CAS-004 Security Architecture Practice Question
A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?
⚠ Common exam trap
The trap here is assuming that any authenticated encryption mode preserves equality lookups, when in fact only deterministic modes do so.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deterministic encryption using AES-SIV
The requirement for repeatable ciphertext that still supports equality lookups points to a deterministic authenticated encryption mode. AES-SIV derives its nonce from the plaintext and associated data, so the same input always yields the same output while still providing integrity. Randomized modes and salted hashing break the equality-search property the database design depends on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SHA-256 hashing of the account number with a per-row salt
Why it's wrong here
A per-row salt guarantees a unique digest for every row even when the account number repeats, so equality matching on the stored value cannot work. Hashing is also one-way, so the original account number can never be recovered for legitimate business use, which the scenario requires.
- ✓
Deterministic encryption using AES-SIV
Why this is correct
AES-SIV is a misuse-resistant AEAD mode that produces a deterministic ciphertext for a given plaintext and associated data, so identical account numbers map to identical ciphertext. This preserves equality searches, joins, and unique indexes while keeping values unreadable to DBAs who lack the key, satisfying the stated business requirement.
- ✗
RSA-4096 OAEP encryption of each account number
Why it's wrong here
RSA-OAEP is a randomized public-key scheme, so encrypting the same account number twice yields different ciphertexts and defeats equality search. It is also far slower and produces variable-length output unsuitable for an indexed column, making it a poor fit for high-volume database field encryption.
- ✗
AES-256-GCM with a random 96-bit nonce per record
Why it's wrong here
GCM with a fresh random nonce produces a different ciphertext each time the same account number is encrypted, so equality lookups and unique constraints on the ciphertext column fail. This is the correct choice for general confidentiality, but it directly breaks the deterministic-lookup requirement described in the scenario.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.