
Introduction-to-Cryptography Dumps - Kickstart your Career with Real Updated Questions
Earn Quick And Easy Success With Introduction-to-Cryptography Dumps
NEW QUESTION # 46
(Which certificate encoding process is binary-based?)
- A. Rivest-Shamir-Adleman (RSA)
- B. Privacy Enhanced Mail (PEM)
- C. Public Key Infrastructure (PKI)
- D. Distinguished Encoding Rules (DER)
Answer: D
Explanation:
DER (Distinguished Encoding Rules) is a binary encoding format used to represent ASN.1 structures in a canonical, unambiguous way. X.509 certificates are defined using ASN.1, and DER provides a strict subset of BER (Basic Encoding Rules) that guarantees a single, unique encoding for any given data structure. That
"unique encoding" property is important for cryptographic operations such as hashing and digital signatures, because different encodings of the same abstract data could otherwise produce different hashes and break signature verification. In contrast, PEM is not a binary encoding; it is essentially a Base64-encoded text wrapper around DER data, bounded by header/footer lines (e.g., "BEGIN CERTIFICATE"). PKI is an overall framework for certificate issuance, trust, and lifecycle management-not an encoding. RSA is an asymmetric algorithm used for encryption/signing, not a certificate encoding format. Therefore, the binary-based certificate encoding process among the options is DER.
NEW QUESTION # 47
(Which additional input element can be used to implement integrity in combination with symmetric ciphers?)
- A. Hash function
- B. Initialization vector
- C. Encoding algorithm
- D. Nonce value
Answer: A
Explanation:
Symmetric encryption alone typically provides confidentiality, but it does not automatically provide integrity. Many encryption modes (especially older ones like CBC without authentication) are malleable, meaning an attacker may be able to modify ciphertext and cause predictable changes in plaintext after decryption. To add integrity, systems commonly combine symmetric encryption with a cryptographic hash-based integrity mechanism, such as a hash function used in an HMAC (Hash-based Message Authentication Code) or a dedicated authenticated-encryption mode like GCM that internally uses authentication tags. Among the given options, a hash function is the fundamental additional element that enables integrity checks: it allows construction of a MAC (e.g., HMAC-SHA-256) that the receiver verifies to detect any tampering. An initialization vector and a nonce value are used to ensure uniqueness and randomness properties for encryption but do not, by themselves, guarantee integrity.
An encoding algorithm changes representation, not security. Therefore, the correct additional input element for implementing integrity alongside symmetric encryption is a hash function, typically as part of an HMAC or similar MAC construction.
NEW QUESTION # 48
(What is modular arithmetic in cryptography?)
- A. The process of encoding messages using large integers
- B. A method of encrypting messages using modular operations
- C. The art of deciphering messages using prime numbers
- D. The study of secret codes
Answer: B
Explanation:
Modular arithmetic is the mathematics of working with remainders after division by a fixed number called the modulus. In cryptography, it underpins many core constructions because it defines arithmetic in finite sets (rings and fields) where values "wrap around," enabling stable, repeatable operations with bounded results.
Public-key systems like RSA rely on modular exponentiation (raising integers to powers modulo a composite number), while Diffie-Hellman and many elliptic-curve schemes operate in groups defined by modular arithmetic properties. Encryption and key exchange use modular operations because they allow efficient computation forward (e.g., exponentiation modulo a large number) while making certain inverse problems computationally hard without secret information (e.g., factoring or discrete logarithms). Modular reduction also helps keep intermediate values manageable and supports group properties needed for proofs of security.
Although modular arithmetic is not "encryption by itself," it is a foundational method used inside encryption algorithms and protocols. Therefore, among the options, describing it as a method used for encryption via modular operations best matches cryptographic usage.
NEW QUESTION # 49
(How does a cryptographic policy contribute to incident response?)
- A. By increasing the likelihood of data breaches
- B. By limiting the use of encryption tools during incidents
- C. By providing guidelines for secure data recovery and communication
- D. By slowing down the incident resolution process
Answer: C
Explanation:
A cryptographic policy defines how encryption, keys, certificates, and integrity mechanisms are used and managed across an organization. During incident response, that policy becomes a playbook for making safe, consistent decisions under pressure. It can specify how to rotate or revoke compromised keys, how to validate and reissue certificates, how to preserve evidence integrity with hashing, and how to securely communicate sensitive incident details (e.g., using approved encrypted channels). It can also define backup encryption requirements and key escrow or recovery procedures, enabling secure data recovery without exposing protected data. Policies typically outline roles and responsibilities (who can access keys, who can approve rekeying), logging requirements, and escalation steps-reducing confusion and preventing ad hoc crypto changes that might worsen exposure. The goal is not to limit encryption; it is to ensure cryptography is used correctly to contain and remediate incidents. Therefore, providing guidelines for secure recovery and communication is the correct contribution of cryptographic policy to incident response.
NEW QUESTION # 50
(Which default port must be allowed by firewalls for the key exchange of the IPsec handshaking process to be successful?)
- A. TCP 500
- B. UDP 443
- C. UDP 500
- D. TCP 443
Answer: C
Explanation:
IPsec's initial key exchange is commonly performed using IKE (Internet Key Exchange), which negotiates Security Associations (SAs), authenticates peers, and establishes shared keys for ESP/AH protection. The traditional and default transport for IKEv1 and IKEv2 is UDP port 500. During negotiation, peers exchange proposals (crypto suites), perform Diffie-Hellman to derive key material, and authenticate using pre-shared keys, certificates, or EAP methods. If a firewall blocks UDP 500, the IKE negotiation cannot begin, preventing IPsec tunnels from forming. In many real deployments, NAT traversal is also used; in that case, traffic typically shifts to UDP 4500 (NAT-T) after detection of NAT, but UDP 500 is still required for the initial exchange and NAT detection in many configurations. TCP 500 is not standard for IKE. Port 443 is associated with HTTPS/TLS and some SSL VPNs, not IPsec IKE. Therefore, among the options provided, the firewall must allow UDP 500 for IPsec key exchange to succeed.
NEW QUESTION # 51
(Which authentication method allows a web service installed on a network operating system to prove its identity to a customer?)
- A. One-way server authentication
- B. End-to-end authentication
- C. Mutual authentication
- D. One-way client authentication
Answer: A
Explanation:
One-way server authentication is the standard model used by most TLS-enabled web services to prove the server's identity to a client. In this model, the server presents an X.509 certificate during the TLS handshake. The client validates the certificate chain to a trusted root CA, checks hostname binding (CN
/SAN), validates validity dates, and may check revocation status. If validation succeeds, the client gains cryptographic assurance that it is communicating with the holder of the private key corresponding to the server certificate's public key, and that the certificate is issued to the expected domain/identity. This proves the server's identity to the customer without requiring the customer to present a certificate.
Mutual authentication would require both client and server to authenticate each other using certificates (commonly in certain enterprise APIs), but the question asks specifically about the web service proving its identity to the customer, which is satisfied by server-only authentication. One-way client authentication is the opposite direction (client proves identity to server). "End-to-end authentication" is a broader concept and not the specific TLS identity proof mechanism described here. Thus, one-way server authentication is the correct choice.
NEW QUESTION # 52
(Which of the following is an example of a software encryption solution for disk storage?)
- A. Hardware Security Module (HSM)
- B. USB encryption hardware
- C. Virtual Private Network (VPN)
- D. BitLocker and FileVault
Answer: D
Explanation:
Disk/storage encryption protects data at rest by encrypting the contents of a drive so it remains unreadable without the correct authentication and keys. BitLocker (commonly on Windows) and FileVault (commonly on macOS) are well-known software-based full-disk encryption solutions integrated into their operating systems.
They encrypt sectors on disk and typically tie key protection to user credentials and, where available, hardware features such as a TPM or secure enclave to reduce key extraction risk. A VPN encrypts network traffic in transit, not disk storage. An HSM is specialized hardware used to generate, store, and protect cryptographic keys and perform crypto operations; it is not a disk encryption product itself. USB encryption hardware refers to hardware-encrypted removable media, not a software solution for a system disk. Therefore, the correct example of a software encryption solution for disk storage is BitLocker and FileVault.
NEW QUESTION # 53
(Which technique involves spotting variations in encrypted data and plotting how the characters relate to standard English characters?)
- A. Known plaintext
- B. Chosen ciphertext
- C. Brute force
- D. Frequency analysis
Answer: D
Explanation:
Frequency analysis is a classical cryptanalysis technique that exploits predictable statistical patterns in natural language. In English, certain letters (like E, T, A, O, I, N) occur more frequently than others, and common digrams/trigrams (TH, HE, IN, ER) appear with recognizable distribution. When a cipher preserves character boundaries (as in many substitution ciphers), the ciphertext will also show frequency patterns-though mapped to different symbols. The analyst counts ciphertext character occurrences, compares the distribution to expected English letter frequencies, and infers likely plaintext mappings. "Spotting variations" refers to observing differences in how often symbols appear and using that to plot relationships between ciphertext and standard English. Brute force instead tries all keys; known-plaintext attacks rely on having plaintext-ciphertext pairs; chosen-ciphertext attacks involve decrypting attacker-selected ciphertexts. Those are different attack models. Frequency analysis is specifically about statistical correlation between ciphertext symbols and language characteristics, which is why it is effective against monoalphabetic substitution and weak polyalphabetic schemes with short periods.
NEW QUESTION # 54
(What is the value of 51 mod 11?)
- A. 07
- B. 05
- C. 0
- D. 04
Answer: A
Explanation:
The value 51 mod 11 is the remainder after dividing 51 by 11. Modular arithmetic is widely used in cryptography to keep computations within a finite set of residues, such as in RSA where values are taken modulo n, or in Diffie-Hellman where exponents and group elements are reduced modulo a prime. To compute 51 mod 11, find the largest multiple of 11 less than or equal to 51. Multiples of 11 are 11, 22, 33, 44,
55. The closest without exceeding 51 is 44. Subtracting gives 51 # 44 = 7, so the remainder is 7. Therefore, 51 mod 11 = 7, matching option "07." This remainder is always in the range 0 through 10 because the modulus is
11. Such residue computations underpin the "wraparound" behavior that makes modular exponentiation and inverse computations well-defined in cryptographic groups.
NEW QUESTION # 55
(Which authentication method allows a web service installed on a network operating system to prove its identity to a customer?)
- A. One-way server authentication
- B. End-to-end authentication
- C. Mutual authentication
- D. One-way client authentication
Answer: A
Explanation:
One-way server authentication is the standard model used by most TLS-enabled web services to prove the server's identity to a client. In this model, the server presents an X.509 certificate during the TLS handshake.
The client validates the certificate chain to a trusted root CA, checks hostname binding (CN/SAN), validates validity dates, and may check revocation status. If validation succeeds, the client gains cryptographic assurance that it is communicating with the holder of the private key corresponding to the server certificate's public key, and that the certificate is issued to the expected domain/identity. This proves the server's identity to the customer without requiring the customer to present a certificate. Mutual authentication would require both client and server to authenticate each other using certificates (commonly in certain enterprise APIs), but the question asks specifically about the web service proving its identity to the customer, which is satisfied by server-only authentication. One-way client authentication is the opposite direction (client proves identity to server). "End-to-end authentication" is a broader concept and not the specific TLS identity proof mechanism described here. Thus, one-way server authentication is the correct choice.
NEW QUESTION # 56
(Which wireless security standard uses an authentication server with 802.1X and EAP?)
- A. TKIP
- B. WEP
- C. WPA-Enterprise
- D. WPA-PSK
Answer: C
Explanation:
802.1X is a port-based network access control framework that enables centralized authentication using an authentication server (commonly RADIUS). EAP (Extensible Authentication Protocol) runs within
802.1X to support many credential types (password-based methods like PEAP, certificate-based methods like EAP-TLS, and others). WPA-Enterprise is the wireless security mode that explicitly uses
802.1X + EAP with an authentication server to perform per-user/per-device authentication and to derive dynamic session keys. By contrast, WPA-PSK uses a pre-shared key without an external authentication server; all users share the same PSK, which is weaker for enterprise identity management. WEP is an older mechanism using static keys and does not provide modern 802.1X/EAP enterprise authentication in the WPA-Enterprise sense. TKIP is an encryption/integrity protocol used under WPA, not the full authentication "standard" involving an authentication server. Therefore, the correct choice is WPA-Enterprise.
NEW QUESTION # 57
(What is the maximum key size (in bits) supported by AES?)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
AES supports three standardized key sizes: 128, 192, and 256 bits, with a fixed block size of 128 bits.
The maximum of these supported key sizes is 256 bits (AES-256). Key size affects resistance to brute- force key search: larger keys exponentially increase the search space. In practice, AES-128 is already considered strong against brute force with contemporary computing capabilities, while AES-256 is often chosen for compliance requirements, conservative security margins, or to hedge against future advances. AES-512 is not part of the AES standard; if 512-bit keys are desired, systems typically use different constructions (like using AES-256 in certain key-derivation or wrapping schemes) rather than changing AES itself. Therefore, the correct maximum supported AES key size is 256 bits.
NEW QUESTION # 58
(An organization wants to digitally sign its software to guarantee the integrity of its source code. Which key should the customer use to decrypt the digest of the source code?)
- A. Customer's public key
- B. Organization's public key
- C. Customer's private key
- D. Organization's private key
Answer: B
Explanation:
When software is digitally signed, the organization computes a cryptographic hash (digest) of the software (or its manifest) and then signs that digest using the organization's private key. Verification works in the opposite direction: the customer (verifier) uses the organization's public key to validate the signature and recover/confirm the signed digest, then independently hashes the received software and compares the result. If the digests match and the signature validates under the public key, the customer has strong assurance that the software has not been altered since it was signed and that it was signed by the holder of the corresponding private key. The customer never needs the organization's private key-sharing it would destroy security and enable forgery. Likewise, the customer's own keys are irrelevant to verifying the publisher's signature. The organization's public key is typically delivered inside a certificate chain (code signing certificate) so the verifier can also validate publisher identity and trust. Therefore, the customer uses the organization's public key for signature verification (often described as "decrypting" the signed digest).
NEW QUESTION # 59
(What makes the RC4 cipher unique compared to RC5 and RC6?)
- A. Stream
- B. Asymmetric
- C. Symmetric
- D. Block
Answer: A
Explanation:
RC4 is unique among the RC family listed because it is a stream cipher. It generates a pseudorandom keystream and encrypts data by XORing that keystream with plaintext bytes (and decryption is the same XOR operation). This differs from RC5 and RC6, which are block ciphers: they encrypt fixed-size blocks of data through multiple rounds of operations (such as modular addition, XOR, and rotations) using a secret key. The stream-cipher design means RC4 historically fit protocols where data arrives continuously (e.g., early wireless and web encryption) and where simple, fast software implementation was desired. However, stream ciphers demand careful handling of nonces/IVs to avoid keystream reuse; reuse can catastrophically leak plaintext relationships. RC4 also has well-documented statistical biases in its keystream, leading to practical attacks in protocols like WEP and later concerns in TLS, which is why RC4 has been deprecated in modern security standards. Still, from a classification standpoint, "stream" is the distinguishing characteristic versus RC5/RC6 being block ciphers.
NEW QUESTION # 60
(Which type of exploit involves looking for different inputs that generate the same hash?)
- A. Algebraic attack
- B. Birthday attack
- C. Differential cryptanalysis
- D. Linear cryptanalysis
Answer: B
Explanation:
A birthday attack targets hash functions by exploiting the birthday paradox: collisions (two different inputs producing the same hash output) can be found much faster than brute-forcing a specific preimage. For an n-bit hash, the expected work to findanycollision is on the order of 2^(n/2), not 2^n.
The attack is relevant because many security constructions rely on collision resistance-digital signatures, certificate fingerprints, integrity checks, and some commitment schemes. If an attacker can generate two different documents with the same hash, they may trick a signer into signing one version while later presenting the other as "signed," depending on the protocol. Linear cryptanalysis and differential cryptanalysis are primarily techniques against block ciphers, analyzing relationships between plaintext/ciphertext differences or linear approximations across rounds. Algebraic attacks treat the cipher as a system of equations. The description "looking for different inputs that generate the same hash" is the hallmark of collision-finding, and the classic framing for that is the birthday attack.
NEW QUESTION # 61
(How does Electronic Codebook (ECB) mode encryption function?)
- A. Converts from block to stream, then uses a counter value and a nonce to encrypt the data
- B. Uses a self-synchronizing stream on the blocks, where the IV is encrypted and XORed with the data stream
- C. Uses an IV to encrypt the first block, then uses the result to encrypt the next block
- D. Encrypts each block with the same key, where each block is independent of the others
Answer: D
Explanation:
ECB is the simplest block cipher mode: each plaintext block is encrypted independently using the same key and the block cipher primitive. There is no IV and no chaining, so identical plaintext blocks produce identical ciphertext blocks. This property leaks patterns and structure in the plaintext, which is why ECB is generally considered insecure for most real-world data beyond tiny, random-looking inputs. For example, images encrypted with ECB often reveal outlines because repeated pixel blocks map to repeated ciphertext blocks. Option A describes CTR mode, option C describes CBC mode, and option B resembles feedback-based modes. ECB's independence also means it can be parallelized, but the pattern leakage is a severe weakness. Modern practice prefers authenticated encryption modes (like GCM) or, at minimum, modes with IVs and chaining (like CBC with proper padding and MAC).
Therefore, the correct statement is that ECB encrypts each block with the same key and each block is independent of the others.
NEW QUESTION # 62
(Which operation can be performed on a certificate during the "Issued" stage?)
- A. Creation
- B. Distribution
- C. Key archiving
- D. Key recovery
Answer: B
Explanation:
The "Issued" stage in a certificate lifecycle indicates that the certificate has been generated and signed by the issuing CA and is now valid for use (subject to validity dates, policy constraints, and revocation status). At this point, the operational focus shifts from creating the certificate to making it available to the subject and relying parties. "Distribution" is the lifecycle activity most directly associated with an issued certificate:
installing it on servers or endpoints, provisioning it into keystores, publishing it to directories if required, and ensuring the chain (intermediates) is accessible for validation. By contrast, "Creation" is earlier in the process (key generation, CSR creation, identity validation, issuance/signing). "Key recovery" and "key archiving" relate to private key management and escrow policies (often for encryption keys, not signing keys), and are governed by organizational policy and key management systems rather than the certificate's issued state itself.
A certificate can be distributed after issuance regardless of whether any key escrow features exist. Therefore, the operation that fits the certificate's "Issued" stage best is distribution of the issued credential for operational use.
NEW QUESTION # 63
(What is the correlation between the number of rounds and the key length used in the AES algorithm?)
- A. The number of rounds is the same regardless of the key length.
- B. The key length is the same regardless of the number of rounds.
- C. The number of rounds decreases as the key length increases.
- D. The number of rounds increases as the key length increases.
Answer: D
Explanation:
In AES, the number of rounds is explicitly tied to the key length. AES-128 uses 10 rounds, AES-192 uses 12 rounds, and AES-256 uses 14 rounds. The purpose of additional rounds is to increase diffusion and confusion, strengthening resistance against cryptanalysis as the key schedule and state transformations iterate more times. Although key length primarily affects brute-force resistance, AES's designers and standardization parameters link longer keys with more rounds to maintain security margins across variants, especially considering differences in the key schedule structure. Thus, as key length increases from 128 to 192 to 256 bits, the number of rounds increases correspondingly from 10 to
12 to 14. This relationship is fixed by the AES specification and does not vary dynamically at runtime.
Therefore, the correct correlation is that the number of rounds increases as the key length increases.
NEW QUESTION # 64
(What are the primary characteristics of Bitcoin proof of work?)
- A. Difficult to produce and easy to verify
- B. Easy to produce and easy to verify
- C. Easy to produce and difficult to verify
- D. Difficult to produce and difficult to verify
Answer: A
Explanation:
Bitcoin's proof of work (PoW) is designed so that finding a valid block is computationally difficult, but checking validity is computationally easy. Miners must repeatedly hash candidate block headers (double SHA-
256) with different nonces until they find a hash value below a network-defined target. This trial-and-error search requires significant work and energy because the probability of success per attempt is extremely low at current difficulty levels. However, verification is straightforward: any node can hash the block header once (or a small number of times) and confirm the resulting hash meets the target threshold and that the block contents follow protocol rules. This "hard to produce, easy to verify" property is essential: it makes it expensive for attackers to rewrite history or outpace honest miners, while allowing all participants-even low- power devices-to validate blocks efficiently. Therefore, the primary characteristic of Bitcoin proof of work is that it is difficult to produce and easy to verify.
NEW QUESTION # 65
(How is Public Key Infrastructure (PKI) commonly utilized in web browsers?)
- A. To compress encrypted messages for storage
- B. To securely manage digital certificates and keys
- C. To authenticate users during data transmission
- D. To encrypt data at rest
Answer: B
Explanation:
Web browsers rely on PKI to establish trust in secure connections, primarily through X.509 certificates and a built-in set of trusted root Certificate Authorities (CAs). When a browser connects to an HTTPS site, the server presents a certificate chain. The browser validates that chain up to a trusted root, checks that the certificate is valid for the domain (SAN/CN matching), confirms validity dates, and may check revocation status. This PKI process allows browsers to authenticate the website's identity and negotiate encrypted session keys for TLS, enabling confidentiality and integrity for the connection. In practical terms, the browser' s PKI components include certificate stores, validation logic, and mechanisms for handling intermediates, trust policies, and revocation. While PKI supports authentication as an outcome, the best description of how browsers utilize PKI is that they manage and validate digital certificates and associated keys to establish trust.
PKI is not about compressing messages or encrypting data at rest; it is about identity binding and trust chains that make secure web communication possible.
NEW QUESTION # 66
(What is a digital signature?)
- A. A method of encrypting messages
- B. A unique identifier for digital files
- C. A cryptographic technique to verify the authenticity and integrity of a message
- D. A type of encryption algorithm
Answer: C
Explanation:
A digital signature is a cryptographic mechanism that enables a recipient to verify who created a message (authenticity) and that the message has not been altered (integrity). It is typically built using asymmetric cryptography: the signer uses a private key to sign a hash (digest) of the message, producing a signature.
Anyone with the signer's public key can verify that the signature matches the message digest, confirming the signature was created by the corresponding private key and that the content remains unchanged. Digital signatures do not primarily provide confidentiality; the signed message may still be readable unless separately encrypted. They also support nonrepudiation in many operational contexts because a valid signature can be strong evidence that the private key holder authorized the signed data, assuming key protection and policy controls. Common digital signature algorithms include RSA-PSS, ECDSA, and EdDSA. Certificates (X.509) are often used to bind public keys to identities, allowing verifiers to trust the claimed signer. Therefore, the best definition is a technique to verify authenticity and integrity.
NEW QUESTION # 67
(Why should a forensic investigator create a hash of a victim's hard drive and of the bitstream copy of the hard drive?)
- A. To certify the information on the drive is correct
- B. To establish who created the files on the drives
- C. To verify that the drives are identical
- D. To identify if someone opened the drive
Answer: C
Explanation:
In digital forensics, investigators must preserve evidence integrity and demonstrate an unbroken chain of custody. Creating a cryptographic hash (such as SHA-256) of the original drive and then hashing the forensic bitstream image provides a strong mathematical assurance that the copy is an exact, bit-for-bit replica.
Because secure hash functions are designed so that any tiny change in data produces a dramatically different digest, matching hashes indicate the image contains identical data to the source at the time of acquisition. This is critical in legal and investigative contexts: analysis is performed on the copy, not the original, to avoid altering evidence. If the hashes match, the investigator can testify that the evidence examined is identical to what was collected, supporting admissibility and credibility. Hashing does not prove who created files, nor does it directly show whether someone "opened the drive"; it specifically validates the integrity and equivalence of the captured image. Therefore, hashing both artifacts is done to verify that the original and the bitstream copy are identical.
NEW QUESTION # 68
(What describes a true random number generator?)
- A. Fast and deterministic, and the same input produces the same results
- B. Unique integer determined through factorization of integers
- C. Integer increased by one to match requests and responses
- D. Slow and nondeterministic, and the same input produces different results
Answer: D
Explanation:
A true random number generator (TRNG) draws randomness from physical phenomena that are inherently unpredictable and not algorithmically reproducible. Because of this, it is nondeterministic:
you cannot feed it the same "input" and expect the same output stream. TRNGs are often slower than PRNGs because they depend on collecting entropy from hardware sources and may require conditioning to remove bias. This aligns with option B: slow and nondeterministic, producing different results even under similar or repeated conditions. Option A describes a deterministic PRNG, where identical seeds yield identical sequences. Option C is unrelated; factorization is a hard math problem used in cryptography (e.g., RSA security assumptions), not a randomness generator definition. Option D describes a counter, which is deterministic and not random. In secure systems, TRNG output may seed a cryptographically secure PRNG to provide both unpredictability and high throughput; but the defining characteristic of a TRNG is nondeterminism from physical entropy. Therefore, option B is correct.
NEW QUESTION # 69
(Which component is used to verify the integrity of a message?)
- A. TKIP
- B. IV
- C. HMAC
- D. AES
Answer: C
Explanation:
HMAC (Hash-based Message Authentication Code) is a standard mechanism used to verify both integrity and authenticity of a message when two parties share a secret key. It combines a cryptographic hash function (such as SHA-256) with a secret key in a structured way that resists common attacks on naive keyed-hash constructions. The sender computes an HMAC tag over the message and transmits the message plus tag. The receiver recomputes the HMAC using the same shared secret key and compares the result; if the tag matches, the receiver can be confident the message was not modified in transit and that it came from someone who knows the shared key. AES is an encryption algorithm primarily providing confidentiality; it can provide integrity only when used in authenticated modes (e.g., GCM) but "AES" alone is not the integrity component. An IV helps randomize encryption but does not validate integrity. TKIP is a legacy WLAN protocol component, not the general integrity verifier. Therefore, the correct component for verifying message integrity among the options is HMAC.
NEW QUESTION # 70
(Which default port must be allowed by firewalls for the key exchange of the IPsec handshaking process to be successful?)
- A. TCP 500
- B. UDP 443
- C. UDP 500
- D. TCP 443
Answer: C
Explanation:
IPsec's initial key exchange is commonly performed using IKE (Internet Key Exchange), which negotiates Security Associations (SAs), authenticates peers, and establishes shared keys for ESP/AH protection. The traditional and default transport for IKEv1 and IKEv2 is UDP port 500. During negotiation, peers exchange proposals (crypto suites), perform Diffie-Hellman to derive key material, and authenticate using pre-shared keys, certificates, or EAP methods. If a firewall blocks UDP 500, the IKE negotiation cannot begin, preventing IPsec tunnels from forming. In many real deployments, NAT traversal is also used; in that case, traffic typically shifts to UDP 4500 (NAT-T) after detection of NAT, but UDP 500 is still required for the initial exchange and NAT detection in many configurations. TCP
500 is not standard for IKE. Port 443 is associated with HTTPS/TLS and some SSL VPNs, not IPsec IKE. Therefore, among the options provided, the firewall must allow UDP 500 for IPsec key exchange to succeed.
NEW QUESTION # 71
......
Free Introduction-to-Cryptography pdf Files With Updated and Accurate Dumps Training: https://www.pass4surecert.com/WGU/Introduction-to-Cryptography-practice-exam-dumps.html
Top-Class Introduction-to-Cryptography Question Answers Study Guide: https://drive.google.com/open?id=1McKYUXOAh44G0-Istcusv38IYsG0fZBD