212-81V3 Sample Questions & Answers
Information theory, block ciphers, and cipher modes of operation take the largest share, built on classical cipher history, number theory behind asymmetric algorithms, certificate and authentication standards, cryptanalysis, and quantum computing's impact.
Launch the full 212-81V3 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Applications of Cryptography · PKI Infrastructure
The command to generate a new 4096-bit RSA private key using OpenSSL and save it to a file named
server.keyisopenssl genrsa -out server.key _____.Which value correctly completes the command?
Show answer & explanation
Correct answer: B
In the
openssl genrsacommand, the number of bits for the key size is specified as the last argument without any preceding flag. Therefore,4096is the correct value to complete the command. - Question 2Beginner
Introduction and History of Cryptography · Classical Ciphers
A cryptographer is analyzing an ancient cipher where each letter of the alphabet is consistently replaced by another single letter. For example, every 'A' becomes a 'Q', every 'B' becomes an 'X', and so on. The cryptographer successfully breaks the cipher by analyzing the frequency of letters in the ciphertext and comparing it to the known frequency of letters in the English language. What type of cipher is being analyzed?
Show answer & explanation
Correct answer: C
A mono-alphabetic substitution cipher uses a fixed substitution over the entire message. This preserves the underlying frequency distribution of the original language, making it vulnerable to frequency analysis, as described in the scenario. The Caesar and Atbash ciphers are specific examples of this type.
- Question 3Intermediate
Applications of Cryptography · VPN Technologies
A security team is configuring a site-to-site VPN using IPsec. They need to decide which mode to use. The goal is to encrypt the entire original IP packet, including the IP headers, and then encapsulate it within a new IP packet for transmission across the public network. This provides the highest level of security by hiding the original source and destination IP addresses from network eavesdroppers. Which IPsec mode should be used?
graph TD subgraph Original_Packet IP_Header TCP_Header Data end subgraph Encapsulated_Packet New_IP_Header IPsec_Header Encrypted_Original_Packet end Original_Packet -->|Encapsulation| Encrypted_Original_PacketShow answer & explanation
Correct answer: A
IPsec Tunnel Mode encrypts the entire original IP packet (header and payload) and encapsulates it within a new IP packet. This is ideal for site-to-site VPNs as it hides the internal network addressing. Transport Mode, in contrast, only encrypts the payload of the original packet, leaving the original IP header intact.
- Question 4Beginner
Symmetric Cryptography & Hashes · Hash Algorithms
A developer is choosing a hash function for a new application that requires high resistance to collision attacks. Which of the following algorithms has known practical collision attacks and should be avoided for this purpose?
Show answer & explanation
Correct answer: B
The MD5 algorithm has been cryptographically broken and is known to have practical collision attacks, meaning different inputs can be found that produce the same hash value. For applications requiring collision resistance, such as digital signatures, MD5 is considered insecure and should not be used. SHA-256, SHA-3, and BLAKE2 are all considered secure alternatives.
- Question 5Intermediate
Number Theory and Asymmetric Cryptography · Elliptic Curve Cryptography
When comparing RSA and Elliptic Curve Cryptography (ECC) for implementing public-key encryption, what is the primary advantage of using ECC?
Show answer & explanation
Correct answer: B
The main advantage of ECC over RSA is that it offers equivalent cryptographic strength with much smaller key sizes. For example, a 256-bit ECC key provides comparable security to a 3072-bit RSA key. This results in faster computations, lower power consumption, and reduced storage and bandwidth requirements, making ECC ideal for mobile and IoT devices.
- Question 6Intermediate
Applications of Cryptography · PKI Infrastructure
A systems administrator is troubleshooting a TLS handshake failure between a client and a web server. The client is reporting an 'unsupported certificate' error. The administrator inspects the certificate presented by the server and finds it was issued by an internal, private Certificate Authority (CA). What is the most likely cause of this error?
Show answer & explanation
Correct answer: C
For a TLS connection to be established, the client must trust the Certificate Authority that issued the server's certificate. In the case of a private CA, the CA's root certificate is not included in the default trust stores of browsers and operating systems. The client cannot validate the server's certificate chain back to a trusted root, causing the handshake to fail. The solution is to install the private CA's root certificate into the client's trust store.
- Question 7Intermediate
Applications of Cryptography · PGP Certificates
A software development team uses Pretty Good Privacy (PGP) to sign their software releases. Instead of relying on a central Certificate Authority, each developer signs the public keys of other developers they trust, creating a decentralized trust model. What is this PGP trust model called?
Show answer & explanation
Correct answer: B
The Web of Trust is a decentralized trust model used by PGP. Unlike the hierarchical model of X.509 PKI that relies on CAs, the Web of Trust allows any user to sign another user's public key certificate, vouching for the association between that public key and the person or entity listed on it. Trust is established based on these interconnected endorsements.
- Question 8Intermediate
Symmetric Cryptography & Hashes · DES and Variants
A security auditor is reviewing the design of a legacy system that uses the DES algorithm. The auditor notes that the 56-bit key size of DES is vulnerable to brute-force attacks with modern hardware. The system cannot be upgraded to AES, but a modification to the existing DES implementation is possible. Which of the following is the most common and standardized method to increase the effective key size and security of DES?
Show answer & explanation
Correct answer: C
Triple DES (3DES) is the standard method for overcoming the small key size of DES. It applies the DES cipher algorithm three times to each data block. The most common variant uses a Keying Option 1 (K1, K2, K1) approach, which involves an encrypt-decrypt-encrypt sequence with two different keys, providing an effective key length of 112 bits and significantly increasing its resistance to brute-force attacks.
- Question 9Intermediate
Number Theory and Asymmetric Cryptography · Diffie-Hellman
The Diffie-Hellman key exchange algorithm's security is based on the computational difficulty of which mathematical problem?
Show answer & explanation
Correct answer: C
The security of the classic Diffie-Hellman key exchange relies on the difficulty of the discrete logarithm problem. Given
g,p, andg^x mod p, it is computationally infeasible to findx. The integer factorization problem is the basis for RSA's security, and the elliptic curve discrete logarithm problem is the basis for ECDH/ECDSA. - Question 10Advanced
Applications of Cryptography · SSL/TLS
Case Study:
Company Background:
Global Logistics Inc. (GLI) is a large shipping and logistics company that operates a worldwide network of warehouses and transportation hubs. They are developing a new IoT-based tracking system for high-value cargo. Each cargo container will be equipped with a small, battery-powered device that reports its location, temperature, and shock sensor data to a central server every 15 minutes over a cellular network.Technical Requirements:
The data transmitted from the IoT devices must be encrypted to prevent eavesdropping and tampering. Due to the limited processing power and battery life of the devices, the chosen cryptographic solution must be highly efficient. The cryptographic keys used for each device must be unique and managed securely. The central server needs to authenticate each device to prevent spoofed data from being injected into the system.Security Concerns:
The security team is concerned about the long-term viability of the chosen cryptographic algorithm, especially given the expected 10-year lifespan of the tracking devices. They are particularly worried about the potential for a large-scale key compromise at the central server, which could expose the communications of the entire fleet of devices. Therefore, the compromise of the server's long-term key should not compromise the security of past communications.Question:
Given the constraints of the IoT devices and the security requirements, which of the following cryptographic solutions is the MOST appropriate for GLI to implement for securing the communication between the devices and the central server?Show answer & explanation
Correct answer: C
This solution addresses all requirements. ECC (ECDHE, ECDSA) is highly efficient and ideal for resource-constrained IoT devices. TLS 1.3 is the current standard for transport security. ECDHE provides Perfect Forward Secrecy, meeting the requirement that a server key compromise does not expose past sessions. AES-128-GCM provides authenticated encryption efficiently. Using a private CA is appropriate for managing device certificates within a closed ecosystem.
Ready for the real thing?
The full 212-81V3 simulator has every exam-style question, timed mode, and instant scoring.