GSEC · domain
Cryptography Application
The Cryptography Application domain on GSEC covers how encryption, hashing, and PKI are deployed in real systems rather than as pure theory. Questions present operational scenarios — TLS negotiation, database encryption, integrity verification, certificate lifecycle — and ask you to select the correct algorithm, mode, or PKI function and justify why it satisfies the stated requirement.
Focused practice
Practice Cryptography Application questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cryptography Application
Be able to map a stated requirement — forward secrecy, integrity, reversibility, trust — to the specific algorithm, mode, or PKI function that satisfies it. The single most important thing is reading the requirement precisely and not selecting a control that solves a different problem.
Selecting TLS 1.3 cipher suites that provide forward secrecy via ephemeral key exchange
Choosing hash functions by collision resistance for file and data integrity verification
Applying reversible encryption with integrity protection, such as authenticated modes, to stored PII
Identifying core PKI functions including certificate issuance, validation, and revocation
Watch out for
Common Cryptography Application exam traps
- ▸Confusing collision resistance with preimage resistance when the question asks about two different inputs producing one hash
- ▸Assuming any TLS version guarantees forward secrecy instead of checking the key exchange mechanism
- ▸Treating encryption alone as sufficient for integrity, ignoring authenticated encryption or MAC requirements
Question index
All Cryptography Application questions (10)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?
Medium2A security analyst is hardening a web server to ensure that only modern, secure protocols are used for HTTPS traffic. Which configuration best aligns with GSEC security standards for data in transit?
Medium3When selecting a cryptographic hash function for verifying file integrity, which property is most important to ensure that an attacker cannot create two different files that produce the same hash value?
Easy4A security engineer is selecting a hash function to protect stored user passwords in a new application. The threat model assumes an attacker who steals the password database and has substantial GPU resources for offline cracking. Which choice best addresses this threat?
Hard5A security analyst is reviewing a legacy application that uses RSA for digital signatures. The application generates a 1024-bit RSA key pair and signs messages using SHA-1. The analyst must recommend an upgrade that maintains the same algorithm family but meets current security standards. Which change should be recommended?
Easy6A security engineer is designing an internal Public Key Infrastructure (PKI) and needs to issue a subordinate certificate authority (sub-CA) certificate. To prevent this sub-CA from accidentally or maliciously issuing certificates for unauthorized domains, what specific X.509 extension must be correctly configured?
Hard7An organization needs to encrypt a database of PII. The requirements state that the encryption must be reversible by authorized staff and provide data integrity. Which implementation should the security engineer recommend?
Medium8A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?
Easy9An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?
Medium10A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Cryptography Application domain cover on the GSEC exam?
- Be able to map a stated requirement — forward secrecy, integrity, reversibility, trust — to the specific algorithm, mode, or PKI function that satisfies it. The single most important thing is reading the requirement precisely and not selecting a control that solves a different problem.
- How many questions are in this domain?
- This page lists all 10 Cryptography Application questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cryptography Application questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.