SSCP Systems Security Certified PractitionerCryptographyHard

A forensic investigator is examining encrypted files found on a suspect's computer. The files were encrypted using a custom application. The investigator notices that a common attack vector involves guessing a short, predictable passphrase, which then directly acts as the encryption key. What cryptographic vulnerability is being exploited in this scenario?

  1. ALack of key stretching
  2. BWeak initialization vector (IV)
  3. CAbsence of a digital signature
  4. DInsufficient block size
Show answer & explanation

Correct answer: A. Lack of key stretching

This scenario describes a lack of key stretching, where a short, predictable passphrase is directly used as a cryptographic key. Key stretching (like using a PBKDF) is essential to transform weak, human-memorable passwords into strong, unpredictable keys that are computationally expensive to brute-force.

Why the other options are wrong

  • B. A weak IV affects confidentiality and uniqueness of ciphertext, but the core issue here is the predictability of the key derived from the passphrase.
  • C. Digital signatures provide authenticity and non-repudiation, which are separate concerns from the strength of an encryption key derived from a passphrase.
  • D. Insufficient block size is a property of block ciphers, not directly related to the strength or derivation of a key from a passphrase.

Key Stretching

A technique used to increase the strength of a weak key, typically derived from a password or passphrase, by making it computationally more expensive to brute-force or guess.

  • Transforms weak passwords into stronger keys.
  • Uses iterative hashing or PBKDFs.
  • Slows down brute-force attacks significantly.

Memory trick: Stretch the Key, Secure the Secret.

More Cryptography questions