StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 3: Security architecture & engineering

Cryptanalytic attacks: brute force, side channel, man-in-the-middle, pass the hash, ransomware

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Cryptanalytic attacks try to defeat cryptography or the systems built around it. The surprising lesson from decades of real incidents is that attackers rarely break the mathematics of a modern algorithm such as the Advanced Encryption Standard (AES). Instead they exploit weak keys, poor implementations, leaked credentials, careless users or the fact that data must eventually be decrypted to be used. The CISSP outline groups several of these together, and your job as a security professional is to recognize each category and match it to the defense that actually works.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan