1. An organization is implementing a new authentication system that allows users to log in once to access multiple independent software systems without re-entering their credentials. This system relies on a central identity provider and security tokens. What is this authentication concept called?
Access Controls
A.Biometric authentication
B.Single Sign-On (SSO)
C.Federated identity management
D.Multi-factor authentication (MFA)
Show answerAnswer
B. Single Sign-On (SSO)
Single Sign-On (SSO) is an authentication scheme that allows a user to log in with a single ID and password to gain access to a connected system or systems without using different usernames or passwords.
2. A cryptocurrency project aims to use a hashing algorithm that is resistant to quantum computer attacks. The developers are concerned that traditional hash functions might eventually be vulnerable to quantum algorithms that could find collisions more efficiently. Which characteristic is primarily sought in a post-quantum cryptographic hashing algorithm for this purpose?
Cryptography
A.Pre-image resistance against Grover's algorithm
B.Resistance to quantum collision-finding algorithms
C.Collision resistance against Shor's algorithm
D.Second pre-image resistance against quantum parallelism
Show answerAnswer
B. Resistance to quantum collision-finding algorithms
The primary concern for hashing algorithms in a quantum computing context is their collision resistance. While Grover's algorithm can speed up pre-image attacks, quantum algorithms like those based on the birthday paradox (e.g., in a quantum search) can find collisions in hash functions much faster than classical methods. Therefore, a post-quantum hash needs to specifically resist quantum collision-finding.
3. A security engineer is evaluating different cryptographic algorithms for securing data in transit across a high-speed network. The primary concern is maintaining confidentiality and integrity with minimal latency. Which of the following cryptographic primitives, when correctly implemented, offers both confidentiality and integrity in a single operation?
Cryptography
A.RSA
B.AES-GCM
C.AES-CBC
D.SHA-256
Show answerAnswer
B. AES-GCM
AES-GCM (Galois/Counter Mode) is an authenticated encryption mode. It provides both confidentiality (encryption) and authenticity/integrity (via a Message Authentication Code or MAC) in a single, efficient operation, making it ideal for high-speed network communication.
4. A software development team is implementing a feature that requires encrypting small, fixed-size data blocks (e.g., credit card numbers) before storing them in a database. They are considering using AES in Electronic Codebook (ECB) mode. What is the PRIMARY security concern with using AES-ECB for this purpose, especially if the same data blocks might appear multiple times?
Cryptography
A.It is computationally intensive and slow for small data blocks.
B.It requires a complex key management system, making implementation difficult.
C.It is susceptible to replay attacks due to lack of initialization vector.
D.It does not hide data patterns, as identical plaintext blocks produce identical ciphertext blocks.
Show answerAnswer
D. It does not hide data patterns, as identical plaintext blocks produce identical ciphertext blocks.
ECB mode encrypts each block independently using the same key. This means that identical plaintext blocks will always produce identical ciphertext blocks. For data like credit card numbers, which might repeat or have common patterns (e.g., leading digits), this reveals patterns in the encrypted data, making it vulnerable to analysis.
5. A company is implementing a Public Key Infrastructure (PKI) to secure its internal communications. As part of this implementation, a server is designated to issue, revoke, and manage digital certificates. What role does this server fulfill within the PKI?
Cryptography
A.Certificate Authority (CA)
B.Registration Authority (RA)
C.Certificate Repository (CR)
D.Validation Authority (VA)
Show answerAnswer
A. Certificate Authority (CA)
The Certificate Authority (CA) is the trusted entity responsible for issuing, revoking, and managing digital certificates within a PKI.
6. A system administrator needs to securely exchange a symmetric encryption key with a remote user over an insecure channel without prior shared secrets. Which cryptographic protocol is commonly used for this purpose?
Cryptography
A.MD5 (Message-Digest Algorithm 5)
B.AES (Advanced Encryption Standard)
C.RSA (Rivest–Shamir–Adleman)
D.Diffie-Hellman
Show answerAnswer
D. Diffie-Hellman
Diffie-Hellman is a key exchange protocol that allows two parties to establish a shared secret key over an insecure communication channel without prior shared secrets.
7. A financial institution requires its customers to use a username and password, along with a one-time code sent to their registered mobile device, to access their online banking portal. What type of authentication is being used?
Access Controls
A.Multi-factor authentication (MFA)
B.Biometric authentication
C.Federated authentication
D.Single-factor authentication
Show answerAnswer
A. Multi-factor authentication (MFA)
Multi-factor authentication (MFA) requires a user to present two or more different authentication factors. In this case, 'something you know' (username/password) and 'something you have' (mobile device receiving a one-time code) are used.
8. A system uses a custom block cipher in Electronic Codebook (ECB) mode to encrypt sensitive image files. A security audit reveals that while the encryption works, distinct patterns from the original image are still visible in the encrypted output. What is the fundamental reason for this vulnerability?
Cryptography
A.ECB mode encrypts identical plaintext blocks into identical ciphertext blocks
B.Lack of a strong key derivation function
C.Insufficient key length of the block cipher
D.The absence of a digital certificate for key exchange
Show answerAnswer
A. ECB mode encrypts identical plaintext blocks into identical ciphertext blocks
Electronic Codebook (ECB) mode encrypts each block of plaintext independently. If two plaintext blocks are identical, they will produce identical ciphertext blocks. In images, areas of uniform color or repeating patterns will result in repeating ciphertext blocks, revealing patterns in the encrypted output, thereby compromising confidentiality.
9. An organization is implementing a new system where access to highly confidential documents is granted based on a combination of the user's security clearance level, the document's classification, the user's department, and the time of day. For example, a 'Top Secret' document can only be accessed by a 'Top Secret' cleared user from the 'Research' department between 9 AM and 5 PM. Which advanced authorization mechanism is best suited for this scenario?
Access Controls
A.Attribute-Based Access Control (ABAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
Show answerAnswer
A. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is designed for highly granular and dynamic authorization decisions based on multiple attributes of the subject (user's clearance, department), the object (document classification), and the environment (time of day). This flexibility is ideal for complex, context-aware access policies.
10. A large e-commerce company is implementing a new customer identity management system. They want to allow customers to use their existing social media accounts (e.g., Google, Facebook) to sign up and log in, rather than creating new credentials. Which identity and access management (IAM) concept is being implemented?
Access Controls
A.Privileged Access Management (PAM)
B.Decentralized Identity Management
C.Federated Identity Management
D.Centralized Identity Management
Show answerAnswer
C. Federated Identity Management
Federated Identity Management allows users to authenticate with one identity provider (like Google or Facebook) and gain access to resources in other service providers without re-authenticating. This is precisely what the e-commerce company is trying to achieve.
11. A system administrator is configuring a new file server. They decide that instead of assigning individual permissions to each user, they will create groups based on departments (e.g., 'Finance', 'HR', 'IT') and assign permissions to these groups. Users will then be added to the appropriate department group. Which access control model is this administrator implementing?
Access Controls
A.Role-Based Access Control (RBAC)
B.Mandatory Access Control (MAC)
C.Rule-Based Access Control
D.Discretionary Access Control (DAC)
Show answerAnswer
A. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns permissions to roles, and then users are assigned to those roles. In this scenario, 'department groups' function as roles, and permissions are assigned to these groups, not directly to individual users.
12. A small business is implementing a secure communication channel for its online transactions. They are considering a cryptographic algorithm that offers both confidentiality and integrity for streamed data, where data is processed bit by bit or byte by byte. Which of the following best describes such an algorithm?
Cryptography
A.Block Cipher
B.Asymmetric Algorithm
C.Stream Cipher
D.Hash Function
Show answerAnswer
C. Stream Cipher
A stream cipher encrypts data continuously, bit by bit or byte by byte, making it suitable for streaming data. It maintains a state that changes with each encryption operation, unlike block ciphers.
13. A security architect is designing a system for secure communication between two IoT devices over an unreliable network. They need a cryptographic primitive that provides both data confidentiality and data integrity, while also allowing for efficient processing on resource-constrained devices. Which type of cryptographic algorithm is best suited for this combined requirement?
Cryptography
A.Symmetric-key block cipher with a separate hashing algorithm
B.Authenticated Encryption with Associated Data (AEAD)
C.Digital signature algorithm
D.Asymmetric-key encryption
Show answerAnswer
B. Authenticated Encryption with Associated Data (AEAD)
AEAD modes (like GCM or CCM) combine encryption for confidentiality and message authentication codes (MACs) for integrity and authenticity into a single, efficient cryptographic primitive. This avoids the complexities and potential pitfalls of 'encrypt-then-MAC' or 'MAC-then-encrypt' schemes, making it ideal for resource-constrained devices needing both confidentiality and integrity.
14. A system administrator is configuring a new web server to use HTTPS. During the setup, they are prompted to select a cipher suite that ensures a unique session key is generated for every new connection, even if the server's long-term private key is compromised in the future. Which property does this requirement describe?
Cryptography
A.Key Separation
B.Perfect Forward Secrecy (PFS)
C.Key Derivation
D.Key Escrow
Show answerAnswer
B. Perfect Forward Secrecy (PFS)
Perfect Forward Secrecy (PFS) ensures that a compromise of a server's long-term private key will not compromise past session keys. Each session key is independently generated and discarded after the session ends.
15. A financial institution is implementing a system for secure online transactions. They require a mechanism to ensure that a customer cannot later deny having initiated a specific transaction, even if their private key is compromised after the transaction. Which cryptographic property, when properly implemented, primarily addresses this 'non-denial' aspect?
Cryptography
A.Integrity
B.Confidentiality
C.Non-repudiation
D.Availability
Show answerAnswer
C. Non-repudiation
Non-repudiation is the cryptographic property that provides irrefutable proof of an action, such that the originator cannot later deny having performed it. Digital signatures, applied correctly, are the primary mechanism to achieve non-repudiation for transactions.
16. A security auditor is reviewing an organization's cryptographic key management practices. The auditor discovers that the same symmetric key is used for both encrypting sensitive data at rest and for generating Message Authentication Codes (MACs) for data integrity. What is the most significant cryptographic risk introduced by this practice?
Cryptography
A.Vulnerability to replay attacks
B.Key compromise leading to loss of both confidentiality and integrity
C.Reduced key entropy
D.Increased computational overhead
Show answerAnswer
B. Key compromise leading to loss of both confidentiality and integrity
Using the same key for different cryptographic functions (encryption and MAC generation) violates the principle of key separation. If this single key is compromised, an attacker gains both the ability to decrypt the data (breaking confidentiality) and to forge MACs (breaking integrity), allowing them to alter data undetectably.
17. A large enterprise is designing a new internal application that requires strong user authentication. They want to implement a system where user passwords are never stored in plain text and are difficult to reverse engineer, even if the database is compromised. Which cryptographic technique is BEST suited for this requirement?
Cryptography
A.Digital signatures
B.Asymmetric encryption
C.Hashing with a salt
D.Symmetric encryption
Show answerAnswer
C. Hashing with a salt
Hashing with a salt is the standard and most effective method for storing user passwords. Hashing transforms the password into a fixed-size string, making it irreversible, and the salt prevents rainbow table attacks and ensures identical passwords hash to different values.
18. An organization uses an access control system where a subject's access rights to an object are determined by comparing the subject's security clearance level with the object's security classification label. The system strictly prevents a subject from writing information to an object with a lower security classification than their own clearance. Which access control model and specific property are being described?
Access Controls
A.Mandatory Access Control (MAC) and the *-Property (Star Property)
B.Discretionary Access Control (DAC) and the Simple Security Property
C.Role-Based Access Control (RBAC) and the No Write Down rule
D.Attribute-Based Access Control (ABAC) and the No Read Up rule
Show answerAnswer
A. Mandatory Access Control (MAC) and the *-Property (Star Property)
Mandatory Access Control (MAC) uses security labels and clearances to enforce access. The *-Property (Star Property) in MAC specifically states that a subject cannot write to an object with a lower security classification (no write-down), which prevents information from flowing from a higher security level to a lower one.
19. A security architect is designing an access control system for a highly dynamic environment where access decisions must be made in real-time based on a combination of a user's current location, the time of day, their role, and the sensitivity level of the data they are trying to access. Which access control model would be most suitable for this complex requirement?
Access Controls
A.Mandatory Access Control (MAC)
B.Role-Based Access Control (RBAC)
C.Attribute-Based Access Control (ABAC)
D.Discretionary Access Control (DAC)
Show answerAnswer
C. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is designed for highly dynamic and granular access control. It evaluates a set of attributes (user, object, environment) to make real-time access decisions, perfectly matching the complex requirements described.
20. A security policy states that all administrative actions on critical systems must be approved by a second administrator before execution. This ensures that no single individual can perform a sensitive operation without oversight. Which access control principle is being enforced?
Access Controls
A.Defense in depth
B.Need-to-know
C.Least privilege
D.Separation of duties
Show answerAnswer
D. Separation of duties
Separation of duties is an access control principle that divides critical functions among multiple individuals to prevent any single person from being able to perform a complete sensitive operation, thereby reducing the risk of fraud, error, or malicious activity.
21. A security engineer is designing a system that uses a Public Key Infrastructure (PKI) to manage digital certificates. They need to ensure that when a certificate is revoked, all relying parties are quickly and efficiently informed of its invalidation. Which method provides the most timely and resource-efficient way to check the revocation status of a single certificate in real-time?
Cryptography
A.Certificate Revocation List (CRL) distribution point
B.Online Certificate Status Protocol (OCSP)
C.Manual certificate verification
D.Trust Anchor distribution
Show answerAnswer
B. Online Certificate Status Protocol (OCSP)
OCSP (Online Certificate Status Protocol) provides real-time, lightweight status checks for individual certificates. Instead of downloading a potentially large CRL, a client sends a request for a specific certificate's status to an OCSP responder, which returns a signed response indicating 'good,' 'revoked,' or 'unknown.' This is more efficient and timely than CRLs for single certificate checks.
22. A software developer is implementing a new secure file storage system. The requirement is to encrypt large files efficiently while ensuring that the encryption process can be easily parallelized across multiple processor cores. Which type of encryption algorithm is best suited for this scenario?
Cryptography
A.Asymmetric encryption
B.Stream cipher
C.Block cipher in ECB mode
D.Block cipher in CBC mode
Show answerAnswer
B. Stream cipher
Stream ciphers encrypt data bit by bit or byte by byte, making them inherently suitable for parallelization as each unit can be processed independently. This allows for high throughput, especially with large data sets.
23. A security analyst is reviewing a system that prevents users from downgrading the security classification of a document they are editing, even if they have read and write permissions at their current clearance level. This ensures that sensitive information does not accidentally or maliciously get released to a lower security domain. Which security model principle is being applied here?
Access Controls
A.Strong Tranquility Property
B.Simple Security Property (No Read Up)
C.Discretionary Security Property
D.*-Property (Star Property or No Write Down)
Show answerAnswer
D. *-Property (Star Property or No Write Down)
The Bell-LaPadula model's *-Property (Star Property) states that a subject cannot write to an object with a lower security classification (no write down). This prevents information from flowing from a higher security level to a lower one, directly matching the scenario.
24. A security auditor is reviewing a company's data at rest encryption strategy. The auditor notes that a significant portion of sensitive PII (Personally Identifiable Information) is encrypted using a symmetric key that is stored on the same server as the encrypted data. Which of the following cryptographic best practices is being violated?
Cryptography
A.Key stretching
B.Key derivation
C.Key escrow
D.Key separation
Show answerAnswer
D. Key separation
Storing the encryption key on the same server as the encrypted data violates the principle of key separation, which dictates that keys should be stored separately from the data they protect to prevent single points of compromise.
25. A security administrator is configuring access for a new human resources application. The application requires that users can only read their own personnel files but can view an aggregated, anonymized report of all employee salaries. What access control model best supports this specific requirement?
Access Controls
A.Role-Based Access Control (RBAC)
B.Discretionary Access Control (DAC)
C.Context-Based Access Control
D.Mandatory Access Control (MAC)
Show answerAnswer
C. Context-Based Access Control
Context-Based Access Control (CBAC) allows access decisions to be made based on environmental factors and the specific context of the request, such as the user's role, the time of access, the data being accessed, and the action being performed. This flexibility is ideal for scenarios where access varies dynamically based on the situation.
Cryptographic algorithms designed to be secure against attacks from quantum computers, which could break many of the currently used public-key cryptographic algorithms.
Aims to replace current public-key cryptography.
Focuses on algorithms resistant to Shor's and Grover's algorithms.
Includes lattice-based, code-based, hash-based, and multivariate polynomial cryptography.
A type of encryption that simultaneously provides confidentiality, integrity, and authenticity for data. If any part of the ciphertext or associated authenticated data is modified, decryption and verification will fail.
Combines encryption with a Message Authentication Code (MAC).
Protects against tampering, decryption, and replay attacks.
Electronic Codebook (ECB) mode for block ciphers encrypts each block independently, leading to identical plaintext blocks producing identical ciphertext blocks, thus revealing data patterns.
Not suitable for encrypting large amounts of data or data with repeating patterns.
Often illustrated with the 'Tux' penguin example, where the outline of the penguin remains visible after encryption.
Should generally be avoided in favor of modes like CBC, CTR, or GCM for most applications.
The vulnerability of Electronic Codebook (ECB) mode where identical plaintext blocks are encrypted into identical ciphertext blocks, revealing patterns in the encrypted data and compromising confidentiality.
Encrypts each block independently.
No chaining or initialization vector (IV).
Suitable only for very short, random data (e.g., encrypting other keys).
An authorization mechanism that grants or denies access to resources based on policies that evaluate attributes of the subject, object, action, and environmental conditions.
Provides highly granular and dynamic access control.
Scales well for complex environments with many users, resources, and conditions.
Policies are expressed as 'If-Then' rules based on attribute values.
A system that allows for the portability of identity information across multiple, independent domains, enabling users to authenticate once and access various services without re-authentication.
Uses trusted identity providers (IdPs).
Enhances user convenience (single sign-on).
Reduces administrative burden for service providers.
A symmetric key cipher that encrypts plaintext digits (bits or bytes) one at a time, and whose transformation of successive digits depends on the internal state of the cipher.
Encrypts data bit by bit or byte by byte.
Ideal for streaming data, real-time communication, and data of unknown length.
Requires a keystream generator to produce a pseudo-random sequence.
Authenticated Encryption with Associated Data (AEAD)
Flip card
A type of encryption that simultaneously provides confidentiality (data privacy), integrity (data hasn't been altered), and authenticity (data comes from the expected source). It can also authenticate 'associated data' that is not encrypted.
Combines encryption and message authentication.
Prevents common cryptographic implementation pitfalls.
Often more efficient than separate encryption and MAC schemes.
A property of key agreement protocols that ensures that if one of the long-term keys is compromised, it does not compromise any past session keys derived from it.
Each session uses a unique, ephemeral session key.
Session keys are not derived directly from a master secret that could be compromised later.
Often implemented using Diffie-Hellman key exchange or elliptic curve Diffie-Hellman (ECDHE).
A cryptographic service that provides undeniable proof of the origin or integrity of data, or the identity of the sender, preventing the sender from falsely denying having sent a message or initiated a transaction.
The principle that different cryptographic keys should be used for different cryptographic functions (e.g., encryption, signing, MAC generation) to prevent a compromise of one key from undermining the security of other functions.
Assigns distinct keys for distinct operations.
Minimizes impact of key compromise.
Prevents cryptanalytic attacks that exploit multi-use keys.
A cryptographic technique for securely storing passwords by transforming them into irreversible hash values, combined with a unique, random string (salt) for each password.
Protects against rainbow table attacks.
Ensures two identical passwords yield different hash values.
Makes brute-force attacks more computationally intensive.
A security property within the Bell-LaPadula confidentiality model that prevents a subject from writing to an object that has a lower security classification (no write-down).
Aims to prevent information from flowing downwards to lower security levels.
Part of Mandatory Access Control (MAC).
Crucial for maintaining confidentiality in multi-level security systems.
An access control principle that divides critical functions and responsibilities among multiple individuals to prevent any single person from controlling an entire sensitive process end-to-end.
Reduces the risk of fraud, error, or malicious acts.
Requires multiple parties to complete a critical task.
Often implemented with dual control or two-person rules.
A protocol used to obtain the revocation status of an X.509 digital certificate in real-time. Clients query an OCSP responder for the status of a specific certificate, receiving a signed response.
Provides real-time certificate revocation status.
More efficient than CRLs for single certificate checks.
Reduces network overhead compared to downloading large CRLs.
A rule in the Bell-LaPadula access control model that states a subject at a given security level cannot write to an object at a lower security level (also known as 'no write down').
Prevents information flow from higher to lower classification levels.
Crucial for maintaining confidentiality in multi-level security systems.
Works in conjunction with the Simple Security Property ('no read up').
An access control model where decisions are made based on the context of the access request, including factors like user identity, time, location, data sensitivity, and the operation being performed.
Provides highly granular and dynamic access control.
Considers environmental and situational attributes.
Often used in environments with complex, changing access requirements.
An access control mechanism that grants or denies access to resources based on a set of predefined rules or policies. These rules often incorporate conditions like time of day, location, or protocol.
Highly flexible and dynamic.
Rules are typically defined by administrators.
Can be used in conjunction with other models like RBAC or ABAC.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.