✅ 12th Grade Other: Certificate Transparency Logs Quiz
✅ 12th Grade Other: Certificate Transparency Logs Quiz
What is the primary goal of Certificate Transparency (CT) logs in the context of internet security?
A) To encrypt all data sent between a user and a website.B) To provide a public, auditable record of all issued SSL/TLS certificates.
C) To replace the need for Certificate Authorities (CAs) entirely.
D) To speed up the loading time of websites using HTTPS.
Which entity is responsible for issuing the digital certificates that are recorded in a Certificate Transparency log?
A) The Web BrowserB) The Internet Service Provider (ISP)
C) The Certificate Authority (CA)
D) The Domain Name System (DNS)
Certificate Transparency logs are described as "append-only." What does this term mean?
A) Data can be added to the log, but existing data cannot be changed or deleted.B) Data can only be added to the log if it is less than 100% accurate.
C) Data is automatically deleted after 90 days to save space.
D) Only the owner of the domain can add information to the log.
What happens if a domain owner finds a certificate for their website in a CT log that they did not authorize?
A) The website is automatically shut down by the log server.B) The domain owner can use the log as evidence to request a revocation of the fake certificate.
C) The log server will automatically delete the unauthorized certificate.
D) The domain owner must pay a fine to the Certificate Authority.
Which of the following is a major web browser that requires Certificate Transparency for a website to be trusted?
A) Internet Explorer 6B) Google Chrome
C) Netscape Navigator
D) Basic HTML Viewer
In the CT ecosystem, what is the role of a "Log Server"?
A) To store and display the list of certificates for anyone to inspect.B) To generate private keys for website owners.
C) To block users from visiting unencrypted websites.
D) To act as a backup for the entire internet's DNS records.
What is a Signed Certificate Timestamp (SCT)?
A) A password used by the website administrator to log into the server.B) A promise from a log server that a certificate will be added to the log within a certain timeframe.
C) A digital signature that proves the user has paid for their internet connection.
D) A timestamp showing exactly when a user visited a specific website.
How does Certificate Transparency help prevent Man-in-the-Middle (MitM) attacks?
A) By encrypting the user's keyboard input.B) By making it difficult for attackers to use a secretly issued fake certificate without being detected.
C) By increasing the speed of the Wi-Fi connection.
D) By requiring a physical key to be plugged into the computer.
What is the specific function of a "Monitor" in the Certificate Transparency framework?
A) To watch log servers for certificates issued to specific domains and alert the owners.B) To provide the hardware screen for the log server.
C) To issue new certificates to users for free.
D) To delete old logs to make room for new ones.
If a modern browser encounters a certificate that lacks the required Signed Certificate Timestamps (SCTs), what is the most likely result?
A) The browser will ignore the issue and load the page normally.B) The browser will display a security warning or refuse to connect to the site.
C) The browser will automatically fix the certificate for the website owner.
D) The browser will uninstall itself from the computer.
CT logs use a specific data structure to ensure they are tamper-proof and efficient to verify. What is this structure called?
A) A Linked ListB) A Merkle Tree
C) A Random Array
D) A Flat Text File
Consider a scenario where a log server is compromised. How does the "Auditor" role help maintain the integrity of the CT system?
A) By physically guarding the server room with security cameras.B) By verifying that the log server is behaving consistently and not showing different versions of the log to different users.
C) By paying the hackers to return control of the server.
D) By rewriting the code of the log server every 24 hours.
What is the purpose of a "Pre-certificate" in the CT issuance process?
A) It is a draft certificate used for testing purposes only.B) It is a special format sent to the log server to obtain an SCT before the final certificate is created.
C) It is a certificate that has expired and is waiting to be renewed.
D) It is a certificate that does not require any encryption.
In a Merkle Tree used for a CT log with $ n $ entries, what is the approximate mathematical complexity for a browser to verify that a specific certificate is included in the log?
A) $ O(n) $B) $ O(1) $
C) $ O(\log n) $
D) $ O(n^{2}) $
Scan QR Code for Answer Key & Detailed Solutions
https://www.eokultv.com/worksheet-generator/12th-grade-other-certificate-transparency-logs/quizzes