Courseiva
Cryptography →mediumMultiple Choice

SSCP Cryptography Practice Question

A financial services company is deploying a new VPN concentrator that must support perfect forward secrecy (PFS) for all client sessions. The security team is configuring the IPsec phase 2 (Quick Mode) proposals. Which of the following should be configured to achieve PFS?

⚠ Common exam trap

It's easy for candidates to confuse authentication or encryption algorithms with key exchange mechanisms, assuming that strong encryption alone provides perfect forward secrecy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Diffie-Hellman group 14 in the phase 2 proposal.

Perfect forward secrecy in IPsec is achieved by including a Diffie-Hellman group in the phase 2 (Quick Mode) proposal. This forces a new key exchange for each session, ensuring that compromise of one session key does not compromise other sessions. Encryption algorithms and authentication methods do not provide PFS; they serve different purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the phase 1 lifetime to be shorter than the phase 2 lifetime.

    Why it's wrong here

    The lifetimes of phase 1 and phase 2 are independent and do not provide perfect forward secrecy. Shortening phase 1 lifetime may trigger more frequent rekeying of the IKE SA, but without a new DH exchange in phase 2, the session keys remain derivable from the original keying material, so PFS is not achieved.

  • ✗

    Configure the phase 1 proposal to use RSA signatures for authentication.

    Why it's wrong here

    RSA signatures are used for authentication in IKE phase 1, not for key exchange. They do not provide perfect forward secrecy. PFS requires an ephemeral Diffie-Hellman exchange in phase 2 to generate unique session keys. Authentication methods like RSA signatures or pre-shared keys do not affect the forward secrecy property.

  • ✓

    Enable Diffie-Hellman group 14 in the phase 2 proposal.

    Why this is correct

    Perfect forward secrecy in IPsec is achieved by performing a new Diffie-Hellman key exchange during phase 2 (Quick Mode). Specifying a DH group such as group 14 (2048-bit MODP) in the phase 2 proposal ensures that a fresh key is generated for each session, so compromise of one session key does not expose past or future session keys.

  • ✗

    Use AES-256-GCM for the phase 2 encryption algorithm.

    Why it's wrong here

    AES-256-GCM is a strong encryption algorithm that provides confidentiality and integrity, but it does not by itself provide perfect forward secrecy. PFS depends on the key exchange method, not the encryption algorithm. Without an ephemeral DH exchange in phase 2, using AES-256-GCM still allows session keys to be derived from a compromised long-term key.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.