Certified Encryption Specialist (ECES v3) Free Sample Questions

20 free sample questions253 in the full practice test

Try simulator

212-81V3 Sample Questions

  1. Question 1

    A financial institution is implementing a new secure messaging system. The primary requirement is that if the long-term private key of a recipient is compromised, an attacker should not be able to decrypt past messages that were sent to that recipient. Which cryptographic property must the key exchange protocol implement to meet this requirement?

    Answer and explanation

    Correct answer: B

    Perfect Forward Secrecy (PFS) ensures that a session key derived from a set of long-term keys will not be compromised if one of the long-term private keys is compromised in the future. This is achieved by generating new, ephemeral keys for each session and then discarding them. Diffie-Hellman Ephemeral (DHE) and Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) are common key exchange mechanisms that provide PFS.

  2. Question 2

    A developer is implementing AES encryption for a system that transmits large video files. Due to potential packet loss on the network, a requirement is that the corruption of a single ciphertext block must not affect the decryption of subsequent blocks. Additionally, the encryption process for different blocks should be parallelizable to improve performance. Which block cipher mode of operation should be selected?

    Answer and explanation

    Correct answer: C

    Counter (CTR) mode turns a block cipher into a stream cipher. It encrypts a counter value which is then XORed with the plaintext. This means each block's encryption/decryption is independent of others, allowing for parallel processing. A corrupted ciphertext block only affects the corresponding plaintext block, preventing error propagation, which is ideal for streaming media over unreliable networks.

  3. Question 3

    Multiple answers

    A security analyst is investigating a data breach where password hashes were exfiltrated. The hashes were generated using a standard MD5 algorithm without any additional security measures. The analyst plans to use precomputed hash values to crack the passwords. Which of the following attack methods is the analyst employing? (Select TWO)

    Answer and explanation

    Correct answers: A, D

    Rainbow tables are a specific type of precomputed lookup table used to reverse cryptographic hash functions, typically for cracking password hashes. They are highly effective against unsalted hashes like the ones described.

    A rainbow table attack is a classic example of a time-memory trade-off attack. It uses a large amount of storage (memory) to precompute hash chains, which significantly reduces the time required to crack each individual password compared to a brute-force attack.

  4. Question 4

    True or False: The primary purpose of the S-box (Substitution-box) within a Feistel network-based block cipher like DES is to provide the property of diffusion.

    Answer and explanation

    Correct answer: B

    False. The primary purpose of the S-box is to provide confusion, which obscures the relationship between the key and the ciphertext. Diffusion, which spreads the influence of a single plaintext bit over many ciphertext bits, is primarily provided by the P-box (Permutation-box) in ciphers like DES.

  5. Question 5

    A government agency needs to select a post-quantum cryptography algorithm for securing classified communications. Their primary concern is establishing a shared secret over an insecure channel, which must be resistant to attacks from future quantum computers. They are evaluating the candidates from the NIST Post-Quantum Cryptography (PQC) standardization process. Which of the following algorithms is specifically designed for Key Encapsulation Mechanisms (KEM) and has been selected by NIST as a primary standard for this purpose?

    Answer and explanation

    Correct answer: C

    CRYSTALS-Kyber is a lattice-based Key Encapsulation Mechanism (KEM) that NIST has selected as the primary standard for general-purpose public-key encryption and key establishment in the post-quantum era. CRYSTALS-Dilithium and SPHINCS+ are digital signature algorithms, not KEMs.

  6. Question 6

    The command to generate a new 4096-bit RSA private key using OpenSSL and save it to a file named server.key is openssl genrsa -out server.key _____.

    Which value correctly completes the command?

    Answer and explanation

    Correct answer: B

    In the openssl genrsa command, the number of bits for the key size is specified as the last argument without any preceding flag. Therefore, 4096 is the correct value to complete the command.

  7. Question 7

    A cryptographer is analyzing an ancient cipher where each letter of the alphabet is consistently replaced by another single letter. For example, every 'A' becomes a 'Q', every 'B' becomes an 'X', and so on. The cryptographer successfully breaks the cipher by analyzing the frequency of letters in the ciphertext and comparing it to the known frequency of letters in the English language. What type of cipher is being analyzed?

    Answer and explanation

    Correct answer: C

    A mono-alphabetic substitution cipher uses a fixed substitution over the entire message. This preserves the underlying frequency distribution of the original language, making it vulnerable to frequency analysis, as described in the scenario. The Caesar and Atbash ciphers are specific examples of this type.

  8. Question 8

    A security team is configuring a site-to-site VPN using IPsec. They need to decide which mode to use. The goal is to encrypt the entire original IP packet, including the IP headers, and then encapsulate it within a new IP packet for transmission across the public network. This provides the highest level of security by hiding the original source and destination IP addresses from network eavesdroppers. Which IPsec mode should be used?

    graph TD subgraph Original_Packet IP_Header TCP_Header Data end subgraph Encapsulated_Packet New_IP_Header IPsec_Header Encrypted_Original_Packet end Original_Packet -->|Encapsulation| Encrypted_Original_Packet

    Answer and explanation

    Correct answer: A

    IPsec Tunnel Mode encrypts the entire original IP packet (header and payload) and encapsulates it within a new IP packet. This is ideal for site-to-site VPNs as it hides the internal network addressing. Transport Mode, in contrast, only encrypts the payload of the original packet, leaving the original IP header intact.

  9. Question 9

    A developer is choosing a hash function for a new application that requires high resistance to collision attacks. Which of the following algorithms has known practical collision attacks and should be avoided for this purpose?

    Answer and explanation

    Correct answer: B

    The MD5 algorithm has been cryptographically broken and is known to have practical collision attacks, meaning different inputs can be found that produce the same hash value. For applications requiring collision resistance, such as digital signatures, MD5 is considered insecure and should not be used. SHA-256, SHA-3, and BLAKE2 are all considered secure alternatives.

  10. Question 10

    When comparing RSA and Elliptic Curve Cryptography (ECC) for implementing public-key encryption, what is the primary advantage of using ECC?

    Answer and explanation

    Correct answer: B

    The main advantage of ECC over RSA is that it offers equivalent cryptographic strength with much smaller key sizes. For example, a 256-bit ECC key provides comparable security to a 3072-bit RSA key. This results in faster computations, lower power consumption, and reduced storage and bandwidth requirements, making ECC ideal for mobile and IoT devices.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 253 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon