Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?

⚠ Common exam trap

The trap here is assuming that any authenticated encryption mode preserves equality lookups, when in fact only deterministic modes do so.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deterministic encryption using AES-SIV

The requirement for repeatable ciphertext that still supports equality lookups points to a deterministic authenticated encryption mode. AES-SIV derives its nonce from the plaintext and associated data, so the same input always yields the same output while still providing integrity. Randomized modes and salted hashing break the equality-search property the database design depends on.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SHA-256 hashing of the account number with a per-row salt

    Why it's wrong here

    A per-row salt guarantees a unique digest for every row even when the account number repeats, so equality matching on the stored value cannot work. Hashing is also one-way, so the original account number can never be recovered for legitimate business use, which the scenario requires.

  • ✓

    Deterministic encryption using AES-SIV

    Why this is correct

    AES-SIV is a misuse-resistant AEAD mode that produces a deterministic ciphertext for a given plaintext and associated data, so identical account numbers map to identical ciphertext. This preserves equality searches, joins, and unique indexes while keeping values unreadable to DBAs who lack the key, satisfying the stated business requirement.

  • ✗

    RSA-4096 OAEP encryption of each account number

    Why it's wrong here

    RSA-OAEP is a randomized public-key scheme, so encrypting the same account number twice yields different ciphertexts and defeats equality search. It is also far slower and produces variable-length output unsuitable for an indexed column, making it a poor fit for high-volume database field encryption.

  • ✗

    AES-256-GCM with a random 96-bit nonce per record

    Why it's wrong here

    GCM with a fresh random nonce produces a different ciphertext each time the same account number is encrypted, so equality lookups and unique constraints on the ciphertext column fail. This is the correct choice for general confidentiality, but it directly breaks the deterministic-lookup requirement described in the scenario.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.