Courseiva

CCNA Cryptography Questions

14 questions · Cryptography topic · All types, answers revealed

1
MCQmedium

A security team is deploying a new internal TLS certificate authority (CA) for service-to-service authentication. The CA private key must be protected, and the team wants to ensure that if the key is compromised, the attacker cannot forge certificates without detection. Which of the following is the MOST effective control to detect unauthorized certificate issuance?

A.Enforce a minimum RSA key size of 4096 bits for the CA key pair.
B.Require Certificate Revocation List (CRL) checking on all clients.
C.Publish all issued certificates to an internal Certificate Transparency (CT) log.
D.Configure certificate pinning in all client applications.
AnswerC

CT logs provide an append-only, publicly auditable record of issued certificates. Publishing internal certificates to a CT log allows the security team to monitor for unauthorized issuance; any forged certificate would appear in the log, enabling detection. This is the most effective detective control among the options, as it directly addresses the risk of undetected certificate forgery.

Why this answer

Certificate Transparency logs create a verifiable record of all certificates issued by a CA. By publishing internal certificates to a CT log, the team can monitor for unexpected entries, which would indicate unauthorized issuance. This detective control is more effective than preventive measures like key size or pinning, which do not alert on forgery.

Exam trap

The trap here is assuming that stronger cryptographic keys or client-side pinning will detect a compromised CA, when detection requires an auditable record such as Certificate Transparency.

2
MCQmedium

A security analyst is reviewing the configuration of a VPN gateway that uses IPsec in tunnel mode. The analyst notices that the gateway is configured to use IKEv2 with a pre-shared key (PSK) for authentication. Which of the following is the PRIMARY security concern with this configuration?

A.PSK authentication cannot be used with IKEv2; it requires IKEv1.
B.PSK authentication does not encrypt the IKEv2 handshake, exposing the PSK in plaintext.
C.PSK authentication is vulnerable to offline dictionary attacks if an attacker captures the handshake.
D.PSK authentication does not provide perfect forward secrecy (PFS).
AnswerC

In IKEv2 with PSK, the authentication exchange involves a hash of the PSK and other values. An attacker who captures the handshake can perform an offline dictionary attack to recover the PSK if it is weak. This is a serious concern because PSKs are often human-chosen and may be susceptible to guessing. Unlike certificate-based authentication, there is no public key infrastructure to provide strong authentication.

Why this answer

Pre-shared key authentication in IKEv2 relies on a secret that is shared among peers. If an attacker captures the authentication exchange, they can attempt to guess the PSK offline, especially if it is weak. This makes PSK authentication vulnerable to dictionary attacks, which is a primary security concern compared to certificate-based authentication.

Exam trap

The trap here is thinking that PSK is sent in plaintext or that it prevents PFS, when the real risk is offline dictionary attacks against a shared secret.

3
MCQmedium

An organization is migrating to a cloud environment and must ensure that data remains encrypted while in use by applications. Which technology should the security team implement to achieve this?

A.Transport Layer Security (TLS)
B.Full Disk Encryption (FDE)
C.Homomorphic Encryption
D.Database Transparent Data Encryption
AnswerC

Homomorphic encryption allows mathematical operations to be performed directly on ciphertext. The result of the operation, when decrypted, matches the result that would have been obtained if the operations were performed on the original plaintext, providing a unique method for keeping data secure while it is being actively processed.

Why this answer

Homomorphic encryption is a sophisticated cryptographic technique that allows computations to be performed on encrypted data without first needing to decrypt it. This ensures that the data is never exposed in cleartext within the application's memory or on the cloud provider's host, effectively providing security for data-in-use. This is a powerful, though performance-intensive, solution for highly regulated industries like finance or healthcare that require data protection even during processing in untrusted environments.

Exam trap

Candidates frequently choose 'TLS' or 'AES encryption,' forgetting that these protect data in transit or at rest, but fail to address the 'in-use' (processing) requirement.

4
MCQmedium

An administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?

A.DES with CBC mode
B.Blowfish with ECB mode
C.AES-256 with XTS mode
D.RSA-4096 with OAEP
AnswerC

AES-256 provides a significant security margin, and XTS is the standard mode designed specifically for block-oriented storage media. It prevents data manipulation attacks and provides high performance when combined with AES-NI hardware acceleration, making it the preferred choice for modern full disk encryption implementations across diverse hardware platforms.

Why this answer

AES-256 with XTS mode is the industry standard for disk encryption, providing high security against block manipulation attacks. Leveraging hardware-level acceleration via AES-NI instructions ensures that encryption overhead is minimized, preventing performance degradation for end users. This balance of cryptographic strength and operational efficiency is vital for protecting data at rest on mobile devices that are prone to physical theft or unauthorized access attempts.

Exam trap

Candidates often select 'AES-256' without specifying the 'XTS' mode, forgetting that XTS is the standard for disk encryption to prevent block-level manipulation and data patterns.

5
Multi-Selecthard

A developer is implementing an application that stores user passwords in a database. Which THREE of the following practices are essential for ensuring the cryptographic security of these stored secrets?

Select 3 answers
A.Using a unique, random salt for every user
B.Using the Argon2id hashing algorithm
C.Storing passwords using SHA-256 with no salt
D.Applying a high iteration count (stretching)
E.Encrypting the database table with AES-128
AnswersA, B, D

Salting ensures that two users with the same password have different hashes stored in the database. This prevents attackers from using precomputed rainbow tables to crack multiple accounts simultaneously and forces them to perform a unique attack against each user, drastically increasing the time required for successful password recovery.

Why this answer

Proper password storage requires a unique salt to prevent rainbow table attacks, a high-work-factor key derivation function to slow down brute-force attempts, and a secure hashing algorithm designed for slow computation. These defenses are mandatory because standard cryptographic hashes like MD5 or SHA-256 are too fast, enabling attackers to perform trillions of guesses per second on modern hardware, making the stored hashes vulnerable to rapid offline cracking if the database is leaked.

Exam trap

Candidates often include legacy algorithms like MD5 or SHA-256 in their selection, failing to realize these are too fast and insecure for modern password storage requirements.

6
MCQmedium

A security engineer at a hospital must encrypt a 40 GB database backup for archival to offsite tape. The tape library appliance has very limited CPU resources, and the engineer wants a symmetric mode that allows the archive to be decrypted in independent chunks without needing to read the entire stream first. Which cipher mode BEST satisfies these requirements?

A.Counter Mode (CTR)
B.Cipher Block Chaining (CBC)
C.Galois/Counter Mode (GCM)
D.Electronic Codebook (ECB)
AnswerA

CTR turns a block cipher into a stream cipher by encrypting sequential counter values, so any block can be decrypted independently once the correct counter value is known. This allows parallel processing and random access, which suits a low-CPU tape appliance and a multi-gigabyte archive. The engineer must still ensure counter values are never reused with the same key, but CTR meets the independent-chunk requirement without the chaining dependency of CBC.

Why this answer

Counter Mode generates a keystream by encrypting successive counter values, so ciphertext blocks have no dependency on one another. That independence enables parallel encryption and decryption and permits retrieval of arbitrary archive segments without reading the whole stream, which matches the constrained tape appliance. CTR provides confidentiality only, so a separate integrity mechanism would be needed if tamper detection matters for the archive.

Exam trap

The trap here is assuming that an authenticated mode such as GCM is always the better choice for bulk archival data, when its whole-message tag actually prevents the independent chunk decryption the scenario requires.

7
Multi-Selecthard

A security engineer is implementing a digital signature solution using RSA. The engineer must ensure that signatures provide authenticity, integrity, and non-repudiation. Which TWO of the following practices are essential to achieve these goals? (Choose two.)

Select 2 answers
A.Hash the message with a collision-resistant hash function before signing.
B.Include a timestamp from a trusted Time Stamping Authority (TSA) in the signature.
C.Use the recipient's public key to encrypt the hash before signing.
D.Encrypt the entire message with the sender's private key.
E.Sign the hash with the sender's private key.
AnswersA, E

Signing a hash of the message rather than the raw message is essential for performance and security. A collision-resistant hash ensures that it is infeasible to find two different messages with the same hash, which would allow signature forgery. This practice is fundamental to achieving integrity and non-repudiation in digital signatures.

Why this answer

To create a digital signature with RSA, the sender must hash the message using a collision-resistant hash function and then sign that hash with their private key. This provides integrity (via the hash), authenticity and non-repudiation (via the private key signature). The recipient can verify by hashing the message and decrypting the signature with the sender's public key.

Exam trap

The trap here is confusing digital signatures with encryption, leading to the misconception that the recipient's public key or the sender's private key is used to encrypt the whole message.

8
MCQhard

A security architect is designing a system that requires cryptographic keys to be generated, stored, and used without ever exposing the private key material to the operating system. The keys must be usable for TLS server authentication and must support high transaction volumes. Which of the following solutions BEST meets these requirements?

A.A cloud key management service (KMS) that stores keys in a multi-tenant environment.
B.A Hardware Security Module (HSM) with TLS offloading capabilities.
C.A software-based key store protected by a strong passphrase and file system permissions.
D.A Trusted Platform Module (TPM) 2.0 chip on each server.
AnswerB

An HSM is a dedicated hardware device that generates, stores, and uses cryptographic keys within a tamper-resistant boundary. Private keys never leave the HSM in plaintext, so the operating system cannot access them. HSMs support high-performance TLS acceleration, making them suitable for high transaction volumes. This meets all requirements: key isolation and performance.

Why this answer

An HSM provides a dedicated, tamper-resistant environment where private keys are generated and used without ever leaving the device. This ensures the operating system never sees the key material. HSMs are also designed for high-performance cryptographic operations, including TLS acceleration, making them ideal for high-volume server authentication.

Exam trap

The trap here is confusing a TPM with an HSM; TPMs are for platform integrity and low-volume crypto, not high-performance TLS key protection.

9
MCQeasy

A security administrator is configuring a Linux server to encrypt a new block device that will store sensitive data. The administrator wants to ensure that data is encrypted at rest and that the encryption key is protected by a passphrase. Which of the following tools is designed specifically for this purpose?

A.eCryptfs
B.OpenSSL
C.dm-crypt with LUKS
D.GnuPG (GPG)
AnswerC

dm-crypt is a Linux kernel subsystem that provides transparent disk encryption, and LUKS (Linux Unified Key Setup) is a standard format for storing key material. Together, they allow encrypting a block device with a passphrase-protected key. LUKS manages multiple passphrases and stores metadata in the device header. This is the standard tool for full disk encryption on Linux.

Why this answer

dm-crypt with LUKS is the standard Linux solution for block device encryption. dm-crypt provides the kernel-level encryption, while LUKS provides a standardized header and key management, allowing multiple passphrases to unlock the encryption key. This directly meets the requirement of encrypting a block device with a passphrase-protected key.

Exam trap

The trap here is confusing file-level encryption tools like GnuPG or eCryptfs with block-level encryption, which requires dm-crypt/LUKS for full disk encryption.

10
MCQhard

A security analyst is investigating a suspected man-in-the-middle attack against an HTTPS service. The analyst finds that the client is ignoring certificate validation errors. Which cryptographic failure is most likely occurring?

A.Lack of Perfect Forward Secrecy
B.Improper certificate chain verification
C.Weak cipher suite negotiation
D.Use of outdated TLS 1.0 protocol
AnswerB

If the client code ignores certificate validation, it fails to verify the digital signature of the certificate against trusted Root CAs. This allows any attacker to issue a fraudulent certificate for the target domain, which the client will accept as valid, thereby facilitating a successful man-in-the-middle attack scenario.

Why this answer

The failure to validate certificates allows an attacker to present a forged certificate that the client blindly trusts. This breaks the fundamental trust model of PKI, allowing an attacker to intercept, inspect, and potentially modify encrypted traffic. This is a common flaw in poorly configured internal applications where developers disable validation to bypass expired or self-signed certificate warnings, creating a significant security hole that leaves users vulnerable to eavesdropping and credential theft.

Exam trap

Candidates often select general man-in-the-middle or encryption algorithm failures, missing that the root cause specifically stems from improper validation of the certificate chain by the client application.

11
MCQhard

A financial services firm is designing a key management process for its internal certificate authority. The security architect wants a single hardware security module (HSM) cluster to protect the CA's signing key while ensuring that a compromise of one HSM appliance does not expose the key in plaintext to an attacker who gains root on that appliance. Which deployment property BEST addresses this requirement?

A.Configure the HSM cluster so the CA key is generated in and never leaves the tamper-protected boundary, with cryptographic operations performed inside the module.
B.Split the CA key using Shamir's Secret Sharing and store one share on each HSM, reconstructing the key in memory when signing is required.
C.Enable FIPS 140-3 Level 1 validation on the HSM and replicate the CA key to a standby appliance using a vendor export command.
D.Store the CA private key in an encrypted file on each HSM's local disk, protected by a passphrase entered at boot.
AnswerA

Generating the key inside the HSM and performing all signing operations within its tamper-responsive boundary means the private key is never exported in plaintext, even to a privileged host process. Root access on the appliance exposes the operating system, not the key material inside the module. This non-exportability is the defining property that satisfies the requirement and is standard practice for CA key protection.

Why this answer

Keeping the CA private key generated within and never exportable from the HSM's tamper-protected boundary ensures that even root compromise of the host operating system cannot yield plaintext key material. Signing occurs inside the module, so the key is never exposed to the host. Validation levels and secret-sharing schemes address adjacent concerns but do not prevent plaintext exposure to a privileged local attacker.

Exam trap

The trap here is treating a FIPS validation level or a secret-sharing scheme as equivalent to non-exportability, when neither prevents a root-level attacker from capturing the key in host memory.

12
MCQeasy

A junior administrator is asked to verify the integrity of a downloaded Linux distribution ISO before installing it on a production server. The vendor publishes a SHA-256 checksum and a detached PGP signature. Which action BEST confirms both that the file is intact and that it genuinely originated from the vendor?

A.Import the vendor's public key, verify the detached signature against the ISO, and confirm the signature is valid.
B.Run the ISO through an antivirus scanner and confirm no malware is detected.
C.Compute the SHA-256 hash of the ISO and compare it to the published checksum only.
D.Encrypt the ISO with the vendor's public key and confirm the operation succeeds.
AnswerA

Verifying the detached PGP signature with the vendor's public key confirms both integrity and origin: a valid signature proves the file was signed by the holder of the corresponding private key and that the content has not changed since signing. This single verification satisfies both requirements. The administrator must first obtain and trust the vendor's public key through an out-of-band channel to avoid a substituted key.

Why this answer

A valid detached PGP signature verified with the vendor's trusted public key simultaneously proves that the file content is unchanged and that it was signed by the vendor's private key. The hash comparison alone provides integrity but not origin, and encryption or antivirus scanning addresses entirely different concerns. The public key must be obtained and validated through a trusted channel.

Exam trap

The trap here is believing that matching a published checksum proves the file came from the vendor, when the checksum itself could have been altered alongside the file.

13
MCQhard

Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?

A.The RSA key length is insufficient for modern requirements
B.The private key will be stored without passphrase protection
C.The certificate will be self-signed and untrusted
D.The output file format defaults to a deprecated encoding
AnswerB

The -nodes flag explicitly disables encryption of the generated private key. This means the key is saved in cleartext, creating a significant security risk where any user or process with read access to the file can steal the identity of the server without needing to provide a password.

Why this answer

The -nodes flag instructs OpenSSL to generate a private key without a passphrase, leaving it stored in plaintext on the file system. In a production environment, this is critical because an attacker with unauthorized read access to the server's filesystem can immediately compromise the private key. Protecting private keys with a passphrase ensures that even if files are exfiltrated, the keys remain encrypted and unusable without the secret passphrase.

Exam trap

Candidates often mistake the -nodes flag for disabling network connectivity or public key generation, missing its specific role regarding private key passphrase protection.

14
MCQhard

A software vendor distributes signed firmware updates to customers. During an incident review, an analyst discovers that an attacker who obtained the vendor's code-signing private key was able to produce updates that passed signature verification on customer devices. The vendor wants to redesign the signing process so that compromise of a single signing key no longer allows an attacker to forge valid updates. Which change best achieves this goal?

A.Increase the RSA key size from 2048 to 4096 bits.
B.Require each update to be signed by a threshold of multiple independent keys.
C.Publish the firmware hashes to a public transparency log.
D.Switch the signature algorithm from RSA to ECDSA with P-256.
AnswerB

Threshold signing requires a quorum of distinct private keys, often held in separate HSMs or by separate administrators, to produce one valid signature. An attacker who compromises a single key cannot meet the threshold, so forged updates fail verification. This directly addresses the goal of making single-key compromise insufficient, and it is supported by standards such as FIPS 186-5 and common HSM quorum configurations.

Why this answer

Threshold signing distributes the signing capability across multiple independent keys so that no single compromised key can produce a valid signature. Increasing key size, changing to ECDSA, or adding a transparency log all leave a single key capable of forging updates. Only requiring a quorum of keys changes the trust model so that one stolen key is insufficient.

Exam trap

The trap here is conflating stronger cryptography with stronger key custody; a bigger key or a modern algorithm cannot protect against an attacker who already holds the private key.

Ready to test yourself?

Try a timed practice session using only Cryptography questions.