CISA COMPREHENSIVE EXAM 2026 QUESTIONS AND
ANSWERS GRADED A+
✔✔Cipher - ✔✔is an algorithm for performing encryption (and the reverse, decryption)
— a series of well-defined steps that can be followed as a procedure. The encrypting
procedure is varied depending on the key, which changes the detailed operation of the
algorithm. A key must be selected before using a cipher to encrypt a message.
✔✔Symmetric Key Algorithms - ✔✔In a symmetric key algorithm (e.g., DES and AES),
the sender and receiver must have a shared key set up in advance and kept secret from
all other parties; the sender uses this key for encryption, and the receiver uses the
same key for decryption. (block ciphers, or stream ciphers)
✔✔Asymmetric Key Algorithms - ✔✔In an asymmetric key algorithm (e.g., RSA), there
are two separate keys: a public key is published and enables any sender to perform
encryption, while a private key is kept secret by the receiver and enables him to perform
decryption. (PKI)
✔✔Certificate Authority (CA) - ✔✔issues and manages security credentials and public
keys for message encryption. This includes revocation and suspension and issuance
and distribution of the subscriber certificate. Generation and distribution of the CA public
key is also part of the CA key life cycle management process and, as such, cannot be
delegated.
✔✔Registration Authority (RA) - ✔✔verifies user requests for a digital cert. and tells the
CA to issue it. Establishing a link between the requesting entity and its public key is a
function of a registration authority.
✔✔A public key infrastructure consists of - ✔✔• A certificate authority (CA) that issues
and verifies digital certificate. A certificate includes the public key or information about
the public key
• A registration authority (RA) that acts as the verifier for the certificate authority before
a digital certificate is issued to a requestor
• One or more directories where the certificates (with their public keys) are held
• A certificate management system
✔✔Identification - ✔✔the process of identifying a user (e.g. unique user name).
✔✔Authentication - ✔✔the process of identification verification.
✔✔Authorization - ✔✔the process of determining whether a valid identifier is authorized
to access a service.
✔✔Hashing - ✔✔works one way. By applying a hashing algorithm to a message, a
message hash/digest is created. If the same hashing algorithm is applied to the
, message digest, it will not result in the original message. As such, hashing is
irreversible, while encryption is reversible. This is the basic difference between hashing
and encryption. Hashing creates an output that is smaller than the original message,
and encryption creates an output of the same length as the original message. Hashing
is used to verify the integrity of the message and does not address security. The same
hashing algorithm is used at the sending and receiving ends to generate and verify the
massage hash/digest. Encryption will not necessarily use the same algorithm at the
sending and receiving end to encrypt and decrypt.
✔✔Encapsulation or tunneling - ✔✔is a technique used to carry the traffic of one
protocol over a network that does not support that protocol directly. The original packet
is wrapped in another packet.
✔✔Secure Sockets Layer (SSL) - ✔✔a protocol developed by Netscape for transmitting
private documents via the Internet. SSL uses a cryptographic system that uses two keys
to encrypt data − a public key known to everyone and a private or secret key known
only to the recipient of the message (PKI).
✔✔S/HTTP - ✔✔An extension to the HTTP protocol to support sending data securely
over the World Wide Web. Whereas SSL is designed to establish a secure connection
between two computers, S-HTTP is designed to send individual messages securely.
✔✔IP Security (IPSec) - ✔✔a set of protocols developed by the IETF to support secure
exchange of packets at the IP layer. IPsec has been deployed widely to implement
Virtual Private Networks (VPNs). Operates at the network layer.
✔✔IPsec supports two encryption modes - ✔✔• Transport mode encrypts only the data
portion (payload) of each packet, but leaves the header untouched.
• The more secure Tunnel mode encrypts both the header and the payload. On the
receiving side, an IPSec-compliant device decrypts each packet.
✔✔SSH - ✔✔Secure Shell is a program to log into another computer over a network, to
execute commands in a remote machine, and to move files from one machine to
another. It provides strong authentication and secure communications over insecure
channels (Application Layer).
✔✔S/MIME - ✔✔Secure e-mail protocol that supports encryption of messages.
✔✔Secure Electronic Transaction (SET) - ✔✔is a standard that will enable secure credit
card transactions on the Internet. SET has been endorsed by virtually all the major
players in the electronic commerce arena (PKI, Application Layer).
✔✔A digital certificate - ✔✔is an electronic "credit card" that establishes your
credentials when doing business or other transactions on the Web. It is issued by a
certification authority. It contains your name, a serial number, expiration dates, a copy of
ANSWERS GRADED A+
✔✔Cipher - ✔✔is an algorithm for performing encryption (and the reverse, decryption)
— a series of well-defined steps that can be followed as a procedure. The encrypting
procedure is varied depending on the key, which changes the detailed operation of the
algorithm. A key must be selected before using a cipher to encrypt a message.
✔✔Symmetric Key Algorithms - ✔✔In a symmetric key algorithm (e.g., DES and AES),
the sender and receiver must have a shared key set up in advance and kept secret from
all other parties; the sender uses this key for encryption, and the receiver uses the
same key for decryption. (block ciphers, or stream ciphers)
✔✔Asymmetric Key Algorithms - ✔✔In an asymmetric key algorithm (e.g., RSA), there
are two separate keys: a public key is published and enables any sender to perform
encryption, while a private key is kept secret by the receiver and enables him to perform
decryption. (PKI)
✔✔Certificate Authority (CA) - ✔✔issues and manages security credentials and public
keys for message encryption. This includes revocation and suspension and issuance
and distribution of the subscriber certificate. Generation and distribution of the CA public
key is also part of the CA key life cycle management process and, as such, cannot be
delegated.
✔✔Registration Authority (RA) - ✔✔verifies user requests for a digital cert. and tells the
CA to issue it. Establishing a link between the requesting entity and its public key is a
function of a registration authority.
✔✔A public key infrastructure consists of - ✔✔• A certificate authority (CA) that issues
and verifies digital certificate. A certificate includes the public key or information about
the public key
• A registration authority (RA) that acts as the verifier for the certificate authority before
a digital certificate is issued to a requestor
• One or more directories where the certificates (with their public keys) are held
• A certificate management system
✔✔Identification - ✔✔the process of identifying a user (e.g. unique user name).
✔✔Authentication - ✔✔the process of identification verification.
✔✔Authorization - ✔✔the process of determining whether a valid identifier is authorized
to access a service.
✔✔Hashing - ✔✔works one way. By applying a hashing algorithm to a message, a
message hash/digest is created. If the same hashing algorithm is applied to the
, message digest, it will not result in the original message. As such, hashing is
irreversible, while encryption is reversible. This is the basic difference between hashing
and encryption. Hashing creates an output that is smaller than the original message,
and encryption creates an output of the same length as the original message. Hashing
is used to verify the integrity of the message and does not address security. The same
hashing algorithm is used at the sending and receiving ends to generate and verify the
massage hash/digest. Encryption will not necessarily use the same algorithm at the
sending and receiving end to encrypt and decrypt.
✔✔Encapsulation or tunneling - ✔✔is a technique used to carry the traffic of one
protocol over a network that does not support that protocol directly. The original packet
is wrapped in another packet.
✔✔Secure Sockets Layer (SSL) - ✔✔a protocol developed by Netscape for transmitting
private documents via the Internet. SSL uses a cryptographic system that uses two keys
to encrypt data − a public key known to everyone and a private or secret key known
only to the recipient of the message (PKI).
✔✔S/HTTP - ✔✔An extension to the HTTP protocol to support sending data securely
over the World Wide Web. Whereas SSL is designed to establish a secure connection
between two computers, S-HTTP is designed to send individual messages securely.
✔✔IP Security (IPSec) - ✔✔a set of protocols developed by the IETF to support secure
exchange of packets at the IP layer. IPsec has been deployed widely to implement
Virtual Private Networks (VPNs). Operates at the network layer.
✔✔IPsec supports two encryption modes - ✔✔• Transport mode encrypts only the data
portion (payload) of each packet, but leaves the header untouched.
• The more secure Tunnel mode encrypts both the header and the payload. On the
receiving side, an IPSec-compliant device decrypts each packet.
✔✔SSH - ✔✔Secure Shell is a program to log into another computer over a network, to
execute commands in a remote machine, and to move files from one machine to
another. It provides strong authentication and secure communications over insecure
channels (Application Layer).
✔✔S/MIME - ✔✔Secure e-mail protocol that supports encryption of messages.
✔✔Secure Electronic Transaction (SET) - ✔✔is a standard that will enable secure credit
card transactions on the Internet. SET has been endorsed by virtually all the major
players in the electronic commerce arena (PKI, Application Layer).
✔✔A digital certificate - ✔✔is an electronic "credit card" that establishes your
credentials when doing business or other transactions on the Web. It is issued by a
certification authority. It contains your name, a serial number, expiration dates, a copy of