Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

A security architect is selecting a cipher suite for TLS 1.3 to ensure forward secrecy and high performance. Which cipher suite should be recommended?

⚠ Common exam trap

The trap here is that candidates may select a TLS 1.2 cipher suite that includes ECDHE and GCM, thinking it provides forward secrecy and performance, but TLS 1.3 only accepts the simplified TLS_<AEAD>_<HASH> naming format and prohibits CBC and static RSA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TLS_AES_256_GCM_SHA384

TLS_AES_256_GCM_SHA384 is the only option that is a valid TLS 1.3 cipher suite. TLS 1.3 removed RSA key transport and all CBC-mode ciphers, mandating AEAD (Authenticated Encryption with Associated Data) ciphers and ephemeral key exchange for forward secrecy. This suite uses AES-256 in GCM mode for authenticated encryption and SHA-384 for the HKDF-based key schedule, delivering both high performance (AES-NI accelerated) and strong security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TLS_RSA_WITH_AES_256_CBC_SHA

    Why it's wrong here

    This suite uses RSA key transport, so a compromised private key exposes past sessions, breaking forward secrecy, and CBC adds overhead. It is tempting because RSA suites are widely recognised and supported, and would be correct where TLS 1.2 interoperability with legacy clients is required.

  • ✓

    TLS_AES_256_GCM_SHA384

    Why this is correct

    TLS_AES_256_GCM_SHA384 uses ephemeral Diffie-Hellman key exchange, which is mandatory in TLS 1.3, delivering the required forward secrecy. AES-256-GCM provides authenticated encryption with hardware-accelerated performance, while SHA-384 strengthens the handshake. It satisfies both the forward secrecy and high-performance constraints.

  • ✗

    TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

    Why it's wrong here

    This is a TLS 1.2 cipher suite; TLS 1.3 does not use DHE explicitly but ECDHE.

  • ✗

    TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

    Why it's wrong here

    TLS 1.3 removed CBC-mode and static RSA key exchange suites entirely, so this suite cannot be negotiated in a TLS 1.3 handshake; only AEAD suites with (EC)DHE are permitted. It tempts architects familiar with TLS 1.2, where ECDHE_RSA_WITH_AES_128_CBC_SHA256 was a valid forward-secret option.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.