Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free WGU Introduction to Cryptography Introduction-to-Cryptography Exam Questions

Page: 1 / 10 Total 93 questions

Want more questions? Get Premium Access.

Question 1

(What are the primary characteristics of Bitcoin proof of work?)

Correct Answer: B. Difficult to produce and easy to verify
Explanation:

Bitcoin's proof of work (PoW) is designed so that finding a valid block is computationally difficult, but checking validity is computationally easy. Miners must repeatedly hash candidate block headers (double SHA-256) with different nonces until they find a hash value below a network-defined target. This trial-and-error search requires significant work and energy because the probability of success per attempt is extremely low at current difficulty levels. However, verification is straightforward: any node can hash the block header once (or a small number of times) and confirm the resulting hash meets the target threshold and that the block contents follow protocol rules. This ''hard to produce, easy to verify'' property is essential: it makes it expensive for attackers to rewrite history or outpace honest miners, while allowing all participants---even low-power devices---to validate blocks efficiently. Therefore, the primary characteristic of Bitcoin proof of work is that it is difficult to produce and easy to verify.


Question 2

(Which encryption algorithm uses an 80-bit key and operates on 64-bit data blocks?)

Correct Answer: D. Skipjack
Explanation:

Skipjack is a symmetric block cipher historically associated with the Clipper chip initiative. Its defining parameters match the question: it operates

on 64-bit blocks and uses an 80-bit key. The other options do not fit those exact sizes. Twofish is a 128-bit block cipher with key sizes up to 256 bits. Blowfish is a 64-bit block cipher, but its key size is variable from 32 up to 448 bits and is not fixed at 80 bits as a defining property. Camellia is a 128-bit block cipher with key sizes of 128, 192, or 256 bits. Skipjack's smaller key size and legacy design make it unsuitable for modern security needs, but the question is purely about identifying the algorithm that matches an 80-bit key and 64-bit blocks. Therefore, the correct answer is Skipjack.


Question 3

(What is a digital signature?)

Correct Answer: B. A cryptographic technique to verify the authenticity and integrity of a message
Explanation:

A digital signature is a cryptographic mechanism that enables a recipient to verify who created a message (authenticity) and that the message has not been altered (integrity). It is typically built using asymmetric cryptography: the signer uses a private key to sign a hash (digest) of the message, producing a signature. Anyone with the signer's public key can verify that the signature matches the message digest, confirming the signature was created by the corresponding private key and that the content remains unchanged. Digital signatures do not primarily provide confidentiality; the signed message may still be readable unless separately encrypted. They also support nonrepudiation in many operational contexts because a valid signature can be strong evidence that the private key holder authorized the signed data, assuming key protection and policy controls. Common digital signature algorithms include RSA-PSS, ECDSA, and EdDSA. Certificates (X.509) are often used to bind public keys to identities, allowing verifiers to trust the claimed signer. Therefore, the best definition is a technique to verify authenticity and integrity.


Question 4

(What is used to randomize the initial value when generating Initialization Vectors (IVs)?)

Correct Answer: D. Nonce
Explanation:

An IV (Initialization Vector) is a value used to ensure that encrypting identical plaintext under the same key produces different ciphertexts, preventing pattern leakage. In many secure designs, the IV must be unique (and often unpredictable) per encryption operation. A common way to ensure uniqueness is to incorporate a nonce---a ''number used once.'' A nonce can be random, pseudo-random, or a counter-based value depending on the mode and security requirements. For example, CTR mode uses a nonce combined with a counter to produce unique input blocks; GCM uses a nonce/IV to ensure unique authentication and encryption behavior. The encryption key should remain stable across many operations and should not be used as the ''randomizer'' for IV generation; mixing key material into IV creation in an ad hoc way can create reuse or correlation issues. Plaintext and algorithm do not provide the needed uniqueness property. The nonce concept is specifically about ensuring one-time uniqueness of the starting value so that IV reuse does not repeat keystream blocks (stream modes) or reveal plaintext equality (CBC/CTR). Therefore, the correct choice is Nonce.


Question 5

(What is a key benefit of using a cryptography framework?)

Correct Answer: D. It provides a structured approach to implementing encryption practices.
Explanation:

A cryptography framework provides a consistent, repeatable way to select, deploy, and manage cryptographic controls across an organization. Its key benefit is structure: it defines approved algorithms and key sizes, acceptable modes of operation, key management rules (generation, storage, rotation, revocation, backup), certificate handling, and secure protocol configurations (e.g., TLS settings). This reduces ad hoc implementations that often lead to vulnerabilities such as weak ciphers, key reuse, improper randomness, or missing integrity protections. A framework also clarifies roles and processes---who can access keys, how secrets are audited, and how exceptions are handled---improving governance and operational reliability. Importantly, it does not guarantee perfect security; no framework can eliminate all risk, and secure outcomes still depend on correct implementation, monitoring, and maintenance. It also does not eliminate the need for training; human error is a major source of crypto misconfiguration. While frameworks help with compliance, they are not solely about regulation; they are about sound security engineering and lifecycle management. Therefore, the primary benefit is providing a structured approach to implementing encryption practices.


Question 6

(Which number of bits gets encrypted each time encryption is applied during stream encryption?)

Correct Answer: A. 1
Explanation:

In the classical definition, a stream cipher encrypts data in very small units---often described as one bit at a time---by combining plaintext with a keystream (commonly via XOR). While many practical stream ciphers operate on bytes or words for efficiency, the conceptual distinction compared to block ciphers is that stream encryption processes data as a continuous stream rather than fixed-size blocks. This is why the standard teaching answer is ''1 bit'' per application of the keystream. Block ciphers, by contrast, encrypt blocks like 64 bits (DES/3DES) or 128 bits (AES) in each invocation of the block primitive. Options like 40, 192, and 256 are not typical stream cipher ''per-step'' processing sizes; 40 and 256 are often associated with key sizes, and 192 could be a key size for AES, not an encryption granularity. The essential security requirement for stream ciphers is that the keystream must be unpredictable and never reused with the same key/nonce combination; otherwise XOR properties allow attackers to recover relationships between plaintexts. Thus, the best answer is 1.


Question 7

(Which symmetric encryption technique uses a 112-bit key size and a 64-bit block size?)

Correct Answer: B. 3DES
Explanation:

3DES (Triple DES) is a symmetric block cipher that retains DES's 64-bit block size while increasing effective security by applying DES multiple times. The common ''two-key 3DES'' variant uses two independent 56-bit DES keys (K1 and K2) in an Encrypt--Decrypt--Encrypt (EDE) sequence: Encrypt with K1, Decrypt with K2, then Encrypt again with K1. Because each DES key is 56 bits (ignoring parity bits), the total keying material is 112 bits. This matches the question's ''112-bit key size and 64-bit block size.'' Plain DES uses only a 56-bit effective key and a 64-bit block size, so it does not match the 112-bit key size. AES has a 128-bit block size and key sizes of 128/192/256. IDEA uses a 64-bit block size but has a 128-bit key. Therefore, the correct algorithm is 3DES. Although 3DES improved on DES, it is now considered legacy due to its small 64-bit block size (birthday-bound issues for large data volumes) and performance overhead compared to AES.


Question 8

(What are the roles of keys when using digital signatures?)

Correct Answer: B. A private key is used for signing, and a public key is used for signature validation.
Explanation:

Digital signatures provide integrity, authenticity, and typically non-repudiation by using an asymmetric key pair. The signer uses the private key to create a signature over a message (usually over a hash/digest of the message). Because the private key is kept secret, only the legitimate signer should be able to produce a valid signature. Anyone who has the corresponding public key can then validate the signature: they verify that the signature matches the message digest under the public key and that the signed data has not been altered. This is why the public key can be widely distributed (often inside an X.509 certificate) while the private key must be protected by the signer. If a public key were used to sign, anyone could forge signatures; if a private key were required for validation, only the signer could validate, defeating the purpose of public verifiability. Therefore, the correct key roles are private key for signing and public key for signature validation.


Question 9

(How does adding salt to a password improve security?)

Correct Answer: A. Salt creates a different hash if two people use the same password.
Explanation:

A salt is a unique, random value stored alongside a password hash and combined with the password during hashing. Its main security benefit is that it ensures identical passwords do not produce identical hashes across different accounts or systems. If two users choose the same password, their stored hashes will differ because their salts differ, which directly prevents attackers from spotting shared passwords by comparing hashes. Salts also defeat precomputation attacks such as rainbow tables, because an attacker would need to regenerate tables for each possible salt value---a task that becomes infeasible when salts are large and unique per password. Salt does not enforce password complexity rules (that's a policy/validation function), does not guarantee users choose different passwords, and does not prevent password reuse across sites. The correct statement is that salt makes the resulting hash different even for the same password, improving resistance to offline cracking at scale and eliminating the ''same hash = same password'' shortcut attackers rely on.


Question 10

(How are limits managed for the number of bitcoins that can be created and stored in a blockchain?)

Correct Answer: A. Rewards for mining reduce over time
Explanation:

Bitcoin's supply is controlled by protocol rules enforced by consensus: new bitcoins enter circulation through the block subsidy awarded to miners for producing valid blocks. This subsidy is programmed to halve at fixed intervals (every 210,000 blocks), which steadily reduces the rate of new coin creation over time and asymptotically approaches a capped total supply (commonly cited as 21 million BTC). This mechanism is often called the halving schedule and is the primary way limits are managed. The number of participants is not fixed; anyone can run a node or mine. There is no per-country cap and no per-person maximum enforced by the protocol---addresses and ownership are not limited that way. The supply cap emerges from the decreasing issuance schedule combined with consensus validation rules that reject blocks creating coins beyond what the schedule allows. Therefore, the correct answer is that limits are managed because rewards for mining reduce over time.