Courseiva
Cryptography Application →mediumMultiple Choice

GSEC Cryptography Application Practice Question

An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?

⚠ Common exam trap

Candidates frequently select standard Diffie-Hellman or RSA instead of looking for the ephemeral variant, overlooking the specific requirement that session keys must not be tied to static private keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Elliptic Curve Diffie-Hellman Ephemeral

Perfect forward secrecy ensures that session keys are not compromised even if the primary private key of the server is compromised in the future. Ephemeral Diffie-Hellman guarantees this by generating unique per-session parameters that are never stored persistently on disk. Proper enforcement prevents long-term bulk decryption of historical intercepted traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RSA key transport mechanism

    Why it's wrong here

    RSA key transport relies entirely on the server static private key to encrypt the pre-master secret directly. If an attacker records the encrypted handshake and later steals the private key, every historical session is instantly compromised, completely failing forward secrecy requirements.

  • ✓

    Elliptic Curve Diffie-Hellman Ephemeral

    Why this is correct

    ECDHE leverages transient elliptic curve parameters for each unique handshake transaction. Because the server private key is only used to digitally sign the ephemeral exchange and is never used to derive the session key directly, past sessions remain entirely secure against future key compromises.

  • ✗

    Pre-Shared Key authentication mode

    Why it's wrong here

    Pre-shared keys bypass public-key cryptography entirely during the initial authentication phase. While fast, they do not inherently generate ephemeral session parameters unless explicitly combined with an underlying Diffie-Hellman exchange, making them dependent on the specific implementation parameters chosen.

  • ✗

    Static Diffie-Hellman key agreement

    Why it's wrong here

    Static Diffie-Hellman utilizes long-term parameters configured identically across multiple sessions. Because the private components remain constant over extended operational periods, compromising the static key material instantly exposes all derived session keys to retroactive decryption attacks.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.