wk1 ssl Flashcards

1
Q
Which of the following is not an attack against SSL?
Select one:
a. Length extension attack
b. CRIME
c. Hash overflow
d. Renegotiation denial of service 
e. I don't know.
A

Hash overflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
Based on the path /etc/ssl/certs/cpu.cpanel.net.crt, what SSL component can you guess would likely be contained in this file?
Select one:
a. Public Key
b. Private Key 
c. Cipher Suite
d. I don't know.
e. CA Bundle
A

Public Key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Certificates should be:
Select one:
a. Compressed into ZIP format
b. Issued from a trusted certificate authority 
c. Hashed with the MD5 hashing algorithm
d. Self-signed
e. I don't know.
A

Issued from a trusted certificate authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is SSL used for?
Select one:
a. Protecting my application from SQL injection attacks
b. I don’t know.
c. Stopping certificate warning messages
d. Protecting my Web server from malware
e. Preventing the interception and tampering of data

A

Preventing the interception and tampering of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
What utility should you use to verify a CA bundle certificate file?
Select one:
a. I don't know.
b. bundlechk
c. cpkeyclt
d. openssl
e. cpsrvd
A

openssl

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
You can defend your web application against the BEAST attack by:
Select one:
a. Disabling SSLv2
b. Disabling CBC-mode ciphers
c. I don't know. 
d. Only using SSL on your website
e. Disabling SSL renegotiation
A

Disabling CBC-mode ciphers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which of these commands would successfully provide the md5 sum for the myserver.crt certificate file?
Select one:
a. openssl x509 -noout -modulus -in myserver.crt | openssl md5
b. I don’t know.
c. openssl md5 -out myserver.crt | openssl x509
d. md5sum -c myserver.crt | openssl
e. openssl x509 -md5 -in myserver.crt

A

openssl x509 -noout -modulus -in myserver.crt | openssl md5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which of the following commands would successfully establish a secure HTTPS connection to cpanel.com?
Select one:
a. openssl ssl_client -connect cpanel.com
b. openssl s_client -connect cpanel.com
c. I don’t know.
d. openssl s_client -connect https://cpanel.com
e. openssl s_client -connect cpanel.com:443

A

openssl s_client -connect cpanel.com:443

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
Which of these folder paths are service-related SSL certificates stored in, on a cPanel & WHM server?
Select one:
a. /var/cpanel/ssl
b. /usr/local/cpanel/ssl
c. /etc/ssl 
d. /opt/service/ssl
e. I don't know.
A

/var/cpanel/ssl

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which of the following commands would successfully output the readable details of a private key certificate file?
Select one:
a. openssl pki -noout -text -in filename.key
b. openssl rsa -noout -text -in filename.key
c. openssl x509 -noout -text -in filename.crt
d. I don’t know.
e. openssl cert -noout -text -in filename.crt

A

openssl rsa -noout -text -in filename.key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Service Name Indication (SNI) provides what capability?
Select one:
a. Allows a server to install multiple certificates to the same IP address.
b. Increases SSL validity by verifying the hostname with an external resource.
c. I don’t know.
d. Facilitates the CA bundle installation process by automatically retrieving a bundle based on the root certificate authority.
e. None of the above.

A

Allows a server to install multiple certificates to the same IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
"PKI" stands for..
Select one:
a. Private Key Infrastructure
b. Public Key Infrastructure 
c. I don't know.
d. Powerful Kludge Improvement
e. Procedure for Key Initialization
A

Public Key Infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
What is the minimum length a cypher key should be?
Select one:
a. I don't know.
b. 128 bits 
c. 256 bits
d. 512 bits
e. 40 bits
A

128 bits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
"SSL" stands for..
Select one:
a. Scrambled Safely, Locked
b. Secure Sockets Layer 
c. Socket Security Layer
d. I don't know.
e. Safe Sockets Layer
A

Secure Sockets Layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly