ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While creating security test cases for a PRNG that supplies encryption keys for a new web service, you must determine which property to validate first. Which characteristic is most critical to confirm that the generator delivers cryptographic-grade randomness before the application goes live?
Confirm that the generator can output more than 2^64 unique values before any repetition occurs.
Run uniform-distribution tests to show every byte value appears within 0.5 % of expectation in a 1 GB sample.
Verify that the entropy collected for the initial seeding provides sufficient unpredictability, such as at least 256 bits for 256-bit security strength.
Measure the generator's throughput to ensure it can produce 10 MB of random data per second under peak load.
For a cryptographic PRNG, security hinges on the unpredictability of its output. That unpredictability is derived from the entropy present in the initial seed material. If the seed does not contain enough truly random bits-NIST SP 800-90A requires entropy commensurate with the desired security strength (e.g., 256 bits for a 256-bit strength DRBG)-an attacker who can guess or infer the seed can predict all subsequent values, no matter how long the period or how well the output passes statistical tests. Throughput or small-sample uniformity may matter for performance tuning, but they do not establish cryptographic strength.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is entropy and why is it important for PRNGs?
Open an interactive chat with Bash
What is NIST SP 800-90A, and how does it relate to PRNGs?
Open an interactive chat with Bash
How does entropy differ from the period or uniformity in randomness testing?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .