CV0-004 Security Practice Question
Which encryption standard is most commonly used for data at rest in cloud storage services?
⚠ Common exam trap
CV0-004 often tests the confusion between symmetric encryption algorithms (AES) used for bulk data-at-rest and asymmetric algorithms (RSA) used for key exchange or signatures — candidates may pick RSA thinking 'stronger equals better' for storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES-256
AES-256 is the de facto standard for data-at-rest encryption in cloud storage services such as Amazon S3, Azure Blob Storage, and Google Cloud Storage. It provides strong symmetric encryption with a 256-bit key, is FIPS 140-2/3 validated, and is widely supported by hardware acceleration. Cloud providers default to AES-256 (or AES-128 in some cases) for server-side encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Blowfish
Why it's wrong here
Blowfish uses a 64-bit block size, making it vulnerable to birthday attacks on large datasets, so it is unsuitable for bulk cloud storage; AES, with its 128-bit block, is the standard. Blowfish is tempting as a fast, unpatented symmetric cipher, and it would be correct for small, legacy embedded systems with limited processing power.
- ✗
DES
Why it's wrong here
DES uses a 56-bit key, which is brute-forceable, so it cannot meet modern data-at-rest protection requirements; cloud providers instead deploy AES-256. It is tempting because DES was the original symmetric encryption standard, and it would be the correct choice only for legacy systems where interoperability with old hardware demands it.
- ✓
AES-256
Why this is correct
AES-256 is the symmetric block cipher overwhelmingly adopted for cloud data-at-rest encryption, offering 256-bit keys resistant to brute force. It satisfies the stem's requirement for the encryption standard most commonly used by cloud storage services.
- ✗
RSA
Why it's wrong here
RSA is an asymmetric algorithm for key exchange and digital signatures, not bulk data-at-rest encryption; it is far too slow for large objects. AES in Galois/Counter Mode or CBC is the symmetric standard cloud providers use for storage encryption.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.