CISSP Communication and Network Security Practice Question
A security administrator is evaluating secure file transfer protocols. Which THREE of the following protocols provide encryption for data in transit? (Select THREE.)
⚠ Common exam trap
Candidates often confuse SFTP (SSH-based) and FTPS (SSL/TLS-based), or mistakenly believe that TFTP (Trivial FTP) has security features. On the CISSP exam, remember that FTP and TFTP send credentials and data in cleartext, while SFTP, SCP, and FTPS provide encryption in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SFTP
SFTP (B) is correct because it runs over SSH (typically TCP port 22) and encrypts all data and commands in transit. SCP (D) is correct because it also operates over SSH, providing encrypted file transfer using the SSH transport layer. FTPS (E) is correct because it wraps FTP in TLS/SSL, encrypting the control and data channels. FTP (A) is not marked correct because it transmits credentials and data in cleartext, and TFTP (C) is not marked correct because it uses UDP with no encryption or authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FTP
Why it's wrong here
File Transfer Protocol (FTP) is an application-layer protocol designed for transferring files between a client and server on a computer network. A significant security vulnerability of FTP is that it transmits both control commands (like usernames and passwords) and data in cleartext, meaning the information is unencrypted and easily intercepted by network sniffers. This lack of confidentiality makes FTP unsuitable for transferring sensitive or confidential information in environments requiring data protection.
- ✓
SFTP
Why this is correct
Secure File Transfer Protocol (SFTP) is a network protocol that provides file access, file transfer, and file management functionalities over any reliable data stream. Crucially, SFTP runs as a subsystem of the Secure Shell (SSH) protocol, leveraging SSH's robust encryption capabilities to secure both the authentication credentials and the data being transferred. This ensures confidentiality and integrity, making SFTP a highly secure choice for transferring sensitive files across untrusted networks.
- ✗
TFTP
Why it's wrong here
Trivial File Transfer Protocol (TFTP) is a very simple, lightweight protocol primarily used for booting diskless workstations or transferring configuration files. Unlike FTP, TFTP lacks authentication mechanisms and offers no encryption whatsoever, transmitting all data in cleartext over UDP port 69. Its design prioritizes simplicity and minimal resource usage over security, rendering it completely inappropriate for any scenario requiring confidentiality or integrity of data.
- ✓
SCP
Why this is correct
Secure Copy Protocol (SCP) is a network protocol that facilitates the secure transfer of computer files between a local host and a remote host, or between two remote hosts. Similar to SFTP, SCP utilizes the Secure Shell (SSH) protocol for data transfer and authentication, ensuring that files are encrypted during transit and that the connection is authenticated. While effective for simple file copying, SCP is generally less feature-rich than SFTP, lacking directory listing or remote file deletion capabilities.
- ✓
FTPS
Why this is correct
File Transfer Protocol Secure (FTPS) is an extension of the traditional FTP protocol that adds support for the Transport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL), cryptographic protocols. FTPS can operate in either explicit (AUTH TLS) or implicit (dedicated port 990) modes to establish an encrypted control channel and/or data channel, protecting both authentication credentials and file contents from eavesdropping. This integration allows FTP to achieve confidentiality and integrity, addressing the cleartext vulnerability of standard FTP.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.