Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?

⚠ Common exam trap

The trap is mixing up KEM and digital signature algorithms — candidates may pick Dilithium or Falcon because they are also NIST PQC standards, but only Kyber is a KEM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CRYSTALS-Kyber

CRYSTALS-Kyber is the NIST-standardized algorithm for key encapsulation (KEM), selected in the post-quantum cryptography standardization process. It is designed for secure key exchange and is efficient for both client and server. NIST selected Kyber as the primary KEM standard (FIPS 203).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CRYSTALS-Dilithium

    Why it's wrong here

    CRYSTALS-Dilithium is a lattice-based digital signature algorithm, used to sign data rather than to encapsulate keys. It is tempting because it shares the MLWE lattice mathematics underpinning ML-KEM and appears in the same NIST selection round, but Dilithium's standardised role is signature generation and verification.

  • ✗

    SPHINCS+

    Why it's wrong here

    SPHINCS+ is a stateless hash-based digital signature scheme, so it verifies authenticity rather than encapsulating a symmetric key. It is tempting because it is one of the NIST-selected post-quantum algorithms, and hash-based constructions are often assumed to cover encryption, yet SPHINCS+ is standardised solely for signatures.

  • ✗

    Falcon

    Why it's wrong here

    Falcon is a lattice-based digital signature scheme, providing authentication rather than establishing a shared secret between parties. It is tempting because Falcon, like ML-KEM, derives its security from lattice problems, so it appears alongside key-encapsulation candidates in NIST's post-quantum portfolio, but its standardised purpose is signing.

  • ✓

    CRYSTALS-Kyber

    Why this is correct

    CRYSTALS-Kyber is the NIST-standardised key encapsulation mechanism (ML-KEM, FIPS 203), built on module learning-with-errors. It satisfies the stem's requirement for a PQC KEM candidate by enabling two parties to establish a shared symmetric key over a public channel, unlike CRYSTALS-Dilithium, which is a digital signature scheme.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.