During a web-application penetration test, you are asked to recommend a cipher suite for servers that must serve battery-constrained ARM devices lacking AES hardware acceleration. The algorithm should be efficient in software, available in TLS 1.3, and currently considered secure. Which symmetric cipher meets these conditions?
ChaCha20 combined with the Poly1305 authenticator is standardized as an AEAD algorithm in RFC 8439 and appears in the TLS 1.3 cipher suite TLS_CHACHA20_POLY1305_SHA256. Because it relies only on fast addition, rotation, and XOR operations, it performs well on processors without AES-NI while still offering 256-bit security and modern authenticated encryption. AES-256-CBC is not permitted in TLS 1.3 and carries padding-oracle risks, 3DES has been deprecated due to its small 64-bit block size and is also absent from TLS 1.3, and RC4 has long been prohibited because of serious statistical weaknesses.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AEAD and how does it enhance encryption security?
Open an interactive chat with Bash
Why do processors without AES hardware acceleration benefit from ChaCha20?
Open an interactive chat with Bash
What makes TLS 1.3 more secure than previous versions of TLS?
Open an interactive chat with Bash
Why is ChaCha20 preferred for devices lacking AES hardware acceleration?
Open an interactive chat with Bash
What makes AES-256-CBC unsuitable for TLS 1.3?
Open an interactive chat with Bash
Why are 3DES and RC4 no longer used in modern cryptographic standards?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .