easyMultiple ChoiceObjective-mapped
SSCP Practice Question: A security administrator needs to store sensitive…
A security administrator needs to store sensitive customer data in a database. To protect the data at rest, which encryption method should be used?
⚠ Common exam trap
Candidates often confuse asymmetric encryption (RSA) with symmetric encryption for data at rest, or they overlook the weaknesses of legacy algorithms like DES and Blowfish, assuming any encryption is sufficient without considering key size and mode of operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES-256 in CBC mode
AES-256 in CBC mode is the correct choice because it is a strong, widely accepted symmetric encryption algorithm that provides confidentiality for data at rest. AES-256 uses a 256-bit key, making it resistant to brute-force attacks, and CBC mode adds an initialization vector (IV) to ensure that identical plaintext blocks produce different ciphertext, preventing pattern leakage. This combination is recommended by standards such as NIST SP 800-38A for protecting sensitive stored data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RSA-2048
Why it's wrong here
RSA is asymmetric and too slow for bulk data encryption.
- ✗
Blowfish in CTR mode
Why it's wrong here
Blowfish has a small 64-bit block size and is less secure than AES.
- ✓
AES-256 in CBC mode
Why this is correct
AES-256 in CBC mode is a strong symmetric encryption suitable for data at rest.
- ✗
DES in ECB mode
Why it's wrong here
DES is outdated and weak; ECB mode reveals patterns.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.