SSCP Systems Security Certified PractitionerCryptographyMedium

An organization is migrating from an older cryptographic algorithm to a stronger one. They are currently using an algorithm with a 56-bit key that is vulnerable to brute-force attacks. Which of the following symmetric encryption algorithms would be a suitable replacement, offering a higher level of security for data at rest?

  1. ARC4 (Rivest Cipher 4)
  2. B3DES (Triple DES)
  3. CAES (Advanced Encryption Standard)
  4. DDES (Data Encryption Standard)
Show answer & explanation

Correct answer: C. AES (Advanced Encryption Standard)

DES uses a 56-bit key and is considered insecure. 3DES uses multiple DES operations but is slower and has a smaller effective key length than AES. RC4 is a stream cipher with known vulnerabilities. AES, with key sizes of 128, 192, or 256 bits, is the current standard for strong symmetric encryption.

Why the other options are wrong

  • A. RC4 is a stream cipher with several known weaknesses and is generally not recommended for new implementations.
  • B. 3DES, while stronger than DES, is slower and commonly considered to have an effective key strength of 112 bits, which is still less robust than AES and has known theoretical attacks.
  • D. DES uses a 56-bit key and is the algorithm explicitly stated as vulnerable, making it unsuitable.

Advanced Encryption Standard (AES)

A symmetric block cipher adopted by the U.S. government and widely used worldwide for secure data encryption.

  • Supports key sizes of 128, 192, and 256 bits.
  • Replaced DES and 3DES as the standard.
  • Efficient in both hardware and software implementations.

Memory trick: When it comes to symmetric strength, AES is the champion, leaving old DES in the dust.

More Cryptography questions