Courseiva

CISSP Communication and Network Security Practice Question

A security administrator is evaluating secure file transfer protocols. Which THREE of the following protocols provide encryption for data in transit? (Select THREE.)

⚠ Common exam trap

Candidates often confuse SFTP (SSH-based) and FTPS (SSL/TLS-based), or mistakenly believe that TFTP (Trivial FTP) has security features. On the CISSP exam, remember that FTP and TFTP send credentials and data in cleartext, while SFTP, SCP, and FTPS provide encryption in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SFTP

SFTP (B) is correct because it runs over SSH (typically TCP port 22) and encrypts all data and commands in transit. SCP (D) is correct because it also operates over SSH, providing encrypted file transfer using the SSH transport layer. FTPS (E) is correct because it wraps FTP in TLS/SSL, encrypting the control and data channels. FTP (A) is not marked correct because it transmits credentials and data in cleartext, and TFTP (C) is not marked correct because it uses UDP with no encryption or authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FTP

    Why it's wrong here

    File Transfer Protocol (FTP) is an application-layer protocol designed for transferring files between a client and server on a computer network. A significant security vulnerability of FTP is that it transmits both control commands (like usernames and passwords) and data in cleartext, meaning the information is unencrypted and easily intercepted by network sniffers. This lack of confidentiality makes FTP unsuitable for transferring sensitive or confidential information in environments requiring data protection.

  • ✓

    SFTP

    Why this is correct

    Secure File Transfer Protocol (SFTP) is a network protocol that provides file access, file transfer, and file management functionalities over any reliable data stream. Crucially, SFTP runs as a subsystem of the Secure Shell (SSH) protocol, leveraging SSH's robust encryption capabilities to secure both the authentication credentials and the data being transferred. This ensures confidentiality and integrity, making SFTP a highly secure choice for transferring sensitive files across untrusted networks.

  • ✗

    TFTP

    Why it's wrong here

    Trivial File Transfer Protocol (TFTP) is a very simple, lightweight protocol primarily used for booting diskless workstations or transferring configuration files. Unlike FTP, TFTP lacks authentication mechanisms and offers no encryption whatsoever, transmitting all data in cleartext over UDP port 69. Its design prioritizes simplicity and minimal resource usage over security, rendering it completely inappropriate for any scenario requiring confidentiality or integrity of data.

  • ✓

    SCP

    Why this is correct

    Secure Copy Protocol (SCP) is a network protocol that facilitates the secure transfer of computer files between a local host and a remote host, or between two remote hosts. Similar to SFTP, SCP utilizes the Secure Shell (SSH) protocol for data transfer and authentication, ensuring that files are encrypted during transit and that the connection is authenticated. While effective for simple file copying, SCP is generally less feature-rich than SFTP, lacking directory listing or remote file deletion capabilities.

  • ✓

    FTPS

    Why this is correct

    File Transfer Protocol Secure (FTPS) is an extension of the traditional FTP protocol that adds support for the Transport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL), cryptographic protocols. FTPS can operate in either explicit (AUTH TLS) or implicit (dedicated port 990) modes to establish an encrypted control channel and/or data channel, protecting both authentication credentials and file contents from eavesdropping. This integration allows FTP to achieve confidentiality and integrity, addressing the cleartext vulnerability of standard FTP.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.