mediumMultiple ChoiceObjective-mapped
CAS-004 Practice Question: A financial services company is implementing a…
A financial services company is implementing a risk management framework. The security team has identified that the current encryption algorithm for customer data in transit is deprecated. According to NIST SP 800-53, which of the following is the MOST appropriate step to address this finding?
⚠ Common exam trap
Many candidates choose compensating controls (Option A) thinking they can avoid updating the encryption algorithm, but NIST SP 800-53 explicitly requires the use of FIPS 140-2 validated cryptography for data in transit, and compensating controls are not a substitute for a deprecated algorithm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the encryption algorithm to a FIPS 140-2 validated one
NIST SP 800-53 requires that cryptographic algorithms used to protect data in transit must be FIPS 140-2 validated. A deprecated algorithm (e.g., DES, RC4, or 3DES) is no longer considered secure and must be replaced with a current, approved algorithm such as AES-256 or ChaCha20. Updating the encryption algorithm directly remediates the security finding and aligns with the risk management framework's requirement to maintain adequate security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement compensating controls such as network segmentation
Why it's wrong here
Compensating controls do not address the cryptographic weakness.
- ✓
Update the encryption algorithm to a FIPS 140-2 validated one
Why this is correct
Updating aligns with NIST SP 800-53 cryptographic controls.
- ✗
Accept the risk because the algorithm is still functional
Why it's wrong here
Accepting risk without mitigation is not appropriate for a deprecated algorithm.
- ✗
Transfer the risk by purchasing cyber insurance
Why it's wrong here
Transferring risk does not fix the technical issue.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.