SSCP Cryptography Practice Question
A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?
⚠ Common exam trap
The trap is assuming that any AES mode provides integrity; candidates may pick CBC or ECB thinking they are secure, but only GCM (and other AEAD modes like CCM) provide authenticated encryption natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES in GCM mode
AES in GCM mode provides authenticated encryption, offering both confidentiality and integrity/authenticity in a single operation. GCM (Galois/Counter Mode) is an AEAD (Authenticated Encryption with Associated Data) mode, making it the best choice for data in transit requiring both properties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RC4 stream cipher
Why it's wrong here
RC4 is an unauthenticated stream cipher with keystream biases, so it supplies confidentiality alone and no integrity tag, failing the authenticated-encryption requirement. It tempts because it is symmetric and fast, and would suit legacy TLS configurations where only confidentiality was demanded, but it cannot detect tampering.
- ✗
AES in ECB mode
Why it's wrong here
ECB mode encrypts identical plaintext blocks identically and supplies no integrity or authentication, so it cannot provide authenticated encryption. It is tempting as a fast, simple AES mode. GCM or CCM combine confidentiality with an authentication tag, satisfying both requirements.
- ✓
AES in GCM mode
Why this is correct
AES in GCM mode provides authenticated encryption, combining confidentiality with an authentication tag that detects tampering, which meets both stated requirements for data in transit. Other AES modes such as CBC supply confidentiality only and need a separate MAC.
- ✗
AES in CBC mode
Why it's wrong here
CBC chains blocks for confidentiality but appends no authentication tag, leaving ciphertext malleable and integrity unverified. It tempts because AES-CBC is a long-established symmetric mode, and it would be correct when paired with a separate MAC in an encrypt-then-MAC construction, but alone it fails the authenticated-encryption requirement.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.