Courseiva

GSEC · topic practice

Cryptography Application practice questions

The Cryptography Application domain on GSEC covers how encryption, hashing, and PKI are deployed in real systems rather than as pure theory. Questions present operational scenarios — TLS negotiation, database encryption, integrity verification, certificate lifecycle — and ask you to select the correct algorithm, mode, or PKI function and justify why it satisfies the stated requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cryptography Application

What the exam tests

What to know about Cryptography Application

Be able to map a stated requirement — forward secrecy, integrity, reversibility, trust — to the specific algorithm, mode, or PKI function that satisfies it. The single most important thing is reading the requirement precisely and not selecting a control that solves a different problem.

Selecting TLS 1.3 cipher suites that provide forward secrecy via ephemeral key exchange

Choosing hash functions by collision resistance for file and data integrity verification

Applying reversible encryption with integrity protection, such as authenticated modes, to stored PII

Identifying core PKI functions including certificate issuance, validation, and revocation

Watch out for

Common Cryptography Application exam traps

  • ▸Confusing collision resistance with preimage resistance when the question asks about two different inputs producing one hash
  • ▸Assuming any TLS version guarantees forward secrecy instead of checking the key exchange mechanism
  • ▸Treating encryption alone as sufficient for integrity, ignoring authenticated encryption or MAC requirements

Practice set

Cryptography Application questions

20 questions · select your answer, then reveal the explanation

A security administrator is hardening an SSH server configuration file to protect sensitive administrative access. Which TWO configuration directives must be explicitly enforced to ensure strong cryptographic controls and prevent legacy weak encryption algorithms? (Choose two)

Refer to the exhibit. A security auditor is reviewing the configuration of a legacy signing service. Based on current cryptographic standards, why is this configuration flagged as a high-risk finding?

Exhibit

{
  "algorithm": "RSA",
  "key_size": 1024,
  "padding": "PKCS#1v1.5",
  "usage": "Digital Signatures"
}

A security team is deploying an internal certificate authority (CA) to issue TLS certificates for microservices. They want to automate the enrollment process without manual approval, but the CA must ensure that any issued certificate cannot be used to sign other certificates. The team configures the CA to include the basicConstraints extension with CA:FALSE and pathlen:0. After issuance, a microservice attempts to use its certificate to sign a subordinate certificate. Which statement describes the outcome when a relying party validates the subordinate certificate?

A financial institution is implementing a digital signature solution for its internal document approval workflow. The security architect must select a cryptographic algorithm that provides non-repudiation and ensures that signatures cannot be forged even if an attacker obtains the public key. The institution also requires that the signature scheme be standardized by NIST and widely supported in commercial off-the-shelf (COTS) products. Which algorithm should the architect choose?

A security administrator is configuring encrypted backups for a remote office. The backup software supports AES-256 but requires a mode of operation that allows parallel processing of blocks and does not require the ciphertext to be padded to a multiple of the block size. The administrator must also ensure that identical plaintext blocks do not produce identical ciphertext blocks. Which mode should be selected?

A security engineer is deploying an encrypted backup appliance that will store archives for ten years. Management requires that the data remain confidential even if the encryption key is later compromised, and that the appliance never need to re-encrypt existing archives when keys are rotated. Which key management approach best meets these requirements?

Question 7hardmultiple choice
Read the full VPN explanation →

A security engineer is deploying a new VPN concentrator that will use IPsec in tunnel mode. The engineer must ensure that the encryption algorithm provides both confidentiality and authenticity for each packet, and that the same key is never reused for encryption. Which combination of IPsec protocols should be configured?

A security team must digitally sign firmware images so that devices can verify authenticity offline for years. The signing key will be kept in an HSM, and the team wants signatures that remain verifiable by devices that only support RSA and ECDSA and cannot perform large modular exponentiations quickly. Which signing approach should the team choose?

A security engineer is implementing full-disk encryption on laptops using BitLocker. The organization requires that the encryption key be protected by a hardware module that validates the boot process before releasing the key. Which BitLocker configuration should be used?

A security administrator is configuring a new internal certificate authority (CA) to issue certificates for internal servers. The CA must ensure that certificates can be revoked if a private key is compromised, and that clients can verify the revocation status without directly contacting the CA. Which two mechanisms should be implemented? (Choose two.)

A security engineer is configuring an OpenSSH server on a Linux bastion host. The organization's policy requires that the server accept only SSH keys that provide forward secrecy and are resistant to offline brute-force attacks. The engineer generates a new host key and must select the algorithm that best meets this requirement. Which algorithm should the engineer choose?

A security engineer is designing an internal Public Key Infrastructure (PKI) and needs to issue a subordinate certificate authority (sub-CA) certificate. To prevent this sub-CA from accidentally or maliciously issuing certificates for unauthorized domains, what specific X.509 extension must be correctly configured?

An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?

A security analyst is hardening a web server to ensure that only modern, secure protocols are used for HTTPS traffic. Which configuration best aligns with GSEC security standards for data in transit?

An organization needs to encrypt a database of PII. The requirements state that the encryption must be reversible by authorized staff and provide data integrity. Which implementation should the security engineer recommend?

Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?

When selecting a cryptographic hash function for verifying file integrity, which property is most important to ensure that an attacker cannot create two different files that produce the same hash value?

A security analyst is reviewing a legacy application that uses RSA for digital signatures. The application generates a 1024-bit RSA key pair and signs messages using SHA-1. The analyst must recommend an upgrade that maintains the same algorithm family but meets current security standards. Which change should be recommended?

Question 19easymultiple choice
Read the full VPN explanation →

A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?

A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cryptography Application sessions

Start a Cryptography Application only practice session

Every question in these sessions is drawn from the Cryptography Application domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Cryptography Application?
Be able to map a stated requirement — forward secrecy, integrity, reversibility, trust — to the specific algorithm, mode, or PKI function that satisfies it. The single most important thing is reading the requirement precisely and not selecting a control that solves a different problem.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cryptography Application questions in a focused session?
Yes — the session launcher on this page draws every question from the Cryptography Application domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.