Intro to Cryptography C839 OA and PA
Comprehensive Prep Test Questions and
Correct Answers/ WGU D334 OA and PA
Prep/ WGU C839 Objective Assessment
Prep Bundle
TEST BANK 1: FOUNDATIONAL PRINCIPLES & CLASSICAL CRYPTOGRAPHY
(Questions 1-50)
1. According to Kerckhoffs's Principle, what should the security of a
cryptosystem depend on?
• A. The secrecy of the encryption algorithm
• B. The complexity of the mathematics
• C. The secrecy of the key
• D. The length of the plaintext
Rationale: Kerckhoffs's Principle states that a cryptosystem should be secure even
if everything about the system, except the key, is public. Security through
obscurity (hiding the algorithm) is a fatal flaw because reverse engineering or
leaks expose the system entirely .
2. A cryptanalyst finds a repeated sequence of characters "KXD" in a ciphertext
18 characters apart, and another sequence "LGH" 36 characters apart. Which
classical cryptanalysis technique is being applied?
• A. Frequency Analysis
• B. Index of Coincidence
• C. Kasiski Examination
• D. Meet-in-the-Middle
,Rationale: The Kasiski Examination looks for repeating strings in the ciphertext to
guess the length of the keyword in polyalphabetic ciphers like Vigenère. The
greatest common divisor (GCD) of the distances (18, 36) suggests the key length .
3. Why is the One-Time Pad (OTP) considered theoretically unbreakable?
• A. It uses complex mathematical formulas
• B. The key is truly random, as long as the message, and never reused
• C. It uses a public key infrastructure
• D. It requires a digital signature
Rationale: Claude Shannon proved the OTP provides perfect secrecy. However,
the practical limitations (key distribution, key length, and single use) make it
infeasible for most modern applications .
4. What was the major cryptographic flaw in the Enigma machine?
• A. It used a mono-alphabetic substitution
• B. It could not encrypt numbers
• C. A letter could never be encrypted to itself
• D. The key was only 40 bits long
Rationale: The Enigma machine's reflector ensured that no plaintext letter could
ever map to the same ciphertext letter. This weakness provided a "hook" for
cryptanalysts like Alan Turing to deduce the plugboard settings .
5. What is the primary purpose of the "diffusion" property in a secure cipher?
• A. To obscure the relationship between the key and the ciphertext
• B. To spread the influence of a single plaintext bit over many ciphertext
bits
• C. To compress the data for faster transmission
• D. To ensure the key is exactly the same length as the message
Rationale: Claude Shannon identified confusion (making key-ciphertext
relationship complex) and diffusion (spreading plaintext influence). The Avalanche
Effect—changing one bit changes ~half the output bits—is a measure of good
diffusion .
6. Which cipher uses a 5x5 matrix (combining I and J) for encryption?
, • A. Bifid
• B. Playfair
• C. Caesar
• D. Vigenère
Rationale: The Playfair cipher is a digraph substitution cipher that encrypts pairs
of letters using a 5x5 grid filled with a keyword .
7. Shifting each letter in the alphabet a fixed number of spaces is an example of
what?
• A. Mono-alphabetic substitution
• B. Polyalphabetic substitution
• C. Transposition
• D. Steganography
Rationale: The Caesar cipher uses a single fixed shift value, making it a mono-
alphabetic (single alphabet) substitution cipher .
8. What is the most commonly used format for certificates?
• A. PEM
• B. DER
• C. X.509 v3
• D. PKCS #12
Rationale: X.509 v3 is the most commonly used format for certificates in PKI
environments .
9. What is referenced to determine if a certificate has been revoked?
• A. CA
• B. Certificate Revocation List (CRL)
• C. RFC
• D. RA
Rationale: A Certificate Revocation List (CRL) is used to determine if a certificate
has been revoked by the Certificate Authority .
10. What does the OCSP protocol provide?
, • A. A list of revoked certificates
• B. A real-time protocol for verifying certificates
• C. A method for encrypting emails
• D. A secure key exchange protocol
Rationale: Online Certificate Status Protocol (OCSP) provides real-time certificate
verification, offering an alternative to downloading and parsing CRLs .
11. Which encryption standard uses the same key to encrypt and decrypt
messages?
• A. Symmetric encryption
• B. Asymmetric encryption
• C. Hash function
• D. Digital signature
Rationale: Symmetric encryption uses the same key for both encryption and
decryption operations .
12. Which algorithm is designated as a Type 2 product by the National Security
Agency (NSA)?
• A. AES
• B. Skipjack
• C. DES
• D. RSA
Rationale: Skipjack is designated as a Type 2 product by the NSA .
13. What needs to be installed on end users' computers to allow them to trust
applications that have been digitally signed by the developer?
• A. Sender's (developer's) public key
• B. Sender's private key
• C. Receiver's public key
• D. Receiver's private key
Rationale: Digital signatures are verified using the sender's (developer's) public
key. Without access to the sender's public key, the signature cannot be validated .
Comprehensive Prep Test Questions and
Correct Answers/ WGU D334 OA and PA
Prep/ WGU C839 Objective Assessment
Prep Bundle
TEST BANK 1: FOUNDATIONAL PRINCIPLES & CLASSICAL CRYPTOGRAPHY
(Questions 1-50)
1. According to Kerckhoffs's Principle, what should the security of a
cryptosystem depend on?
• A. The secrecy of the encryption algorithm
• B. The complexity of the mathematics
• C. The secrecy of the key
• D. The length of the plaintext
Rationale: Kerckhoffs's Principle states that a cryptosystem should be secure even
if everything about the system, except the key, is public. Security through
obscurity (hiding the algorithm) is a fatal flaw because reverse engineering or
leaks expose the system entirely .
2. A cryptanalyst finds a repeated sequence of characters "KXD" in a ciphertext
18 characters apart, and another sequence "LGH" 36 characters apart. Which
classical cryptanalysis technique is being applied?
• A. Frequency Analysis
• B. Index of Coincidence
• C. Kasiski Examination
• D. Meet-in-the-Middle
,Rationale: The Kasiski Examination looks for repeating strings in the ciphertext to
guess the length of the keyword in polyalphabetic ciphers like Vigenère. The
greatest common divisor (GCD) of the distances (18, 36) suggests the key length .
3. Why is the One-Time Pad (OTP) considered theoretically unbreakable?
• A. It uses complex mathematical formulas
• B. The key is truly random, as long as the message, and never reused
• C. It uses a public key infrastructure
• D. It requires a digital signature
Rationale: Claude Shannon proved the OTP provides perfect secrecy. However,
the practical limitations (key distribution, key length, and single use) make it
infeasible for most modern applications .
4. What was the major cryptographic flaw in the Enigma machine?
• A. It used a mono-alphabetic substitution
• B. It could not encrypt numbers
• C. A letter could never be encrypted to itself
• D. The key was only 40 bits long
Rationale: The Enigma machine's reflector ensured that no plaintext letter could
ever map to the same ciphertext letter. This weakness provided a "hook" for
cryptanalysts like Alan Turing to deduce the plugboard settings .
5. What is the primary purpose of the "diffusion" property in a secure cipher?
• A. To obscure the relationship between the key and the ciphertext
• B. To spread the influence of a single plaintext bit over many ciphertext
bits
• C. To compress the data for faster transmission
• D. To ensure the key is exactly the same length as the message
Rationale: Claude Shannon identified confusion (making key-ciphertext
relationship complex) and diffusion (spreading plaintext influence). The Avalanche
Effect—changing one bit changes ~half the output bits—is a measure of good
diffusion .
6. Which cipher uses a 5x5 matrix (combining I and J) for encryption?
, • A. Bifid
• B. Playfair
• C. Caesar
• D. Vigenère
Rationale: The Playfair cipher is a digraph substitution cipher that encrypts pairs
of letters using a 5x5 grid filled with a keyword .
7. Shifting each letter in the alphabet a fixed number of spaces is an example of
what?
• A. Mono-alphabetic substitution
• B. Polyalphabetic substitution
• C. Transposition
• D. Steganography
Rationale: The Caesar cipher uses a single fixed shift value, making it a mono-
alphabetic (single alphabet) substitution cipher .
8. What is the most commonly used format for certificates?
• A. PEM
• B. DER
• C. X.509 v3
• D. PKCS #12
Rationale: X.509 v3 is the most commonly used format for certificates in PKI
environments .
9. What is referenced to determine if a certificate has been revoked?
• A. CA
• B. Certificate Revocation List (CRL)
• C. RFC
• D. RA
Rationale: A Certificate Revocation List (CRL) is used to determine if a certificate
has been revoked by the Certificate Authority .
10. What does the OCSP protocol provide?
, • A. A list of revoked certificates
• B. A real-time protocol for verifying certificates
• C. A method for encrypting emails
• D. A secure key exchange protocol
Rationale: Online Certificate Status Protocol (OCSP) provides real-time certificate
verification, offering an alternative to downloading and parsing CRLs .
11. Which encryption standard uses the same key to encrypt and decrypt
messages?
• A. Symmetric encryption
• B. Asymmetric encryption
• C. Hash function
• D. Digital signature
Rationale: Symmetric encryption uses the same key for both encryption and
decryption operations .
12. Which algorithm is designated as a Type 2 product by the National Security
Agency (NSA)?
• A. AES
• B. Skipjack
• C. DES
• D. RSA
Rationale: Skipjack is designated as a Type 2 product by the NSA .
13. What needs to be installed on end users' computers to allow them to trust
applications that have been digitally signed by the developer?
• A. Sender's (developer's) public key
• B. Sender's private key
• C. Receiver's public key
• D. Receiver's private key
Rationale: Digital signatures are verified using the sender's (developer's) public
key. Without access to the sender's public key, the signature cannot be validated .