shieldCISSP Practice Domain 3 — Security Architecture and Engineering Q21 of 120

Which type of attack against AES exploits implementation timing or power consumption rather than cryptanalytic weakness?

A CISSP practice question covering Domain 3: Security Architecture and Engineering. Try answering before reading the explanation below.

Show options & answer
A
Birthday attack
B
Side-channel attack
✓ Correct answer
C
Known-plaintext attack
D
Meet-in-the-middle attack
Why "Side-channel attack" is the right answer

Side-channel attacks measure physical phenomena (timing, power, EM emissions, sound) to extract keys without breaking the algorithm itself. Constant-time implementations and noise injection mitigate them. The other options are mathematical attack categories.

Study videos for this topic

Want to go deeper on Domain 3? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →