Skip to main content
RelixQ
Menu

HNDL Fundamentals · Final assessment

14 questions, 80% to pass

Answer every question you can, then submit. Grading happens on our server, not in your browser, so the score behind your HNDL Fundamentals — Certificate of Completion reflects what you actually chose.

Question 1 of 14

A junior engineer says: "We don't need to worry about post-quantum migration because no quantum computer that can break our encryption exists yet."

What is the most accurate response, given HNDL?

Question 2 of 14

Which statement about cryptographically relevant quantum computers (CRQCs) is accurate?

Question 3 of 14

A document management system stores digitally signed contracts. An adversary captures a copy of a signed contract today.

Which statement correctly describes the risk?

Question 4 of 14

A service protects data with AES-256 for storage, but establishes the encryption key using RSA key transport, and that RSA-wrapped key exchange is visible to a network observer.

What accurately describes this service's exposure?

Question 5 of 14

A team states that their protocol is safe from HNDL because it uses ephemeral Diffie-Hellman parameters for every session, a form of forward secrecy.

Is this claim correct?

Question 6 of 14

A CDN provider announces that it now negotiates `X25519MLKEM768` by default for supporting clients.

What is the most accurate implication for HNDL?

Question 7 of 14

A dataset must remain confidential per policy for 25 years from its creation date. It was created 10 years ago.

What is its remaining confidentiality lifetime (X) for HNDL purposes today?

Question 8 of 14

Customer records are stored only on an internal system with no network exposure, no backups leave the building, and no third party ever receives a copy.

How should this data flow be treated for HNDL purposes?

Question 9 of 14

A backup is encrypted with a data key that is itself wrapped by a key-encryption key established through classical RSA. The backup file is stored in third-party cloud storage.

Where should the HNDL analysis actually focus?

Question 10 of 14

An architecture diagram lists a partner connection as 'encrypted with TLS,' with no further detail recorded.

What should happen before this flow can be scored for HNDL exposure?

Question 11 of 14

Two analysts disagree: one wants to record an unconfirmed vendor's key exchange as 'hybrid' because that is increasingly common; the other wants to record it as 'unknown, low confidence' until the vendor responds.

Which approach is defensible?

Question 12 of 14

A data class has a confidentiality lifetime (X) of 8 years and an estimated migration time (Y) of 4 years.

Under Mosca's inequality, what does X + Y = 12 years imply?

Question 13 of 14

What is the current status of NIST IR 8547?

Question 14 of 14

A security team is choosing between prioritizing migration of (1) a database of decades-long-retention insurance claims replicated to a third-party analytics vendor over a classical TLS connection, and (2) an internal admin dashboard's session cookies, which live for 30 minutes and never leave the internal network.

Which prioritization is best supported by the four-variable model in this course?

0 of 14 answered. An unanswered question counts as incorrect, so it is safe to submit a partial attempt to see where you stand.