CAS-004 Security Engineering Practice Question
A security architect is selecting a cipher suite for TLS 1.3 to ensure forward secrecy and high performance. Which cipher suite should be recommended?
⚠ Common exam trap
The trap here is that candidates may select a TLS 1.2 cipher suite that includes ECDHE and GCM, thinking it provides forward secrecy and performance, but TLS 1.3 only accepts the simplified TLS_<AEAD>_<HASH> naming format and prohibits CBC and static RSA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TLS_AES_256_GCM_SHA384
TLS_AES_256_GCM_SHA384 is the only option that is a valid TLS 1.3 cipher suite. TLS 1.3 removed RSA key transport and all CBC-mode ciphers, mandating AEAD (Authenticated Encryption with Associated Data) ciphers and ephemeral key exchange for forward secrecy. This suite uses AES-256 in GCM mode for authenticated encryption and SHA-384 for the HKDF-based key schedule, delivering both high performance (AES-NI accelerated) and strong security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TLS_RSA_WITH_AES_256_CBC_SHA
Why it's wrong here
This suite uses RSA key transport, so a compromised private key exposes past sessions, breaking forward secrecy, and CBC adds overhead. It is tempting because RSA suites are widely recognised and supported, and would be correct where TLS 1.2 interoperability with legacy clients is required.
- ✓
TLS_AES_256_GCM_SHA384
Why this is correct
TLS_AES_256_GCM_SHA384 uses ephemeral Diffie-Hellman key exchange, which is mandatory in TLS 1.3, delivering the required forward secrecy. AES-256-GCM provides authenticated encryption with hardware-accelerated performance, while SHA-384 strengthens the handshake. It satisfies both the forward secrecy and high-performance constraints.
- ✗
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
Why it's wrong here
This is a TLS 1.2 cipher suite; TLS 1.3 does not use DHE explicitly but ECDHE.
- ✗
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
Why it's wrong here
TLS 1.3 removed CBC-mode and static RSA key exchange suites entirely, so this suite cannot be negotiated in a TLS 1.3 handshake; only AEAD suites with (EC)DHE are permitted. It tempts architects familiar with TLS 1.2, where ECDHE_RSA_WITH_AES_128_CBC_SHA256 was a valid forward-secret option.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.