Skip to content

212-81V3 Certified Encryption Specialist (ECES v3) Practice Questions

Prepare for 212-81V3 with more than an answer.

253 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$250 USD
Level
Specialist
Domains covered on the exam 6
  1. Introduction and History of Cryptography15%
  2. Symmetric Cryptography & Hashes30%
  3. Number Theory and Asymmetric Cryptography25%
  4. Applications of Cryptography20%
  5. Cryptanalysis5%
  6. Quantum Computing and Cryptography5%
  1. 1

    A security researcher is using steganalysis to detect the presence of hidden messages in a large set of digital images. The researcher's technique involves analyzing the statistical properties of the least significant bits (LSB) of the pixel color values and comparing them to the expected statistical properties of untouched images. Which of the following steganalysis techniques is being described?

    Show answer details

    Correct answer: D

    Chi-Square analysis is a statistical method used in steganalysis to detect LSB steganography. It measures how the observed frequencies of color values in an image (the 'pairs of values') deviate from the expected frequencies. When data is embedded in the LSBs, it disrupts the natural statistical properties of the image, which can be detected by a Chi-Square test.

  2. 2

    A cryptographer is designing a system that requires a Message Authentication Code (MAC) to ensure both data integrity and authenticity. They decide to construct the MAC using a cryptographic hash function and a secret key. Which of the following is a standardized and widely accepted construction for creating a MAC from a hash function?

    Show answer details

    Correct answer: B

    HMAC is a specific type of MAC that involves a cryptographic hash function in combination with a secret cryptographic key. It follows a standard construction (RFC 2104) that was designed to be secure even when the underlying hash function has certain weaknesses. It is widely used in protocols like TLS and IPsec to provide message authenticity and integrity.

  3. 3

    The security of the RSA cryptosystem is based on the difficulty of factoring the product of two large prime numbers. True or False?

    Show answer details

    Correct answer: A

    True. The security of the RSA algorithm relies on the fact that it is easy to multiply two large prime numbers to get their product (the modulus n), but it is computationally very difficult to perform the reverse operation: factoring n back into its original prime components. This is known as the integer factorization problem.

  4. 4

    Which of the following are characteristics of the Electronic Codebook (ECB) mode of operation for a block cipher? (Select TWO)

    Show answer details

    Correct answer: A, C

    ECB mode is deterministic because each block is encrypted independently of all other blocks. This means that if the same plaintext block appears multiple times in a message, it will always produce the same ciphertext block, which can leak information about the plaintext.

    Since each block in ECB mode is encrypted independently, the encryption process for multiple blocks can be parallelized, which can be a performance advantage in some applications.

  5. 5

    A cryptanalyst has intercepted several ciphertexts that were all encrypted with the same key. The analyst does not have access to any of the corresponding plaintexts. Which type of cryptanalytic attack is the analyst limited to performing?

    Show answer details

    Correct answer: C

    In a ciphertext-only attack, the attacker only has access to a set of ciphertexts. This is the most difficult type of attack to mount as the attacker has the least amount of information. The goal is to deduce the key or the plaintext through statistical analysis or by finding weaknesses in the algorithm.

  6. 6

    A financial institution is implementing a new secure messaging system. The primary requirement is that if the long-term private key of a recipient is compromised, an attacker should not be able to decrypt past messages that were sent to that recipient. Which cryptographic property must the key exchange protocol implement to meet this requirement?

    Show answer details

    Correct answer: B

    Perfect Forward Secrecy (PFS) ensures that a session key derived from a set of long-term keys will not be compromised if one of the long-term private keys is compromised in the future. This is achieved by generating new, ephemeral keys for each session and then discarding them. Diffie-Hellman Ephemeral (DHE) and Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) are common key exchange mechanisms that provide PFS.

  7. 7

    A developer is implementing AES encryption for a system that transmits large video files. Due to potential packet loss on the network, a requirement is that the corruption of a single ciphertext block must not affect the decryption of subsequent blocks. Additionally, the encryption process for different blocks should be parallelizable to improve performance. Which block cipher mode of operation should be selected?

    Show answer details

    Correct answer: C

    Counter (CTR) mode turns a block cipher into a stream cipher. It encrypts a counter value which is then XORed with the plaintext. This means each block's encryption/decryption is independent of others, allowing for parallel processing. A corrupted ciphertext block only affects the corresponding plaintext block, preventing error propagation, which is ideal for streaming media over unreliable networks.

  8. 8

    A security analyst is investigating a data breach where password hashes were exfiltrated. The hashes were generated using a standard MD5 algorithm without any additional security measures. The analyst plans to use precomputed hash values to crack the passwords. Which of the following attack methods is the analyst employing? (Select TWO)

    Show answer details

    Correct answer: A, D

    Rainbow tables are a specific type of precomputed lookup table used to reverse cryptographic hash functions, typically for cracking password hashes. They are highly effective against unsalted hashes like the ones described.

    A rainbow table attack is a classic example of a time-memory trade-off attack. It uses a large amount of storage (memory) to precompute hash chains, which significantly reduces the time required to crack each individual password compared to a brute-force attack.

  9. 9

    True or False: The primary purpose of the S-box (Substitution-box) within a Feistel network-based block cipher like DES is to provide the property of diffusion.

    Show answer details

    Correct answer: B

    False. The primary purpose of the S-box is to provide confusion, which obscures the relationship between the key and the ciphertext. Diffusion, which spreads the influence of a single plaintext bit over many ciphertext bits, is primarily provided by the P-box (Permutation-box) in ciphers like DES.

  10. 10

    A government agency needs to select a post-quantum cryptography algorithm for securing classified communications. Their primary concern is establishing a shared secret over an insecure channel, which must be resistant to attacks from future quantum computers. They are evaluating the candidates from the NIST Post-Quantum Cryptography (PQC) standardization process. Which of the following algorithms is specifically designed for Key Encapsulation Mechanisms (KEM) and has been selected by NIST as a primary standard for this purpose?

    Show answer details

    Correct answer: C

    CRYSTALS-Kyber is a lattice-based Key Encapsulation Mechanism (KEM) that NIST has selected as the primary standard for general-purpose public-key encryption and key establishment in the post-quantum era. CRYSTALS-Dilithium and SPHINCS+ are digital signature algorithms, not KEMs.

Create an account to continue.