ITN 260 EXAM WITH QUESTIONS
ANSWERED CORRECTLY
Which of these is the strongest symmetric cryptographic algorithm? - Answer-Advanced
Encryption Standard
If Bob wants to send a secure message to Alice using an asymmetric cryptographic
algorithm, which key does he use to encrypt the message? - Answer-Alice's public key
Public key systems that generate random public keys that are different for each session
are called _____. - Answer-perfect forward secrecy
Which of these is NOT a characteristic of a secure hash algorithm? - Answer-Collisions
should be rare.
Which areas of a file cannot be used by steganography to hide data? - Answer-in the
directory structure of the file system
What entity calls in crypto modules to perform cryptographic tasks? - Answer-Crypto
service provider
Which trust model has multiple CAs, one of which acts as a facilitator? - Answer-Bridge
Which of the following block ciphers XORs each block of plaintext with the previous
block of ciphertext before being encrypted? - Answer-Cipher Block Chaining (CBC)
Which of the following is NOT a method for strengthening a key? - Answer-Variability
Public key infrastructure (PKI) _____. - Answer-is the management of digital certificates
Which statement is NOT true regarding hierarchical trust models? - Answer-It is
designed for use on a large scale.
Digital certificates can be used for each of these EXCEPT _____. - Answer-to verify the
authenticity of the Registration Authorizer
An entity that issues digital certificates is a _____. - Answer-Certificate Authority (CA)
A centralized directory of digital certificates is called a(n) _____. - Answer-Certificate
Repository (CR)
, Which of these is considered the strongest cryptographic transport protocol? - Answer-
TLS v1.2
A digital certificate associates _____. - Answer-the user's identity with his public key
_____ refers to a situation in which keys are managed by a third party, such as a
trusted CA. - Answer-Key escrow
_____ performs a real-time lookup of a digital certificate's status. - Answer-Online
Certificate Status Protocol (OCSP)
Which digital certificate displays the name of the entity behind the website? - Answer-
Extended Validation (EV) Certificate
What is a value that can be used to ensure that hashed plaintext will not consistently
result in the same digest? - Answer-salt
The strongest technology that would assure Alice that Bob is the sender of a message
is a(n) _____. - Answer-digital certificate
_____ are symmetric keys to encrypt and decrypt information exchanged during the
session and to verify its integrity. - Answer-Session keys
A(n) _____ is a published set of rules that govern the operation of a PKI. - Answer-
certificate policy (CP)
Which of these is NOT part of the certificate life cycle? - Answer-authorization
_____ is a protocol for securely accessing a remote computer. - Answer-Secure Shell
(SSH)
What kind of attack is performed by an attacker who takes advantage of the inadvertent
and unauthorized access built through three succeeding systems that all trust one
another? - Answer-privilege escalation
What is the basis of an SQL injection attack? - Answer-to insert SQL statements
through unfiltered user input
Which statement is correct regarding why traditional network security devices cannot be
used to block web application attacks? - Answer-Traditional network security devices
ignore the content of HTTP traffic, which is the vehicle of web application attacks.
Attackers who register domain names that are similar to legitimate domain names are
performing _____. - Answer-URL hijacking
ANSWERED CORRECTLY
Which of these is the strongest symmetric cryptographic algorithm? - Answer-Advanced
Encryption Standard
If Bob wants to send a secure message to Alice using an asymmetric cryptographic
algorithm, which key does he use to encrypt the message? - Answer-Alice's public key
Public key systems that generate random public keys that are different for each session
are called _____. - Answer-perfect forward secrecy
Which of these is NOT a characteristic of a secure hash algorithm? - Answer-Collisions
should be rare.
Which areas of a file cannot be used by steganography to hide data? - Answer-in the
directory structure of the file system
What entity calls in crypto modules to perform cryptographic tasks? - Answer-Crypto
service provider
Which trust model has multiple CAs, one of which acts as a facilitator? - Answer-Bridge
Which of the following block ciphers XORs each block of plaintext with the previous
block of ciphertext before being encrypted? - Answer-Cipher Block Chaining (CBC)
Which of the following is NOT a method for strengthening a key? - Answer-Variability
Public key infrastructure (PKI) _____. - Answer-is the management of digital certificates
Which statement is NOT true regarding hierarchical trust models? - Answer-It is
designed for use on a large scale.
Digital certificates can be used for each of these EXCEPT _____. - Answer-to verify the
authenticity of the Registration Authorizer
An entity that issues digital certificates is a _____. - Answer-Certificate Authority (CA)
A centralized directory of digital certificates is called a(n) _____. - Answer-Certificate
Repository (CR)
, Which of these is considered the strongest cryptographic transport protocol? - Answer-
TLS v1.2
A digital certificate associates _____. - Answer-the user's identity with his public key
_____ refers to a situation in which keys are managed by a third party, such as a
trusted CA. - Answer-Key escrow
_____ performs a real-time lookup of a digital certificate's status. - Answer-Online
Certificate Status Protocol (OCSP)
Which digital certificate displays the name of the entity behind the website? - Answer-
Extended Validation (EV) Certificate
What is a value that can be used to ensure that hashed plaintext will not consistently
result in the same digest? - Answer-salt
The strongest technology that would assure Alice that Bob is the sender of a message
is a(n) _____. - Answer-digital certificate
_____ are symmetric keys to encrypt and decrypt information exchanged during the
session and to verify its integrity. - Answer-Session keys
A(n) _____ is a published set of rules that govern the operation of a PKI. - Answer-
certificate policy (CP)
Which of these is NOT part of the certificate life cycle? - Answer-authorization
_____ is a protocol for securely accessing a remote computer. - Answer-Secure Shell
(SSH)
What kind of attack is performed by an attacker who takes advantage of the inadvertent
and unauthorized access built through three succeeding systems that all trust one
another? - Answer-privilege escalation
What is the basis of an SQL injection attack? - Answer-to insert SQL statements
through unfiltered user input
Which statement is correct regarding why traditional network security devices cannot be
used to block web application attacks? - Answer-Traditional network security devices
ignore the content of HTTP traffic, which is the vehicle of web application attacks.
Attackers who register domain names that are similar to legitimate domain names are
performing _____. - Answer-URL hijacking