Quiz: Module 5 Assignment: Cryptography, Certificates, and Zero Trust Instructions: This assignment is designed to test your practical understanding of the concepts covered in Module 5. Complete the three parts below. When you are finished, compile your answers and screenshots into a single PDF document and upload it to the LMS. Part 1: The Avalanche Effect (Hands-On) Objective: Prove that hashing is highly sensitive to input changes, a critical concept for data integrity and password security. Go to the CyberChef website (linked in your Resource Vault) or use the command line in your Kali Linux VM. Hash the phrase: CyberShield2024 using the SHA-256 algorithm. Change exactly one character (e.g., make the “C” lowercase, or change “2024” to “2025”). Hash the new phrase using SHA-256. Deliverable: Provide the two resulting 64-character hashes. In one short sentence, explain why this “Avalanche Effect” makes it impossible for a hacker to guess a password by looking at its hash. Part 2: The SSL Consultant (Hands-On) Objective: Practice auditing web server configurations using industry-standard tools. Go to Qualys SSL Labs (ssllabs.com/ssltest). Find a small, local business website in your area (e.g., a local restaurant, a small accounting firm, or a local boutique). Do not scan major sites like Google or Amazon. Run the SSL Server Test on that website. Deliverable: Provide a screenshot of the final “Grade” (e.g., A, B, F) the website received. Write a 3-to-4 sentence “pitch” to the business owner explaining what the grade means in plain English, why it is a problem (mentioning Google penalties or customer trust), and offering to fix it for them. (Hint: Use the monetization angle from Lesson 5.2!) Part 3: Securing the Perimeter (Action & Reflection) Objective: Apply Zero Trust and IAM principles to your own digital life. Log into your primary personal email account (Google, Microsoft, etc.) and navigate to the Security settings. Check the “Two-Step Verification” or “MFA” settings. Deliverable: Take a screenshot showing that you have MFA enabled (blur out any sensitive personal info like your phone number). Answer in 2-3 sentences: What specific method of MFA are you currently using (SMS, Authenticator App, Hardware Key)? Based on Lesson 5.3, if you are using SMS, what is the specific security risk (attack name) you are vulnerable to, and what should you upgrade to? Grading Criteria: Part 1: Correct hashes provided and accurate explanation of the avalanche effect. (33%) Part 2: Screenshot of a real scan provided and a professional, easy-to-understand pitch written. (34%) Part 3: Screenshot of active MFA provided and accurate identification of MFA methods and SMS vulnerabilities. (33%) - The Acinge Network

Partner with us to develop
something extraordinary

Navigation Links

Subscribe to The Acinge Newsletter

Join our mailing list for thoughtful articles, case studies, and practical guidance on building reliable digital systems.

You have been successfully Subscribed! Ops! Something went wrong, please try again.

© 2026 Copyright. The Acinge. All Rights Reserved

Scroll to Top