Courseiva
Cryptography →mediumMultiple Select

SSCP Cryptography Practice Question

A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)

⚠ Common exam trap

The trap is that Blowfish sounds modern and 'strong' to candidates who recall it as a successor to DES, but its 64-bit block size disqualifies it; the exam expects you to recognize AES and ChaCha20 as the two current standard symmetric ciphers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ChaCha20

Option B (ChaCha20) is correct because it is a modern, secure stream cipher standardized by the IETF in RFC 8439, offering strong 256-bit security and excellent performance in software without hardware acceleration. Option C (AES) is correct because it is the current NIST-approved symmetric block cipher, available in 128-, 192-, and 256-bit key sizes, and is the standard replacement for deprecated algorithms like 3DES. Option A (DES) is not acceptable because its 56-bit key is trivially brute-forced and it has been obsolete for decades. Option D (RC4) is not acceptable because it is a broken stream cipher with well-known biases (e.g., in WEP/TLS) and is prohibited by RFC 7465. Option E (Blowfish) is not acceptable as a modern choice because its 64-bit block size makes it vulnerable to birthday attacks (e.g., SWEET32) and it has been superseded by Twofish/AES.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DES

    Why it's wrong here

    DES has a 56-bit effective key, brute-forceable in hours, and is withdrawn by NIST; it cannot replace 3DES. It is tempting because DES is the direct ancestor of 3DES and shares its block structure, but its short key length makes it weaker, not modern.

  • ✓

    ChaCha20

    Why this is correct

    ChaCha20 is a modern stream cipher using a 256-bit key and 96-bit nonce, avoiding 3DES's small block size and short effective key. It provides strong confidentiality, particularly in software without AES hardware acceleration, making it an acceptable replacement.

  • ✓

    AES

    Why this is correct

    AES is a symmetric block cipher with 128-, 192- and 256-bit key lengths, replacing 3DES's 64-bit effective key and 64-bit block size. Its larger block size and resistance to Sweet32-style collision attacks make it an acceptable modern replacement.

  • ✗

    RC4

    Why it's wrong here

    RC4 is a stream cipher with documented biases and is prohibited for TLS by RFC 7465; it is not a modern replacement for 3DES. It is tempting because RC4 is far faster than 3DES in software, but speed does not make a broken keystream acceptable for protecting data.

  • ✗

    Blowfish

    Why it's wrong here

    Blowfish's 64-bit block size makes it unsuitable for bulk data, and its 448-bit key schedule is slow to initialise, so it fails the migration's modern-algorithm requirement. It is tempting because Blowfish is a legitimate symmetric cipher, and would suit a legacy system needing a fast, licence-free replacement for DES.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.