Courseiva
Cryptography →mediumMultiple Choice

GSEC Cryptography Practice Question

An administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?

⚠ Common exam trap

Candidates often select 'AES-256' without specifying the 'XTS' mode, forgetting that XTS is the standard for disk encryption to prevent block-level manipulation and data patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AES-256 with XTS mode

AES-256 with XTS mode is the industry standard for disk encryption, providing high security against block manipulation attacks. Leveraging hardware-level acceleration via AES-NI instructions ensures that encryption overhead is minimized, preventing performance degradation for end users. This balance of cryptographic strength and operational efficiency is vital for protecting data at rest on mobile devices that are prone to physical theft or unauthorized access attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DES with CBC mode

    Why it's wrong here

    DES is considered legacy and insecure due to its small 56-bit key size, which is vulnerable to brute-force attacks. Using such a weak cipher for disk encryption would fail to meet current compliance standards and expose sensitive data to decryption by modern computing resources in a short time.

  • ✗

    Blowfish with ECB mode

    Why it's wrong here

    Blowfish is a legacy block cipher with a 64-bit block size that is susceptible to birthday attacks on large datasets. Additionally, ECB mode is fundamentally insecure for disk encryption because it preserves patterns in plaintext, allowing attackers to infer structure within the encrypted data without needing the key.

  • ✓

    AES-256 with XTS mode

    Why this is correct

    AES-256 provides a significant security margin, and XTS is the standard mode designed specifically for block-oriented storage media. It prevents data manipulation attacks and provides high performance when combined with AES-NI hardware acceleration, making it the preferred choice for modern full disk encryption implementations across diverse hardware platforms.

  • ✗

    RSA-4096 with OAEP

    Why it's wrong here

    RSA is an asymmetric algorithm primarily used for key exchange and digital signatures, not for bulk data encryption of disks. Using RSA for disk encryption would be computationally prohibitive due to the extreme overhead and complexity, making it an inappropriate and impractical choice for protecting large volumes of data.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.