nerdexam
(ISC)2

CISSP-ISSAP · Question #178

John works as a professional Ethical Hacker. He has been assigned the project of testing the a man-in-the-middle attack since the key exchange process of the cryptographic algorithm it is using does…

The correct answer is D. Diffie-Hellman. Diffie-Hellman (D) is vulnerable to man-in-the-middle attacks precisely because it is a key exchange protocol that authenticates no one - it allows two parties to establish a shared secret over an insecure channel, but an attacker can intercept and impersonate both sides…

Infrastructure Security

Question

John works as a professional Ethical Hacker. He has been assigned the project of testing the a man-in-the-middle attack since the key exchange process of the cryptographic algorithm it is using does not thenticate participants. Which of the following cryptographic algorithms is being used by the We-are-secure server?

Options

  • ABlowfish
  • BTwofish
  • CRSA
  • DDiffie-Hellman

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    12% (4)
  • C
    3% (1)
  • D
    82% (27)

Explanation

Diffie-Hellman (D) is vulnerable to man-in-the-middle attacks precisely because it is a key exchange protocol that authenticates no one - it allows two parties to establish a shared secret over an insecure channel, but an attacker can intercept and impersonate both sides without detection during that exchange.

Why the distractors are wrong:

  • Blowfish (A) and Twofish (B) are symmetric-key block ciphers used for encrypting data, not for key exchange - they don't have a "key exchange process" to exploit.
  • RSA (C) is an asymmetric algorithm that does support authentication (via digital signatures and certificates), making it resistant to unauthenticated MITM scenarios; it is also used for encryption, not pure key exchange.

Memory tip: Think "DH = Do Handshake (but don't verify who you're shaking hands with)." Diffie-Hellman gives you a secret tunnel but never checks who's standing at the other end - that's the MITM gap. HTTPS fixes this by wrapping DH inside TLS with certificate-based authentication.

Topics

#Diffie-Hellman#Key exchange#Man-in-the-middle attacks#Cryptographic authentication

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice