GSEC Cryptography Practice Question
Exhibit
openssl req -new -newkey rsa:2048 -nodes -out cert.csr -keyout cert.key
Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?
⚠ Common exam trap
Candidates often mistake the -nodes flag for disabling network connectivity or public key generation, missing its specific role regarding private key passphrase protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The private key will be stored without passphrase protection
The -nodes flag instructs OpenSSL to generate a private key without a passphrase, leaving it stored in plaintext on the file system. In a production environment, this is critical because an attacker with unauthorized read access to the server's filesystem can immediately compromise the private key. Protecting private keys with a passphrase ensures that even if files are exfiltrated, the keys remain encrypted and unusable without the secret passphrase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The RSA key length is insufficient for modern requirements
Why it's wrong here
A 2048-bit RSA key length is currently considered the industry minimum for secure communications. While 3072-bit or higher is recommended for longer-term security, 2048-bit does not constitute a critical vulnerability in the context of generating a CSR, unlike the exposure of the private key itself.
- ✓
The private key will be stored without passphrase protection
Why this is correct
The -nodes flag explicitly disables encryption of the generated private key. This means the key is saved in cleartext, creating a significant security risk where any user or process with read access to the file can steal the identity of the server without needing to provide a password.
- ✗
The certificate will be self-signed and untrusted
Why it's wrong here
The command generates a CSR, not a final certificate. A CSR is intended to be sent to a Certificate Authority for signing. The lack of a passphrase does not affect whether the resulting certificate will be signed or trusted by external entities, but rather compromises the security of the key.
- ✗
The output file format defaults to a deprecated encoding
Why it's wrong here
OpenSSL defaults to PEM encoding for CSRs and private keys, which is the standard format for most web servers and infrastructure. The -nodes flag affects the encryption status of the key file, not the encoding format or the structure of the data generated by the OpenSSL utility.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.