Courseiva
Security Engineering →hardMultiple Select

CAS-004 Security Engineering Practice Question

A company is migrating its legacy VPN to use IPsec with IKEv2. The security team wants to ensure the strongest possible security. Which THREE configuration options should be selected?

⚠ Common exam trap

The trap is selecting SHA-1 for integrity because it is a known algorithm, but SHA-1 is deprecated and insecure; the exam expects recognition that modern IPsec configurations must avoid SHA-1 and IKEv1.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use ECDSA P-384 for authentication

Option A (ECDSA P-384) is correct because elliptic-curve signatures at the 384-bit level provide roughly 192-bit security strength, far exceeding RSA-2048, and are well supported in IKEv2 for strong peer authentication. Option C (AES-256-GCM) is correct because AES-256 gives a 256-bit key and GCM is an AEAD mode that provides both confidentiality and integrity in a single efficient primitive, making it the strongest symmetric choice here. Option E (perfect forward secrecy via DHE) is correct because Diffie-Hellman ephemeral key exchange ensures that compromise of the long-term key cannot decrypt previously captured sessions, which is essential for 'strongest possible security' in an IKEv2 deployment. Option B (SHA-1) is not appropriate because SHA-1 is cryptographically broken for integrity and should be replaced by SHA-256 or stronger. Option D (IKEv1) is not appropriate because IKEv2 is more secure, more robust, and supports modern features like MOBIKE and stronger authentication methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use ECDSA P-384 for authentication

    Why this is correct

    ECDSA P-384 provides a 192-bit security strength, exceeding RSA-2048 and matching the strongest IKEv2 authentication options. It satisfies the stem's demand for maximum security by using elliptic-curve cryptography, which delivers equivalent strength with smaller keys and is approved for CNSA suite compliance.

  • ✗

    Use SHA-1 for integrity

    Why it's wrong here

    SHA-1 is cryptographically broken for collision resistance, so it cannot provide the integrity assurance the scenario demands; SHA-256 or stronger is required. It is tempting because SHA-1 was long the default hash in IPsec proposals and still interoperates with legacy devices, but it would only be the correct choice where peer support mandates it.

  • ✓

    Use AES-256-GCM for encryption

    Why this is correct

    AES-256-GCM provides authenticated encryption, combining confidentiality with integrity checking in a single pass, which satisfies the requirement for the strongest possible security. Its 256-bit key resists brute-force attacks, and GCM's built-in authentication eliminates the need for a separate integrity algorithm, unlike AES-CBC with HMAC.

  • ✗

    Use IKEv1 instead of IKEv2

    Why it's wrong here

    IKEv1 lacks IKEv2's support for stronger integrity algorithms and its more robust rekeying and denial-of-service resistance, so selecting it weakens the tunnel. It is tempting because IKEv1 is the established legacy standard and remains valid for interoperability with older peers, but the scenario explicitly requires the strongest security.

  • ✓

    Enable perfect forward secrecy (DHE)

    Why this is correct

    Perfect forward secrecy using Diffie-Hellman ephemeral key exchange generates a fresh session key for each IKEv2 negotiation, so compromising one key cannot decrypt past or future tunnels. This directly satisfies the stem's demand for the strongest possible IPsec security, since static keys would otherwise expose all historical traffic.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.