712-50 exam dumps

712-50 practice question 337 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 337

Select 3Identify the different components of a cryptosystem

A global enterprise is redesigning its file-encryption service after an internal audit found that teams were using the term "encryption" inconsistently across architecture documents. During a steering committee meeting, the CISO asks which elements must be explicitly identified to describe a complete cryptosystem for the service so that security, procurement, and operations teams all understand what is being protected and how. Which THREE components should be documented as core parts of the cryptosystem?

  1. A

    The cryptographic algorithm(s) used, such as AES for encryption and SHA-256 or HMAC for integrity-related functions

  2. B

    The keys involved, including how they are generated, stored, distributed, rotated, and retired

  3. C

    The plaintext and ciphertext handled by the system, including what data is input and what protected output is produced

  4. D

    The vendor's quarterly patch cycle, because patching defines the cryptosystem's trust model

  5. E

    The data center's HVAC redundancy, because environmental resilience is a required cryptosystem component

Show answer and explanation

Correct answers: A, B, C

Explanation

A cryptosystem is more than just an encryption product name or a checkbox indicating that data is encrypted. At a minimum, organizations should identify the data being transformed (plaintext), the protected output (ciphertext), the algorithm or algorithms used, and the keys that drive the transformation. In leadership and governance contexts such as CCISO, candidates are expected to connect this definition to real-world control design: if the enterprise cannot clearly document algorithms, keys, and data flows, it cannot effectively manage risk, validate compliance, or assure consistent implementation across teams. Best practices from NIST, including FIPS 140 validation considerations and NIST SP 800-57 on key management, reinforce that secure cryptography depends not only on approved algorithms but also on disciplined key lifecycle management. Supporting controls like patching, facilities resilience, and vendor processes are important to the broader security program, but they are not the core components that define the cryptosystem itself.

  • A. Correct.

    Correct. A cryptosystem fundamentally includes the cryptographic algorithm or set of algorithms that transform data or provide related security services. In practice, this includes specifying the approved cipher or mechanism and the mode or construction where applicable. For example, documenting AES alone is not enough without understanding how it is applied; similarly, integrity mechanisms must identify the specific hash-based or MAC-based construction. Candidates may choose this because algorithms are one of the most visible parts of any cryptographic design, and that is appropriate.

  • B. Correct.

    Correct. Keys are a core component of a cryptosystem. In executive governance and architecture review, it is not enough to know that a key exists; the organization must document key generation, storage, escrow where applicable, distribution, access controls, rotation, revocation, archival, and destruction. NIST guidance consistently emphasizes that key management is central to cryptographic security. Many real-world failures come not from broken algorithms but from weak key lifecycle controls.

  • C. Correct.

    Correct. A cryptosystem includes the plaintext input and ciphertext output, because the system is defined by the transformation of readable data into protected form and, where applicable, back again. In a business setting, documenting what data is being encrypted and what the protected representation looks like is important for scope, classification, and control validation. This helps ensure teams understand exactly what information is protected and at which points in the process.

  • D. Incorrect.

    Incorrect. Patch management is important for operational security, but it is not itself a core component of a cryptosystem. A system that implements cryptography should absolutely be patched and maintained, yet patch cadence belongs to operational and vulnerability management practices rather than the definition of the cryptosystem. Someone might choose this because software assurance affects trust, but it does not define the cryptographic components themselves.

  • E. Incorrect.

    Incorrect. HVAC redundancy may support availability of the hosting environment, especially for critical infrastructure or data centers, but it is not a cryptosystem component. This distractor tests whether the candidate can distinguish between supporting infrastructure controls and the actual elements of a cryptosystem. Environmental resilience matters to business continuity, not to the formal composition of the cryptographic system.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam