SSCP Systems Security Certified PractitionerCryptographyEasy

A security analyst is investigating a suspected man-in-the-middle (MITM) attack against an internal web application. The application uses SSL/TLS for secure communication. Which of the following cryptographic concepts is primarily designed to prevent an attacker from successfully impersonating the legitimate server to the client?

  1. ASymmetric encryption
  2. BHashing
  3. CDigital certificates
  4. DKey derivation functions
Show answer & explanation

Correct answer: C. Digital certificates

Digital certificates, specifically server certificates, are used in SSL/TLS to bind a public key to an entity (the server) and are signed by a trusted Certificate Authority. This allows the client to verify the server's identity and detect impersonation attempts.

Why the other options are wrong

  • A. Symmetric encryption provides confidentiality but does not inherently address server identity verification.
  • B. Hashing ensures data integrity but does not verify the identity of the communicating parties.
  • D. Key derivation functions create cryptographic keys from a master secret but are not directly used for identity verification in this context.

Digital Certificate

An electronic document used to prove ownership of a public key, binding it to an individual or organization, and is signed by a trusted Certificate Authority.

  • Binds a public key to an identity.
  • Signed by a Certificate Authority (CA) for trust.
  • Used for authentication, integrity, and non-repudiation.

Memory trick: Certificates Verify Servers Authentically.

More Cryptography questions