. By mandating TLS 1.2 or higher, the organization ensures that cryptographic primitives remain robust against known vulnerabilities. This practice is foundational for GSEC-compliant environments, as it mitigates the risk of man-in-the-middle interception where outdated handshake mechanisms allow attackers to force the use of weaker, exploitable encryption algorithms during the initial connection setup.

Exam trap

Candidates often include TLS 1.1 in their selection, believing it to be 'secure enough.' GSEC standards strictly mandate disabling anything below TLS 1.2 to prevent known protocol downgrade attacks.

3
MCQeasy

When selecting a cryptographic hash function for verifying file integrity, which property is most important to ensure that an attacker cannot create two different files that produce the same hash value?

A.Pre-image resistance.
B.Collision resistance.
C.Reversibility.
D.High computational speed.
AnswerB

Collision resistance specifically addresses the difficulty of finding any two distinct inputs that map to the same hash value. This prevents attackers from creating a 'doppelganger' file that passes integrity checks designed for a known-good file, which is a key requirement for secure file verification and distribution systems.

Why this answer

Collision resistance is the property of a hash function that makes it computationally infeasible to find two distinct inputs that result in the same output hash. This is critical for integrity verification; if an attacker could generate a malicious file with the same hash as a legitimate file, they could bypass security controls, leading to the execution of arbitrary, potentially malicious code while the system assumes the file is authentic and untampered.

Exam trap

Candidates frequently confuse 'collision resistance' with 'pre-image resistance.' They are distinct properties, and collision resistance is specifically required to prevent two different files from sharing the same hash.

4
MCQhard

A security engineer is selecting a hash function to protect stored user passwords in a new application. The threat model assumes an attacker who steals the password database and has substantial GPU resources for offline cracking. Which choice best addresses this threat?

A.A memory-hard password hashing function such as Argon2id with a tuned memory cost, time cost, and parallelism, plus a unique per-user salt.
B.HMAC-SHA-1 keyed with a single global application secret, because the secret prevents attackers from computing hashes without it.
C.SHA-256 applied twice to each password with a per-user salt, because iterating a fast hash twice doubles the attacker's work.
D.AES-256 in CBC mode encrypting each password with a key stored in the same database, because encryption hides the password values.
AnswerA

Argon2id is purpose-built for password storage and its memory-hard design sharply limits GPU parallelism, because each guess requires substantial memory that GPUs cannot multiply cheaply. Tuned time and memory costs plus unique per-user salts make offline cracking of a stolen database far more expensive than with fast general-purpose hashes.

Why this answer

Password storage needs a deliberately slow, memory-hard function so each offline guess is expensive and GPU parallelism is blunted. Argon2id with tuned parameters and unique per-user salts achieves this, whereas fast hashes, reversible encryption, and a single global secret all fail against an attacker with stolen data and strong cracking hardware.

Exam trap

The trap here is assuming that salting or iterating a fast general-purpose hash like SHA-256 is sufficient, when only a memory-hard function meaningfully raises the cost of GPU-accelerated offline cracking.

5
MCQeasy

A security analyst is reviewing a legacy application that uses RSA for digital signatures. The application generates a 1024-bit RSA key pair and signs messages using SHA-1. The analyst must recommend an upgrade that maintains the same algorithm family but meets current security standards. Which change should be recommended?

A.Keep the 1024-bit RSA key but replace SHA-1 with SHA-3.
B.Replace RSA with HMAC-SHA256 for signing.
C.Increase the RSA key size to 2048 bits and replace SHA-1 with SHA-256.
D.Switch to Elliptic Curve Digital Signature Algorithm (ECDSA) with P-256 and SHA-256.
AnswerC

Increasing RSA key size to 2048 bits and replacing SHA-1 with SHA-256 aligns with current standards such as NIST SP 800-57 and CA/Browser Forum requirements. This maintains the RSA algorithm family while addressing vulnerabilities in both key length and hash function. It provides a stronger security margin without changing the underlying cryptographic approach.

Why this answer

To meet current security standards while preserving the RSA algorithm family, the analyst should recommend increasing the RSA key size to 2048 bits and replacing SHA-1 with SHA-256. This addresses both the weak key length and the deprecated hash function, providing a secure and compliant digital signature solution without changing the underlying public-key algorithm.

Exam trap

The trap here is focusing only on the hash function and overlooking the insufficient RSA key size, which also requires upgrading to meet modern standards.

6
MCQhard

A security engineer is designing an internal Public Key Infrastructure (PKI) and needs to issue a subordinate certificate authority (sub-CA) certificate. To prevent this sub-CA from accidentally or maliciously issuing certificates for unauthorized domains, what specific X.509 extension must be correctly configured?

A.Key Usage extension populated solely with Digital Signature, Non-Repudiation, and Key Encipherment flags.
B.Authority Information Access extension pointing directly to the organization's primary online OCSP responder.
C.Name Constraints extension configured with explicit permitted and excluded subtree subdirectories for domain namespaces.
D.Extended Key Usage extension restricted strictly to TLS Web Server Authentication and Code Signing.
AnswerC

Name Constraints enforce strict boundaries on subordinate CAs by defining exact permitted and excluded domain namespaces. If a sub-CA attempts to issue a certificate outside these boundaries, relying parties will immediately reject it as invalid.

Why this answer

Name Constraints restrict the namespace within which all subject names in certificates issued by the CA must reside. This crucial X.509 extension prevents a compromised subordinate CA from generating trusted certificates for domains outside its permitted organizational scope, thereby containing blast radius in enterprise PKI hierarchies.

Exam trap

Candidates often select certificate revocation lists or basic constraints, missing that namespace restriction specifically requires the name constraints extension.

7
MCQmedium

An organization needs to encrypt a database of PII. The requirements state that the encryption must be reversible by authorized staff and provide data integrity. Which implementation should the security engineer recommend?

A.Use SHA-256 hashing for all database fields.
B.Implement AES-256 in GCM mode.
C.Use RSA-4096 for encrypting large datasets.
D.Apply XOR-based encryption with a static global key.
AnswerB

AES-256 in GCM mode offers high-speed, symmetric encryption that ensures confidentiality while simultaneously providing integrity through an authentication tag. This approach satisfies the dual requirements of reversibility for authorized users and protection against data tampering, which is the gold standard for protecting sensitive database records in modern systems.

Why this answer

Using AES-256 in GCM mode provides both confidentiality and authenticity. Symmetric encryption is appropriate for database encryption where authorized entities hold the decryption keys. GCM mode is preferred because it acts as an Authenticated Encryption with Associated Data (AEAD) algorithm, preventing unauthorized modification of the ciphertext.

This is critical for database security, where verifying that data has not been tampered with is as important as preventing unauthorized disclosure of the stored information.

Exam trap

Candidates often select asymmetric encryption or simple hashing. They fail to realize that database encryption requires symmetric performance and that GCM provides the necessary integrity checking for data.

8
MCQeasy

A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?

A.Key encapsulation, so that the long-term secret directly encrypts each session key and guarantees confidentiality of the exchange.
B.Collision resistance, so that two different sessions cannot produce the same derived key material during the handshake.
C.Perfect forward secrecy, so that each session key is derived independently and compromise of one does not expose others or the long-term secret.
D.Non-repudiation, so that each VPN endpoint can prove it participated in the session and cannot deny sending traffic.
AnswerC

Perfect forward secrecy derives each session key from ephemeral values that are discarded after the exchange, so a later compromise of a session key or long-term secret cannot reconstruct other sessions' keys. This directly satisfies the requirement that no session key reveal another or the long-term authentication secret.

Why this answer

Perfect forward secrecy uses ephemeral key agreement such as Diffie-Hellman with per-session values, so the long-term authentication secret never encrypts session keys directly. Even if one session key is later compromised, the ephemeral secrets needed to derive other sessions have been erased, and the long-term secret remains protected.

Exam trap

The trap here is confusing confidentiality of the handshake with forward secrecy, assuming any encrypted key exchange prevents one compromised session key from affecting others when only ephemeral, discarded secrets do.

9
MCQmedium

An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?

A.RSA key transport mechanism
B.Elliptic Curve Diffie-Hellman Ephemeral
C.Pre-Shared Key authentication mode
D.Static Diffie-Hellman key agreement
AnswerB

ECDHE leverages transient elliptic curve parameters for each unique handshake transaction. Because the server private key is only used to digitally sign the ephemeral exchange and is never used to derive the session key directly, past sessions remain entirely secure against future key compromises.

Why this answer

Perfect forward secrecy ensures that session keys are not compromised even if the primary private key of the server is compromised in the future. Ephemeral Diffie-Hellman guarantees this by generating unique per-session parameters that are never stored persistently on disk. Proper enforcement prevents long-term bulk decryption of historical intercepted traffic.

Exam trap

Candidates frequently select standard Diffie-Hellman or RSA instead of looking for the ephemeral variant, overlooking the specific requirement that session keys must not be tied to static private keys.

10
Multi-Selectmedium

A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)

Select 2 answers
A.The file is encrypted with a stream cipher using a nonce that is reused across all files for simplicity.
B.A static initialization vector equal to the file creation timestamp is used for every encryption operation to ensure reproducibility.
C.A password-based key derivation function with a unique random salt and a high iteration count is used to derive the file encryption key.
D.An authenticated encryption mode such as AES-GCM or ChaCha20-Poly1305 is used to provide confidentiality and integrity of the ciphertext.
E.The encryption key is embedded in the file header obfuscated with Base64 so the tool can decrypt without prompting the user.
AnswersC, D

A salted, high-iteration KDF forces an attacker to spend significant work per guessed passphrase and prevents precomputed rainbow-table attacks across files. Because the salt is unique per file, identical passphrases still yield different keys, so copying a file without the passphrase leaves the attacker facing a costly brute-force effort.

Why this answer

A salted, high-iteration KDF makes passphrase guessing expensive and prevents cross-file precomputation, while authenticated encryption binds a tag to the ciphertext so any modification is detected. Together they ensure a copied file cannot be decrypted without the passphrase and that tampering is evident.

Exam trap

The trap here is treating encoding such as Base64 or an obfuscated header as encryption, when it provides no confidentiality and leaves the key trivially recoverable from a copied file.

Ready to test yourself?

Try a timed practice session using only Cryptography Application questions.