A security architect must select a block cipher mode for encrypting a large
database where random read access to any record is required, and each record
is exactly one block. Which mode is most appropriate?
A. Cipher Block Chaining (CBC)
B. Electronic Codebook (ECB)
C. Counter (CTR)
D. Cipher Feedback (CFB)
Correct Answer: C - Counter (CTR)
RATIONALE
CTR mode allows random access because each block is encrypted
independently using a counter, and it does not require padding. CBC,
CFB, and ECB require sequential processing or have security
weaknesses for this use case. ECB especially leaks patterns and is not
suitable for database encryption.
Question 2
In the context of RSA, which mathematical property ensures that decryption
recovers the original message when using the standard key generation?
A. The totient function (n) is prime.
B. The public exponent e is coprime to (n).
C. The modulus n is a prime number.
D. The private exponent d is equal to e^{-1} mod n.
Correct Answer: B - The public exponent e is coprime to (n).
RATIONALE
For RSA to work, e must be coprime to (n) so that a modular inverse d
exists. This ensures that (m^e)^d m mod n. The modulus n is
composite (product of two primes), and d is the inverse of e modulo
(n), not modulo n.
Page 2
, Question 3
Which of the following best describes the security provided by a cryptographic
hash function when used in a digital signature scheme?
A. It ensures confidentiality of the message.
B. It provides non-repudiation by encrypting the message digest.
C. It compresses the message to a fixed-size digest, enabling efficient
signing and ensuring integrity.
D. It guarantees that the message cannot be altered without detection,
even if the private key is compromised.
Correct Answer: C - It compresses the message to a fixed-size
digest, enabling efficient signing and ensuring integrity.
RATIONALE
Hash functions compress arbitrary-length messages into fixed-length
digests, which are then signed, providing integrity and efficiency.
They do not provide confidentiality, and non-repudiation comes from
the signature, not the hash alone. If the private key is compromised,
integrity is not guaranteed.
Question 4
A company uses Diffie-Hellman key exchange over an unauthenticated
channel. An attacker actively intercepts and replaces public keys. Which
security property is violated?
A. Confidentiality of the shared secret
B. Integrity of the key exchange
C. Authentication of the parties
D. Forward secrecy
Correct Answer: C - Authentication of the parties
Page 3
, RATIONALE
Diffie-Hellman without authentication is vulnerable to
man-in-the-middle attacks, where the attacker establishes separate
keys with each party. This violates authentication, as parties cannot
verify each other's identity. Confidentiality and integrity of the shared
secret are compromised as a result, but the root issue is lack of
authentication.
Question 5
Which of the following statements about AES key expansion is correct?
A. The key schedule uses the same algorithm for all key sizes.
B. The number of rounds is fixed at 10 regardless of key size.
C. The key expansion for AES-256 produces 15 round keys.
D. The key schedule is invertible to recover the original key from round
keys.
Correct Answer: A - The key schedule uses the same algorithm
for all key sizes.
RATIONALE
AES key expansion uses a consistent algorithm (with variations in the
number of words) for 128, 192, and 256-bit keys. The number of
rounds varies (10, 12, 14), and AES-256 produces 15 round keys
(including initial). The key schedule is not designed to be invertible to
recover the original key.
Question 6
In a PKI, a certificate revocation list (CRL) is used to:
A. List all valid certificates issued by the CA.
B. Provide a real-time status of certificate validity.
C. Identify certificates that have been revoked before their expiration
date.
D. Store the private keys of revoked certificates.
Page 4