CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which TWO of the following are symmetric encryption algorithms?
⚠ Common exam trap
Test-takers frequently confuse key exchange protocols (like Diffie-Hellman) and asymmetric algorithms (like RSA and ECC) with symmetric encryption, because all are used in cryptography but serve fundamentally different roles in securing communications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES
AES (Option C) is a symmetric block cipher standardized by NIST (FIPS 197) that uses the same secret key for both encryption and decryption, with key sizes of 128, 192, or 256 bits. 3DES (Option E) is also symmetric: it applies the DES cipher three times to each data block using a shared secret key (typically two or three 56-bit keys, giving 112 or 168 bits of effective key strength). In contrast, Diffie-Hellman (Option A) is a key-exchange protocol used to establish a shared secret over an insecure channel, not an encryption algorithm itself. RSA (Option B) and ECC (Option D) are asymmetric (public-key) cryptosystems, where encryption uses a public key and decryption uses a distinct private key, so they do not qualify as symmetric algorithms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Diffie-Hellman
Why it's wrong here
Diffie-Hellman is a key-agreement protocol, not a cipher; it negotiates a shared secret without encrypting data. It is tempting because it underpins symmetric sessions, but it performs asymmetric key exchange, whereas symmetric algorithms such as AES or 3DES use one shared key for both encryption and decryption.
- ✗
RSA
Why it's wrong here
RSA is asymmetric, using a public key to encrypt and a mathematically related private key to decrypt, so it cannot be a symmetric algorithm. It is tempting because RSA also performs encryption, and would be correct where public-key distribution or digital signatures are required.
- ✓
AES
Why this is correct
AES is a symmetric block cipher: encryption and decryption use the same secret key, satisfying the question's requirement for a symmetric algorithm. It operates on 128-bit blocks with 128-, 192- or 256-bit keys, unlike asymmetric algorithms such as RSA, which use a public/private key pair.
- ✗
ECC
Why it's wrong here
ECC is asymmetric, relying on a public/private key pair over an elliptic curve, so it is not symmetric. It is tempting because ECC provides strong encryption with small keys, and would be correct for key exchange or digital signatures rather than bulk symmetric encryption.
- ✓
3DES
Why this is correct
3DES is symmetric: it applies the DES cipher three times with the same shared secret key, so encryptor and decryptor hold identical key material. This satisfies the stem's symmetric criterion, distinguishing it from asymmetric algorithms like RSA or Diffie-Hellman that rely on key pairs.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.