考题篇(5.2) 18. 证书 ❀ 飞塔 (Fortinet) 网络安全专家 NSE4
Bob wants to send Alice a file that is encrypted using public key cryptography.〖鲍勃要给爱丽丝发送一个使用公钥加密算法加密的文件〗
Which of the following statements is correct regarding the use of public key cryptography in this scenario?〖下面哪些关于这种情况下使用公钥加密的描述是正确的?〗
A. Bob will use his private key to encrypt the file and Alice will use her private key to decrypt the file.〖鲍勃要使用私钥加密文件,爱丽丝要使用私钥解密文件〗
B. Bob will use his public key to encrypt the file and Alice will use Bob's private key to decrypt the file.〖鲍勃要使用公钥加密文件,爱丽丝要使用鲍勃的私钥解密文件〗
C. Bob will use Alice's public key to encrypt the file and Alice will use her private key to decrypt the file.〖鲍勃要使用爱丽丝的公钥加密文件,爱丽丝要使用自己的私钥解密文件〗
D. Bob will use his public key to encrypt the file and Alice will use her private key to decrypt the file.〖鲍勃要使用他的公钥加密文件,爱丽丝要她的私钥解密文件〗
【分析】
非对称**,用本人的公钥加密,再用本人的私钥解密。
【答案】C
Which tasks fall under the responsibility of the SSL proxy in a typical HTTPS connection? (Choose two)〖在一个典型的HTTPS连接中哪些任务属于SSL代理的责任? (选择两个)〗
A. The web client SSL handshake.〖web客户端SSL握手〗
B. The web server SSL handshake. 〖web服务器SSL握手〗
C. File buffering. 〖文件缓存〗
D. Communication with the URL filter process. 〖通迅和地址过滤处理〗
An SSL Proxy is a device, usually a router or computer, that routes traffic from a client to other servers using the Secure Sockets Layer (SSL) protocol. SSL is an encrypted protocol that creates a secure connection from a client to another client or server. SSL is often used in conjunction with Hypertext Transfer Protocol to create a more secure connection when browsing the Internet; the resulting protocol, or language in simpler terms, is known as HTTPS.
SSLProxy是一个设备,通常是一个路由器或计算机,从客户机流量路由到其他服务器使用安全套接字层(SSL)协议。SSL是一个加密的协议,它创建了一个从客户端到另一客户端(或服务器)的安全连接,通常是使用SSL与超文本传输协议来创建一个更安全的浏览互联网连接,最终的协议,或用更简单的术语来说,称为HTTPS。
【答案】AB
When the SSL proxy is NOT doing man-in-the-middle interception of SSL traffic, which certificate field can be used to determine the rating of a website? 〖当SSL代理不做中间人拦截SSL流量,哪些证书字段可以被用来决定一个网站的评级?〗
A. Organizational Unit.〖组织单元〗
B. Common Name. 〖通用名〗
C. Serial Number.〖***〗
D. Validity.〖有效性〗
【分析】
Man-in-the-middle(中间人,简称为 MITM),能够与网络通讯两端分别创建连接,交换其收到的数据,使得通讯两端都认为自己直接与对方对话,事实上整个会话都被中间人所控制。简而言之,在真正的服务端看来,中间人是客户端;而真正的客户端会认为中间人是服务端。
【答案】B