SSCP Systems Security Certified PractitionerCryptographyHard

An incident response team is investigating a data breach where an attacker exfiltrated encrypted data from a database. The database used a simple key management system where the encryption key was stored on the same server as the encrypted data. If the attacker gained root access to the server, what core cryptographic principle was violated, making the encryption ineffective?

  1. AWork factor
  2. BNon-repudiation
  3. CKey separation
  4. DKerckhoffs's Principle
Show answer & explanation

Correct answer: C. Key separation

Key separation is the principle that different keys should be used for different cryptographic purposes, and critically, keys should be stored and managed independently from the data they protect. Storing the encryption key on the same server as the encrypted data, especially without additional protection, violates this principle and renders the encryption useless if the server itself is compromised.

Why the other options are wrong

  • A. Work factor refers to the computational effort required to break a cryptosystem, which is not directly the issue here once the key is compromised.
  • B. Non-repudiation ensures that an action cannot be denied, which is unrelated to the key storage issue described.
  • D. Kerckhoffs's Principle states that a cryptosystem should be secure even if everything about the system, except the key, is public.

Key Separation

A cryptographic principle stating that different keys should be used for different cryptographic purposes (e.g., encryption, signing) and that keys should be stored and managed separately from the data they protect to prevent a single point of compromise.

  • Distinct keys for distinct purposes.
  • Keys should be stored separately from encrypted data.
  • Reduces impact of a single key compromise.

Memory trick: Keep your secret key in a different safe than your secret data.

More Cryptography questions