Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

A security analyst is reviewing a packet capture and observes that a client and server negotiate a session key using ephemeral Diffie-Hellman, after which all application data is encrypted with a symmetric cipher. The analyst wants to document which security property the ephemeral key exchange provides that a static RSA key transport would not. Which property is that?

⚠ Common exam trap

Watch out — candidates often confuse the authentication and integrity services of TLS with the key-agreement property, when the real benefit of ephemeral key exchange is protection of past sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forward secrecy, because compromise of the long-term private key does not reveal past session keys.

Ephemeral Diffie-Hellman creates a unique shared secret per session and erases the private ephemeral values, so a later compromise of the server's long-term key cannot decrypt previously captured traffic. Static RSA key transport ties the premaster secret to the long-term key, so that compromise exposes all recorded sessions. The distinguishing property is forward secrecy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perfect confidentiality of the server certificate, because the certificate is encrypted during the handshake.

    Why it's wrong here

    The server certificate is sent in the clear in TLS 1.2 and earlier, and in TLS 1.3 it is encrypted only after handshake keys are derived, not because of Diffie-Hellman itself. The certificate's confidentiality is not the security property that ephemeral key exchange adds. This statement also misuses the term perfect confidentiality, which is not the concept at issue.

  • ✓

    Forward secrecy, because compromise of the long-term private key does not reveal past session keys.

    Why this is correct

    Ephemeral Diffie-Hellman generates a fresh key pair per session and discards it afterward, so the session key is never derivable from the server's long-term private key. Even if that long-term key is later compromised, previously recorded sessions remain protected. Static RSA key transport encrypts the premaster secret with the long-term key, so its compromise retroactively exposes past sessions, which is exactly the property ephemeral DH adds.

  • ✗

    Non-repudiation, because the ephemeral key pair proves the server's identity to the client.

    Why it's wrong here

    Non-repudiation is provided by digital signatures over the handshake, not by the ephemeral key agreement itself. Ephemeral Diffie-Hellman provides no proof of identity on its own; authentication comes from certificates or pre-shared keys. This property is therefore unrelated to the key exchange mechanism and would not be the difference the analyst should document.

  • ✗

    Data integrity, because Diffie-Hellman produces a message authentication code over each record.

    Why it's wrong here

    Record integrity in TLS comes from the AEAD construction or a separate MAC, not from the Diffie-Hellman exchange. Diffie-Hellman establishes a shared secret but does not authenticate individual records. Attributing integrity to the key agreement mischaracterizes the protocol layering and does not distinguish ephemeral DH from static RSA transport.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.