WorksheetsEncryption and Cryptography Quiz (Multiple Choice)
Total questions: 20
Worksheet time: 15mins
In the Caesar Cipher, what does the term 'plaintext' refer to?
The encrypted message
The original, unencrypted message
The encryption key
The decryption process
Why are symmetric encryption systems potentially vulnerable?
They are too slow
They require multiple keys
The key exchange process can be intercepted
They only work for short messages
What makes the Advanced Encryption Standard (AES) secure?
It uses multiple keys
Computers cannot realistically guess the key by brute force
It works only for small amounts of data
It is completely unbreakable
What problem does 'hashing with salt' solve in password protection?
It makes passwords longer
It prevents users from forgetting passwords
It ensures that identical passwords produce different hash values
It increases password complexity
In the context of healthcare systems, what does 'data in transit' refer to?
Data stored on physical servers
Data moving between different systems
Data permanently archived
Data waiting to be processed
What makes the RSA algorithm significant in cryptography?
It uses a single key for encryption
It allows safe key exchange using different keys
It works only for small messages
It is completely unbreakable
What is the primary challenge with storing passwords securely?
Remembering complex passwords
Preventing users from writing passwords down
Ensuring passwords cannot be reverse-engineered
Creating universally acceptable password rules
What is a potential weakness in basic password hashing?
Passwords are stored in plaintext
Users with identical passwords create identical hash values
Hashing is too slow
It requires constant internet connection
How does adding 'salt' improve password security?
It makes passwords longer
It ensures different hash values for identical passwords
It prevents password forgetting
It increases typing complexity
DoK 1: What is the key difference between symmetric and asymmetric encryption systems? Provide a concise definition of each.
DoK 1: In password hashing, what is the purpose of a salt?
To speed up encryption
To make identical passwords produce different hashes and resist precomputed attacks
To enable replay of logins
To convert symmetric keys into asymmetric keys
DoK 1: What is a key reason the RSA algorithm is significant in modern cryptography?
It is a classical cipher used for frequency analysis
It enables public-key cryptography for secure key exchange and digital signatures
It replaces all symmetric algorithms
It is primarily a rolling code system
DoK 3: A car thief records a valid rolling code transmission. Explain why replaying it later fails, and describe a condition under which a replay might still succeed.
In symmetric cryptosystems like the Advanced Encryption Standard (AES), what is the primary structural vulnerability known as the "key distribution problem"?
The encryption process is too computationally slow to handle bulk data.
Both parties must securely share the single identical key beforehand; if intercepted in transit, an attacker can decrypt all communications.
It relies on a mathematically linked key pair, which requires a public directory to distribute.
It is highly vulnerable to quantum computing decryption but perfectly secure against brute-force attacks.
During the verification of a digital signature, how does the recipient mathematically prove the integrity of the received document?
The recipient uses a symmetric AES key to scramble the file and checks if the resulting ciphertext is unreadable.
The recipient decrypts the signature using the sender's public key to recover the original digest, hashes the received document independently, and compares the two digests.
The recipient encrypts the document with their own private key and checks if it matches the sender's public key.
The recipient requests a new temporary session key from a RADIUS server to decrypt the entire document.
From an administrative and security perspective, why is WPA2-Personal (PSK) considered a significant risk for a school network compared to WPA2/WPA3-Enterprise?
Personal mode does not encrypt traffic in transit, exposing files to packet sniffers.
Personal mode uses a single pre-shared key for everyone; if one user's device is compromised, the entire network is exposed, and access cannot be revoked per-device.
Enterprise mode requires a physical hardware key (TPM chip) to be soldered to every student's laptop before they can connect.
Enterprise mode relies entirely on manual "dipping" of physical switches to grant network access.
Which encryption protocol is most commonly used to secure data transmitted over VPN connections?
SHA-1
MD5
AES
WEP
What is a key advantage of using a VPN with strong encryption for remote access?
It increases internet speed
It prevents unauthorized access to transmitted data
It disables firewall protection
It allows unlimited data usage
Which of the following best describes how VPN encryption protects user privacy?
By converting all data into unreadable ciphertext during transmission
By blocking all incoming connections
By hiding the user's device location
By storing passwords in plaintext
What is a major limitation of BitLocker device encryption?
It cannot encrypt operating system drives, only external USB storage.
It degrades network speed by adding immense cryptographic overhead to wireless traffic.
It is highly vulnerable to key extraction via legacy dial-in protocols.
It only protects "data at rest"; it does not block remote software-based threats (malware, phishing) while a user is actively logged in.
