PKI and Cryptographic Protocols Flashcards

1
Q

Cleartext

A

unencrypted data thats not supposed to be encrypted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What states does encryption protect?

A

processing, transit, rest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are digital signatures?

A

Electronic signatures to verify the sender

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a digital certificate?

A

Public key associated with users and has been signed by a trusted third party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CA

A

Certificate Authorities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What do CAs do?

A

Makes and manages digital certificates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CSR

A

Certificate Signing Request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How can a digital certificate be authenticated?

A

Email, Documents, In-person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a weakness in a single centralized CA?

A

Bottlenecks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you ensure security and integrity when managing CAs

A

Offline CA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CR

A

Certificate Repository

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a CR?

A

Public centralized directory of digital signatures where you can see the status

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens to a digital certificate before its expiration date?

A

Revoked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CRL

A

Certificate Revocation List

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a CRL?

A

list of certificates revokes by serial numbers
can have a local CRL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

OCSP

A

Online Certificate Status Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

OCSP Stapling

A

Web server sends queries to responders at intervals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is a OCSP?

A

Real-time look up of revocation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Browsers that use OCSP

A

Chrome, Safari, Firefox, Opera, IE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Root Digital Certificate

A

Self-signed
End is user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Domain Digital Certificate

A

Web server and browser key exchange
Entry-Lvl
no trust just verifies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Extended Domain Digital Certificate

A

Audit to follow ev standards
owner verifies by intermediate CA
authorized by intermediate and signature from officer of company

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Wildcard Digital Certificate (Domain)

A

validate main and subdomains

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Subject Alternatuve Name Digital Certificate (Domain)

A

Unified Communications Certificate
Multiple servers or domain names uses same certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What is the standard for digital certificate?
X.509
26
Direct Trust
knows each other
27
Third-Party Trust
trust bc they trust a common 3rd party
28
Web of trust
a direct trust signs digital certificate then exchange
29
Hierarchical trust model
One mast CA named root backlog can happen signs all w one key
30
Distributed trust model
multiple CAs basis on internet
31
Bridge trust model
One CA is an faciliitor that doesnt issue certificates but connects rest of CAs Hub
32
CP
Certificate Policy
33
What is a CP
Rules that govern PKI Recommended baseline security
34
CPS
Certificate Practice Statement
35
What is a CPS
More technical How CA manages and uses
36
What is the 4 Certification life cycle
creation suspension revocation expiration
37
Key Escrow
Keys managed by 3rd party
38
M-of-N control
Private key divided and distrubited among people
39
What recovers lost or damaged certificates?
Key Recovery Agent
40
KRA
Key Recovery Agent
41
SSL
Secure Sockets Layer
42
What is SSL
By netscape addressed internet security encrypted path w client and server to be an OS
43
SSL stripping
Intercepting an HTTP connection
44
TLS
Transport Layer Security
45
What is TLS
Replaced SSL Perfect forward secrecy of public key exchange and encrypts handshakes after serverhello
46
Cipher suite
Encryption, authentication, Message Authentication Code browser and server initial connection descriptive names
47
SSH
Secure Shell
48
What is a SSH
alternative to telnet Linux/UNIX based commands slogin, ssh, scp
49
S/MIME
Secure/Multipurpose Internet Mail Extension
50
What is S/MIME
securing email how emails will be organized and encrypted
51
SRTP
Secure Real-Time Transport Protocol
52
What is SRTP
Like S/MIME Protects VoIP authentication and confidentiality
53
IPSec
Securing internet communications Encrypts and authenticates IP packets of session transparent OS or Hardware
54
AH
Authentication Header (IPSec)
55
ESP
Encapsulating Security Payload (IPSec)
56
ISAKMP/Oakley
Internet Security Association and Key Management Protocol encrypts Key Management (IPSec)
57
Transport Encryption
encrypts data only
58
Tunnel encryption
encrypts header and data network-to-network
59
Key strength
randomness cryptoperiod length
60
Keyspace
Character-set^Key-lengths
61
ECB
Electronic Code Book
62
What is an ECB
Most basic plaintext divided and encrypted chance of identical encryption not suitable
63
CBC
Cipher Block Chaining
64
What is CBC
Ciphertect block fed back in process to encrypt next 'XORed'
65
CTR
Counter
66
What is CTR
computes new value each ciphertext block is exchanged needs to be sync
67
GCM
Galois/Counter
68
What is GCM
encrypts and computes a MAC to ensure integrity adds ADD
69
ADD
Additional Authentication Data
70
Crypto Service Providers
crypto modules to do task part of OS often software and hardware