Organisational Security Flashcards

1
Q

PEM

A

Privacy Enhanced Mail
BASE64 encoded DER certificate
ASCII human readable format so it isn’t modified by email system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DER

A

Distinguished Encoding Rules certificate binary format
Common for JAVA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PKCS #12

A

Public Key Cryptography Standards 12
Personal information exchange syntax standard
Container format for many certificates to store in .p12/.pfx file
Extended from MS format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

PKCS#7

A

Cryptographic Message Syntax Standard with .p7b files
ASCII human readable
Certificates and chain certificates
Windows, Java format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PKI operational considerations?

A

Generation
Exchange
Storage
Use
Destruction
Replacement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

PKI design considerations?

A

Protocol
Key Servers
User procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Certificate Authority (CA)

A

Creates certificates and owns the policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Subordinate/intermediate CA

A

Also known as Registration Authority sits below the route
Regularly issued certificates
Has ability to revoke

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CRL

A

Certificate Revocation List

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

OSCP

A

Online Certificate Status Protocol

Faster way to check a status y submitting request to CA rather than checking file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CSR

A

Certificate Signing Request
Is the message sent to the CA with information to get a certificate created

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SAN (certificates)

A

Subject Alternative Domain
Multiple domains/IP in single certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Wildcard (certificate)

A

Multiple servers in a domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Root Certificate

A

The trust anchor of the whole chain of trust. Root authorities RA regularly held offline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Stapling

A

Used by web server to provide validity of its own certificate essentially using OCSP response in advance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Pinning

A

To mitigate the use of fraudulent certificates, once sent is ‘pinned’ to host

17
Q

Trust models (certificates)

A

Bridge
Hierarchical -most common
Hybrid
Mesh

18
Q

SCAP

A

Security Content Automation FrameworK
CVE common vulnerabilities
CVSS vulnerability scoring
CCE common configuration
CPE common platform