SSCP Cryptography Practice Question
A healthcare company must store backup tapes offsite for seven years. The tapes contain patient records, and the company wants a symmetric encryption algorithm that is fast, widely supported, and approved by NIST for protecting data at rest. Which algorithm best meets these requirements?
⚠ Common exam trap
It's easy for candidates to confuse integrity mechanisms such as hashing with confidentiality mechanisms, or assuming that any NIST-approved algorithm works for bulk encryption regardless of whether it is symmetric or asymmetric.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES with a 256-bit key
AES is a NIST-approved symmetric block cipher that provides strong confidentiality with high performance, which is essential for encrypting large volumes of backup data. A 256-bit key offers a conservative security margin for long-term storage. Hashing provides integrity only, RSA and Diffie-Hellman are asymmetric mechanisms not suited to bulk data-at-rest encryption, so AES is the appropriate choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Diffie-Hellman key exchange with a 2048-bit group
Why it's wrong here
Diffie-Hellman is a key agreement protocol that lets two parties derive a shared secret over an untrusted channel. It does not itself encrypt stored data, and it is not used to protect backup tapes at rest. The company needs a symmetric cipher to encrypt the tapes, not a key exchange mechanism used during a live session.
- ✓
AES with a 256-bit key
Why this is correct
AES is a symmetric block cipher standardized by NIST and is the current approved algorithm for protecting sensitive data at rest. A 256-bit key provides a strong security margin, and AES performs efficiently on modern hardware, making it suitable for encrypting large backup tapes. It is widely supported across storage and backup platforms, matching the healthcare company's operational needs.
- ✗
RSA with a 2048-bit key
Why it's wrong here
RSA is an asymmetric algorithm used for key transport and digital signatures, not for bulk data-at-rest encryption. Encrypting large backup volumes with RSA would be prohibitively slow, and RSA key sizes are unrelated to symmetric bulk encryption needs. Although NIST approves RSA for certain uses, it does not satisfy the requirement for a fast symmetric algorithm to protect the tapes.
- ✗
SHA-256 hashing of each backup file
Why it's wrong here
SHA-256 is a cryptographic hash function designed to provide integrity, not confidentiality. Hashing a backup file does not hide its contents; it only produces a fixed-length digest that can be used to detect changes. The requirement is to protect patient records from unauthorized disclosure, so a hashing algorithm cannot substitute for an encryption algorithm.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.