CISSP · Free practice question 4 of 12
Known-plaintext cryptanalytic attack
An attacker has captured several encrypted invoices from Dalby Wholesale. Every invoice begins with the same publicly known company letterhead text, and the attacker uses those matching plaintext and ciphertext pairs to try to recover the key. What kind of attack is this?
- A.A ciphertext-only attack
- B.A birthday attack
- C.A chosen-ciphertext attack
- D.A known-plaintext attack
Show answer and explanation
Correct answer: D. A known-plaintext attack
Why: In a known-plaintext attack, the analyst has samples of both plaintext and the corresponding ciphertext, here the predictable letterhead, and uses them to deduce the key or algorithm behavior. A ciphertext-only attack has no plaintext at all, a chosen-ciphertext attack requires the ability to have chosen ciphertexts decrypted, and a birthday attack looks for hash collisions.
More free CISSP questions
- Senior management ultimate security accountability
- Wassenaar Arrangement export of cryptography
- Brewer-Nash model prevents conflicts of interest
- Air-gapped network physical segmentation
- Role-based access control by job function
- Misuse case testing of abuse scenarios
- Breach and attack simulation platforms
- Proactive hypothesis-driven threat hunting
- Lessons learned after incident closure
- Access control vestibule stops tailgating
- Cold site characteristics and recovery time