Cryptography & PKI
18 practice questions with explanations — 15 free to try
2 of these 18 questions are in the free 15-question taster · the full topic is part of Premium
PassNova has 18 GIAC GSEC (Security Essentials) practice questions on Cryptography & PKI, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Cryptography & PKI: example questions & answers
2 worked examples with answers and explanations below. Try 15 GIAC GSEC (Security Essentials) questions free in the browser; the full 18-question Cryptography & PKI bank is part of PassNova Premium.
Which statement correctly describes symmetric encryption?
- AThe same secret key both encrypts and decrypts the data✓
- BA public key encrypts and a matching private key decrypts
- CA one-way function reduces data to a fixed-length digest
- DNo shared secret is needed between the two parties
Answer: Symmetric algorithms such as AES and ChaCha20 use one shared secret key for both encryption and decryption, which makes them fast enough for bulk data but raises the problem of distributing that key securely. A public/private key pair is asymmetric cryptography, a one-way digest is hashing, and removing the need for a pre-shared secret is what asymmetric key exchange provides.
A software vendor publishes a SHA-256 value next to each download. Which property of the hash lets users detect a tampered file?
- AThe digest can be decrypted to recover the original file
- BAny change to the file produces a different digest✓
- CSHA-256 compresses the file so that it downloads faster
- DThe digest grows in length along with the file's size
Answer: A cryptographic hash maps any input to a fixed-length digest (256 bits for SHA-256), and even a one-bit change produces a completely different value, so recomputing the hash with Get-FileHash or sha256sum and comparing reveals tampering. Hashes are one-way, so nothing can be decrypted from them, and they neither compress data nor grow with the input. The published value must come from a trusted channel, ideally signed, or an attacker can swap both.