Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security analyst is reviewing TLS 1.3 configuration for a web server. The analyst wants to ensure that the configuration provides forward secrecy and prevents the reuse of session keys. Which of the following is a characteristic of TLS 1.3 that supports these goals?

⚠ Common exam trap

CAS-005 often tests the misconception that 0-RTT or static RSA provide forward secrecy, when in fact TLS 1.3's ephemeral Diffie-Hellman is the key mechanism for forward secrecy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use of ephemeral Diffie-Hellman key exchange

TLS 1.3 mandates the use of ephemeral Diffie-Hellman key exchange (DHE or ECDHE) for all handshakes, which provides forward secrecy by generating a unique session key for each session that cannot be derived from the server's long-term private key. This ensures that even if the server's private key is compromised later, past session keys remain secure and cannot be reused.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    0-RTT session resumption

    Why it's wrong here

    0-RTT resumption lets a client replay early data using a previously established pre-shared key, which permits replay attacks and weakens forward secrecy. It suits latency-sensitive reconnections; TLS 1.3's ephemeral Diffie-Hellman key exchange is what delivers forward secrecy and fresh per-session keys.

  • ✗

    Support for static RSA key exchange

    Why it's wrong here

    Static RSA key exchange encrypts the premaster secret with the server's long-term key, so anyone later obtaining that private key can decrypt recorded sessions; TLS 1.3 removed it precisely to guarantee forward secrecy. It is tempting because static RSA was a valid TLS 1.2 option, but it is the mechanism TLS 1.3 eliminated.

  • ✓

    Use of ephemeral Diffie-Hellman key exchange

    Why this is correct

    Ephemeral Diffie-Hellman generates a unique key pair per session, then discards it, so compromising the server's long-term private key cannot decrypt past traffic — satisfying the forward secrecy requirement. Because each handshake derives fresh session keys, reuse across sessions is impossible, meeting the stem's second constraint.

  • ✗

    Removal of CBC mode cipher suites

    Why it's wrong here

    CBC mode removal addresses padding-oracle and MAC-then-encrypt weaknesses, not key reuse; forward secrecy in TLS 1.3 comes from ephemeral (EC)DHE key exchange, which derives unique per-session keys. Removing CBC is tempting because it hardens cipher configuration, but it does not itself prevent session-key reuse.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.