PKI Flashcards

1
Q

What is symmetric encryption?

A

Sharing one key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is asymmetric encryption?

A

Having a public and private key-pair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which version of SSL/TLS should be used?

A

TLS v1.2 or v1.3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does SSL/TLS ensure?

A

Confidentiality. authentication, and data integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a CA?

A

Certificate authority. Issues certificates so you can verify your identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the three types of SSL/TLS certificates?

A

Domain validated, organization validated, and extended validated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are domain validated certificates?

A

Basically just checks if the applicant has the right to use the domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are organizational validated certificates?

A

Checks if the applicant has the right to use the domain AND checks that the organization is legit.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are extended validated certificates?

A

Makes SURE that that organization is who they say they are. Like 10,000% sure. that someone owns that domain and is who they say they are.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which certificates are easy to differentiate?

A

EV is easy to tell, DV and OV are much, much harder.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the requirements of certificates?

A

Only the CA can create and update certs. Anyone can read it and verify it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is X.509?

A

A framework for authentication It contains the public key of the user and gets signed with the private key if a trusted CA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the certificate elements?

A

Version, serial num, algorithm identifier, issuer, period of validity, subject name, subjects public key info, issuer unique ID, subject unique ID, extensions, signature.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are some common certificate formats?

A

PEM, DER (PEM but in binary format), P7B/PKCS#7 and PFX/PKCS#12

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is base 64?

A

Using a-z, A-Z, 0-9 and “+” and “/” as “digits”. It is used to transmit data over a network designed to deal only with text.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Symantec?

A

They majorly screwed up certificate stuff.