SSCP Cryptography Practice Question
A financial services company is deploying a new VPN concentrator that must support perfect forward secrecy (PFS) for all client sessions. The security team is configuring the IPsec phase 2 (Quick Mode) proposals. Which of the following should be configured to achieve PFS?
⚠ Common exam trap
It's easy for candidates to confuse authentication or encryption algorithms with key exchange mechanisms, assuming that strong encryption alone provides perfect forward secrecy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Diffie-Hellman group 14 in the phase 2 proposal.
Perfect forward secrecy in IPsec is achieved by including a Diffie-Hellman group in the phase 2 (Quick Mode) proposal. This forces a new key exchange for each session, ensuring that compromise of one session key does not compromise other sessions. Encryption algorithms and authentication methods do not provide PFS; they serve different purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the phase 1 lifetime to be shorter than the phase 2 lifetime.
Why it's wrong here
The lifetimes of phase 1 and phase 2 are independent and do not provide perfect forward secrecy. Shortening phase 1 lifetime may trigger more frequent rekeying of the IKE SA, but without a new DH exchange in phase 2, the session keys remain derivable from the original keying material, so PFS is not achieved.
- ✗
Configure the phase 1 proposal to use RSA signatures for authentication.
Why it's wrong here
RSA signatures are used for authentication in IKE phase 1, not for key exchange. They do not provide perfect forward secrecy. PFS requires an ephemeral Diffie-Hellman exchange in phase 2 to generate unique session keys. Authentication methods like RSA signatures or pre-shared keys do not affect the forward secrecy property.
- ✓
Enable Diffie-Hellman group 14 in the phase 2 proposal.
Why this is correct
Perfect forward secrecy in IPsec is achieved by performing a new Diffie-Hellman key exchange during phase 2 (Quick Mode). Specifying a DH group such as group 14 (2048-bit MODP) in the phase 2 proposal ensures that a fresh key is generated for each session, so compromise of one session key does not expose past or future session keys.
- ✗
Use AES-256-GCM for the phase 2 encryption algorithm.
Why it's wrong here
AES-256-GCM is a strong encryption algorithm that provides confidentiality and integrity, but it does not by itself provide perfect forward secrecy. PFS depends on the key exchange method, not the encryption algorithm. Without an ephemeral DH exchange in phase 2, using AES-256-GCM still allows session keys to be derived from a compromised long-term key.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.