CAS-004 Security Architecture Practice Question
A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?
⚠ Common exam trap
The trap is mixing up KEM and digital signature algorithms — candidates may pick Dilithium or Falcon because they are also NIST PQC standards, but only Kyber is a KEM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CRYSTALS-Kyber
CRYSTALS-Kyber is the NIST-standardized algorithm for key encapsulation (KEM), selected in the post-quantum cryptography standardization process. It is designed for secure key exchange and is efficient for both client and server. NIST selected Kyber as the primary KEM standard (FIPS 203).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CRYSTALS-Dilithium
Why it's wrong here
CRYSTALS-Dilithium is a lattice-based digital signature algorithm, used to sign data rather than to encapsulate keys. It is tempting because it shares the MLWE lattice mathematics underpinning ML-KEM and appears in the same NIST selection round, but Dilithium's standardised role is signature generation and verification.
- ✗
SPHINCS+
Why it's wrong here
SPHINCS+ is a stateless hash-based digital signature scheme, so it verifies authenticity rather than encapsulating a symmetric key. It is tempting because it is one of the NIST-selected post-quantum algorithms, and hash-based constructions are often assumed to cover encryption, yet SPHINCS+ is standardised solely for signatures.
- ✗
Falcon
Why it's wrong here
Falcon is a lattice-based digital signature scheme, providing authentication rather than establishing a shared secret between parties. It is tempting because Falcon, like ML-KEM, derives its security from lattice problems, so it appears alongside key-encapsulation candidates in NIST's post-quantum portfolio, but its standardised purpose is signing.
- ✓
CRYSTALS-Kyber
Why this is correct
CRYSTALS-Kyber is the NIST-standardised key encapsulation mechanism (ML-KEM, FIPS 203), built on module learning-with-errors. It satisfies the stem's requirement for a PQC KEM candidate by enabling two parties to establish a shared symmetric key over a public channel, unlike CRYSTALS-Dilithium, which is a digital signature scheme.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.