Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?

⚠ Common exam trap

The trap is confusing key encapsulation with digital signatures; candidates may pick CRYSTALS-Dilithium because it is also a NIST PQC algorithm, but it is for signatures, not KEM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CRYSTALS-Kyber

CRYSTALS-Kyber is a NIST-approved post-quantum cryptographic algorithm designed for key encapsulation (KEM), selected in the NIST PQC standardization process. It is based on module learning with errors (MLWE) and provides secure key exchange resistant to quantum attacks. RSA-4096 and ECDHE are classical algorithms vulnerable to quantum computers, and CRYSTALS-Dilithium is designed for digital signatures, not key encapsulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RSA-4096

    Why it's wrong here

    RSA-4096 is a classical algorithm whose security rests on integer factorisation, which Shor's algorithm defeats on a sufficiently large quantum computer, so it offers no post-quantum protection. It is tempting because it is NIST-approved and widely deployed for key transport today, and would be correct for current non-quantum key exchange.

  • ✓

    CRYSTALS-Kyber

    Why this is correct

    CRYSTALS-Kyber is a lattice-based key encapsulation mechanism (KEM), standardised by NIST as ML-KEM, which secures symmetric keys through public-key encryption. It directly satisfies the stem's requirement for a post-quantum algorithm designed for key encapsulation, unlike CRYSTALS-Dilithium or SPHINCS+, which are digital signature schemes.

  • ✗

    ECDHE

    Why it's wrong here

    ECDHE is a classical elliptic-curve key-agreement method, not a post-quantum algorithm, and it remains breakable by Shor's algorithm. It is tempting because ECDHE performs key establishment and is widely deployed in TLS, and it would be correct for forward-secret session key exchange against conventional attackers, not quantum ones.

  • ✗

    CRYSTALS-Dilithium

    Why it's wrong here

    CRYSTALS-Dilithium is a digital signature scheme, not a key encapsulation mechanism, so it cannot establish the shared symmetric key the scenario requires. It is tempting because NIST selected it alongside the KEM standard, and it would be the right choice when signing firmware or certificates against quantum forgery.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.