GSEC Cryptography Application Practice Question
A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)
⚠ Common exam trap
The trap here is treating encoding such as Base64 or an obfuscated header as encryption, when it provides no confidentiality and leaves the key trivially recoverable from a copied file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A password-based key derivation function with a unique random salt and a high iteration count is used to derive the file encryption key.
A salted, high-iteration KDF makes passphrase guessing expensive and prevents cross-file precomputation, while authenticated encryption binds a tag to the ciphertext so any modification is detected. Together they ensure a copied file cannot be decrypted without the passphrase and that tampering is evident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file is encrypted with a stream cipher using a nonce that is reused across all files for simplicity.
Why it's wrong here
Reusing a nonce with the same stream cipher key causes the keystream to repeat, so XORing two ciphertexts cancels the keystream and leaks plaintext relationships. It also does nothing to detect ciphertext modification, so it fails both the confidentiality and integrity expectations of the scenario.
- ✗
A static initialization vector equal to the file creation timestamp is used for every encryption operation to ensure reproducibility.
Why it's wrong here
A predictable, reused initialization vector in modes like CBC causes identical plaintext blocks to produce identical ciphertext and enables chosen-plaintext attacks. It also provides no integrity protection, so ciphertext modification would go undetected, failing the tamper-detection requirement.
- ✓
A password-based key derivation function with a unique random salt and a high iteration count is used to derive the file encryption key.
Why this is correct
A salted, high-iteration KDF forces an attacker to spend significant work per guessed passphrase and prevents precomputed rainbow-table attacks across files. Because the salt is unique per file, identical passphrases still yield different keys, so copying a file without the passphrase leaves the attacker facing a costly brute-force effort.
- ✓
An authenticated encryption mode such as AES-GCM or ChaCha20-Poly1305 is used to provide confidentiality and integrity of the ciphertext.
Why this is correct
Authenticated encryption produces a tag over the ciphertext and associated data, so any modification of the encrypted file is detected during decryption. This satisfies the requirement that tampering be detectable while also keeping the file contents confidential, provided the key is derived securely from the passphrase.
- ✗
The encryption key is embedded in the file header obfuscated with Base64 so the tool can decrypt without prompting the user.
Why it's wrong here
Base64 is an encoding, not encryption; anyone can decode the header and recover the key, so a copied file decrypts without any passphrase. This defeats the core requirement that an attacker who copies the file cannot decrypt it without the user's passphrase.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.