A developer must encrypt a 10 GB database backup for long-term archival.
Which AES mode provides authenticated encryption and is recommended by
NIST for this purpose?
A. AES-CBC with HMAC-SHA256
B. AES-GCM
C. AES-ECB
D. AES-CTR
Correct Answer: B - AES-GCM
RATIONALE
AES-GCM is an authenticated encryption mode providing
confidentiality and integrity in one pass, and is NIST-approved for
high-volume data. CBC with HMAC is secure but requires two keys
and separate MAC, while ECB and CTR lack authentication.
Question 2
In a Diffie-Hellman key exchange over an unauthenticated channel, an attacker
intercepts and replaces public keys. Which security property is directly
compromised?
A. Confidentiality of the shared secret
B. Integrity of the exchanged messages
C. Authentication of the parties
D. Forward secrecy of session keys
Correct Answer: C - Authentication of the parties
RATIONALE
Without authentication, DH is vulnerable to man-in-the-middle, where
the attacker impersonates each party. Confidentiality of the shared
secret is still achieved between attacker and each party, but the parties
are not authenticated to each other.
Page 2
, Question 3
A security team must store user passwords for authentication. Which approach
best mitigates offline brute-force attacks if the password database is stolen?
A. SHA-256 hashing with a unique salt per user
B. AES-256 encryption of passwords with a secret key
C. Argon2id with a unique salt and tuned memory/iterations
D. MD5 hashing with a global salt
Correct Answer: C - Argon2id with a unique salt and tuned
memory/iterations
RATIONALE
Argon2id is a memory-hard, slow hashing function designed to resist
GPU/ASIC brute-force, and is current best practice (e.g., OWASP).
SHA-256 is fast and vulnerable to brute-force; AES encryption
requires key management and is reversible; MD5 is cryptographically
broken.
Question 4
A digital signature scheme must provide non-repudiation and integrity. Which
key is used to generate the signature, and which to verify it?
A. Sign with sender's private key; verify with sender's public key
B. Sign with sender's public key; verify with sender's private key
C. Sign with a shared secret key; verify with the same key
D. Sign with recipient's public key; verify with recipient's private key
Correct Answer: A - Sign with sender's private key; verify with
sender's public key
RATIONALE
Digital signatures use the sender's private key to sign and the
corresponding public key to verify, ensuring only the private key
holder could have signed. This provides non-repudiation and integrity.
Shared-key signatures (HMAC) do not provide non-repudiation.
Page 3
, Question 5
Which statement accurately distinguishes a cryptographic hash function from a
message authentication code (MAC)?
A. A hash function uses a secret key; a MAC does not.
B. A MAC provides integrity and authentication; a hash alone does not.
C. A hash provides confidentiality; a MAC provides integrity.
D. A MAC is reversible; a hash is one-way.
Correct Answer: B - A MAC provides integrity and
authentication; a hash alone does not.
RATIONALE
A MAC (e.g., HMAC) uses a secret key to provide data integrity and
authenticity, while an unkeyed hash only provides a digest. Neither
provides confidentiality. Both are one-way; MACs are not reversible.
Question 6
A TLS 1.3 handshake uses ephemeral Diffie-Hellman. What is the primary
security benefit of using ephemeral keys over static DH?
A. It reduces computational overhead.
B. It provides forward secrecy.
C. It enables session resumption.
D. It authenticates the server.
Correct Answer: B - It provides forward secrecy.
RATIONALE
Ephemeral DH generates a new key pair per session, so compromise
of long-term keys does not compromise past session keys-this is
forward secrecy. It does not authenticate the server (certificates do)
and may add overhead, not reduce it.
Page 4