CAS-004 Security Engineering Practice Question
A security analyst is investigating a potential side-channel attack on an IoT device. The device's cryptographic operations show variable execution times based on the key and plaintext. Which mitigation is most effective against timing attacks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use constant-time cryptographic implementations.
Timing attacks exploit variations in execution time. Using constant-time algorithms ensures that operations take the same amount of time regardless of input, preventing information leakage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a faster processor to reduce execution time.
Why it's wrong here
A faster processor shortens absolute execution time but preserves the relative timing differences between key and plaintext paths, which is exactly what the attacker measures. Faster hardware suits throughput or latency budgets, not side-channel resistance, which requires constant-time code.
- ✓
Use constant-time cryptographic implementations.
Why this is correct
Constant-time implementations execute identical instruction sequences and memory access patterns regardless of key or plaintext values, eliminating the timing variance the analyst observed. This removes the correlation between execution duration and secret data that enables timing attacks.
- ✗
Implement random delays in cryptographic operations.
Why it's wrong here
Random delays add noise but leave the underlying data-dependent timing variation intact, so statistical averaging still recovers the key. Delays suit throttling brute-force or rate-limiting abuse, not removing the correlation between execution time and secret values that constant-time implementation eliminates.
- ✗
Disable caching in the CPU during cryptographic operations.
Why it's wrong here
Cache timing attacks are a distinct side channel; disabling CPU caching does nothing to the variable instruction paths and branch timings this device exhibits. Cache-flushing defences belong to scenarios where secret-dependent memory access patterns, such as AES table lookups, leak through cache hits.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.