GSEC Cryptography Application Practice Question
An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?
⚠ Common exam trap
Candidates frequently select standard Diffie-Hellman or RSA instead of looking for the ephemeral variant, overlooking the specific requirement that session keys must not be tied to static private keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Elliptic Curve Diffie-Hellman Ephemeral
Perfect forward secrecy ensures that session keys are not compromised even if the primary private key of the server is compromised in the future. Ephemeral Diffie-Hellman guarantees this by generating unique per-session parameters that are never stored persistently on disk. Proper enforcement prevents long-term bulk decryption of historical intercepted traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RSA key transport mechanism
Why it's wrong here
RSA key transport relies entirely on the server static private key to encrypt the pre-master secret directly. If an attacker records the encrypted handshake and later steals the private key, every historical session is instantly compromised, completely failing forward secrecy requirements.
- ✓
Elliptic Curve Diffie-Hellman Ephemeral
Why this is correct
ECDHE leverages transient elliptic curve parameters for each unique handshake transaction. Because the server private key is only used to digitally sign the ephemeral exchange and is never used to derive the session key directly, past sessions remain entirely secure against future key compromises.
- ✗
Pre-Shared Key authentication mode
Why it's wrong here
Pre-shared keys bypass public-key cryptography entirely during the initial authentication phase. While fast, they do not inherently generate ephemeral session parameters unless explicitly combined with an underlying Diffie-Hellman exchange, making them dependent on the specific implementation parameters chosen.
- ✗
Static Diffie-Hellman key agreement
Why it's wrong here
Static Diffie-Hellman utilizes long-term parameters configured identically across multiple sessions. Because the private components remain constant over extended operational periods, compromising the static key material instantly exposes all derived session keys to retroactive decryption attacks.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.