CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security engineer is tasked with securing a fleet of IoT devices deployed in remote locations. These devices have limited processing power and memory but must securely communicate with a central cloud platform. Which cryptographic algorithm should be prioritized for data encryption to balance security with resource constraints?
- AAES-256 in GCM mode
- BBlowfish
- CTriple DES (3DES)
- DRSA with 4096-bit keys
Show answer & explanationAnswer & explanation
Correct answer: A. AES-256 in GCM mode
AES-256 in GCM (Galois/Counter Mode) provides strong symmetric encryption with authenticated encryption capabilities, offering both confidentiality and integrity. It is computationally efficient, making it suitable for resource-constrained IoT devices while maintaining modern security standards.
Why the other options are wrong
- B. Blowfish is an older symmetric block cipher, generally considered less secure and less efficient than AES, and not as widely supported in modern cryptographic libraries or hardware accelerators relevant to IoT.
- C. 3DES is an older symmetric algorithm that is significantly slower and less secure than AES, and generally deprecated due to its 64-bit block size and susceptibility to meet-in-the-middle attacks.
- D. RSA 4096-bit is an asymmetric algorithm primarily used for key exchange and digital signatures, not efficient for bulk data encryption, and computationally intensive for IoT devices.
AES (Advanced Encryption Standard)
A symmetric block cipher adopted as an encryption standard by the U.S. government, widely used globally for its strength and efficiency.
- Symmetric encryption algorithm.
- Supports 128, 192, and 256-bit key sizes.
- Efficient in hardware and software, suitable for IoT.
Memory trick: Small devices need efficient AES, not big RSA.