Which AES mode provides authenticated encryption with associated data (AEAD)?
A CISSP practice question covering Domain 3: Security Architecture and Engineering. Try answering before reading the explanation below.
Show options & answer
Why "GCM" is the right answer
GCM provides confidentiality plus integrity via a Galois-mode authentication tag. CBC requires a separate MAC for integrity. ECB has neither integrity nor strong confidentiality. ChaCha20-Poly1305 is the modern alternative AEAD.
Study videos for this topic
Want to go deeper on Domain 3? Watch the full breakdown — every video is free, no account, no upsell.
CISSP Domain 3: Bell-LaPadula vs Biba (No More Mix-Ups)
Domain 3 — Security Architecture and Engineering
CISSP Domain 3: TPM, Reference Monitor, and TCB
Domain 3 — Security Architecture and Engineering
CISSP Domain 3: Cloud, ICS, IoT & Container Vulnerabilities
Domain 3 — Security Architecture and Engineering
CISSP Crypto: Which Key for Privacy vs Signing?
Domain 3 — Security Architecture and Engineering
Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.