CompTIA SecurityX (CAS-005)Security EngineeringHard

A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, even against future advances in cryptanalysis. The data is highly sensitive and regulatory requirements mandate protection from quantum computer attacks. Which cryptographic approach should be prioritized?

  1. ASymmetric Key Cryptography (AES-256)
  2. BElliptic Curve Cryptography (ECC)
  3. CRSA with larger key sizes
  4. DPost-Quantum Cryptography (PQC)
Show answer & explanation

Correct answer: D. Post-Quantum Cryptography (PQC)

Post-Quantum Cryptography (PQC) refers to cryptographic algorithms designed to be secure against attacks by quantum computers. Given the requirement to maintain confidentiality and integrity for 'several decades' and 'protection from quantum computer attacks', PQC is the only approach specifically designed to address this future threat.

Why the other options are wrong

  • A. AES-256 is generally considered quantum-resistant in terms of key search (Grover's algorithm), but the question also implies public-key cryptography for key exchange/digital signatures, where PQC is critical.
  • B. ECC, while currently strong, is vulnerable to Shor's algorithm on a sufficiently powerful quantum computer.
  • C. RSA, even with larger key sizes, is also vulnerable to Shor's algorithm and therefore not quantum-resistant.

Post-Quantum Cryptography (PQC)

Cryptographic algorithms that are designed to be secure against a cryptanalytic attack by a quantum computer, as well as by a classical computer.

  • Resistant to Shor's and Grover's algorithms (where applicable)
  • Essential for long-term data security against future quantum threats
  • Actively being standardized by NIST (e.g., CRYSTALS-Kyber, CRYSTALS-Dilithium)

Memory trick: PQC: Protecting your secrets from the quantum leap of computing power.

More Security Engineering questions