CAS-004 Security Engineering Practice Question
An organization requires a cryptographic algorithm that provides both encryption and authentication in a single pass. Which algorithm should be selected?
⚠ Common exam trap
The trap is thinking CBC with a separate HMAC counts as 'single pass' or that RSA can do both; the exam expects you to recognize AEAD modes like GCM as the only single-pass encryption+authentication algorithms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES-256-GCM
AES-256-GCM (Galois/Counter Mode) is an authenticated encryption with associated data (AEAD) algorithm that provides both confidentiality (encryption) and integrity/authentication in a single pass. It combines AES counter mode encryption with GHASH for authentication, making it efficient and secure. This meets the requirement for a single algorithm that does both.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AES-256-GCM
Why this is correct
AES-256-GCM combines AES counter-mode encryption with GHASH authentication, producing ciphertext and a tag in one operation. This satisfies the stem's single-pass requirement, unlike separate encrypt-then-MAC schemes. It also delivers the confidentiality and integrity the organization demands, using a 256-bit key for strong protection.
- ✗
AES-256-CBC
Why it's wrong here
AES-256-CBC provides confidentiality only; it supplies no authentication tag, so ciphertext tampering goes undetected. It is tempting because AES is the standard symmetric cipher, but it would be correct when pairing with a separate MAC, not for single-pass authenticated encryption.
- ✗
SHA-256
Why it's wrong here
SHA-256 is an unkeyed hash providing integrity only; it performs no encryption and no authentication of a shared key. It is tempting because it is a cryptographic primitive, but it would be the correct choice for verifying message integrity, not for combined confidentiality and authenticity.
- ✗
RSA 4096
Why it's wrong here
RSA 4096 encrypts or signs using asymmetric key pairs, requiring separate operations for confidentiality and authenticity rather than a single pass. It is tempting as a strong, well-known algorithm, but it would be correct for key transport or digital signatures, not combined authenticated encryption.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.