Be able to map a stated requirement — forward secrecy, integrity, reversibility, trust — to the specific algorithm, mode, or PKI function that satisfies it. The single most important thing is reading the requirement precisely and not selecting a control that solves a different problem.
Start practicing
Cryptography Application — choose a session length
Free · No account required
Domain overview
The Cryptography Application domain on GSEC covers how encryption, hashing, and PKI are deployed in real systems rather than as pure theory. Questions present operational scenarios — TLS negotiation, database encryption, integrity verification, certificate lifecycle — and ask you to select the correct algorithm, mode, or PKI function and justify why it satisfies the stated requirement.
Exam objectives
Selecting TLS 1.3 cipher suites that provide forward secrecy via ephemeral key exchange
Choosing hash functions by collision resistance for file and data integrity verification
Applying reversible encryption with integrity protection, such as authenticated modes, to stored PII
Identifying core PKI functions including certificate issuance, validation, and revocation
Confusing collision resistance with preimage resistance when the question asks about two different inputs producing one hash
Assuming any TLS version guarantees forward secrecy instead of checking the key exchange mechanism
Treating encryption alone as sufficient for integrity, ignoring authenticated encryption or MAC requirements
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security engineer is designing an internal Public Key Infrastructure (PKI) and needs to issue a subordinate certificate authority (sub-CA) certificate. To prevent this sub-CA from accidentally or maliciously issuing certificates for unauthorized domains, what specific X.509 extension must be correctly configured?
2An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?
3A security analyst is hardening a web server to ensure that only modern, secure protocols are used for HTTPS traffic. Which configuration best aligns with GSEC security standards for data in transit?
4An organization needs to encrypt a database of PII. The requirements state that the encryption must be reversible by authorized staff and provide data integrity. Which implementation should the security engineer recommend?
5Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?
6When selecting a cryptographic hash function for verifying file integrity, which property is most important to ensure that an attacker cannot create two different files that produce the same hash value?
7A security analyst is reviewing a legacy application that uses RSA for digital signatures. The application generates a 1024-bit RSA key pair and signs messages using SHA-1. The analyst must recommend an upgrade that maintains the same algorithm family but meets current security standards. Which change should be recommended?
8A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?
9A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)
10A security engineer is selecting a hash function to protect stored user passwords in a new application. The threat model assumes an attacker who steals the password database and has substantial GPU resources for offline cracking. Which choice best addresses this threat?
Be able to map a stated requirement — forward secrecy, integrity, reversibility, trust — to the specific algorithm, mode, or PKI function that satisfies it. The single most important thing is reading the requirement precisely and not selecting a control that solves a different problem.
The Courseiva GSEC question bank contains 10 questions in the Cryptography Application domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cryptography Application domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included