CAS-004 Security Architecture Practice Question
A security architect is evaluating cryptographic agility for a system that must be resistant to quantum computing attacks. Which TWO algorithms are part of the NIST PQC standards? (Select TWO.)
⚠ Common exam trap
CAS-005 often tests whether candidates can distinguish between NIST PQC asymmetric algorithms and classical symmetric/hash algorithms; a common mistake is selecting AES or SHA as PQC standards because they are quantum-resistant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CRYSTALS-Dilithium
CRYSTALS-Dilithium (option B) is correct because NIST selected it in July 2022 as a post-quantum digital signature algorithm, standardized in FIPS 204 (ML-DSA), designed to resist quantum attacks via lattice-based cryptography. CRYSTALS-Kyber (option E) is also correct because NIST selected it as the post-quantum key-encapsulation mechanism (KEM), standardized in FIPS 203 (ML-KEM), also based on module-lattice hardness. RSA-4096 (option A) is not a PQC algorithm; its security relies on integer factorization, which Shor's algorithm on a quantum computer can break. AES-256 (option C) is a symmetric cipher, not a NIST PQC standard, though it retains quantum resistance via Grover only reducing effective strength to 128 bits. SHA-256 (option D) is a hash function, not a PQC algorithm, and is likewise not part of the NIST PQC standardization selections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RSA-4096
Why it's wrong here
RSA-4096 relies on integer factorisation, which Shor's algorithm breaks on a sufficiently large quantum computer, so it is not a NIST post-quantum standard. It is tempting because it is a widely deployed, strong classical algorithm, and would be correct where quantum resistance is not required.
- ✓
CRYSTALS-Dilithium
Why this is correct
CRYSTALS-Dilithium is a lattice-based digital signature scheme selected by NIST for post-quantum cryptography standardisation, providing quantum-resistant authentication. It satisfies the stem's requirement for cryptographic agility against quantum attacks, unlike RSA or ECDSA, whose security collapses under Shor's algorithm. Its selection as a NIST PQC standard confirms its suitability.
- ✗
AES-256
Why it's wrong here
AES-256 is a symmetric block cipher, not a post-quantum algorithm; NIST's PQC standards cover key encapsulation and digital signatures. It is tempting because it is quantum-resistant in practice via Grover, and would be correct for symmetric encryption of data at rest or in transit.
- ✗
SHA-256
Why it's wrong here
SHA-256 is a hash function, not a post-quantum algorithm; the NIST PQC standards specify KEMs and signature schemes. It is tempting because it is quantum-resistant for collision resistance, and would be correct for integrity verification or as a building block inside PQC constructions.
- ✓
CRYSTALS-Kyber
Why this is correct
CRYSTALS-Kyber is a lattice-based key-encapsulation mechanism selected by NIST for post-quantum standardisation, providing quantum-resistant confidentiality. Its security rests on the hardness of module learning-with-errors, which Shor's algorithm cannot efficiently solve, unlike RSA or elliptic-curve key exchange.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.