CAS-004 Security Engineering Practice Question
A security analyst is reviewing cryptographic implementations for a new application. The application needs to support digital signatures that are quantum-resistant and provide high performance. Which TWO algorithms should the analyst consider? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
XMSS (eXtended Merkle Signature Scheme)
Ed25519 is a high-performance signature algorithm based on Curve25519, but it is not quantum-resistant. BLAKE3 is a hash function, not a signature. ECDSA P-384 is also not quantum-resistant. Currently, NIST is standardizing post-quantum algorithms like CRYSTALS-Dilithium and XMSS (hash-based). CRYSTALS-Dilithium is a lattice-based signature scheme, and XMSS is a hash-based signature scheme that is quantum-resistant. Both are suitable for high performance in software.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ed25519
Why it's wrong here
Ed25519 is not quantum-resistant.
- ✓
XMSS (eXtended Merkle Signature Scheme)
Why this is correct
XMSS is a hash-based signature scheme that is quantum-resistant.
- ✗
ECDSA P-384
Why it's wrong here
ECDSA is not quantum-resistant.
- ✗
BLAKE3
Why it's wrong here
BLAKE3 is a hash function, not a signature.
- ✓
CRYSTALS-Dilithium
Why this is correct
Dilithium is a lattice-based post-quantum signature algorithm.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.