CompTIA SecurityX (CAS-005)Security EngineeringEasy

A security architect is designing a long-term data archival system that must remain secure against future cryptographic breakthroughs, including the potential advent of practical quantum computers. The data needs to be recoverable and verifiable for several decades. Which advanced cryptographic concept should the architect prioritize to address this specific threat?

  1. AHomomorphic Encryption
  2. BPost-Quantum Cryptography (PQC)
  3. CElliptic Curve Cryptography (ECC)
  4. DSymmetric Key Cryptography (AES-256)
Show answer & explanation

Correct answer: B. Post-Quantum Cryptography (PQC)

Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are resistant to attacks by quantum computers. Since the requirement is to remain secure against 'future cryptographic breakthroughs, including the potential advent of practical quantum computers' for 'several decades', PQC is the only option specifically designed to address this long-term quantum threat.

Why the other options are wrong

  • A. Homomorphic Encryption allows computations on encrypted data but does not address the threat of quantum attacks against the underlying cryptographic primitives.
  • C. ECC is currently strong but is known to be vulnerable to quantum attacks (Shor's algorithm).
  • D. AES-256 is generally considered resistant to quantum attacks for symmetric keys, but asymmetric key needs (for key exchange, digital signatures) would still be vulnerable.

Post-Quantum Cryptography (PQC)

Cryptographic algorithms designed to be secure against attacks by quantum computers, which pose a significant future threat to current public-key cryptography standards.

  • Resistant to quantum computer attacks.
  • Focuses on public-key algorithms (e.g., lattice-based, hash-based).
  • Essential for long-term data security.

Memory trick: PQC is the POST-QUANTUM solution.

More Security Engineering questions