Courseiva
Cryptography →hardMultiple Select

SSCP Cryptography Practice Question

A company is selecting a cryptographic algorithm for digital signatures. Which THREE of the following algorithms can be used for digital signatures? (Select THREE.)

⚠ Common exam trap

SSCP often tests the confusion between hash functions (SHA-256), symmetric ciphers (AES), and asymmetric signature algorithms (DSA, RSA, ECDSA), catching candidates who select SHA-256 thinking it 'signs' data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DSA

DSA (Option B) is a Digital Signature Algorithm designed specifically to generate and verify digital signatures using discrete logarithms, so it is correct. RSA (Option D) can produce digital signatures by signing a hash with the private key and verifying with the public key, making it a valid signature algorithm. ECDSA (Option E) is the Elliptic Curve Digital Signature Algorithm, which provides digital signatures based on elliptic-curve cryptography and is also correct. SHA-256 (Option A) is only a hash function used to create message digests, not a signature algorithm by itself, and AES (Option C) is a symmetric block cipher for encryption, not for digital signatures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SHA-256

    Why it's wrong here

    SHA-256 is a hash function producing a message digest; it cannot sign because it holds no private key. It is tempting because signatures hash the message first, so SHA-256 appears inside signing schemes, but it is the correct choice for integrity verification, not the signing algorithm itself.

  • ✓

    DSA

    Why this is correct

    DSA is a FIPS-approved asymmetric algorithm designed solely for digital signatures, relying on the discrete logarithm problem over finite fields. It satisfies the stem's requirement directly, generating signatures through a per-message random value k rather than supporting encryption.

  • ✗

    AES

    Why it's wrong here

    AES is a symmetric block cipher for confidentiality, not signature generation; it has no key pair to sign with. It is tempting because AES appears throughout PKI for encrypting data and keys, and it would be the right pick for bulk data-at-rest encryption, not digital signatures.

  • ✓

    RSA

    Why this is correct

    RSA is an asymmetric algorithm whose trapdoor permutation (integer factorisation) supports both encryption and signature generation, typically via PKCS#1 v1.5 or PSS padding. This satisfies the stem's requirement for a digital signature algorithm, unlike symmetric ciphers such as AES.

  • ✓

    ECDSA

    Why this is correct

    ECDSA generates and verifies digital signatures using elliptic-curve cryptography, satisfying the stem's requirement for a signature-capable algorithm. Its security derives from the elliptic-curve discrete logarithm problem, delivering equivalent strength to RSA at far smaller key sizes — ideal where bandwidth or storage is constrained.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.