Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?

⚠ Common exam trap

The trap is confusing symmetric and asymmetric encryption. Candidates might think AES is asymmetric because it's strong, but the key characteristic is that it uses a single shared key. Also, hashing is sometimes mistaken for encryption, but it's irreversible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Symmetric encryption

AES-256 is a symmetric encryption algorithm, meaning it uses the same key for both encryption and decryption. It is widely used for data at rest due to its strength and efficiency. The '256' refers to the key size in bits, making it highly resistant to brute-force attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hashing algorithm

    Why it's wrong here

    Hashing is a one-way function producing a fixed-length digest for integrity checking, and it is irreversible, so it cannot encrypt data at rest. Hashing is correct for verifying file integrity or storing password digests, not for AES-256 confidentiality.

  • ✗

    Digital signature

    Why it's wrong here

    A digital signature provides authenticity and integrity through asymmetric cryptography; it does not encrypt data at rest. Signing is the correct control when proving a document's origin and detecting tampering, not when satisfying an AES-256 encryption-at-rest policy.

  • ✗

    Asymmetric encryption

    Why it's wrong here

    Asymmetric encryption uses key pairs such as RSA or ECC, whereas AES-256 is a symmetric block cipher using one shared key. Asymmetric cryptography is correct for key exchange and digital signatures, not for bulk data-at-rest encryption under this policy.

  • ✓

    Symmetric encryption

    Why this is correct

    AES-256 uses a single shared secret key for both encryption and decryption, making it symmetric. Asymmetric algorithms such as RSA instead use a public-private key pair. The policy's requirement for AES-256 therefore specifies symmetric encryption, not hashing or asymmetric cryptography.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.