SSCP Cryptography Practice Question
A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)
⚠ Common exam trap
The trap is that Blowfish sounds modern and 'strong' to candidates who recall it as a successor to DES, but its 64-bit block size disqualifies it; the exam expects you to recognize AES and ChaCha20 as the two current standard symmetric ciphers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ChaCha20
Option B (ChaCha20) is correct because it is a modern, secure stream cipher standardized by the IETF in RFC 8439, offering strong 256-bit security and excellent performance in software without hardware acceleration. Option C (AES) is correct because it is the current NIST-approved symmetric block cipher, available in 128-, 192-, and 256-bit key sizes, and is the standard replacement for deprecated algorithms like 3DES. Option A (DES) is not acceptable because its 56-bit key is trivially brute-forced and it has been obsolete for decades. Option D (RC4) is not acceptable because it is a broken stream cipher with well-known biases (e.g., in WEP/TLS) and is prohibited by RFC 7465. Option E (Blowfish) is not acceptable as a modern choice because its 64-bit block size makes it vulnerable to birthday attacks (e.g., SWEET32) and it has been superseded by Twofish/AES.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DES
Why it's wrong here
DES has a 56-bit effective key, brute-forceable in hours, and is withdrawn by NIST; it cannot replace 3DES. It is tempting because DES is the direct ancestor of 3DES and shares its block structure, but its short key length makes it weaker, not modern.
- ✓
ChaCha20
Why this is correct
ChaCha20 is a modern stream cipher using a 256-bit key and 96-bit nonce, avoiding 3DES's small block size and short effective key. It provides strong confidentiality, particularly in software without AES hardware acceleration, making it an acceptable replacement.
- ✓
AES
Why this is correct
AES is a symmetric block cipher with 128-, 192- and 256-bit key lengths, replacing 3DES's 64-bit effective key and 64-bit block size. Its larger block size and resistance to Sweet32-style collision attacks make it an acceptable modern replacement.
- ✗
RC4
Why it's wrong here
RC4 is a stream cipher with documented biases and is prohibited for TLS by RFC 7465; it is not a modern replacement for 3DES. It is tempting because RC4 is far faster than 3DES in software, but speed does not make a broken keystream acceptable for protecting data.
- ✗
Blowfish
Why it's wrong here
Blowfish's 64-bit block size makes it unsuitable for bulk data, and its 448-bit key schedule is slow to initialise, so it fails the migration's modern-algorithm requirement. It is tempting because Blowfish is a legitimate symmetric cipher, and would suit a legacy system needing a fast, licence-free replacement for DES.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.