A14.1 Cryptography in System Design + A14.2 Symmetric and Asymmetric Encryption Concepts
Module Assessment
A14 — Cryptography and Key Management Concepts
This 25-question assessment checks whether you can reason across the complete cryptography architecture lifecycle: protection goals, encryption models, integrity, signing, PKI, key management, data protection, policy, recovery, evidence, and final design decisions.
Answers remain hidden until you use the quiz controls. The questions are defensive and conceptual; no real secrets, credentials, cryptographic attacks, or live-system testing are required.
Readiness Check
Before You Start
0/4 ready
Assessment Coverage
What the 25 Questions Measure
A14.3 Hashing, Salting, and Integrity Concepts
A14.4 Digital Signatures Conceptually
A14.5 Certificates and PKI Concepts
A14.6 Key Storage and Rotation
A14.7 Common Crypto Design Mistakes
A14.8 Encryption in Transit and At Rest
A14.9 Crypto Policy and Compliance Concepts
A14.10 Key Management Design Lab
Module Test
25 Questions — Answers Hidden Until Reveal
Check Your Understanding
A14 Module Test: Cryptography and Key Management Concepts
Choose your answers first. Explanations appear only after submission.
1. A security architect begins a cryptography review. What should be identified before choosing a cryptographic mechanism?
2. Which statement best describes symmetric encryption?
3. Which architecture problem is asymmetric cryptography especially useful for?
4. Why do many real systems use hybrid encryption concepts?
5. What is the primary conceptual difference between hashing and encryption?
6. Why is a unique salt used in password-verifier storage?
7. A file's observed hash matches a trusted reference digest. What does that support most directly?
8. What does a digital signature primarily add beyond a plain hash?
9. Which key should remain under narrow control in a digital-signature architecture?
10. Why does a valid digital signature not automatically authorize a business action?
11. What is the main purpose of a certificate in PKI?
12. What role does a root certificate authority play?
13. Which statement correctly distinguishes certificate expiration and revocation?
14. Why should production and development certificate trust be intentionally separated?
15. What is a major advantage of a managed key service?
16. Why is key versioning important during rotation?
17. What should happen before an old encryption-key version is retired?
18. Which situation is the clearest example of a crypto architecture mistake?
19. Why can strong cryptographic algorithms still be part of a weak design?
20. What is the main difference between encryption in transit and encryption at rest?
21. Why does database encryption at rest not replace database authorization?
22. What is strongest for an encrypted backup repository?
23. What makes a cryptography-policy exception well governed?
24. A backup key inventory is current, but the last full restore test is fourteen months old. What is the strongest decision?
25. An enterprise cryptography review finds strong modern controls but three high-impact Blocked legacy trust paths. What is the strongest final decision?
Performance Guide
Interpret Your Score
Strong
21–25You can reason across cryptographic purpose, trust, key lifecycle, PKI, recovery, evidence, and governance. Review any missed questions before continuing.
Good
17–20You understand most of the module. Revisit the lesson groups connected to your missed questions, especially lifecycle and integrated architecture decisions.
Partial
13–16Several important distinctions still need reinforcement. Rebuild the affected portfolio artifacts and retake the test after review.
Rebuild
0–12Return to the core sequence from protection goals through key management, PKI, data coverage, and governance before moving forward.
Targeted Review
Use Missed Questions to Decide What to Revisit
Confusing hashing with encryption
Focus: One-way digests, trusted references, integrity, salting, and password-verifier concepts.
Confusing signatures with encryption or authorization
Focus: Signer authenticity, private signing-key custody, verification trust, and authorization separation.
Weak PKI understanding
Focus: Certificate subject, issuer, root/intermediate trust, validity, renewal, revocation, and relying systems.
Weak rotation reasoning
Focus: Key scope, versions, dependency mapping, recovery, transition, and retirement.
Missing architecture mistakes
Focus: Hard-coded secrets, broad trust, environment overlap, stale ownership, lifecycle drift, and recovery gaps.
Transit vs. at-rest confusion
Focus: Data states, endpoint trust, storage boundaries, backups, exports, replication, and authorization separation.
Weak policy / exception reasoning
Focus: Policy, standards, evidence, exceptions, compensating controls, Accepted Risk, and review cadence.
Difficulty making final decisions
Focus: Evidence conflicts, Blocked vs. Conditional states, release criteria, remediation, validation evidence, and HOLD decisions.
Defender Habits
A14 Final Competency Checklist
Key Takeaways
What You Should Remember
Portfolio Checkpoint
Enterprise Cryptography and Key Management Review
Your strongest A14 portfolio artifact should now connect protection goals, encryption models, integrity, signer trust, PKI, key lifecycle, transit/rest coverage, design mistakes, governance, exceptions, evidence states, remediation, residual risk, and a final architecture recommendation.
Assessment Safety Boundary
This assessment is conceptual and defensive
Do not attempt to crack encryption, recover real keys, extract secrets, forge signatures, manipulate certificates, alter trust stores, intercept protected traffic, or access real encrypted data. All scenarios in the module are fictional.
Module Complete
A14 — Cryptography and Key Management Concepts
After you finish the assessment and review any missed concepts, the next Advanced module is A15 — Risk Management and Compliance.