Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

An organization is deploying a new IoT device that must securely update its firmware over the air (OTA). The device has limited processing power and memory. Which cryptographic solution would provide the BEST balance of security and performance for verifying firmware updates?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ed25519 digital signatures

Ed25519 is a fast and secure digital signature algorithm that performs well on constrained devices. RSA 4096 is computationally expensive. HMAC-SHA256 is a symmetric key technique and requires key management overhead. AES-256-GCM is for encryption, not verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RSA-4096 digital signatures

    Why it's wrong here

    RSA-4096 verification demands large modular exponentiation and key storage, exceeding the constrained device's processing and memory budget. It is tempting because RSA signatures are widely trusted, but RSA would be the correct choice where ample compute exists and legacy compatibility outweighs efficiency.

  • ✓

    Ed25519 digital signatures

    Why this is correct

    Ed25519 signatures verify firmware authenticity with minimal computation, satisfying the constrained processor and memory requirement. Its compact 64-byte signatures and 32-byte keys reduce storage and transmission overhead, while verification is far faster than RSA at equivalent security. This makes it ideal for OTA updates on resource-limited IoT devices.

  • ✗

    HMAC-SHA256 with pre-shared key

    Why it's wrong here

    HMAC-SHA256 with a pre-shared key verifies integrity and authenticity but cannot provide non-repudiation, and every device holding the same key means one compromise forges updates fleet-wide. It is tempting because HMAC is fast and lightweight, and would suit closed environments where a single trusted party signs and distributes firmware.

  • ✗

    AES-256-GCM for authentication

    Why it's wrong here

    AES-256-GCM is a symmetric cipher providing confidentiality and authentication, but the verifier must hold the same secret key as the signer, so any device can forge firmware. It is tempting because GCM is fast and hardware-accelerated, and would be correct for encrypting firmware payloads in transit rather than verifying publisher authenticity.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.