SSCP Cryptography Practice Question
A security administrator is evaluating encryption protocols for email communication. Which of the following protocols can secure email in transit? (Select TWO)
⚠ Common exam trap
A common challenge on the SSCP exam is distinguishing between protocols that secure email in transit (IMAPS, SMTPS) versus protocols that secure other services (HTTPS for web, SSH for remote access, SFTP for file transfer). Candidates may confuse secure versions of unrelated protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IMAPS
IMAPS (Option A) is correct because it wraps the IMAP mail-retrieval protocol inside TLS (typically on TCP port 993), encrypting the client-to-server session so credentials and message contents are protected in transit. SMTPS (Option D) is correct because it applies TLS to SMTP (commonly on TCP port 465, or via STARTTLS on 587/25), securing the transport of outgoing email between mail clients and servers or between mail relays. HTTPS (Option B) secures web traffic via TLS but is not an email transport protocol, so it does not directly secure email in transit. SSH (Option C) provides an encrypted remote-shell/tunneling channel and is not an email protocol, and SFTP (Option E) is a file-transfer protocol over SSH, unrelated to securing email delivery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IMAPS
Why this is correct
IMAPS wraps IMAP within TLS, encrypting mail retrieval between client and server on port 993. This protects credentials and message content in transit, satisfying the requirement to secure email communication against interception during mailbox access.
- ✗
HTTPS
Why it's wrong here
HTTPS encrypts web traffic between a browser and server, so it protects webmail sessions but not the underlying SMTP, POP3 or IMAP transport. It is tempting because webmail access is encrypted, and would be correct for securing browser-based access to a mail portal.
- ✗
SSH
Why it's wrong here
SSH provides an encrypted channel for remote terminal access and tunnelling, not for transporting email messages between mail servers or clients. It is tempting because it secures traffic in transit generally, and would be correct for administering a mail server or forwarding ports securely.
- ✓
SMTPS
Why this is correct
SMTPS tunnels SMTP over TLS, encrypting message submission and relay between mail servers or clients on port 465. This protects email content in transit, satisfying the requirement to secure email communication against eavesdropping during transmission.
- ✗
SFTP
Why it's wrong here
SFTP encrypts file transfers over SSH, moving files between hosts, but it does not handle SMTP, POP3 or IMAP message delivery. It is tempting because it protects data in transit, and would be correct for securely uploading or downloading files rather than sending email.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.