GSEC Cryptography Practice Question
An administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?
⚠ Common exam trap
Candidates often select 'AES-256' without specifying the 'XTS' mode, forgetting that XTS is the standard for disk encryption to prevent block-level manipulation and data patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES-256 with XTS mode
AES-256 with XTS mode is the industry standard for disk encryption, providing high security against block manipulation attacks. Leveraging hardware-level acceleration via AES-NI instructions ensures that encryption overhead is minimized, preventing performance degradation for end users. This balance of cryptographic strength and operational efficiency is vital for protecting data at rest on mobile devices that are prone to physical theft or unauthorized access attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DES with CBC mode
Why it's wrong here
DES is considered legacy and insecure due to its small 56-bit key size, which is vulnerable to brute-force attacks. Using such a weak cipher for disk encryption would fail to meet current compliance standards and expose sensitive data to decryption by modern computing resources in a short time.
- ✗
Blowfish with ECB mode
Why it's wrong here
Blowfish is a legacy block cipher with a 64-bit block size that is susceptible to birthday attacks on large datasets. Additionally, ECB mode is fundamentally insecure for disk encryption because it preserves patterns in plaintext, allowing attackers to infer structure within the encrypted data without needing the key.
- ✓
AES-256 with XTS mode
Why this is correct
AES-256 provides a significant security margin, and XTS is the standard mode designed specifically for block-oriented storage media. It prevents data manipulation attacks and provides high performance when combined with AES-NI hardware acceleration, making it the preferred choice for modern full disk encryption implementations across diverse hardware platforms.
- ✗
RSA-4096 with OAEP
Why it's wrong here
RSA is an asymmetric algorithm primarily used for key exchange and digital signatures, not for bulk data encryption of disks. Using RSA for disk encryption would be computationally prohibitive due to the extreme overhead and complexity, making it an inappropriate and impractical choice for protecting large volumes of data.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.