EC-Council Certified Encryption Specialist (ECES) Practice Questions
Prepare for 212-81 with more than an answer.
- Exam fee
- $250 USD
- Level
- Specialist
- Valid for
- 1 year (renewable annually with CE fees; 3-year ECE cycle requires ECE credits)
Domains covered on the exam 6
- Introduction and History of Cryptography12%
- Symmetric Cryptography and Hashes25%
- Number Theory and Asymmetric Cryptography22%
- Applications of Cryptography25%
- Cryptanalysis10%
- Quantum Computing and Cryptography6%
- 1
When implementing the Advanced Encryption Standard (AES) for a government database, an engineer must configure the algorithm according to FIPS 197 standards. If the engineer selects the AES-256 variant, how many internal processing rounds and what block size will the algorithm utilize?
Show answer details
Correct answer: A
The Advanced Encryption Standard (AES) maintains a fixed block size of exactly 128 bits, regardless of the key size. The number of internal rounds depends on the key length: AES-128 uses 10 rounds, AES-192 uses 12 rounds, and AES-256 uses 14 rounds.
- 2
While reviewing legacy systems, a security administrator discovers an old database field encrypted using the original Data Encryption Standard (DES). What is the actual effective key length of DES that determines its resistance to brute-force attacks?
Show answer details
Correct answer: B
While the total key size provided to the DES algorithm is 64 bits, 8 of those bits are used solely for parity checking. Therefore, the actual effective key length that contributes to cryptographic security is only 56 bits. This short key length is the primary reason DES is highly vulnerable to modern brute-force attacks.
- 3
Many classical and modern block ciphers, including DES and Blowfish, are built using a Feistel network structure. Which TWO of the following statements accurately describe properties of a Feistel cipher? (Select TWO)
Show answer details
Correct answer: A, C
One of the major advantages of a Feistel network is that the encryption and decryption processes are structurally identical. To decrypt, the exact same algorithm is run, but the subkeys are applied in reverse order. Furthermore, the round function (F-function) itself does not need to be mathematically reversible.
A standard Feistel network splits the input data block into a left half and a right half. In each round, the right half is passed through a round function (with a subkey), and the output is XORed with the left half. The halves are then swapped for the next round.
- 4
An organization is implementing a new digital contract system. The legal department requires that once a user signs a contract using their private key, they cannot later claim they did not authorize the transaction. Which cryptographic goal specifically addresses this legal requirement?
Show answer details
Correct answer: D
Non-repudiation is the cryptographic goal that ensures a sender cannot deny having sent a message or authorized a transaction. This is typically achieved through digital signatures, which bind the identity of the signer to the document. While authentication verifies identity, non-repudiation provides proof of origin that can be verified by a third party.
- 5
When configuring an Affine cipher using the mathematical formula E(x) = (ax + b) mod m, a cryptography student chooses a = 13 and m = 26 for the English alphabet. Why will this specific configuration fail to produce a reversible ciphertext?
Show answer details
Correct answer: B
For an Affine cipher to be reversible (decryptable), the key value 'a' must be coprime to the alphabet size 'm'. This means their greatest common divisor (GCD) must be 1. Since 13 and 26 share a common divisor of 13, 'a' does not have a modular multiplicative inverse mod 26. This causes multiple plaintext letters to map to the same ciphertext letter, destroying the data.
- 6
A cybersecurity analyst is examining a historical ciphertext intercepted during a forensics investigation. The text appears to be English but makes no sense. The analyst runs a frequency analysis and finds that the letter 'E' appears at a frequency of 3%, 'X' at 11%, and 'Q' at 12%. Furthermore, the analyst identifies that the sequence 'XRQ' repeats at intervals of 12, 24, and 36 characters.
Based on these findings, the analyst determines this is a polyalphabetic substitution cipher.
Which of the following techniques should the analyst use next to determine the exact length of the encryption key?
Show answer details
Correct answer: A
The Kasiski examination is used to break polyalphabetic ciphers like the Vigenere cipher. By finding repeating sequences of characters in the ciphertext and calculating the distances between them (12, 24, 36), the analyst can find the Greatest Common Divisor (GCD). The GCD represents the probable length of the keyword (in this case, likely 3, 4, 6, or 12). Once the key length is known, the ciphertext can be broken down into mono-alphabetic blocks for standard frequency analysis.
flowchart TD A[Identify Repeating Sequences] --> B[Calculate Distances Between Repeats] B --> C[Find Factors of Distances] C --> D[Determine GCD] D --> E[Probable Key Length]
