hardMultiple Select
CAS-004 Practice Question: Which THREE of the following are common…
Which THREE of the following are common techniques to mitigate side-channel attacks?
⚠ Common exam trap
CompTIA often tests the misconception that adding random delays (Option E) is a valid side-channel mitigation, but candidates must recognize that statistical averaging defeats such noise, whereas constant-time algorithms (Option B) and noise injection (Option C) are standard, effective techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement constant-time algorithms for cryptographic operations
Option B is correct because constant-time algorithms execute the same sequence of operations regardless of secret values, eliminating the data-dependent timing variations that timing side-channel attacks exploit. Option C is correct because adding noise to power consumption or electromagnetic emissions masks the correlation between a device's physical leakage and the secret data being processed, which is the core of power-analysis and EM side-channel attacks. Option D is correct because making memory access patterns independent of secret data (e.g., via oblivious access or cache-line-aligned constant-time lookups) prevents cache-timing attacks that infer secrets from which cache lines are accessed. Option A is not a common mitigation: disabling CPU caching is impractical, severely degrades performance, and is not a standard countermeasure. Option E is not correct because random delays only add probabilistic noise to timing and are generally considered weak and insufficient against modern statistical timing attacks, unlike true constant-time execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable CPU caching to prevent cache timing attacks
Why it's wrong here
Disabling CPU caching would cripple performance and is not a deployable mitigation; cache-timing resistance comes from constant-time cryptographic implementations and cache partitioning instead. It is tempting because cache timing is the classic side channel, yet removing caching entirely is neither feasible nor how vendors address it.
- ✓
Implement constant-time algorithms for cryptographic operations
Why this is correct
Constant-time algorithms execute identical instruction sequences and memory accesses regardless of secret values, removing the timing and cache-usage variations that side-channel attackers measure. This directly satisfies the stem's mitigation requirement by eliminating the data-dependent execution path that leaks key material.
- ✓
Add noise to power consumption or electromagnetic emissions
Why this is correct
Injecting random noise into power draw or electromagnetic emissions masks the correlation between a device's operations and its secret data, so an attacker's statistical analysis cannot reliably recover keys. This satisfies the stem's mitigation goal by degrading the signal-to-noise ratio side-channel attacks depend on.
- ✓
Ensure memory access patterns are independent of secret data
Why this is correct
Secret-independent memory access patterns prevent cache-timing leaks, because which cache lines are touched no longer reveals which key bits were processed. This satisfies the stem's mitigation requirement by removing the data-dependent access behaviour that cache-based side-channel attacks exploit.
- ✗
Use random delays in code execution paths
Why it's wrong here
Random delays only blur timing measurements statistically; they do not remove the data-dependent timing variance that leaks secret bits, so an attacker averaging many samples still recovers the key. It is tempting because timing jitter is a genuine hardening layer, but constant-time code is the actual mitigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.