🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company's code-signing service runs in a self-managed hardware security module (HSM). Monitoring shows an external actor is collecting fine-grained measurements of how long the HSM takes to perform 2048-bit RSA private-key operations on different inputs, likely to derive key bits. Which mitigation is most effective against this side-channel attack without changing the cryptographic algorithm or key length?

  • Prepend a random salt to each message before signing to randomize the input data.

  • Modify the HSM firmware so all RSA private-key operations run in constant time, removing timing variability.

  • Rotate the RSA key every 24 hours to limit the window of exposure if a key is compromised.

  • Increase the RSA key size from 2048 bits to 4096 bits to make brute-force attacks impractical.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot