GSEC · domain
Cryptography
GSEC cryptography covers symmetric and asymmetric encryption, hashing, PKI, TLS, IPsec, and key management as applied in defensive operations. Questions present real command output, certificate requests, VPN configurations, or incident scenarios and ask you to identify the vulnerability, the correct control, or the security consequence of a specific setting.
Focused practice
Practice Cryptography questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cryptography
Be able to read real command output and configuration, then name the cryptographic weakness or the correct control. The single most important thing: know what each flag, mode, and key type actually protects, so you can spot when protection is missing.
Interpreting openssl req output and the effect of the -nodes flag on private key storage
Selecting encryption-in-use controls such as confidential computing or secure enclaves
Analyzing code-signing key compromise and why signed malicious firmware passes verification
Evaluating IPsec/IKEv2 authentication choices including PSK versus certificate-based authentication
Watch out for
Common Cryptography exam traps
- ▸Assuming -nodes encrypts the private key; it actually disables passphrase protection, leaving the key unencrypted on disk.
- ▸Confusing encryption at rest, in transit, and in use, then choosing a control that does not protect data during processing.
- ▸Believing signature verification proves vendor intent; a stolen code-signing key produces valid signatures on attacker updates.
Question index
All Cryptography questions (14)
Click any question to see the full explanation, or start a practice session above.
A security team is deploying a new internal TLS certificate authority (CA) for service-to-service authentication. The CA private key must be protected, and the team wants to ensure that if the key is compromised, the attacker cannot forge certificates without detection. Which of the following is the MOST effective control to detect unauthorized certificate issuance?
Medium2A security analyst is reviewing the configuration of a VPN gateway that uses IPsec in tunnel mode. The analyst notices that the gateway is configured to use IKEv2 with a pre-shared key (PSK) for authentication. Which of the following is the PRIMARY security concern with this configuration?
Medium3An organization is migrating to a cloud environment and must ensure that data remains encrypted while in use by applications. Which technology should the security team implement to achieve this?
Medium4An administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?
Medium5A developer is implementing an application that stores user passwords in a database. Which THREE of the following practices are essential for ensuring the cryptographic security of these stored secrets?
Hard6A security engineer at a hospital must encrypt a 40 GB database backup for archival to offsite tape. The tape library appliance has very limited CPU resources, and the engineer wants a symmetric mode that allows the archive to be decrypted in independent chunks without needing to read the entire stream first. Which cipher mode BEST satisfies these requirements?
Medium7A security engineer is implementing a digital signature solution using RSA. The engineer must ensure that signatures provide authenticity, integrity, and non-repudiation. Which TWO of the following practices are essential to achieve these goals? (Choose two.)
Hard8A security architect is designing a system that requires cryptographic keys to be generated, stored, and used without ever exposing the private key material to the operating system. The keys must be usable for TLS server authentication and must support high transaction volumes. Which of the following solutions BEST meets these requirements?
Hard9A security administrator is configuring a Linux server to encrypt a new block device that will store sensitive data. The administrator wants to ensure that data is encrypted at rest and that the encryption key is protected by a passphrase. Which of the following tools is designed specifically for this purpose?
Easy10A security analyst is investigating a suspected man-in-the-middle attack against an HTTPS service. The analyst finds that the client is ignoring certificate validation errors. Which cryptographic failure is most likely occurring?
Hard11A financial services firm is designing a key management process for its internal certificate authority. The security architect wants a single hardware security module (HSM) cluster to protect the CA's signing key while ensuring that a compromise of one HSM appliance does not expose the key in plaintext to an attacker who gains root on that appliance. Which deployment property BEST addresses this requirement?
Hard12A junior administrator is asked to verify the integrity of a downloaded Linux distribution ISO before installing it on a production server. The vendor publishes a SHA-256 checksum and a detached PGP signature. Which action BEST confirms both that the file is intact and that it genuinely originated from the vendor?
Easy13Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?
Hard14A software vendor distributes signed firmware updates to customers. During an incident review, an analyst discovers that an attacker who obtained the vendor's code-signing private key was able to produce updates that passed signature verification on customer devices. The vendor wants to redesign the signing process so that compromise of a single signing key no longer allows an attacker to forge valid updates. Which change best achieves this goal?
HardOther domains
All GSEC exam domains
Frequently asked questions
- What does the Cryptography domain cover on the GSEC exam?
- Be able to read real command output and configuration, then name the cryptographic weakness or the correct control. The single most important thing: know what each flag, mode, and key type actually protects, so you can spot when protection is missing.
- How many questions are in this domain?
- This page lists all 14 Cryptography questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cryptography questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.