Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which TWO of the following are symmetric encryption algorithms?

⚠ Common exam trap

Test-takers frequently confuse key exchange protocols (like Diffie-Hellman) and asymmetric algorithms (like RSA and ECC) with symmetric encryption, because all are used in cryptography but serve fundamentally different roles in securing communications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AES

AES (Option C) is a symmetric block cipher standardized by NIST (FIPS 197) that uses the same secret key for both encryption and decryption, with key sizes of 128, 192, or 256 bits. 3DES (Option E) is also symmetric: it applies the DES cipher three times to each data block using a shared secret key (typically two or three 56-bit keys, giving 112 or 168 bits of effective key strength). In contrast, Diffie-Hellman (Option A) is a key-exchange protocol used to establish a shared secret over an insecure channel, not an encryption algorithm itself. RSA (Option B) and ECC (Option D) are asymmetric (public-key) cryptosystems, where encryption uses a public key and decryption uses a distinct private key, so they do not qualify as symmetric algorithms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Diffie-Hellman

    Why it's wrong here

    Diffie-Hellman is a key-agreement protocol, not a cipher; it negotiates a shared secret without encrypting data. It is tempting because it underpins symmetric sessions, but it performs asymmetric key exchange, whereas symmetric algorithms such as AES or 3DES use one shared key for both encryption and decryption.

  • ✗

    RSA

    Why it's wrong here

    RSA is asymmetric, using a public key to encrypt and a mathematically related private key to decrypt, so it cannot be a symmetric algorithm. It is tempting because RSA also performs encryption, and would be correct where public-key distribution or digital signatures are required.

  • ✓

    AES

    Why this is correct

    AES is a symmetric block cipher: encryption and decryption use the same secret key, satisfying the question's requirement for a symmetric algorithm. It operates on 128-bit blocks with 128-, 192- or 256-bit keys, unlike asymmetric algorithms such as RSA, which use a public/private key pair.

  • ✗

    ECC

    Why it's wrong here

    ECC is asymmetric, relying on a public/private key pair over an elliptic curve, so it is not symmetric. It is tempting because ECC provides strong encryption with small keys, and would be correct for key exchange or digital signatures rather than bulk symmetric encryption.

  • ✓

    3DES

    Why this is correct

    3DES is symmetric: it applies the DES cipher three times with the same shared secret key, so encryptor and decryptor hold identical key material. This satisfies the stem's symmetric criterion, distinguishing it from asymmetric algorithms like RSA or Diffie-Hellman that rely on key pairs.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.