Skip to content
ScopefileGet the app

Module 20Domain 9 of 9Cryptography

Cryptography: algorithms, PKI and cryptanalysis

Cryptography closes the CEH blueprint as Module 20, the whole of Domain 9, weighted at 5% in blueprint v5.0 as of Oct 11, 2026. It is mostly recall with little math: algorithm families, what each primitive guarantees, how PKI decides whom to trust, and the names of cryptanalysis attacks. Learn it late, in short daily sessions.

Exam
312-50
Domain
9 of 9
Domain weight
5%
This file
~5%
Targets
17

A study order that front-loads easy recall

  1. Sort the primitives

    Symmetric, asymmetric, hash. Every later question assumes you can file an algorithm name into one of the three on sight; the symmetric vs asymmetric vs hashing file drills the split.
  2. Attach a goal to each

    Confidentiality, integrity, key agreement or proof of origin. Map them back to the security principles in the introduction to ethical hacking module.
  3. Learn PKI as a trust decision

    Who issues a certificate, who checks the requester's identity, how a certificate is revoked and how a client finds out.
  4. Finish with attacks

    Cryptanalysis categories sorted by what the attacker holds. They are pure definitions, so they stick best in the final two weeks.

Algorithm names to file on sight

Families, names and the one thing to remember about each
FamilyNamesKeep in mind
Symmetric blockAES, DES, 3DES, Blowfish, TwofishAES encrypts 128-bit blocks with 128-, 192- or 256-bit keys (FIPS 197). DES's short key is the reason 3DES exists.
Symmetric streamRC4The cipher behind WEP's failure. Treat it as broken.
AsymmetricRSA, Diffie-Hellman, DSA, ECCDiffie-Hellman agrees a key; on its own it neither encrypts nor signs anything.
HashMD5, SHA-1, SHA-2, SHA-3MD5 and SHA-1 are for recognition only; new designs use SHA-2 or SHA-3.
Hybrid in practiceSecure protocols, S/MIME, disk toolsAsymmetric crypto sets up the session key, symmetric crypto moves the bulk data.

AES block and key sizes from NIST FIPS 197 (updated May 2023).

PKI, disks and mail

A certificate binds a public key to an identity and carries the signature of a certificate authority (CA). A registration authority (RA) checks the requester's identity before the CA issues. When a certificate has to die early, the CA either publishes it on a certificate revocation list (CRL) or answers live status queries through OCSP. The first is a list the client downloads; the second is a real-time lookup.

Disk encryption comes in two scopes. Full-disk encryption covers the whole volume, operating system included; file- or folder-level encryption covers only what you select. Either protects a device that is powered off or stolen. Neither helps much once the system is running and the user is signed in.

Hashes and modes

A hash proves integrity only if nobody can swap the hash along with the data, which is why HMAC mixes a secret key into the hash and why signatures are applied to hashes. For stored passwords, a random salt per account makes precomputed tables useless and hides the fact that two users share a password.

Block cipher modes are worth one line each. ECB encrypts identical blocks identically, so patterns in the plaintext survive into the ciphertext. CBC chains each block to the one before. GCM adds authentication, so tampering is detected on decryption.

Mail encryption shows up in two trust models: S/MIME trusts certificates from a CA hierarchy, while web-of-trust tools rely on users vouching for each other's keys.

Steganography sits next door

Cryptography hides what a message says; steganography hides that there is a message at all. Steganalysis is the job of detecting the hidden payload. The pair also appears in the system hacking module, under hiding files.

Put the algorithms to work

Each option note names the job that algorithm or protocol actually does. Read the notes on the options you ruled out quickly as well as on your misses.

Answered 0/17Hits 0

T-01

A client trusts the root CA but rejects a web server's certificate during the TLS handshake. What is the MOST likely cause?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEvery certificate carries a public key; a key-less certificate is not a realistic cause of chain validation failure.
  2. BA cipher-suite mismatch causes the handshake to fail during negotiation, not a rejection of the server's certificate chain.
  3. CThe stem says the client trusts the root CA, so the trust anchor is already in place.
  4. DCorrect: if the server omits the intermediate CA certificate, the client cannot build a path from the server certificate to its trusted root.
T-02

Which cryptography tool would be most appropriate for securing email communications by ensuring data integrity and authenticity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMD5 is a hash function, not an email security tool, and it is deprecated for security use because practical collisions exist.
  2. BCorrect: PGP signs messages for integrity and authenticity and encrypts them for confidentiality, making it a standard tool for securing email.
  3. CVeraCrypt encrypts disks and file containers at rest; it does not sign or protect individual email messages.
  4. DSSL only protects a connection hop between servers and is deprecated in favor of TLS; it does not prove who wrote a message.
T-03

An organization shifts to 7-day short-lived certificates to eliminate OCSP checking overhead. What primary operational risk does this introduce?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACertificate lifetime has no effect on symmetric encryption speed, which depends on the negotiated cipher and hardware.
  2. BKey collisions are not a practical risk from frequent issuance; properly generated keys are effectively unique.
  3. CCorrect: weekly expiry means any renewal failure quickly becomes an outage, so short-lived certificates depend on reliable automated issuance and deployment.
  4. DBrowsers fully support short-lived certificates, and the industry is moving toward shorter lifetimes rather than away from them.
T-04

Which public-key cryptosystem uses elliptic curve mathematics to perform computations and is considered highly efficient for encryption and digital signatures?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADES is a symmetric block cipher, not public-key cryptography, and is deprecated because its 56-bit key is easily brute-forced.
  2. BBlowfish is a symmetric block cipher, not a public-key system, and it does not use elliptic curves.
  3. CRSA is public-key cryptography based on factoring large integers, not on elliptic curves, and needs much larger keys for equivalent strength.
  4. DCorrect: ECC builds public-key operations on elliptic curves, giving strong security with small keys, which suits signatures and key exchange on constrained devices.
T-05

Two ciphertexts were generated using AES-CTR with the same 256-bit key and identical 128-bit nonce. The first ciphertext encrypts a known plaintext header "TRANSACTION:" and the second encrypts an unknown payment amount. What can an attacker derive without recovering the AES key?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: reusing a nonce reuses the keystream, so XORing the ciphertexts yields the XOR of the plaintexts, and the known header exposes the matching bytes of the other message.
  2. BNonce reuse breaks CTR mode's confidentiality; the scheme is secure only when each nonce and key pair is used once.
  3. CKeystream reuse leaks plaintext relationships, but it does not reveal the AES key itself.
  4. DPlain CTR mode produces no authentication tag; tag forgery is a concern for GCM, which adds authentication on top of counter mode.
T-06

What category of cryptography tool allows an attacker to recover the plaintext from a given ciphertext without the key?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASteganography tools hide data inside other files such as images; they do not break encryption.
  2. BDecryption tools turn ciphertext back into plaintext using the correct key, which is the normal legitimate use of encryption.
  3. CEncryption tools turn plaintext into ciphertext; they work in the opposite direction from the stem.
  4. DCorrect: cryptanalysis tools try to recover plaintext or keys without authorized key access, by exploiting weak algorithms, implementations or keys.
T-07

In the context of network security, what term describes data that is actively being transferred from one location to another over a network?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: data in transit is data moving across a network, protected with protocols such as TLS, IPsec or SSH.
  2. BData at rest is stored on disks, databases or backups, protected with storage encryption rather than transport protocols.
  3. CData in memory, also called data in use, is being processed in RAM, not traveling across a network.
  4. DData offline is not a standard data-state category; the usual three are at rest, in transit and in use.
T-08

During a security audit, you identify that several email servers still support the outdated TLS 1.0 protocol. Which of the following vulnerabilities are you MOST LIKELY to exploit to compromise these servers?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASMB relay attacks abuse NTLM authentication over file-sharing protocols and have nothing to do with TLS 1.0.
  2. BHeartbleed was an OpenSSL heartbeat implementation bug that affected specific library versions regardless of protocol version, so TLS 1.0 support does not signal it.
  3. CDNS cache poisoning targets resolvers to redirect names; it is unrelated to the TLS version a mail server offers.
  4. DCorrect: BEAST targets CBC ciphers in SSL 3.0 and TLS 1.0; TLS 1.0 and 1.1 are deprecated and should be disabled in favor of TLS 1.2 or 1.3.
T-09

A high-traffic web server requires forward secrecy but struggles with CPU overhead during TLS handshakes. Which configuration best optimizes performance while minimizing the impact of a potential private key compromise?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AStatic RSA key exchange gives no forward secrecy, so a stolen private key decrypts every recorded past session.
  2. BAES-GCM protects the session data, but without an ephemeral key exchange a private key compromise still exposes past traffic.
  3. CCorrect: ECDHE provides forward secrecy with ephemeral keys and is far cheaper computationally than finite-field DHE at equivalent strength.
  4. DDHE does provide forward secrecy, but its large modular arithmetic makes handshakes CPU-heavy, the exact problem the server already has.
T-10

An organization enforces a manual cryptographic key rotation policy every 24 hours. Recently, this has led to widespread service outages. What is the primary risk of this overly aggressive policy?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: daily manual rotation multiplies opportunities for human error, and a missed or mismatched key update breaks services, so availability suffers.
  2. BModern systems gather ample entropy, so frequent key generation does not by itself produce weak keys.
  3. CGenerating keys more often does not meaningfully increase side-channel timing exposure compared to the outage risk.
  4. DKey rotation does not open a chosen-ciphertext window; that attack depends on algorithm and padding design, not rotation frequency.
T-11

Which attack on cryptographic hash functions relies on finding two different inputs that produce the same hash value?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a collision attack searches for two distinct inputs with the same hash, which breaks signature and integrity guarantees, as shown for MD5 and SHA-1.
  2. BA man-in-the-middle attack intercepts communication between two parties; it does not look for hash collisions.
  3. CA dictionary attack guesses passwords from a word list and compares hashes, aiming to find the original input rather than a colliding pair.
  4. DA rainbow table attack uses precomputed hash chains to reverse unsalted password hashes, not to find two inputs with the same digest.
T-12

Which technology creates an encrypted tunnel between two points across a public network like the internet?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA CDN caches content at edge servers to speed delivery; it is not a private encrypted tunnel between two endpoints.
  2. BCorrect: a VPN encrypts traffic between endpoints or sites over the public internet, using protocols such as IPsec, WireGuard or TLS.
  3. CNAT rewrites addresses so private hosts can share public IPs; it provides no encryption.
  4. DSDN separates the network control plane from forwarding hardware for central management; it is not inherently an encrypted tunnel.
T-13

What is the primary weakness that quantum computing threatens in modern cryptography?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGrover's algorithm only halves effective symmetric key strength, so doubling key length, as with AES-256, keeps symmetric ciphers safe.
  2. BQuantum computing does not inherently break random number generation; weak RNGs are a classical implementation problem.
  3. CCorrect: Shor's algorithm would efficiently factor integers and solve discrete logarithms, breaking RSA, Diffie-Hellman and ECC, which drives post-quantum migration.
  4. DCertificate validation fails indirectly only because the underlying signatures rely on vulnerable public-key math, not as a separate weakness.
T-14

Which encryption method is commonly used to secure communications over the internet between web browsers and servers?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARSA is used inside TLS for key exchange or signatures, but it is an algorithm, not the protocol that secures browser traffic.
  2. BCorrect: TLS secures browser-server traffic; SSL is its deprecated predecessor, and today only TLS 1.2 and 1.3 should be enabled.
  3. CMD5 is a hash function, not an encryption protocol, and it is deprecated for security use because of practical collisions.
  4. DDES is an obsolete symmetric cipher with a 56-bit key that is easily brute-forced and is not used for modern web traffic.
T-15

What term describes the process of converting information into an unreadable format to protect it from unauthorized access during transmission?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADecryption is the reverse process, turning ciphertext back into readable plaintext with the right key.
  2. BEncoding changes data format for compatibility, such as Base64, and can be reversed by anyone without a key.
  3. CA firewall filters network traffic by rules; it does not transform data into an unreadable form.
  4. DCorrect: encryption uses an algorithm and key to turn plaintext into ciphertext that only key holders can read.
T-16

What is the purpose of a Key Distribution Center (KDC) in Kerberos authentication?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AKerberos does not encrypt all network traffic; it handles authentication and issues keys that applications may use.
  2. BCorrect: the KDC, made up of the authentication service and ticket-granting service, issues ticket-granting tickets, service tickets and session keys.
  3. CThe KDC holds long-term keys derived from passwords, but storing passwords is not its purpose; its job is issuing tickets.
  4. DValidating digital signatures is a PKI function; Kerberos relies on symmetric keys and tickets rather than certificates.
T-17

What is the primary purpose of a digital signature?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APassword storage uses salted, slow hashing; digital signatures are not used to store or protect user passwords.
  2. BKey exchange is handled by protocols such as Diffie-Hellman; digital signatures may authenticate an exchange but are not its purpose.
  3. CCorrect: a digital signature, made with the sender's private key, proves who signed the data and that it was not altered, supporting non-repudiation.
  4. DSignatures do not hide content; confidentiality requires encryption, and a signed message remains readable unless it is also encrypted.

File every algorithm name as symmetric, asymmetric or hash before you reread the question.

Cryptanalysis by what the attacker holds

Ciphertext-only
Only encrypted output. The weakest position, and the baseline every cipher must survive.
Known-plaintext
Some plaintext together with its matching ciphertext.
Chosen-plaintext
The attacker can get inputs of their choice encrypted and study the results.
Chosen-ciphertext
The attacker can get ciphertexts of their choice decrypted.
Side-channel
Timing, power draw or emissions from the hardware running the algorithm. The math is never touched.
Meet-in-the-middle
Works on double encryption from both ends at once, which is why double DES never replaced DES.
Rubber-hose
Coercing or bribing the key holder. It is on the list because it bypasses every algorithm.

Sources