SSCP Network and Communications Security Practice Question
A security administrator needs to securely transfer files between two servers over an untrusted network. The administrator wants to use a protocol that provides encryption and authentication and operates over TCP port 22. Which protocol should be used?
⚠ Common exam trap
Test-takers frequently confuse SFTP with FTPS or assuming that FTP can be secured with a simple configuration change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure Shell (SSH) File Transfer Protocol (SFTP)
SFTP is the correct protocol because it runs over SSH on TCP port 22, providing encryption and authentication for file transfers. FTP, TFTP, and HTTP are insecure and do not meet the requirements. SFTP ensures that data remains confidential and integrity-protected during transit, making it suitable for untrusted networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File Transfer Protocol (FTP)
Why it's wrong here
FTP operates over TCP ports 20 and 21 and transmits data and credentials in cleartext. It does not provide encryption or authentication, making it unsuitable for transferring files over an untrusted network. Using FTP would expose sensitive data to eavesdropping and man-in-the-middle attacks. Therefore, it does not meet the security requirements.
- ✗
Hypertext Transfer Protocol (HTTP)
Why it's wrong here
HTTP operates over TCP port 80 and transmits data in cleartext. While it can be used for file downloads, it lacks encryption and authentication. It does not provide the security required for transferring files over an untrusted network. HTTPS would be secure, but HTTP alone is not, and it does not use port 22.
- ✓
Secure Shell (SSH) File Transfer Protocol (SFTP)
Why this is correct
SFTP is a subsystem of SSH that operates over TCP port 22. It provides strong encryption and authentication for file transfers, protecting data in transit. It supports public key and password authentication and is widely used for secure file transfer. This matches the requirement to use TCP port 22 and ensures confidentiality and integrity.
- ✗
Trivial File Transfer Protocol (TFTP)
Why it's wrong here
TFTP operates over UDP port 69 and provides no encryption or authentication. It is used for simple, low-overhead transfers like booting devices, but it is highly insecure. It does not meet the requirement for secure file transfer over TCP port 22. Using TFTP would expose files to interception and modification.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.