Courseiva

GSEC · topic practice

Cryptography practice questions

GSEC cryptography covers symmetric and asymmetric encryption, hashing, PKI, TLS, IPsec, and key management as applied in defensive operations. Questions present real command output, certificate requests, VPN configurations, or incident scenarios and ask you to identify the vulnerability, the correct control, or the security consequence of a specific setting.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cryptography

What the exam tests

What to know about Cryptography

Be able to read real command output and configuration, then name the cryptographic weakness or the correct control. The single most important thing: know what each flag, mode, and key type actually protects, so you can spot when protection is missing.

Interpreting openssl req output and the effect of the -nodes flag on private key storage

Selecting encryption-in-use controls such as confidential computing or secure enclaves

Analyzing code-signing key compromise and why signed malicious firmware passes verification

Evaluating IPsec/IKEv2 authentication choices including PSK versus certificate-based authentication

Watch out for

Common Cryptography exam traps

  • ▸Assuming -nodes encrypts the private key; it actually disables passphrase protection, leaving the key unencrypted on disk.
  • ▸Confusing encryption at rest, in transit, and in use, then choosing a control that does not protect data during processing.
  • ▸Believing signature verification proves vendor intent; a stolen code-signing key produces valid signatures on attacker updates.

Practice set

Cryptography questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full Cryptography explanation →

A security analyst is investigating a suspected man-in-the-middle attack against an internal TLS-secured web application. The analyst reviews the certificate chain and notices that the leaf certificate's public key modulus matches an unauthorized external entity. Which fundamental security property of asymmetric cryptography was compromised in this scenario?

An organization is updating its public key infrastructure policy to enhance digital signature security and align with modern cryptographic standards. Which TWO actions should the security team implement to achieve robust signature integrity and prevent signature forgery? (Choose two)

Question 3mediummultiple choice
Read the full Cryptography explanation →

Which cryptographic property ensures that a digital signature remains valid even if the sender's long-term private key is compromised at a later date?

Question 4mediummultiple choice
Read the full Cryptography explanation →

A hospital's compliance team requires that all data at rest on a fleet of Linux servers be encrypted. The servers have no hardware cryptographic accelerators, and the security architect wants to minimize CPU overhead while still using a widely vetted, NIST-approved block cipher. The architect also insists that the chosen mode must not require a separate random IV for each block and must allow parallel decryption. Which AES mode of operation should the architect select?

Question 5mediummultiple choice
Read the full VPN explanation →

An engineer is configuring an IPsec VPN between two data centers. The requirement is that the VPN must provide confidentiality, data origin authentication, and integrity for the encapsulated packets, and the design must avoid the known weaknesses of using the same key material for both encryption and integrity. Which combination of IPsec protocols and transforms BEST meets this requirement?

Question 6mediummultiple choice
Read the full Cryptography explanation →

A financial services firm runs an internal certificate authority (CA) that issues TLS certificates for service-to-service authentication. The security team must ensure that if the CA's private key is ever compromised, an attacker cannot forge certificates that appear valid to services that have already cached the CA certificate. Which mechanism best mitigates this risk?

Question 7mediummultiple choice
Read the full Cryptography explanation →

An administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?

Question 8hardmultiple choice
Read the full Cryptography explanation →

Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?

Exhibit

openssl req -new -newkey rsa:2048 -nodes -out cert.csr -keyout cert.key
Question 9hardmultiple choice
Read the full Cryptography explanation →

A security analyst is investigating a suspected man-in-the-middle attack against an HTTPS service. The analyst finds that the client is ignoring certificate validation errors. Which cryptographic failure is most likely occurring?

A developer is implementing an application that stores user passwords in a database. Which THREE of the following practices are essential for ensuring the cryptographic security of these stored secrets?

Question 11mediummultiple choice
Read the full Cryptography explanation →

An organization is migrating to a cloud environment and must ensure that data remains encrypted while in use by applications. Which technology should the security team implement to achieve this?

Question 12hardmultiple choice
Read the full Cryptography explanation →

A software vendor distributes signed firmware updates to customers. During an incident review, an analyst discovers that an attacker who obtained the vendor's code-signing private key was able to produce updates that passed signature verification on customer devices. The vendor wants to redesign the signing process so that compromise of a single signing key no longer allows an attacker to forge valid updates. Which change best achieves this goal?

Question 13mediummultiple choice
Read the full Cryptography explanation →

A security team is deploying a new internal TLS certificate authority (CA) for service-to-service authentication. The CA private key must be protected, and the team wants to ensure that if the key is compromised, the attacker cannot forge certificates without detection. Which of the following is the MOST effective control to detect unauthorized certificate issuance?

Question 14hardmultiple choice
Read the full Cryptography explanation →

A security architect is designing a system that requires cryptographic keys to be generated, stored, and used without ever exposing the private key material to the operating system. The keys must be usable for TLS server authentication and must support high transaction volumes. Which of the following solutions BEST meets these requirements?

Question 15mediummultiple choice
Read the full VPN explanation →

A security analyst is reviewing the configuration of a VPN gateway that uses IPsec in tunnel mode. The analyst notices that the gateway is configured to use IKEv2 with a pre-shared key (PSK) for authentication. Which of the following is the PRIMARY security concern with this configuration?

Question 16easymultiple choice
Read the full Cryptography explanation →

A security administrator is configuring a Linux server to encrypt a new block device that will store sensitive data. The administrator wants to ensure that data is encrypted at rest and that the encryption key is protected by a passphrase. Which of the following tools is designed specifically for this purpose?

Question 17mediummultiple choice
Read the full Cryptography explanation →

A security engineer at a hospital must encrypt a 40 GB database backup for archival to offsite tape. The tape library appliance has very limited CPU resources, and the engineer wants a symmetric mode that allows the archive to be decrypted in independent chunks without needing to read the entire stream first. Which cipher mode BEST satisfies these requirements?

A security engineer is implementing a digital signature solution using RSA. The engineer must ensure that signatures provide authenticity, integrity, and non-repudiation. Which TWO of the following practices are essential to achieve these goals? (Choose two.)

Question 19hardmultiple choice
Read the full Cryptography explanation →

A financial services firm is designing a key management process for its internal certificate authority. The security architect wants a single hardware security module (HSM) cluster to protect the CA's signing key while ensuring that a compromise of one HSM appliance does not expose the key in plaintext to an attacker who gains root on that appliance. Which deployment property BEST addresses this requirement?

Question 20easymultiple choice
Read the full Cryptography explanation →

A junior administrator is asked to verify the integrity of a downloaded Linux distribution ISO before installing it on a production server. The vendor publishes a SHA-256 checksum and a detached PGP signature. Which action BEST confirms both that the file is intact and that it genuinely originated from the vendor?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cryptography sessions

Start a Cryptography only practice session

Every question in these sessions is drawn from the Cryptography domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Cryptography?
Be able to read real command output and configuration, then name the cryptographic weakness or the correct control. The single most important thing: know what each flag, mode, and key type actually protects, so you can spot when protection is missing.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cryptography questions in a focused session?
Yes — the session launcher on this page draws every question from the Cryptography domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.