200-201 Security Concepts Practice Question
An organization wants to ensure that data sent over the internet cannot be read if intercepted. Which cryptographic method should be used?
⚠ Common exam trap
The trap is that candidates equate 'cryptographic method' with 'security' and pick hashing or HMAC because they sound protective, forgetting that only encryption provides confidentiality — hashing and signing do not hide data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Symmetric encryption with AES
Symmetric encryption with AES transforms plaintext into ciphertext using a shared secret key, so an attacker who intercepts the data over the internet cannot read it without the key. AES is the standard, NIST-approved symmetric cipher (FIPS 197) used in TLS, VPNs, and disk encryption. This directly satisfies the requirement that intercepted data cannot be read.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Digital signature using RSA
Why it's wrong here
A digital signature using RSA proves origin and integrity but does not conceal the message; the payload remains readable unless separately encrypted. Signatures are tempting because they use asymmetric keys, and a digital signature would be the correct choice when the requirement is non-repudiation and authenticity rather than confidentiality.
- ✗
Hash-based message authentication code (HMAC)
Why it's wrong here
HMAC provides integrity and authenticity through a shared secret key, leaving the payload readable in transit; confidentiality requires encryption such as AES or TLS. HMAC is tempting because it protects messages from tampering, and it would be the correct choice when verifying that data originated from a trusted source and was not altered.
- ✓
Symmetric encryption with AES
Why this is correct
AES is a symmetric block cipher whose confidentiality guarantee renders intercepted ciphertext unreadable without the shared key, satisfying the stem's interception constraint. Symmetric encryption suits bulk data protection, whereas asymmetric algorithms are typically reserved for key exchange and digital signatures.
- ✗
Hashing with SHA-256
Why it's wrong here
SHA-256 is a one-way digest producing a fixed-length fingerprint, so it cannot be reversed to recover the original plaintext; encryption is needed for confidentiality. Hashing is tempting because it secures stored passwords and detects file changes, and it would be the correct choice when verifying integrity rather than hiding content.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.