CompTIA SecurityX Practice Questions: Cryptography

6 free, exam-style CompTIA SecurityX (CAS-005) practice questions covering Cryptography, each with the correct answer and an explanation. Start a timed exam below, or scroll on to read through the questions.

🧠

Mini Exam

25 Questions · 50 minutes

Start Quiz 🚀
🏆

Mock SecurityX Exam

85 Questions · 165 minutes

Start Quiz 🚀
📅

Daily Quiz

10 Questions · 20 minutes

Start Quiz 🚀
🎯

Standard Practice

50 Questions · 100 minutes

Start Quiz 🚀

Cryptography practice questions

Answers and explanations are shown. Take the timed exam above to test yourself first.

Q1. Which of the following is MOST important when implementing homomorphic encryption?

  • A.Performance overhead acceptance✓ Correct
  • B.Disabled encryption
  • C.Plaintext processing
  • D.No key management
Explanation: Homomorphic encryption currently has significant performance costs. Learn more.

Q2. What is the PRIMARY security consideration for post-quantum cryptographic migration?

  • A.Immediate replacement of all algorithms
  • B.Hybrid cryptographic implementations during transition✓ Correct
  • C.Disabled encryption
  • D.No key management
Explanation: Hybrid systems maintain security during quantum transition. Learn more.

Q3. Which encryption method is MOST secure for data at rest in a high-security environment?

  • A.AES-128
  • B.AES-256✓ Correct
  • C.3DES
  • D.Blowfish
Explanation: AES-256 provides the highest level of security among the options. Learn more.

Q4. Which of the following is a hardware security module (HSM) MOST commonly used for?

  • A.Storing plaintext passwords
  • B.Accelerating VPN performance
  • C.Securing cryptographic key management✓ Correct
  • D.Blocking malware
Explanation: HSMs provide secure key generation, storage, and management. Learn more.

Q5. What is the PRIMARY risk of using deprecated SSL/TLS versions?

  • A.Slower performance
  • B.Known vulnerabilities (e.g., POODLE)✓ Correct
  • C.Larger key sizes
  • D.Incompatibility with browsers
Explanation: Older versions (e.g., SSL 3.0, TLS 1.0) have exploitable flaws. Learn more.

Q6. Which cryptographic approach lets a server prove certificate validity without clients downloading full revocation lists?

  • A.OCSP✓ Correct
  • B.FTP
  • C.GRE
  • D.RIP
Explanation: Online Certificate Status Protocol allows clients to check certificate revocation status with an authority responder. Learn more.

More CompTIA SecurityX practice topics

Keep studying CompTIA SecurityX

Full CompTIA SecurityX practice exam · CompTIA SecurityX study guide · All CompTIA practice questions

Last updated