SSCP Systems Security Certified PractitionerCryptographyMedium

A security engineer is evaluating different cryptographic algorithms for securing data in transit across a high-speed network. The primary concern is maintaining confidentiality and integrity with minimal latency. Which of the following cryptographic primitives, when correctly implemented, offers both confidentiality and integrity in a single operation?

  1. ARSA
  2. BAES-GCM
  3. CAES-CBC
  4. DSHA-256
Show answer & explanation

Correct answer: B. AES-GCM

AES-GCM (Galois/Counter Mode) is an authenticated encryption mode. It provides both confidentiality (encryption) and authenticity/integrity (via a Message Authentication Code or MAC) in a single, efficient operation, making it ideal for high-speed network communication.

Why the other options are wrong

  • A. RSA is an asymmetric algorithm primarily used for key exchange and digital signatures, not for bulk data confidentiality and integrity in a single operation.
  • C. AES-CBC provides confidentiality but not integrity directly. It would require a separate MAC for integrity.
  • D. SHA-256 is a hashing algorithm providing integrity (and non-repudiation with signatures) but no confidentiality.

Authenticated Encryption (AEAD)

A type of encryption that simultaneously provides confidentiality, integrity, and authenticity for data. If any part of the ciphertext or associated authenticated data is modified, decryption and verification will fail.

  • Combines encryption with a Message Authentication Code (MAC).
  • Protects against tampering, decryption, and replay attacks.
  • Examples include AES-GCM and ChaCha20-Poly1305.

Memory trick: Crypto Primitives: Confidentiality, Integrity, Authentication, Non-repudiation!

More Cryptography questions