CAS-004 Security Architecture Practice Question
An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?
⚠ Common exam trap
The trap is confusing key encapsulation with digital signatures; candidates may pick CRYSTALS-Dilithium because it is also a NIST PQC algorithm, but it is for signatures, not KEM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CRYSTALS-Kyber
CRYSTALS-Kyber is a NIST-approved post-quantum cryptographic algorithm designed for key encapsulation (KEM), selected in the NIST PQC standardization process. It is based on module learning with errors (MLWE) and provides secure key exchange resistant to quantum attacks. RSA-4096 and ECDHE are classical algorithms vulnerable to quantum computers, and CRYSTALS-Dilithium is designed for digital signatures, not key encapsulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RSA-4096
Why it's wrong here
RSA-4096 is a classical algorithm whose security rests on integer factorisation, which Shor's algorithm defeats on a sufficiently large quantum computer, so it offers no post-quantum protection. It is tempting because it is NIST-approved and widely deployed for key transport today, and would be correct for current non-quantum key exchange.
- ✓
CRYSTALS-Kyber
Why this is correct
CRYSTALS-Kyber is a lattice-based key encapsulation mechanism (KEM), standardised by NIST as ML-KEM, which secures symmetric keys through public-key encryption. It directly satisfies the stem's requirement for a post-quantum algorithm designed for key encapsulation, unlike CRYSTALS-Dilithium or SPHINCS+, which are digital signature schemes.
- ✗
ECDHE
Why it's wrong here
ECDHE is a classical elliptic-curve key-agreement method, not a post-quantum algorithm, and it remains breakable by Shor's algorithm. It is tempting because ECDHE performs key establishment and is widely deployed in TLS, and it would be correct for forward-secret session key exchange against conventional attackers, not quantum ones.
- ✗
CRYSTALS-Dilithium
Why it's wrong here
CRYSTALS-Dilithium is a digital signature scheme, not a key encapsulation mechanism, so it cannot establish the shared symmetric key the scenario requires. It is tempting because NIST selected it alongside the KEM standard, and it would be the right choice when signing firmware or certificates against quantum forgery.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.