SSCP Systems Security Certified PractitionerCryptographyMedium

A system administrator is tasked with securing communication between two web servers over an untrusted network. They decide to use Transport Layer Security (TLS) with a cipher suite that includes an elliptic curve algorithm for key exchange and AES-256 for symmetric encryption. Which component of the TLS handshake process is primarily responsible for establishing a shared secret key for the symmetric encryption?

  1. AClientHello message
  2. BKey Exchange Algorithm
  3. CServer Certificate
  4. DApplication Data
Show answer & explanation

Correct answer: B. Key Exchange Algorithm

The Key Exchange Algorithm, such as Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE), is specifically designed to allow the client and server to securely agree upon a shared symmetric key during the TLS handshake, even over an insecure channel.

Why the other options are wrong

  • A. The ClientHello message initiates the handshake and specifies supported cipher suites, but doesn't establish the key itself.
  • C. The Server Certificate is used for server authentication, not direct shared secret key establishment.
  • D. Application Data is the encrypted data exchanged after the TLS handshake is complete, not part of key establishment.

TLS Key Exchange

A critical phase in the TLS handshake where the client and server securely establish a shared symmetric encryption key for subsequent data transmission.

  • Uses asymmetric cryptography (e.g., RSA, Diffie-Hellman) to establish a symmetric key.
  • Ensures that eavesdroppers cannot determine the symmetric key.
  • Modern implementations prioritize Perfect Forward Secrecy (PFS) using ephemeral keys.

Memory trick: TLS Handshake: Hello, Cert, Key, Change!

More Cryptography questions