200-201 Security Concepts Practice Question
A company's security policy requires that sensitive data be encrypted at rest using AES-256. Which type of encryption does AES-256 represent?
⚠ Common exam trap
The trap is confusing symmetric and asymmetric encryption. Candidates might think AES is asymmetric because it's strong, but the key characteristic is that it uses a single shared key. Also, hashing is sometimes mistaken for encryption, but it's irreversible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Symmetric encryption
AES-256 is a symmetric encryption algorithm, meaning it uses the same key for both encryption and decryption. It is widely used for data at rest due to its strength and efficiency. The '256' refers to the key size in bits, making it highly resistant to brute-force attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hashing algorithm
Why it's wrong here
Hashing is a one-way function producing a fixed-length digest for integrity checking, and it is irreversible, so it cannot encrypt data at rest. Hashing is correct for verifying file integrity or storing password digests, not for AES-256 confidentiality.
- ✗
Digital signature
Why it's wrong here
A digital signature provides authenticity and integrity through asymmetric cryptography; it does not encrypt data at rest. Signing is the correct control when proving a document's origin and detecting tampering, not when satisfying an AES-256 encryption-at-rest policy.
- ✗
Asymmetric encryption
Why it's wrong here
Asymmetric encryption uses key pairs such as RSA or ECC, whereas AES-256 is a symmetric block cipher using one shared key. Asymmetric cryptography is correct for key exchange and digital signatures, not for bulk data-at-rest encryption under this policy.
- ✓
Symmetric encryption
Why this is correct
AES-256 uses a single shared secret key for both encryption and decryption, making it symmetric. Asymmetric algorithms such as RSA instead use a public-private key pair. The policy's requirement for AES-256 therefore specifies symmetric encryption, not hashing or asymmetric cryptography.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.