certslothcertsloth
CCSP/Topic 03

ISC2 / Professional

Cryptography, Certificates and Keys

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Encrypt for secrecy; sign for origin; hash for comparison.

Must remember

Symmetric encryption uses a shared secret and is efficient for bulk data. Asymmetric cryptography uses a key pair for operations such as signatures or key establishment. TLS combines authenticated negotiation with efficient symmetric protection; it does not encrypt with a certificate as though the certificate were a secret key.

Hashing produces a digest without a decryption operation. Password storage needs a suitable salted password-hashing/key-derivation function with work cost; a fast unsalted hash is unsuitable. A salt is unique nonsecret input preventing identical passwords from sharing the same stored result. An HMAC uses a secret key to authenticate a message; a plain hash alone does not prove origin.

Digital signatures use a private signing key and public verification key. Encryption for a recipient and signing as a sender are different operations. PKI binds public keys to identities through certificates and trusted issuers. Validate chain, hostname/SAN, dates, intended use and revocation information such as CRLs/OCSP. A CSR requests issuance; a CA signs the certificate.

Key management includes generation, distribution, storage, access, rotation, revocation, backup and destruction. HSMs protect key operations; TPMs support device-bound measurements and key protection. Losing an encryption key without recovery can make intact backups unusable.

Tokenization replaces sensitive values with references, often using a protected mapping service. Masking obscures displayed data. Steganography hides the existence of a message; encryption hides meaning. Blockchain links records using cryptography and consensus but does not guarantee that input data was true.

Protect data in transit, at rest and in use with controls suited to each state. Cryptographic erase depends on effective key destruction and the absence of surviving usable key copies.

Choose under exam pressure

Requirement Choice and reason
Protect bulk stored data Symmetric encryption with controlled keys.
Verify a publisher A valid digital signature and trusted identity/key binding.
Reduce exposure in test datasets Approved masking, tokenization or synthetic data.

Traps

  • Base64 is encoding, not encryption.
  • A valid certificate does not prove the business behind a site is honest.

Active recall

1. Can a hash be decrypted?

No. It is not ciphertext; attackers instead test candidate inputs.

2. Which key verifies a signature?

The signer’s public verification key.

3. Why salt password hashes?

To make equal passwords produce different stored values and resist precomputed lookup reuse.

4. What does certificate hostname validation prevent?

Accepting an otherwise trusted certificate issued for a different endpoint identity.

5. Why protect encryption-key backups?

They preserve recovery capability but also preserve the ability to decrypt protected data.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.