High School AdvancedA14 Module Test25 Questions

Module Assessment

A14 — Cryptography and Key Management Concepts

This 25-question assessment checks whether you can reason across the complete cryptography architecture lifecycle: protection goals, encryption models, integrity, signing, PKI, key management, data protection, policy, recovery, evidence, and final design decisions.

Answers remain hidden until you use the quiz controls. The questions are defensive and conceptual; no real secrets, credentials, cryptographic attacks, or live-system testing are required.

Readiness Check

Before You Start

0/4 ready

Assessment Coverage

What the 25 Questions Measure

Questions 1–4Cryptography goals and encryption models

A14.1 Cryptography in System Design + A14.2 Symmetric and Asymmetric Encryption Concepts

Questions 5–7Hashing, salting, and integrity

A14.3 Hashing, Salting, and Integrity Concepts

Questions 8–10Digital signatures

A14.4 Digital Signatures Conceptually

Questions 11–14Certificates and PKI

A14.5 Certificates and PKI Concepts

Questions 15–17Key storage and rotation

A14.6 Key Storage and Rotation

Questions 18–19Crypto design mistakes

A14.7 Common Crypto Design Mistakes

Questions 20–22Encryption in transit and at rest

A14.8 Encryption in Transit and At Rest

Question 23Crypto policy and compliance

A14.9 Crypto Policy and Compliance Concepts

Questions 24–25Integrated architecture decisions

A14.10 Key Management Design Lab

Module Test

25 Questions — Answers Hidden Until Reveal

Check Your Understanding

A14 Module Test: Cryptography and Key Management Concepts

Choose your answers first. Explanations appear only after submission.

1. A security architect begins a cryptography review. What should be identified before choosing a cryptographic mechanism?

2. Which statement best describes symmetric encryption?

3. Which architecture problem is asymmetric cryptography especially useful for?

4. Why do many real systems use hybrid encryption concepts?

5. What is the primary conceptual difference between hashing and encryption?

6. Why is a unique salt used in password-verifier storage?

7. A file's observed hash matches a trusted reference digest. What does that support most directly?

8. What does a digital signature primarily add beyond a plain hash?

9. Which key should remain under narrow control in a digital-signature architecture?

10. Why does a valid digital signature not automatically authorize a business action?

11. What is the main purpose of a certificate in PKI?

12. What role does a root certificate authority play?

13. Which statement correctly distinguishes certificate expiration and revocation?

14. Why should production and development certificate trust be intentionally separated?

15. What is a major advantage of a managed key service?

16. Why is key versioning important during rotation?

17. What should happen before an old encryption-key version is retired?

18. Which situation is the clearest example of a crypto architecture mistake?

19. Why can strong cryptographic algorithms still be part of a weak design?

20. What is the main difference between encryption in transit and encryption at rest?

21. Why does database encryption at rest not replace database authorization?

22. What is strongest for an encrypted backup repository?

23. What makes a cryptography-policy exception well governed?

24. A backup key inventory is current, but the last full restore test is fourteen months old. What is the strongest decision?

25. An enterprise cryptography review finds strong modern controls but three high-impact Blocked legacy trust paths. What is the strongest final decision?

Performance Guide

Interpret Your Score

Strong

21–25

You can reason across cryptographic purpose, trust, key lifecycle, PKI, recovery, evidence, and governance. Review any missed questions before continuing.

Good

17–20

You understand most of the module. Revisit the lesson groups connected to your missed questions, especially lifecycle and integrated architecture decisions.

Partial

13–16

Several important distinctions still need reinforcement. Rebuild the affected portfolio artifacts and retake the test after review.

Rebuild

0–12

Return to the core sequence from protection goals through key management, PKI, data coverage, and governance before moving forward.

Targeted Review

Use Missed Questions to Decide What to Revisit

Return to A14.3

Confusing hashing with encryption

Focus: One-way digests, trusted references, integrity, salting, and password-verifier concepts.

Return to A14.4

Confusing signatures with encryption or authorization

Focus: Signer authenticity, private signing-key custody, verification trust, and authorization separation.

Return to A14.5

Weak PKI understanding

Focus: Certificate subject, issuer, root/intermediate trust, validity, renewal, revocation, and relying systems.

Return to A14.6

Weak rotation reasoning

Focus: Key scope, versions, dependency mapping, recovery, transition, and retirement.

Return to A14.7

Missing architecture mistakes

Focus: Hard-coded secrets, broad trust, environment overlap, stale ownership, lifecycle drift, and recovery gaps.

Return to A14.8

Transit vs. at-rest confusion

Focus: Data states, endpoint trust, storage boundaries, backups, exports, replication, and authorization separation.

Return to A14.9

Weak policy / exception reasoning

Focus: Policy, standards, evidence, exceptions, compensating controls, Accepted Risk, and review cadence.

Return to A14.10

Difficulty making final decisions

Focus: Evidence conflicts, Blocked vs. Conditional states, release criteria, remediation, validation evidence, and HOLD decisions.

Defender Habits

A14 Final Competency Checklist

Key Takeaways

What You Should Remember

1.Cryptography begins with protection goals and trust boundaries, not algorithm names.
2.Symmetric, asymmetric, hashing, signing, and certificate mechanisms solve different problems.
3.Private and secret key lifecycle is as important as the cryptographic mechanism itself.
4.PKI trust depends on identity binding, issuers, trust anchors, private-key custody, and lifecycle.
5.Strong algorithms can still sit inside weak architecture.
6.Transit and at-rest encryption protect different data states.
7.Authorization remains separate from cryptographic protection.
8.Recovery must be proven with current evidence.
9.Exceptions and Accepted Risks must be bounded, owned, and reviewable.
10.Material Blocked trust paths should drive final architecture decisions even when many other controls are healthy.

Portfolio Checkpoint

Enterprise Cryptography and Key Management Review

Your strongest A14 portfolio artifact should now connect protection goals, encryption models, integrity, signer trust, PKI, key lifecycle, transit/rest coverage, design mistakes, governance, exceptions, evidence states, remediation, residual risk, and a final architecture recommendation.

Assessment Safety Boundary

This assessment is conceptual and defensive

Do not attempt to crack encryption, recover real keys, extract secrets, forge signatures, manipulate certificates, alter trust stores, intercept protected traffic, or access real encrypted data. All scenarios in the module are fictional.

Module Complete

A14 — Cryptography and Key Management Concepts

After you finish the assessment and review any missed concepts, the next Advanced module is A15 — Risk Management and Compliance.