SSCP Systems Security Certified PractitionerCryptographyEasy
A security analyst is investigating a suspected man-in-the-middle (MITM) attack where a malicious actor intercepted communication between a client and a server. The client's browser displayed a warning about an untrusted certificate. Which cryptographic concept, if properly implemented and verified by the client, would have primarily helped detect or prevent this specific MITM attack?
- ADigital certificates and Certificate Authorities (CAs)
- BSymmetric-key encryption
- CKey stretching
- DHashing algorithms
Show answer & explanationAnswer & explanation
Correct answer: A. Digital certificates and Certificate Authorities (CAs)
Digital certificates, issued by trusted Certificate Authorities, bind a public key to an identity. When a client receives a server's certificate, it verifies the signature from the CA to ensure the certificate is legitimate and has not been tampered with, thus detecting or preventing MITM attacks.
Why the other options are wrong
- B. Symmetric-key encryption encrypts data but doesn't inherently verify the identity of the communicating parties.
- C. Key stretching enhances password security but is not directly involved in preventing MITM attacks via certificate verification.
- D. Hashing algorithms ensure data integrity but do not verify the identity of the source.
Digital Certificates
An electronic document used to prove the ownership of a public key. It is issued by a Certificate Authority (CA) and contains the public key, the owner's identity, the CA's digital signature, and validity dates.
- Binds a public key to an identity.
- Verifies sender's authenticity and data integrity.
- Issued by trusted Certificate Authorities (CAs).
Memory trick: Certificates are like digital passports for secure online meetings.