Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

An organization requires a cryptographic algorithm that provides both encryption and authentication in a single pass. Which algorithm should be selected?

⚠ Common exam trap

The trap is thinking CBC with a separate HMAC counts as 'single pass' or that RSA can do both; the exam expects you to recognize AEAD modes like GCM as the only single-pass encryption+authentication algorithms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AES-256-GCM

AES-256-GCM (Galois/Counter Mode) is an authenticated encryption with associated data (AEAD) algorithm that provides both confidentiality (encryption) and integrity/authentication in a single pass. It combines AES counter mode encryption with GHASH for authentication, making it efficient and secure. This meets the requirement for a single algorithm that does both.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AES-256-GCM

    Why this is correct

    AES-256-GCM combines AES counter-mode encryption with GHASH authentication, producing ciphertext and a tag in one operation. This satisfies the stem's single-pass requirement, unlike separate encrypt-then-MAC schemes. It also delivers the confidentiality and integrity the organization demands, using a 256-bit key for strong protection.

  • ✗

    AES-256-CBC

    Why it's wrong here

    AES-256-CBC provides confidentiality only; it supplies no authentication tag, so ciphertext tampering goes undetected. It is tempting because AES is the standard symmetric cipher, but it would be correct when pairing with a separate MAC, not for single-pass authenticated encryption.

  • ✗

    SHA-256

    Why it's wrong here

    SHA-256 is an unkeyed hash providing integrity only; it performs no encryption and no authentication of a shared key. It is tempting because it is a cryptographic primitive, but it would be the correct choice for verifying message integrity, not for combined confidentiality and authenticity.

  • ✗

    RSA 4096

    Why it's wrong here

    RSA 4096 encrypts or signs using asymmetric key pairs, requiring separate operations for confidentiality and authenticity rather than a single pass. It is tempting as a strong, well-known algorithm, but it would be correct for key transport or digital signatures, not combined authenticated encryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.