nerdexam
CompTIA

CAS-001 · Question #451

Joe, the Chief Executive Officer (CEO), was an Information security professor and a Subject Matter Expert for over 20 years. He has designed a network defense method which he says is significantly…

The correct answer is D. The company should use the method recommended by other respected information security. This question tests the fundamental principle of cryptographic standards: never roll your own crypto. Even highly credentialed experts should not invent proprietary cryptographic algorithms for production use. The correct answer (D) - using methods recommended by respected…

Enterprise Security

Question

Joe, the Chief Executive Officer (CEO), was an Information security professor and a Subject Matter Expert for over 20 years. He has designed a network defense method which he says is significantly better than prominent international standards. He has recommended that the company use his cryptographic method. Which of the following methodologies should be adopted?

Options

  • AThe company should develop an in-house solution and keep the algorithm a secret.
  • BThe company should use the CEO's encryption scheme.
  • CThe company should use a mixture of both systems to meet minimum standards.
  • DThe company should use the method recommended by other respected information security

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    2% (1)
  • D
    92% (49)

Explanation

This question tests the fundamental principle of cryptographic standards: never roll your own crypto. Even highly credentialed experts should not invent proprietary cryptographic algorithms for production use. The correct answer (D) - using methods recommended by respected information security organizations (e.g., NIST, ISO) - is correct because: (1) established algorithms like AES, RSA, and SHA have undergone years of public peer review and cryptanalysis by thousands of experts; (2) Kerckhoffs's Principle states a system should be secure even if everything about it except the key is public - security through obscurity (option A) is not acceptable; (3) the CEO's credentials are impressive, but individual expertise cannot replace the collective scrutiny applied to standardized algorithms. Option A (secret algorithm) violates Kerckhoffs's principle. Option B relies on a single unvetted design. Option C (a mixture) introduces unnecessary complexity and still relies on an unvetted algorithm.

Topics

#cryptographic standards#open design principle#algorithm selection#security best practices

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice