Be able to read real command output and configuration, then name the cryptographic weakness or the correct control. The single most important thing: know what each flag, mode, and key type actually protects, so you can spot when protection is missing.
Start practicing
Cryptography — choose a session length
Free · No account required
Domain overview
GSEC cryptography covers symmetric and asymmetric encryption, hashing, PKI, TLS, IPsec, and key management as applied in defensive operations. Questions present real command output, certificate requests, VPN configurations, or incident scenarios and ask you to identify the vulnerability, the correct control, or the security consequence of a specific setting.
Exam objectives
Interpreting openssl req output and the effect of the -nodes flag on private key storage
Selecting encryption-in-use controls such as confidential computing or secure enclaves
Analyzing code-signing key compromise and why signed malicious firmware passes verification
Evaluating IPsec/IKEv2 authentication choices including PSK versus certificate-based authentication
Assuming -nodes encrypts the private key; it actually disables passphrase protection, leaving the key unencrypted on disk.
Confusing encryption at rest, in transit, and in use, then choosing a control that does not protect data during processing.
Believing signature verification proves vendor intent; a stolen code-signing key produces valid signatures on attacker updates.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?
2Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?
3A security analyst is investigating a suspected man-in-the-middle attack against an HTTPS service. The analyst finds that the client is ignoring certificate validation errors. Which cryptographic failure is most likely occurring?
4A developer is implementing an application that stores user passwords in a database. Which THREE of the following practices are essential for ensuring the cryptographic security of these stored secrets?
5An organization is migrating to a cloud environment and must ensure that data remains encrypted while in use by applications. Which technology should the security team implement to achieve this?
6A software vendor distributes signed firmware updates to customers. During an incident review, an analyst discovers that an attacker who obtained the vendor's code-signing private key was able to produce updates that passed signature verification on customer devices. The vendor wants to redesign the signing process so that compromise of a single signing key no longer allows an attacker to forge valid updates. Which change best achieves this goal?
7A security team is deploying a new internal TLS certificate authority (CA) for service-to-service authentication. The CA private key must be protected, and the team wants to ensure that if the key is compromised, the attacker cannot forge certificates without detection. Which of the following is the MOST effective control to detect unauthorized certificate issuance?
8A security architect is designing a system that requires cryptographic keys to be generated, stored, and used without ever exposing the private key material to the operating system. The keys must be usable for TLS server authentication and must support high transaction volumes. Which of the following solutions BEST meets these requirements?
9A security analyst is reviewing the configuration of a VPN gateway that uses IPsec in tunnel mode. The analyst notices that the gateway is configured to use IKEv2 with a pre-shared key (PSK) for authentication. Which of the following is the PRIMARY security concern with this configuration?
10A security administrator is configuring a Linux server to encrypt a new block device that will store sensitive data. The administrator wants to ensure that data is encrypted at rest and that the encryption key is protected by a passphrase. Which of the following tools is designed specifically for this purpose?
11A security engineer at a hospital must encrypt a 40 GB database backup for archival to offsite tape. The tape library appliance has very limited CPU resources, and the engineer wants a symmetric mode that allows the archive to be decrypted in independent chunks without needing to read the entire stream first. Which cipher mode BEST satisfies these requirements?
12A security engineer is implementing a digital signature solution using RSA. The engineer must ensure that signatures provide authenticity, integrity, and non-repudiation. Which TWO of the following practices are essential to achieve these goals? (Choose two.)
13A financial services firm is designing a key management process for its internal certificate authority. The security architect wants a single hardware security module (HSM) cluster to protect the CA's signing key while ensuring that a compromise of one HSM appliance does not expose the key in plaintext to an attacker who gains root on that appliance. Which deployment property BEST addresses this requirement?
14A junior administrator is asked to verify the integrity of a downloaded Linux distribution ISO before installing it on a production server. The vendor publishes a SHA-256 checksum and a detached PGP signature. Which action BEST confirms both that the file is intact and that it genuinely originated from the vendor?
Be able to read real command output and configuration, then name the cryptographic weakness or the correct control. The single most important thing: know what each flag, mode, and key type actually protects, so you can spot when protection is missing.
The Courseiva GSEC question bank contains 14 questions in the Cryptography domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cryptography domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included