Free Practice Quiz Question List

4 Cryptography Basics Online Quiz Questions

Use this free practice quiz with 20 questions to review 4 Cryptography Basics, test your knowledge, and prepare for your next test or exam.

20 questions
01
True or false
1 point

A system needs to keep messages confidential and detect tampering. It should not assume that ordinary encryption alone provides both protections.

  1. A

    True

  2. B

    False

02
Choose one
1 point

A sender encrypts a message for Bob using a public-key encryption scheme. Which key should Bob use to decrypt it?

  1. A

    Bob’s public key

  2. B

    Bob’s private key

  3. C

    The sender’s private key

  4. D

    A certificate authority’s key

03
Fill in the blank
1 point

A digital certificate binds a website’s identity to its .

04
Written response
1 point

Which two properties should a password-hashing scheme have to avoid relying on a fast general-purpose hash alone? Enter both properties in the format “X and Y.”

05
Choose one
1 point

A team needs to encrypt a large file efficiently, and the sender and recipient already share a secret key. Which approach best fits this task?

  1. A

    Use a digital signature algorithm to encrypt every part of the file.

  2. B

    Use a symmetric algorithm such as AES to encrypt the file.

  3. C

    Use an unkeyed hash function to encrypt the file.

  4. D

    Use a certificate authority to encrypt the file.

06
True or false
1 point

A digital signature can help verify data and its origin, but signing the data does not by itself make the data confidential.

  1. A

    True

  2. B

    False

07
Fill in the blank
1 point

To authenticate data and check its integrity using a shared secret, a system can use a keyed .

08
Written response
1 point

A cryptographic hash function maps data to a fixed-length value. What is that output called?

09
Choose all
1 point

Which statements about digital signature verification are supported? Select all correct answers.

  1. A

    Verification can provide evidence that the signed data has not changed.

  2. B

    Verification can provide evidence that the signature was made with the private key corresponding to the public key used for checking.

  3. C

    A valid signature by itself proves the signer’s real-world identity.

  4. D

    A digital signature encrypts the signed data.

10
Choose one
1 point

Two parties share a secret and need to check that a message has not changed and was created by someone with that secret. Which tool best fits their need?

  1. A

    An unkeyed hash, because anyone can calculate it.

  2. B

    A digital certificate, because it encrypts the message.

  3. C

    A keyed message authentication code (MAC), because the parties share a secret.

  4. D

    A plaintext checksum, because it identifies the sender.

11
Choose all
1 point

When a browser evaluates a website’s certificate, which checks are appropriate? Select all correct answers.

  1. A

    Check whether the certificate is valid for the requested domain name.

  2. B

    Check whether its path chains to a trusted certificate authority.

  3. C

    Check details such as its validity period and intended use.

  4. D

    Assume the certificate encrypts the traffic without further steps.

  5. E

    Accept any public key presented by the website without validation.

12
Open ended
1 point

A team is designing a browser-to-server connection that must authenticate the server and protect a large amount of data. Describe a suitable approach using certificate validation, the TLS handshake, and encryption. Include one key-management precaution.

13
Choose one
1 point

A service stores a message alongside its unkeyed hash. If an attacker can change both the message and the stored hash, what conclusion is correct?

  1. A

    The hash alone proves who created the message because it has fixed length.

  2. B

    The hash alone does not prove who created the message, because an attacker could calculate a new hash after changing it.

  3. C

    The hash encrypts the message so only its creator can read it.

  4. D

    The hash proves the message came from a trusted certificate authority.

14
Choose one
1 point

A team encrypts a file with a secret key shared by its sender and recipient. The recipient uses that same key to recover the file. Which kind of cryptography describes this arrangement?

  1. A

    Asymmetric cryptography, because each party uses a different key

  2. B

    Symmetric cryptography, because the same secret key is used for both operations

  3. C

    Hashing, because both parties calculate a digest

  4. D

    Digital signatures, because the sender creates a signature

15
Choose one
1 point

Two organizations need to establish shared key material, but they have not first distributed a shared secret key. Which approach is supported by the material?

  1. A

    Send a shared secret in an ordinary message before using cryptography

  2. B

    Use a hash function to turn the message into a shared secret

  3. C

    Use an asymmetric method to help establish shared key material

  4. D

    Use a digital certificate as the secret key

16
Choose one
1 point

A development team is choosing how to implement cryptographic protection for a new product. Which plan best follows the practical principles?

  1. A

    Adopt established protocols and reputable, maintained software

  2. B

    Design a new encryption algorithm so the organization controls every detail

  3. C

    Use an unverified public key if it makes deployment faster

  4. D

    Store keys with unrestricted access so recovery is simpler

17
Choose one
1 point

A system requirement is to establish which service is communicating with a client. Which cryptographic goal most directly matches that requirement?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Key rotation

  4. D

    Authentication

18
True or false
1 point

In asymmetric cryptography, the public key can be shared, while the corresponding private key must be protected.

  1. A

    True

  2. B

    False

19
Written response
1 point

Public-key methods can help parties set up shared key material without first distributing a shared secret. What is this task called?

20
Written response
1 point

A system needs to establish who or what is communicating. What cryptographic goal does this describe?