VA-003 Explain encryption as a service Practice Question
An application uses transit encryption with convergent encryption enabled. Which THREE statements are true about convergent encryption? (Choose three.)
⚠ Common exam trap
HashiCorp often tests the misconception that convergent encryption requires a separate key for each context (Option A), when in fact the key is derived from the plaintext and is the same for identical data regardless of context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It produces the same ciphertext for the same plaintext and context.
Convergent encryption derives the encryption key from the plaintext content itself, typically by hashing the plaintext. Because the same plaintext always produces the same key, and the encryption algorithm is deterministic (no random nonce), the resulting ciphertext is identical for identical plaintexts. This property directly enables deduplication of encrypted data, as identical ciphertexts can be identified and stored only once.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It requires a separate key for each context.
Why it's wrong here
The same key can be used; context varies per encryption.
- ✓
It produces the same ciphertext for the same plaintext and context.
Why this is correct
Deterministic output is a key feature of convergent encryption.
- ✗
It is typically slower than non-convergent encryption.
Why it's wrong here
Performance is similar; the overhead of nonce derivation is minimal.
- ✓
It can be used for deduplication of encrypted data.
Why this is correct
Same plaintext yields same ciphertext, enabling deduplication.
- ✓
It uses a nonce that is derived from the plaintext.
Why this is correct
The nonce is computed from the plaintext and context to ensure determinism.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 498 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.