Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Encryption Specialist

Domain 1Objective 3

Cryptographic Principles (Diffusion, Confusion, Kerckhoff Principle) ECES Practice Questions (Page 7)

Part of the Cryptography Foundations and History domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 3–4 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
3concepts

Questions 31–35

  1. 31application · medium

    A startup is building a secure messaging app. The lead engineer argues that the encryption algorithm should be kept secret to add an extra layer of protection. A senior security consultant disagrees, citing Kerckhoffs's principle. Which statement best reflects the consultant's position?

    Select an answer first
  2. 32expert · hard

    A security team is evaluating two ciphers for a high-security application. Cipher A has a very complex substitution box but weak diffusion. Cipher B has strong diffusion but a simple linear substitution. The team wants to minimize the risk of both statistical attacks and key recovery attacks. Which cipher should they choose, and why?

    Select an answer first
  3. 33foundation · easy

    What is the main goal of confusion in a cipher?

    Select an answer first
  4. 34application · medium

    A security team is reviewing a proprietary cipher that uses a simple linear transformation. An analyst points out that the cipher is vulnerable to a known-plaintext attack because the key can be recovered by solving linear equations. Which principle is the cipher violating?

    Select an answer first
  5. 35expert · hard

    A cryptanalyst is analyzing a cipher and finds that the ciphertext bits can be expressed as a linear function of the key bits and plaintext bits. This allows the analyst to recover the key with moderate computational effort. Which principle is the cipher violating, and what design change would most directly address the vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.