CAS-004 Security Engineering Practice Question
A company is migrating its legacy VPN to use IPsec with IKEv2. The security team wants to ensure the strongest possible security. Which THREE configuration options should be selected?
⚠ Common exam trap
The trap is selecting SHA-1 for integrity because it is a known algorithm, but SHA-1 is deprecated and insecure; the exam expects recognition that modern IPsec configurations must avoid SHA-1 and IKEv1.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use ECDSA P-384 for authentication
Option A (ECDSA P-384) is correct because elliptic-curve signatures at the 384-bit level provide roughly 192-bit security strength, far exceeding RSA-2048, and are well supported in IKEv2 for strong peer authentication. Option C (AES-256-GCM) is correct because AES-256 gives a 256-bit key and GCM is an AEAD mode that provides both confidentiality and integrity in a single efficient primitive, making it the strongest symmetric choice here. Option E (perfect forward secrecy via DHE) is correct because Diffie-Hellman ephemeral key exchange ensures that compromise of the long-term key cannot decrypt previously captured sessions, which is essential for 'strongest possible security' in an IKEv2 deployment. Option B (SHA-1) is not appropriate because SHA-1 is cryptographically broken for integrity and should be replaced by SHA-256 or stronger. Option D (IKEv1) is not appropriate because IKEv2 is more secure, more robust, and supports modern features like MOBIKE and stronger authentication methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use ECDSA P-384 for authentication
Why this is correct
ECDSA P-384 provides a 192-bit security strength, exceeding RSA-2048 and matching the strongest IKEv2 authentication options. It satisfies the stem's demand for maximum security by using elliptic-curve cryptography, which delivers equivalent strength with smaller keys and is approved for CNSA suite compliance.
- ✗
Use SHA-1 for integrity
Why it's wrong here
SHA-1 is cryptographically broken for collision resistance, so it cannot provide the integrity assurance the scenario demands; SHA-256 or stronger is required. It is tempting because SHA-1 was long the default hash in IPsec proposals and still interoperates with legacy devices, but it would only be the correct choice where peer support mandates it.
- ✓
Use AES-256-GCM for encryption
Why this is correct
AES-256-GCM provides authenticated encryption, combining confidentiality with integrity checking in a single pass, which satisfies the requirement for the strongest possible security. Its 256-bit key resists brute-force attacks, and GCM's built-in authentication eliminates the need for a separate integrity algorithm, unlike AES-CBC with HMAC.
- ✗
Use IKEv1 instead of IKEv2
Why it's wrong here
IKEv1 lacks IKEv2's support for stronger integrity algorithms and its more robust rekeying and denial-of-service resistance, so selecting it weakens the tunnel. It is tempting because IKEv1 is the established legacy standard and remains valid for interoperability with older peers, but the scenario explicitly requires the strongest security.
- ✓
Enable perfect forward secrecy (DHE)
Why this is correct
Perfect forward secrecy using Diffie-Hellman ephemeral key exchange generates a fresh session key for each IKEv2 negotiation, so compromising one key cannot decrypt past or future tunnels. This directly satisfies the stem's demand for the strongest possible IPsec security, since static keys would otherwise expose all historical traffic.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.