Courseiva
Cryptography →hardMultiple Choice

GSEC Cryptography Practice Question

Exhibit

openssl req -new -newkey rsa:2048 -nodes -out cert.csr -keyout cert.key

Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?

⚠ Common exam trap

Candidates often mistake the -nodes flag for disabling network connectivity or public key generation, missing its specific role regarding private key passphrase protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The private key will be stored without passphrase protection

The -nodes flag instructs OpenSSL to generate a private key without a passphrase, leaving it stored in plaintext on the file system. In a production environment, this is critical because an attacker with unauthorized read access to the server's filesystem can immediately compromise the private key. Protecting private keys with a passphrase ensures that even if files are exfiltrated, the keys remain encrypted and unusable without the secret passphrase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The RSA key length is insufficient for modern requirements

    Why it's wrong here

    A 2048-bit RSA key length is currently considered the industry minimum for secure communications. While 3072-bit or higher is recommended for longer-term security, 2048-bit does not constitute a critical vulnerability in the context of generating a CSR, unlike the exposure of the private key itself.

  • ✓

    The private key will be stored without passphrase protection

    Why this is correct

    The -nodes flag explicitly disables encryption of the generated private key. This means the key is saved in cleartext, creating a significant security risk where any user or process with read access to the file can steal the identity of the server without needing to provide a password.

  • ✗

    The certificate will be self-signed and untrusted

    Why it's wrong here

    The command generates a CSR, not a final certificate. A CSR is intended to be sent to a Certificate Authority for signing. The lack of a passphrase does not affect whether the resulting certificate will be signed or trusted by external entities, but rather compromises the security of the key.

  • ✗

    The output file format defaults to a deprecated encoding

    Why it's wrong here

    OpenSSL defaults to PEM encoding for CSRs and private keys, which is the standard format for most web servers and infrastructure. The -nodes flag affects the encryption status of the key file, not the encoding format or the structure of the data generated by the OpenSSL utility.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.