Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

Which encryption standard is most commonly used for data at rest in cloud storage services?

⚠ Common exam trap

CV0-004 often tests the confusion between symmetric encryption algorithms (AES) used for bulk data-at-rest and asymmetric algorithms (RSA) used for key exchange or signatures — candidates may pick RSA thinking 'stronger equals better' for storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AES-256

AES-256 is the de facto standard for data-at-rest encryption in cloud storage services such as Amazon S3, Azure Blob Storage, and Google Cloud Storage. It provides strong symmetric encryption with a 256-bit key, is FIPS 140-2/3 validated, and is widely supported by hardware acceleration. Cloud providers default to AES-256 (or AES-128 in some cases) for server-side encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Blowfish

    Why it's wrong here

    Blowfish uses a 64-bit block size, making it vulnerable to birthday attacks on large datasets, so it is unsuitable for bulk cloud storage; AES, with its 128-bit block, is the standard. Blowfish is tempting as a fast, unpatented symmetric cipher, and it would be correct for small, legacy embedded systems with limited processing power.

  • ✗

    DES

    Why it's wrong here

    DES uses a 56-bit key, which is brute-forceable, so it cannot meet modern data-at-rest protection requirements; cloud providers instead deploy AES-256. It is tempting because DES was the original symmetric encryption standard, and it would be the correct choice only for legacy systems where interoperability with old hardware demands it.

  • ✓

    AES-256

    Why this is correct

    AES-256 is the symmetric block cipher overwhelmingly adopted for cloud data-at-rest encryption, offering 256-bit keys resistant to brute force. It satisfies the stem's requirement for the encryption standard most commonly used by cloud storage services.

  • ✗

    RSA

    Why it's wrong here

    RSA is an asymmetric algorithm for key exchange and digital signatures, not bulk data-at-rest encryption; it is far too slow for large objects. AES in Galois/Counter Mode or CBC is the symmetric standard cloud providers use for storage encryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.