1
00:00:06,570 --> 00:00:09,300
- So welcome to Lesson 4 Deep Dive Quiz.

2
00:00:09,300 --> 00:00:12,000
And lesson four was all about
explaining the importance

3
00:00:12,000 --> 00:00:14,070
of appropriate cryptographic solutions,

4
00:00:14,070 --> 00:00:16,260
and we did six lessons together.

5
00:00:16,260 --> 00:00:17,910
We did cryptographic primer.

6
00:00:17,910 --> 00:00:20,820
We talked about encryption,
symmetric and asymmetric.

7
00:00:20,820 --> 00:00:22,620
We looked at hashing for integrity

8
00:00:22,620 --> 00:00:25,260
and digital signatures
for non-repudiation.

9
00:00:25,260 --> 00:00:27,240
Then we looked at where
those keys come from

10
00:00:27,240 --> 00:00:29,910
and how we authenticate
someone by looking at

11
00:00:29,910 --> 00:00:33,210
and understanding how
digital certificates work.

12
00:00:33,210 --> 00:00:35,220
Then we looked at emerging cryptography,

13
00:00:35,220 --> 00:00:36,930
some of which is above our pay grade.

14
00:00:36,930 --> 00:00:40,170
And then we wrapped up
talking about steganography.

15
00:00:40,170 --> 00:00:43,140
So now we're gonna do a
10 question quiz together.

16
00:00:43,140 --> 00:00:43,973
Are you ready?

17
00:00:43,973 --> 00:00:45,543
All right, let's get started.

18
00:00:47,340 --> 00:00:49,680
Our first question is a matching question

19
00:00:49,680 --> 00:00:53,850
and it's match the cryptographic
techniques and use cases.

20
00:00:53,850 --> 00:00:56,700
Now remember, put me on
pause whenever you want.

21
00:00:56,700 --> 00:00:59,010
So when you're ready to answer a question,

22
00:00:59,010 --> 00:01:00,720
put me on pause, work it through.

23
00:01:00,720 --> 00:01:02,310
Hopefully you have a
pen and paper together

24
00:01:02,310 --> 00:01:04,050
and, you know, write down your notes

25
00:01:04,050 --> 00:01:04,890
and then come on back

26
00:01:04,890 --> 00:01:06,600
and we'll go through the answers.

27
00:01:06,600 --> 00:01:08,700
So we're gonna match the
cryptographic techniques

28
00:01:08,700 --> 00:01:09,780
and use cases.

29
00:01:09,780 --> 00:01:11,760
On the left hand side, we have hashing,

30
00:01:11,760 --> 00:01:15,750
digital certificate, digital
signature, and encryption.

31
00:01:15,750 --> 00:01:17,790
Those were the techniques we talked about.

32
00:01:17,790 --> 00:01:21,810
On the right we have
authentication, non-repudiation,

33
00:01:21,810 --> 00:01:24,330
integrity, and confidentiality.

34
00:01:24,330 --> 00:01:25,920
Those are our use cases.

35
00:01:25,920 --> 00:01:27,720
So let's match 'em up.

36
00:01:27,720 --> 00:01:29,340
Starting with hashing.

37
00:01:29,340 --> 00:01:31,083
Hashing was, do you recall?

38
00:01:32,430 --> 00:01:35,040
Hashing was integrity.

39
00:01:35,040 --> 00:01:37,350
Next we have our digital certificates.

40
00:01:37,350 --> 00:01:39,090
Remember, that's where
we get our keys from

41
00:01:39,090 --> 00:01:41,670
and that's where we say who we are, right?

42
00:01:41,670 --> 00:01:45,330
And our certificate
authority verifies that.

43
00:01:45,330 --> 00:01:48,093
So that's gonna be authentication.

44
00:01:49,560 --> 00:01:51,300
Next one, digital signatures.

45
00:01:51,300 --> 00:01:53,830
Remember a digital
signature is when we encrypt

46
00:01:54,832 --> 00:01:57,990
a hash with our private
key, and that proves

47
00:01:57,990 --> 00:02:02,520
that that message came
from us or me in this case.

48
00:02:02,520 --> 00:02:05,190
So it would be non-repudiation.

49
00:02:05,190 --> 00:02:08,070
And that leaves us with the
one we knew right away anyway,

50
00:02:08,070 --> 00:02:10,890
which is encryption for confidentiality.

51
00:02:10,890 --> 00:02:12,480
So hashing for integrity,

52
00:02:12,480 --> 00:02:14,610
digital certificates for authentication,

53
00:02:14,610 --> 00:02:17,160
digital signatures for non-repudiation,

54
00:02:17,160 --> 00:02:19,820
and encryption for confidentiality.

55
00:02:19,820 --> 00:02:20,653
Is that what you had?

56
00:02:20,653 --> 00:02:21,600
Do you agree?

57
00:02:21,600 --> 00:02:24,030
Let's check it out and it's correct.

58
00:02:24,030 --> 00:02:25,180
Awesome, let's move on.

59
00:02:27,180 --> 00:02:30,360
The AES algorithm requires
this number of keys

60
00:02:30,360 --> 00:02:33,900
to encrypt and decrypt a message block.

61
00:02:33,900 --> 00:02:38,700
Two, four, one, or three.

62
00:02:38,700 --> 00:02:40,410
So what did you need to
know in this question?

63
00:02:40,410 --> 00:02:42,570
Well, you needed to know what type

64
00:02:42,570 --> 00:02:46,470
of algorithm, symmetric
or asymmetric, AES was.

65
00:02:46,470 --> 00:02:47,730
And I'll give you a hint.

66
00:02:47,730 --> 00:02:49,590
Okay, AES is a block cipher

67
00:02:49,590 --> 00:02:52,350
and it is a current U.S.
government standard.

68
00:02:52,350 --> 00:02:54,240
Nah, but I'm not telling you for which.

69
00:02:54,240 --> 00:02:57,510
So symmetric or asymmetric,
once you recall that,

70
00:02:57,510 --> 00:02:59,610
then you'll know the right number of keys.

71
00:03:01,410 --> 00:03:02,760
Are you ready for an answer?

72
00:03:02,760 --> 00:03:04,980
All right, I'm gonna choose one

73
00:03:04,980 --> 00:03:07,470
because AES also known as Rijndael,

74
00:03:07,470 --> 00:03:10,650
is the U.S. government standard
for symmetric encryption.

75
00:03:10,650 --> 00:03:13,560
And for symmetric encryption,
we only use one key,

76
00:03:13,560 --> 00:03:15,390
the same key to lock and unlock

77
00:03:15,390 --> 00:03:18,630
encrypt and decrypt and encrypt
and decrypt back and forth,

78
00:03:18,630 --> 00:03:19,983
the same key.

79
00:03:21,000 --> 00:03:21,833
Let's check.

80
00:03:22,710 --> 00:03:24,120
And there we go, we are correct.

81
00:03:24,120 --> 00:03:26,940
All right, moving on to question three.

82
00:03:26,940 --> 00:03:31,020
Mary wants to securely
transmit a session key to Bob.

83
00:03:31,020 --> 00:03:35,340
What type of algorithm and
cryptovariable should she use?

84
00:03:35,340 --> 00:03:37,260
So she wants to get a session key to Bob.

85
00:03:37,260 --> 00:03:39,390
She wants to securely transmit it.

86
00:03:39,390 --> 00:03:43,050
She wants to make sure,
right, that only Bob,

87
00:03:43,050 --> 00:03:46,740
only Bob will be able
to get that session key.

88
00:03:46,740 --> 00:03:49,770
So what type of algorithm is she gonna use

89
00:03:49,770 --> 00:03:52,170
and what cryptovariable is she gonna use?

90
00:03:52,170 --> 00:03:56,730
Should she use Bob's public
key and a asymmetric algorithm,

91
00:03:56,730 --> 00:04:00,360
Mary's private key and
a symmetric algorithm,

92
00:04:00,360 --> 00:04:03,960
Mary's public key and
an asymmetric algorithm,

93
00:04:03,960 --> 00:04:07,230
or Bob's private key
and symmetric algorithm?

94
00:04:07,230 --> 00:04:08,460
Now some of these you should be able to

95
00:04:08,460 --> 00:04:11,340
just use a process of
elimination and just get rid of,

96
00:04:11,340 --> 00:04:13,560
'cause we know that
asymmetric requires two keys

97
00:04:13,560 --> 00:04:15,483
and symmetric requires just one key.

98
00:04:16,740 --> 00:04:18,540
This is a good one to put me on pause,

99
00:04:18,540 --> 00:04:22,230
read through these again, and
tell me what type of algorithm

100
00:04:22,230 --> 00:04:24,980
and cryptovariable she should
use of the choices given.

101
00:04:27,630 --> 00:04:29,120
Well, I like the first one.

102
00:04:29,120 --> 00:04:33,240
So she can use Bob's public key
and an asymmetric algorithm.

103
00:04:33,240 --> 00:04:34,800
Remember asymmetric, it
says we're gonna have

104
00:04:34,800 --> 00:04:37,230
two keys mathematically related.

105
00:04:37,230 --> 00:04:39,660
Now, why is she gonna
use Bob's public key?

106
00:04:39,660 --> 00:04:42,450
Because what's the corresponding
key to Bob's public key?

107
00:04:42,450 --> 00:04:43,830
Well, Bob's private key.

108
00:04:43,830 --> 00:04:46,860
And who should have a
copy of Bob's private key?

109
00:04:46,860 --> 00:04:48,360
Only Bob.

110
00:04:48,360 --> 00:04:51,180
So when Bob got that session
key, encrypted session key,

111
00:04:51,180 --> 00:04:54,003
Bob would be the only
one who could decrypt it.

112
00:04:55,500 --> 00:04:57,000
Why wouldn't she use her private key

113
00:04:57,000 --> 00:04:58,050
in a symmetric algorithm?

114
00:04:58,050 --> 00:04:59,760
Well, symmetric says we only use one key,

115
00:04:59,760 --> 00:05:02,220
so that answer doesn't make any sense.

116
00:05:02,220 --> 00:05:05,790
Why not use her public key
and an asymmetric algorithm?

117
00:05:05,790 --> 00:05:07,740
Because that means the corresponding key

118
00:05:07,740 --> 00:05:09,240
would be her private key

119
00:05:09,240 --> 00:05:12,120
and Bob should never
have Mary's private key.

120
00:05:12,120 --> 00:05:14,370
And why wouldn't she use Bob's private key

121
00:05:14,370 --> 00:05:15,630
in a symmetric algorithm?

122
00:05:15,630 --> 00:05:17,520
Again, symmetric only means one key,

123
00:05:17,520 --> 00:05:18,900
so you wouldn't have two.

124
00:05:18,900 --> 00:05:22,080
But she also would never
have Bob's private key.

125
00:05:22,080 --> 00:05:24,720
So the answer we're looking
for is Bob's public key

126
00:05:24,720 --> 00:05:26,370
and an asymmetric algorithm.

127
00:05:26,370 --> 00:05:27,203
You like it?

128
00:05:27,203 --> 00:05:28,590
Let's check it out.

129
00:05:28,590 --> 00:05:29,703
And it is correct.

130
00:05:32,280 --> 00:05:37,280
Question four, this term applied
to a weak crypto component.

131
00:05:38,310 --> 00:05:42,360
Exploitable, deprecated,

132
00:05:42,360 --> 00:05:44,553
broken, or downgraded.

133
00:05:45,540 --> 00:05:47,550
So it's a weak crypto component.

134
00:05:47,550 --> 00:05:52,550
Is this exploitable, deprecated,
broken or downgraded?

135
00:05:53,880 --> 00:05:55,230
Go ahead, make your choice.

136
00:05:57,570 --> 00:05:59,460
So it's a weak component.

137
00:05:59,460 --> 00:06:01,590
I'm gonna choose deprecated.

138
00:06:01,590 --> 00:06:04,830
Deprecated means that it is
weak, that it carries risk.

139
00:06:04,830 --> 00:06:07,290
Broken means it has been exploited, right?

140
00:06:07,290 --> 00:06:09,720
Exploitable also means
it's been exploited.

141
00:06:09,720 --> 00:06:11,640
And downgraded isn't really a term

142
00:06:11,640 --> 00:06:15,360
that we would apply to
a weak crypto component.

143
00:06:15,360 --> 00:06:16,590
So deprecated is my choice.

144
00:06:16,590 --> 00:06:17,760
Is it yours?

145
00:06:17,760 --> 00:06:19,590
All right, let's check.

146
00:06:19,590 --> 00:06:20,763
And that is correct.

147
00:06:22,710 --> 00:06:26,100
Question five, which
statement is not true,

148
00:06:26,100 --> 00:06:27,990
so not is the important word here,

149
00:06:27,990 --> 00:06:31,920
not true about a hash
message authentication code

150
00:06:31,920 --> 00:06:33,180
or an HMAC?

151
00:06:33,180 --> 00:06:37,380
And HMAC cannot be reproduced
without knowing the key.

152
00:06:37,380 --> 00:06:41,670
An HMAC provides integrity
and origin authentication.

153
00:06:41,670 --> 00:06:45,960
An HMAC is used by TLS and IPsec.

154
00:06:45,960 --> 00:06:49,830
And the input for an HMAC
is a concatenated message

155
00:06:49,830 --> 00:06:51,603
and an asymmetric key.

156
00:06:53,370 --> 00:06:56,010
Three of those statements
are true and one is not.

157
00:06:56,010 --> 00:06:57,180
And it's really important, again,

158
00:06:57,180 --> 00:06:58,320
when you're reading your questions

159
00:06:58,320 --> 00:07:01,740
to look for words like best
and least and most likely

160
00:07:01,740 --> 00:07:04,680
and true and false and not, right?

161
00:07:04,680 --> 00:07:07,380
If you read this too
quickly said, which is true

162
00:07:07,380 --> 00:07:09,480
and then just chose the
first answer, you came to,

163
00:07:09,480 --> 00:07:11,340
well you'd have the wrong answer.

164
00:07:11,340 --> 00:07:13,860
So we're asking you which one is not true.

165
00:07:13,860 --> 00:07:14,790
Go ahead put me on pause

166
00:07:14,790 --> 00:07:16,690
if you wanna read through those again.

167
00:07:17,850 --> 00:07:19,710
Well, let's talk through these.

168
00:07:19,710 --> 00:07:22,350
An HMAC cannot be reproduced
without knowing the key.

169
00:07:22,350 --> 00:07:24,510
That's true, because an HMAC, right,

170
00:07:24,510 --> 00:07:27,330
is going to be the message
and a symmetric key,

171
00:07:27,330 --> 00:07:28,803
so you have to know the key.

172
00:07:29,880 --> 00:07:33,240
An HMAC provides integrity,
which it does, right.

173
00:07:33,240 --> 00:07:36,090
Hashing provides integrity
and origin authentication,

174
00:07:36,090 --> 00:07:39,210
it does because of the symmetric
key that we're inserting.

175
00:07:39,210 --> 00:07:41,880
An HMAC is used by TLS and IPsec.

176
00:07:41,880 --> 00:07:43,530
That's also true.

177
00:07:43,530 --> 00:07:45,720
Our last choice, the input for an HMAC

178
00:07:45,720 --> 00:07:49,560
is a concatenated message
and an asymmetric key.

179
00:07:49,560 --> 00:07:51,480
And that's gonna be our false one.

180
00:07:51,480 --> 00:07:53,040
That's the one that's not true.

181
00:07:53,040 --> 00:07:54,453
We use a symmetric key.

182
00:07:55,770 --> 00:07:57,180
So that's the one I'm gonna choose.

183
00:07:57,180 --> 00:07:58,350
Do you agree?

184
00:07:58,350 --> 00:07:59,820
Let's check it out.

185
00:07:59,820 --> 00:08:01,053
And that is correct.

186
00:08:03,450 --> 00:08:05,910
Question six, we're doing great here.

187
00:08:05,910 --> 00:08:10,620
Which authority issues and
revokes digital certificates?

188
00:08:10,620 --> 00:08:13,950
Which authority issues and
revokes digital certificate?

189
00:08:13,950 --> 00:08:17,563
Is this an issuing authority,
a registration authority,

190
00:08:17,563 --> 00:08:21,750
a validation authority, or
a certificate authority?

191
00:08:21,750 --> 00:08:24,060
Now two of these answers are
absolutely made up names.

192
00:08:24,060 --> 00:08:25,740
So hopefully you recognize those

193
00:08:25,740 --> 00:08:27,290
and just scratch 'em right out.

194
00:08:28,650 --> 00:08:31,470
But two are authorities that are used

195
00:08:31,470 --> 00:08:33,990
in digital certificates,
but for different reasons.

196
00:08:33,990 --> 00:08:35,880
I wanna know which one issues

197
00:08:35,880 --> 00:08:39,420
and revokes digital
certificates: an issuing,

198
00:08:39,420 --> 00:08:43,590
a registration, a
validation, or a certificate.

199
00:08:43,590 --> 00:08:45,790
Put me on pause if you
wanna think about it.

200
00:08:47,040 --> 00:08:50,760
Well, I'm gonna choose our
CA, our certificate authority.

201
00:08:50,760 --> 00:08:53,190
Issuing authority, I
think it's a made up term.

202
00:08:53,190 --> 00:08:55,770
Registration authority does
the administrative work

203
00:08:55,770 --> 00:08:58,980
on behalf of a certificate authority.

204
00:08:58,980 --> 00:09:02,010
Validation authority,
that's another made up term.

205
00:09:02,010 --> 00:09:04,530
Certificate Authority
is the one who issues

206
00:09:04,530 --> 00:09:07,260
and revokes our digital certificates.

207
00:09:07,260 --> 00:09:08,313
Let's check it out.

208
00:09:09,390 --> 00:09:10,533
And that is correct.

209
00:09:12,330 --> 00:09:15,420
Question seven, which
protocol should be used

210
00:09:15,420 --> 00:09:20,420
to verify the status of an
extended validation certificate?

211
00:09:20,460 --> 00:09:23,520
OSPF, OCSP,

212
00:09:23,520 --> 00:09:26,970
CRL, or CRC.

213
00:09:26,970 --> 00:09:28,830
So you will need to know abbreviations

214
00:09:28,830 --> 00:09:31,440
and acronyms for the exam.

215
00:09:31,440 --> 00:09:36,440
So once again, OSPF, OCSP, CRL, or CRC.

216
00:09:38,760 --> 00:09:40,500
You might wanna use the
process of elimination,

217
00:09:40,500 --> 00:09:41,970
if you know what some
of the other ones are

218
00:09:41,970 --> 00:09:44,220
and you're not sure what
the right answer is.

219
00:09:46,230 --> 00:09:48,060
I'm gonna choose OCSP.

220
00:09:48,060 --> 00:09:48,893
Do you agree?

221
00:09:49,740 --> 00:09:51,240
Let's check.

222
00:09:51,240 --> 00:09:52,563
And that is correct.

223
00:09:54,330 --> 00:09:55,650
Question eight, we have a matching.

224
00:09:55,650 --> 00:09:56,730
Oh, this one is about

225
00:09:56,730 --> 00:10:00,870
our emerging cryptographic
applications and descriptions.

226
00:10:00,870 --> 00:10:01,800
On the right hand side

227
00:10:01,800 --> 00:10:05,970
we have homomorphic,
quantum, and lightweight.

228
00:10:05,970 --> 00:10:08,790
On the right hand side
our descriptions are:

229
00:10:08,790 --> 00:10:10,380
supports low power devices

230
00:10:10,380 --> 00:10:14,670
with low latency and high
resiliency requirements,

231
00:10:14,670 --> 00:10:16,440
or requires immense computing power to

232
00:10:16,440 --> 00:10:18,690
solve mathematical problems,

233
00:10:18,690 --> 00:10:22,260
or allows data being
processed to remain encrypted.

234
00:10:22,260 --> 00:10:23,703
So we need to match them up.

235
00:10:25,590 --> 00:10:27,540
Well, let's start on the
right hand side this time.

236
00:10:27,540 --> 00:10:29,970
Supports low powered
devices with low latency

237
00:10:29,970 --> 00:10:31,530
and high resiliency.

238
00:10:31,530 --> 00:10:33,813
Homomorphic, quantum or lightweight?

239
00:10:34,795 --> 00:10:36,495
Ah, I think it's lightweight also.

240
00:10:37,800 --> 00:10:41,430
Allows data being processed
to remain encrypted.

241
00:10:41,430 --> 00:10:43,590
Homomorphic or quantum?

242
00:10:43,590 --> 00:10:45,360
I'm going with homomorphic,

243
00:10:45,360 --> 00:10:46,920
and that just leaves my last choice,

244
00:10:46,920 --> 00:10:48,870
requires immense computing power

245
00:10:48,870 --> 00:10:50,910
to solve mathematical problems.

246
00:10:50,910 --> 00:10:52,770
That's gonna be quantum.

247
00:10:52,770 --> 00:10:55,080
So homomorphic allows data being processed

248
00:10:55,080 --> 00:10:56,370
to remain encrypted.

249
00:10:56,370 --> 00:10:58,740
Quantum requires immense computing power

250
00:10:58,740 --> 00:11:00,630
to solve mathematical problems.

251
00:11:00,630 --> 00:11:03,150
And lightweight supports low power devices

252
00:11:03,150 --> 00:11:06,480
with low latency and high
resiliency requirements.

253
00:11:06,480 --> 00:11:07,500
Do you agree?

254
00:11:07,500 --> 00:11:10,083
All right, we'll check and it is correct.

255
00:11:11,730 --> 00:11:14,490
Number nine, I want you
to choose the attributes

256
00:11:14,490 --> 00:11:17,490
that apply to symmetric encryption.

257
00:11:17,490 --> 00:11:20,760
So all these attributes, which
there's a whole list here,

258
00:11:20,760 --> 00:11:22,830
some of them apply to symmetric.

259
00:11:22,830 --> 00:11:24,270
I want you to choose which ones

260
00:11:24,270 --> 00:11:26,910
and you can choose as
many as you think apply.

261
00:11:26,910 --> 00:11:30,330
Single key, secure key exchange,

262
00:11:30,330 --> 00:11:34,590
scalable, U.S. government standard is ECC,

263
00:11:34,590 --> 00:11:39,180
U.S. government standard is
AES, processor intensive,

264
00:11:39,180 --> 00:11:42,933
mathematically related
keys, or a session key.

265
00:11:43,890 --> 00:11:47,040
So which one of these
attributes apply to symmetric?

266
00:11:47,040 --> 00:11:48,810
This is definitely a great
place to put me on pause,

267
00:11:48,810 --> 00:11:49,680
read through them,

268
00:11:49,680 --> 00:11:51,580
choose as many as you think are right.

269
00:11:52,890 --> 00:11:54,420
All right, let's go through them.

270
00:11:54,420 --> 00:11:55,890
Well, I'm gonna choose single key

271
00:11:55,890 --> 00:11:58,115
because symmetric uses one key.

272
00:11:58,115 --> 00:11:59,460
Remember the same key to lock and unlock,

273
00:11:59,460 --> 00:12:01,410
encrypt and decrypt.

274
00:12:01,410 --> 00:12:02,910
We know that one of the problems

275
00:12:02,910 --> 00:12:05,760
with symmetric is the key
exchange is not secure.

276
00:12:05,760 --> 00:12:07,760
I have to find a way to get you the key.

277
00:12:08,640 --> 00:12:09,870
It's not scalable

278
00:12:09,870 --> 00:12:12,300
because I have to have a different key

279
00:12:12,300 --> 00:12:14,253
with everyone I'm communicating with.

280
00:12:15,180 --> 00:12:17,070
The U.S. government standard is ECC.

281
00:12:17,070 --> 00:12:17,937
Well that ECC is

282
00:12:17,937 --> 00:12:20,433
the U.S. government
standard for asymmetric.

283
00:12:21,300 --> 00:12:23,490
The U.S. government standard is AES.

284
00:12:23,490 --> 00:12:24,600
I'm going to choose that one

285
00:12:24,600 --> 00:12:26,010
because the U.S. government standard

286
00:12:26,010 --> 00:12:29,493
for symmetric encryption is
AES, also known as Rijndael.

287
00:12:30,720 --> 00:12:32,493
It's not processor intensive.

288
00:12:33,390 --> 00:12:35,490
We don't have mathematically related keys

289
00:12:35,490 --> 00:12:37,830
'cause we only have one key for symmetric.

290
00:12:37,830 --> 00:12:41,400
And if we're using that key
just one time for one session,

291
00:12:41,400 --> 00:12:44,100
it is referred to as a session key.

292
00:12:44,100 --> 00:12:45,540
So I chose three of them.

293
00:12:45,540 --> 00:12:49,470
The single key, U.S.
government standard is AES,

294
00:12:49,470 --> 00:12:50,613
and a session key.

295
00:12:51,720 --> 00:12:54,870
The other one, secure
key exchange, scalable,

296
00:12:54,870 --> 00:12:57,720
ECC, processor intensive,

297
00:12:57,720 --> 00:12:59,700
and mathematically related keys

298
00:12:59,700 --> 00:13:02,253
all describe asymmetric encryption.

299
00:13:03,270 --> 00:13:04,980
Let's check it out,

300
00:13:04,980 --> 00:13:06,270
and that's correct.

301
00:13:06,270 --> 00:13:09,063
All right, we're gonna move
on to our last question.

302
00:13:09,900 --> 00:13:13,980
What is the most likely
non-cryptographic data control

303
00:13:13,980 --> 00:13:15,783
associated with this image?

304
00:13:16,740 --> 00:13:21,740
Steganography, encryption,
hashing or abstraction?

305
00:13:23,160 --> 00:13:25,950
So right away you should be
able to eliminate two answers

306
00:13:25,950 --> 00:13:27,480
because the question I asked you

307
00:13:27,480 --> 00:13:30,030
was a non-cryptographic data control

308
00:13:30,030 --> 00:13:32,520
and you know that two of
those are cryptographic.

309
00:13:32,520 --> 00:13:35,370
So right away you should have
been able to scratch two out

310
00:13:36,540 --> 00:13:38,460
and then you have two left.

311
00:13:38,460 --> 00:13:39,690
And I want you to make your choice.

312
00:13:39,690 --> 00:13:41,700
We have a picture here, right?

313
00:13:41,700 --> 00:13:44,460
What is the most likely
non-cryptographic data control

314
00:13:44,460 --> 00:13:46,473
associated with this image?

315
00:13:48,870 --> 00:13:51,956
I'm gonna choose steganography.

316
00:13:51,956 --> 00:13:53,910
Remember, steganography
is where we hide a message

317
00:13:53,910 --> 00:13:54,930
and we can hide a message

318
00:13:54,930 --> 00:13:57,990
in a graphic or a picture
like we're seeing here.

319
00:13:57,990 --> 00:14:01,050
We can hide it in audio,
we can hide it in video,

320
00:14:01,050 --> 00:14:03,570
we can even hide it inside other text.

321
00:14:03,570 --> 00:14:05,730
And that's the example
I gave you yesterday

322
00:14:05,730 --> 00:14:08,490
of where we actually
added a little text file

323
00:14:08,490 --> 00:14:10,230
into a picture.

324
00:14:10,230 --> 00:14:11,220
Do you like it?

325
00:14:11,220 --> 00:14:13,020
All right, let's check.

326
00:14:13,020 --> 00:14:14,940
And that would be correct.

327
00:14:14,940 --> 00:14:15,773
Well, fantastic.

328
00:14:15,773 --> 00:14:16,800
You did a great job.

329
00:14:16,800 --> 00:14:18,630
10 questions, we got right through them.

330
00:14:18,630 --> 00:14:19,890
I hope you enjoyed doing this.

331
00:14:19,890 --> 00:14:21,420
That's a good review for you.

332
00:14:21,420 --> 00:14:22,500
So what's up next?

333
00:14:22,500 --> 00:14:23,503
Well, we're going right into

334
00:14:23,503 --> 00:14:26,940
Module 2 Threats,
Vulnerabilities, and Mitigation,

335
00:14:26,940 --> 00:14:31,770
starting with Lesson 5.1
Threat Actors and Attributes.

336
00:14:31,770 --> 00:14:32,720
I'll see you there.
