SSCP Cryptography Practice Question
A company is deploying a VPN that uses IPsec in tunnel mode. The security engineer must choose a key exchange method that provides perfect forward secrecy (PFS) so that compromise of a long-term key does not expose past session keys. Which configuration should the engineer select?
⚠ Common exam trap
The trap here is assuming that using strong authentication or a strong cipher automatically provides perfect forward secrecy, when PFS specifically requires an ephemeral Diffie-Hellman exchange for each session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use IKEv2 with a Diffie-Hellman group for the IKE SA and a separate Diffie-Hellman group for the CHILD_SA.
Perfect forward secrecy requires that each IPsec session key be derived from a fresh, ephemeral Diffie-Hellman exchange. In IKEv2, configuring separate DH groups for the IKE SA and the CHILD_SA ensures that even if the IKE SA key is compromised, past and future child session keys remain protected. Static keys and configurations without a child DH exchange do not provide this property.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use static keying with manually configured security associations and AES-256.
Why it's wrong here
Static keys are long-term secrets; if one is compromised, all traffic encrypted under it is exposed, and there is no forward secrecy. Manual security associations also lack scalability and rekeying. AES-256 provides strong encryption but does not address key compromise retroactively. This approach completely fails the PFS requirement.
- ✓
Use IKEv2 with a Diffie-Hellman group for the IKE SA and a separate Diffie-Hellman group for the CHILD_SA.
Why this is correct
Perfect forward secrecy is achieved when each session key is derived from a fresh Diffie-Hellman exchange rather than from a long-term key. In IKEv2, using a DH group for the IKE SA and a distinct DH group for the CHILD_SA ensures that compromise of the IKE SA key does not compromise the IPsec session keys. This provides the required PFS.
- ✗
Use IKEv2 with RSA signatures for authentication and no additional Diffie-Hellman exchange after the initial IKE SA.
Why it's wrong here
RSA signatures authenticate the peers but do not by themselves provide PFS. If the CHILD_SA keys are derived solely from the initial IKE SA without a fresh DH exchange, then compromise of the IKE SA key could expose child keys. PFS requires an ephemeral DH exchange for each child SA, which this configuration lacks.
- ✗
Use IKEv1 in main mode with pre-shared keys and no DH group for the quick mode.
Why it's wrong here
IKEv1 main mode with pre-shared keys can use DH for the phase 1 exchange, but omitting a DH group in quick mode means the IPsec session keys are derived from the phase 1 keying material. If the long-term pre-shared key or the phase 1 key is later compromised, past session keys may be derivable. This does not provide PFS for the IPsec SAs.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.