Courseiva
Cryptography →mediumMultiple Choice

GSEC Cryptography Practice Question

A security engineer at a hospital must encrypt a 40 GB database backup for archival to offsite tape. The tape library appliance has very limited CPU resources, and the engineer wants a symmetric mode that allows the archive to be decrypted in independent chunks without needing to read the entire stream first. Which cipher mode BEST satisfies these requirements?

⚠ Common exam trap

The trap here is assuming that an authenticated mode such as GCM is always the better choice for bulk archival data, when its whole-message tag actually prevents the independent chunk decryption the scenario requires.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Counter Mode (CTR)

Counter Mode generates a keystream by encrypting successive counter values, so ciphertext blocks have no dependency on one another. That independence enables parallel encryption and decryption and permits retrieval of arbitrary archive segments without reading the whole stream, which matches the constrained tape appliance. CTR provides confidentiality only, so a separate integrity mechanism would be needed if tamper detection matters for the archive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Counter Mode (CTR)

    Why this is correct

    CTR turns a block cipher into a stream cipher by encrypting sequential counter values, so any block can be decrypted independently once the correct counter value is known. This allows parallel processing and random access, which suits a low-CPU tape appliance and a multi-gigabyte archive. The engineer must still ensure counter values are never reused with the same key, but CTR meets the independent-chunk requirement without the chaining dependency of CBC.

  • ✗

    Cipher Block Chaining (CBC)

    Why it's wrong here

    CBC chains each ciphertext block into the next block's encryption, so any block can only be decrypted after all preceding blocks are processed. On a tape appliance with limited CPU, the serial dependency prevents parallel decryption and makes random access to a 40 GB archive impractical. CBC also requires careful IV management and padding, which adds complexity without delivering the independent-chunk capability the engineer needs.

  • ✗

    Galois/Counter Mode (GCM)

    Why it's wrong here

    GCM is an authenticated encryption mode that provides confidentiality and integrity, but its authentication tag covers the entire message, so verification requires processing the whole stream. That conflicts with decrypting the archive in independent chunks. GCM also demands unique nonces per key; reusing a nonce with the same key catastrophically breaks confidentiality and authenticity, which is a serious operational risk for a long-lived archival key.

  • ✗

    Electronic Codebook (ECB)

    Why it's wrong here

    ECB encrypts each block independently, so it technically permits random access, but it leaks plaintext patterns because identical plaintext blocks produce identical ciphertext blocks. A structured database backup contains highly repetitive blocks, so ECB would expose that structure in the archived ciphertext. ECB is also not a recommended mode for bulk data protection under current guidance, making it a poor choice despite its independent-block behavior.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.