Courseiva
Cryptography →mediumMultiple Choice

SSCP Cryptography Practice Question

A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?

⚠ Common exam trap

The trap is assuming that any AES mode provides integrity; candidates may pick CBC or ECB thinking they are secure, but only GCM (and other AEAD modes like CCM) provide authenticated encryption natively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AES in GCM mode

AES in GCM mode provides authenticated encryption, offering both confidentiality and integrity/authenticity in a single operation. GCM (Galois/Counter Mode) is an AEAD (Authenticated Encryption with Associated Data) mode, making it the best choice for data in transit requiring both properties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RC4 stream cipher

    Why it's wrong here

    RC4 is an unauthenticated stream cipher with keystream biases, so it supplies confidentiality alone and no integrity tag, failing the authenticated-encryption requirement. It tempts because it is symmetric and fast, and would suit legacy TLS configurations where only confidentiality was demanded, but it cannot detect tampering.

  • ✗

    AES in ECB mode

    Why it's wrong here

    ECB mode encrypts identical plaintext blocks identically and supplies no integrity or authentication, so it cannot provide authenticated encryption. It is tempting as a fast, simple AES mode. GCM or CCM combine confidentiality with an authentication tag, satisfying both requirements.

  • ✓

    AES in GCM mode

    Why this is correct

    AES in GCM mode provides authenticated encryption, combining confidentiality with an authentication tag that detects tampering, which meets both stated requirements for data in transit. Other AES modes such as CBC supply confidentiality only and need a separate MAC.

  • ✗

    AES in CBC mode

    Why it's wrong here

    CBC chains blocks for confidentiality but appends no authentication tag, leaving ciphertext malleable and integrity unverified. It tempts because AES-CBC is a long-established symmetric mode, and it would be correct when paired with a separate MAC in an encrypt-then-MAC construction, but alone it fails the authenticated-encryption requirement.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.