Cryptography, PKI, and Secure Communications.
Total Questions: 25 | Time Recommended: 45 minutes
SECTION A: MULTIPLE CHOICE (Questions 1–20)
Difficulty Tier 1: Foundational Recall (Questions 1–10)
Q1: Which encryption method uses the same key for both encryption and
decryption?
A) Asymmetric encryption
B) Symmetric encryption
C) Hash-based encryption
D) Quantum encryption
Answer: B
Explanation: Symmetric encryption algorithms like AES and 3DES use a single
shared secret key for both operations, requiring secure key distribution between
parties.
Q2: What is the block size and key length of the Advanced Encryption Standard
(AES)?
A) 64-bit blocks, 56-bit keys
B) 128-bit blocks, 128/192/256-bit keys
C) 64-bit blocks, 168-bit keys
D) Variable blocks, variable keys
Answer: B
Explanation: AES operates on 128-bit blocks and supports key lengths of 128,
192, or 256 bits, with AES-256 providing the highest security margin against
brute-force attacks.
Q3: Which hashing algorithm is considered cryptographically broken due to
practical collision attacks and should not be used for integrity verification?
A) SHA-256
B) SHA-3
, C) MD5
D) SHA-512
Answer: C
Explanation: MD5 has been demonstrated vulnerable to collision attacks since
2004; attackers can generate two different inputs that produce the same hash,
defeating its integrity purpose.
Q4: In a Public Key Infrastructure (PKI), which component is responsible for
issuing, renewing, and revoking digital certificates?
A) Registration Authority (RA)
B) Certificate Authority (CA)
C) Certificate Revocation List (CRL)
D) Online Certificate Status Protocol (OCSP)
Answer: B
Explanation: The Certificate Authority (CA) is the trusted root entity that signs
and issues certificates, validates identities, and maintains the certificate lifecycle
including revocation.
Q5: What is the primary security property provided by a digital signature?
A) Confidentiality
B) Availability
C) Non-repudiation
D) Obfuscation
Answer: C
Explanation: Digital signatures use the signer's private key to create a unique
cryptographic binding, proving the signer originated the message and cannot
later deny having signed it.
Q6: Which TLS version removed support for obsolete algorithms like MD5 and
SHA-1, and reduced handshake latency to a single round trip?
A) SSL 3.0
B) TLS 1.0
C) TLS 1.2