A security team must encrypt a 10 GB database backup for long-term archival.
The requirement is confidentiality and integrity with minimal performance
overhead. Which combination of algorithms is most appropriate?
A. AES-256-GCM for encryption and authentication
B. RSA-4096 for encryption and SHA-256 for integrity
C. 3DES for encryption and HMAC-SHA1 for integrity
D. ChaCha20 for encryption and MD5 for integrity
Correct Answer: A - AES-256-GCM for encryption and
authentication
RATIONALE
AES-256-GCM provides authenticated encryption with high
performance and strong security, ideal for large data. RSA is too slow
for bulk data, 3DES is deprecated, and MD5 is cryptographically
broken.
Question 2
In a Diffie-Hellman key exchange, an attacker intercepts and replaces public
keys to establish separate shared secrets with each party. Which property of the
exchange is compromised?
A. Confidentiality of the shared secret
B. Authentication of the parties
C. Integrity of the transmitted messages
D. Forward secrecy of session keys
Correct Answer: B - Authentication of the parties
Page 2
, RATIONALE
This is a man-in-the-middle attack, which exploits the lack of
authentication in plain Diffie-Hellman. The shared secret remains
confidential to the attacker, but parties are not authenticated. Integrity
and forward secrecy are not directly compromised.
Question 3
A digital signature scheme uses RSA with PKCS#1 v1.5 padding. Which
attack is most feasible if the same message is signed with two different but
related hash functions?
A. Chosen-prefix collision attack
B. Length extension attack
C. Bleichenbacher's padding oracle attack
D. Fault injection attack
Correct Answer: C - Bleichenbacher's padding oracle attack
RATIONALE
Bleichenbacher's attack exploits PKCS#1 v1.5 padding in RSA
signatures when an oracle reveals padding validity. Related hash
functions do not directly enable chosen-prefix collisions or length
extension in this context.
Question 4
Which statement accurately describes the security of SHA-256 against
collision resistance compared to SHA-1?
A. SHA-256 is vulnerable to collision attacks with complexity 2^80,
similar to SHA-1.
B. SHA-256 provides 128-bit collision resistance, while SHA-1 provides
only 80-bit.
C. SHA-256 is broken, but SHA-1 remains secure for digital signatures.
D. Both SHA-256 and SHA-1 have identical collision resistance.
Page 3
, Correct Answer: B - SHA-256 provides 128-bit collision
resistance, while SHA-1 provides only 80-bit.
RATIONALE
SHA-256 offers 128-bit collision resistance due to its 256-bit output,
while SHA-1's 160-bit output gives only 80-bit resistance and is
broken. The other options misstate the security levels.
Question 5
A company uses a certificate authority (CA) that issues certificates with a
validity period of 10 years. What is the primary security risk of this practice?
A. Increased vulnerability to key compromise
B. Higher computational cost for revocation checks
C. Incompatibility with modern browsers
D. Reduced entropy in key generation
Correct Answer: A - Increased vulnerability to key compromise
RATIONALE
Long validity periods increase the window during which a
compromised key can be exploited. Revocation mechanisms exist but
are not the primary risk. Browser compatibility and entropy are not
directly affected by validity period.
Question 6
In a TLS 1.3 handshake, which key exchange mechanism provides forward
secrecy by default?
A. RSA key transport
B. Ephemeral Diffie-Hellman (DHE)
C. Static Diffie-Hellman
D. Pre-shared keys (PSK)
Correct Answer: B - Ephemeral Diffie-Hellman (DHE)
Page 4