nerdexam
Isaca

CDPSE · Question #284

Which of the following is the MOST important key management practice when deploying cryptography for protecting personal data?

The correct answer is B. Protecting the confidentiality and authenticity of private keys. In asymmetric cryptography, the private key is the most sensitive element of the entire system. Confidentiality ensures the key is known only to its owner-if a private key is exposed, an attacker can decrypt all data encrypted with the corresponding public key or forge digital…

Privacy Architecture

Question

Which of the following is the MOST important key management practice when deploying cryptography for protecting personal data?

Options

  • APreventing users from using incorrect private keys
  • BProtecting the confidentiality and authenticity of private keys
  • CPreventing users from using incorrect public keys
  • DProtecting the confidentiality and authenticity of public keys

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    73% (19)
  • C
    8% (2)
  • D
    15% (4)

Explanation

In asymmetric cryptography, the private key is the most sensitive element of the entire system. Confidentiality ensures the key is known only to its owner-if a private key is exposed, an attacker can decrypt all data encrypted with the corresponding public key or forge digital signatures. Authenticity ensures the key genuinely belongs to the claimed owner, preventing impersonation attacks. Public keys (options C and D) are designed to be distributed openly and do not require confidentiality protection. Preventing users from using incorrect keys (A and C) is an operational concern but secondary to the fundamental requirement of keeping private keys secret and verified. Compromising a private key renders all cryptographic protections worthless.

Topics

#Key Management#Cryptography#Private Keys#Data Protection

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice