20+ practice questions focused on Cryptography Application — one of the most tested topics on the GIAC Security Essentials exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Cryptography Application PracticeA security administrator is hardening an SSH server configuration file to protect sensitive administrative access. Which TWO configuration directives must be explicitly enforced to ensure strong cryptographic controls and prevent legacy weak encryption algorithms? (Choose two)
Explanation: Modern SSH hardening requires disabling legacy ciphers and insecure MAC algorithms that are vulnerable to cryptographic collisions or plaintext recovery attacks. Enforcing robust encryption primitives and modern key exchange algorithms ensures that interactive shell sessions remain protected against advanced eavesdropping and active interception threats.
Refer to the exhibit. A security auditor is reviewing the configuration of a legacy signing service. Based on current cryptographic standards, why is this configuration flagged as a high-risk finding?
Explanation: RSA-1024 is no longer considered secure against modern computational capabilities, and PKCS#1v1.5 padding is susceptible to padding oracle attacks. This combination is insufficient for modern digital signatures, which require at least RSA-2048 and more secure padding schemes like PSS. Flagging this is critical because outdated cryptographic foundations allow attackers to forge signatures or perform factoring attacks, compromising the authenticity and non-repudiation of all documents signed by this service.
A security team is deploying an internal certificate authority (CA) to issue TLS certificates for microservices. They want to automate the enrollment process without manual approval, but the CA must ensure that any issued certificate cannot be used to sign other certificates. The team configures the CA to include the basicConstraints extension with CA:FALSE and pathlen:0. After issuance, a microservice attempts to use its certificate to sign a subordinate certificate. Which statement describes the outcome when a relying party validates the subordinate certificate?
Explanation: The microservice certificate is an end-entity certificate because its basicConstraints extension is set to CA:FALSE. When a relying party validates a certificate signed by this microservice, it checks the issuer's basicConstraints and finds that the issuer is not a CA. Therefore, the subordinate certificate is rejected. The pathlen constraint does not apply because the certificate is not a CA.
A financial institution is implementing a digital signature solution for its internal document approval workflow. The security architect must select a cryptographic algorithm that provides non-repudiation and ensures that signatures cannot be forged even if an attacker obtains the public key. The institution also requires that the signature scheme be standardized by NIST and widely supported in commercial off-the-shelf (COTS) products. Which algorithm should the architect choose?
Explanation: RSA with SHA-256 is a NIST-standardized digital signature algorithm that provides non-repudiation and is widely supported in commercial products. It uses a private key for signing and a public key for verification, so an attacker with the public key cannot forge signatures. ECDSA is also standardized but may have less ubiquitous support in older COTS environments, making RSA the better fit for broad compatibility.
A security administrator is configuring encrypted backups for a remote office. The backup software supports AES-256 but requires a mode of operation that allows parallel processing of blocks and does not require the ciphertext to be padded to a multiple of the block size. The administrator must also ensure that identical plaintext blocks do not produce identical ciphertext blocks. Which mode should be selected?
Explanation: The backup software requires a mode that supports parallel block processing, avoids padding, and ensures identical plaintext blocks produce different ciphertext blocks. Galois/Counter Mode (GCM) meets all these criteria because it uses a counter-based keystream that can be parallelized and never repeats for a given key and IV. GCM also adds authentication, which strengthens backup integrity.
+15 more Cryptography Application questions available
Practice all Cryptography Application questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Cryptography Application. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Cryptography Application questions on the GSEC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Cryptography Application is tested as part of the GIAC Security Essentials blueprint. Practicing with targeted Cryptography Application questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GSEC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Cryptography Application is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Cryptography Application practice session with instant scoring and detailed explanations.
Start Cryptography Application Practice →