Question 1
What is the primary purpose of salting passwords before hashing?
Correct Answer:
To prevent rainbow table attacks
Explanation:
Salting passwords before hashing is mainly to defeat rainbow table attacks. Rainbow tables are precomputed lists of password hashes for common passwords, so an attacker can reverse a hash and discover the original password if no salt is used. Introducing a unique, random salt for each password means the value being hashed is different for every user, even if the passwords are the same. This makes precomputed tables useless, because the attacker would have to generate a separate table for every possible salt, which is extremely costly and impractical. The salt is stored with the hash so the system can verify the password during login. The other options don’t capture the purpose of salting. Creating a fixed-length output is a property of the hash function itself, not why you add a salt. Salting doesn’t inherently speed up hashing; the goal is not speed but security against precomputed attacks. It also isn’t about integrity or authenticity, which require mechanisms like MACs or digital signatures.
Question 2
WPA3-Personal replaces WPA2-PSK with which mechanism?
Correct Answer:
SAE (Simultaneous Authentication of Equals)
Explanation:
WPA3-Personal replaces the static pre-shared key with a password-based mutual authentication method that provides stronger protection. This mechanism is SAE, Simultaneous Authentication of Equals, also known as the Dragonfly handshake. In SAE, the client and access point prove knowledge of the shared password through a secure exchange without sending the password itself. Each session derives a fresh, ephemeral shared secret, giving forward secrecy and preventing offline dictionary attacks because an attacker cannot test guesses from captured handshakes without online interaction with the devices. The other options are cryptographic techniques used for signatures or different key-exchange setups in other contexts, not the password-based mutual authentication method used here.
Question 3
Which principle states that a cryptosystem should be secure even if the algorithm is public, and only the key must remain secret?
Correct Answer:
Kerckhoffs's Principle
Explanation:
Security relies on the key being kept secret, even when everyone knows the method used to encrypt. This idea is Kerckhoffs's Principle: a cryptosystem should remain secure if the algorithm is public and only the key remains secret. By making the algorithm open to analysis, its weaknesses can be found and fixed, while the actual protection comes from the secrecy and strength of the key. For example, RSA relies on a publicly known algorithm, with security resting on the difficulty of factoring large numbers and the secrecy of the private key. The other terms describe parts of the process or data, not the principle about keeping cryptographic security tied to the key rather than the obscurity of the algorithm.
Question 4
Which statement defines Integrity?
Correct Answer:
Ensuring data is not altered without authorization.
Explanation:
Integrity is about trustworthiness of data: it means information remains accurate and unchanged by unauthorized parties, and any legitimate changes are detectable and authorized. This is achieved with mechanisms like hashes, checksums, digital signatures, message authentication codes, and audit trails, which help ensure that tampering is detectable and prevent improper modifications. Therefore, the statement that describes data not being altered without authorization best captures integrity. The other options describe authentication (verifying identity), authorization (granting permissions), and confidentiality (restricting access), which are different security properties.
Question 5
In a proof-of-work blockchain, what is the purpose of a nonce?
Correct Answer:
To act as a number that, when hashed, meets difficulty criteria
Explanation:
The main idea is that the nonce is the adjustable value miners vary to produce a hash that meets the network’s difficulty. In proof-of-work, the block header (which includes things like the previous block hash and the Merkle root) is hashed together with a candidate nonce. Because cryptographic hashes behave like random functions, most nonces won’t produce a hash below the difficulty target, but a tiny fraction will. Miners keep trying different nonce values until the hash falls under the required threshold, proving that a certain amount of computational work was done. Once such a nonce is found, the block is considered mined and broadcast. It isn’t used as an encryption seed, it doesn’t identify the miner, and it doesn’t encrypt or alter the block contents. Those roles are separate; the nonce’s sole purpose is to enable the proof-of-work condition by providing the variable value that can be hashed to meet the difficulty.
Question 1
Exam overview

About this Exam

Prepare with the Western Governors University (WGU) ITAS 2142 D830 Introduction to Cryptography Practice Exam practice quiz. This question bank includes 10 questions covering secret, certificates, primary, western, and governors. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Western Governors University (WGU) ITAS 2142 D830 Introduction to Cryptography Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on secret, certificates, primary, western, and governors. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions