Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

Ravi's firm transmits large payroll files to its bank every night. The IT head proposes using AES for the file contents and RSA only to exchange the AES session key. What is the main reason for this hybrid design?

The hybrid design uses AES for bulk data because symmetric encryption is fast, and RSA to deliver the AES session key securely because asymmetric encryption removes the need to share a secret in advance. Together they combine speed with safe key distribution.

  1. ASymmetric encryption is much faster for bulk data, while asymmetric encryption solves the key distribution problemCorrect
  2. BRSA cannot be used to encrypt any data, even small keys
  3. CAES provides non-repudiation, which RSA cannot
  4. DAES keys are public, so they need RSA to hide them

Explanation

Symmetric algorithms like AES are efficient for large volumes but need a secure way to share the key. Asymmetric RSA is slow but can safely transport the small session key. Option on non-repudiation is wrong because symmetric shared keys cannot prove who originated data.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions