Which two next-generation encryption algorithms does Cisco recommend?

Which two next-generation encryption algorithms does Cisco recommend? (Choose two.)
A. AES
B. 3DES
C. DES
D. MD5
E. DH-1024
F. SHA-384

cisco-exams

6 thoughts on “Which two next-generation encryption algorithms does Cisco recommend?

  1. I’m incorrect. AES IS a next-generation encryption method. The answer is AB. AES is an ALTERNATIVE to 3DES for ENCRYPTION.

  2. Check this link out:

    https://www.cisco.com/c/en/us/about/security-center/next-generation-cryptography.html

    This shows all the next-generation algorithms used. It says that SHA-384 is an Integrity algorithm. Encryption is Confidentiality, not Integrity.

    In regards to my guess, AES. There has to be a bit more, since standard AES isn’t next generation. If it had said AES-GCM or AES-CBC, those answers would be correct. I guess they just asked the question wrong. The question should be:

    Which two next-generation algorithms does Cisco recommend? (Choose two.)

    This would make SHA-384 a correct answer.

    If that was the question though, DH-1024 would also be a correct answer unless they added the key word of “usable” in their question. DH-1024 is recommended to AVOID unless it uses a 2048-bit key (DH-2048)

    I see how they got the answer of SHA-384, but that is incorrect in regards to ENCRYPTION stated in the question.

    Poorly worded question that obviously wasn’t vetted.

  3. I don’t believe this is correct. SHA is Secure HASH Algorithm. This isn’t an encryption method. The only three encryption protocols in that selection are DES, 3DES, and AES. Can someone prove me incorrect on this?

    1. You’re right. I had this q on my first attempt and thought the same, but how 3DES can be an answer? That leaves us with AES and SHA. I think it’s another poorly worded question.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.