nerdexam
(ISC)2

CISSP-ISSAP · Question #119

You are the Security Administrator for a consulting firm. One of your clients needs to encrypt traffic. However, he has specific requirements for the encryption algorithm. It must be a symmetric key…

The correct answer is C. DES. DES (Data Encryption Standard) satisfies both requirements: it is a symmetric algorithm (the same key encrypts and decrypts) and a block cipher (it processes data in fixed 64-bit blocks). PGP is eliminated because it is a hybrid encryption system using asymmetric…

Security Architecture Modeling

Question

You are the Security Administrator for a consulting firm. One of your clients needs to encrypt traffic. However, he has specific requirements for the encryption algorithm. It must be a symmetric key block cipher. Which of the following should you choose for this client?

Options

  • APGP
  • BSSH
  • CDES
  • DRC4

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    15% (5)
  • C
    74% (25)
  • D
    9% (3)

Explanation

DES (Data Encryption Standard) satisfies both requirements: it is a symmetric algorithm (the same key encrypts and decrypts) and a block cipher (it processes data in fixed 64-bit blocks). PGP is eliminated because it is a hybrid encryption system using asymmetric (public/private) key pairs for key exchange, making it asymmetric by nature. SSH is a secure communication protocol, not an encryption algorithm, so it doesn't qualify regardless of what ciphers it may use internally. RC4 is a close trap - it is symmetric, but it is a stream cipher (encrypts data bit-by-bit continuously), not a block cipher, which violates the client's second requirement.

Memory tip: Block vs. stream - think of DES as a "cookie cutter" (cuts data into uniform blocks), while RC4 is a "hose" (streams data continuously). If an exam question demands both symmetric and block, look for DES or AES - and since AES isn't listed, DES is your answer.

Topics

#Symmetric Encryption#Block Ciphers#Cryptographic Algorithms#DES

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice