nerdexam
(ISC)2

CISSP-ISSAP · Question #194

Which of the following encryption methods does the SSL protocol use in order to provide communication privacy, authentication, and message integrity? Each correct answer represents a part of the…

The correct answer is A. Public key D. Symmetric. SSL employs a hybrid encryption model: public key (asymmetric) cryptography handles the handshake phase - authenticating parties and securely exchanging session keys - while symmetric encryption handles the bulk data transfer, providing fast, efficient communication privacy and…

Infrastructure Security

Question

Which of the following encryption methods does the SSL protocol use in order to provide communication privacy, authentication, and message integrity? Each correct answer represents a part of the solution. Choose two. (ISC)2 CISSP-ISSAP Exam

Options

  • APublic key
  • BIPsec
  • CMS-CHAP
  • DSymmetric

How the community answered

(45 responses)
  • A
    82% (37)
  • B
    7% (3)
  • C
    11% (5)

Explanation

SSL employs a hybrid encryption model: public key (asymmetric) cryptography handles the handshake phase - authenticating parties and securely exchanging session keys - while symmetric encryption handles the bulk data transfer, providing fast, efficient communication privacy and message integrity. This two-method design gives SSL both the security of asymmetric crypto and the speed of symmetric crypto.

Why the distractors are wrong:

  • B. IPsec is a separate network-layer protocol suite used for VPNs; it operates independently of SSL and is not a component within it.
  • C. MS-CHAP is a Microsoft-specific challenge-handshake authentication protocol used in PPP/dial-up and VPN contexts, not a mechanism SSL uses internally.

Memory tip: Think of SSL as a "handshake then highway" - the public key locks down the handshake (slow but secure authentication), then both sides switch to a symmetric key for the high-speed highway of data transfer. If an answer mentions a full separate protocol (IPsec) or a PPP-era auth protocol (MS-CHAP), it's describing something beside SSL, not inside it.

Topics

#SSL/TLS protocol#Asymmetric encryption#Symmetric encryption#Key exchange

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice