Courseiva
Cryptography →hardMultiple Choice

SSCP Cryptography Practice Question

A security analyst is reviewing a proposed cryptographic design for a new messaging application. The design uses AES-256 in Galois/Counter Mode (GCM) for confidentiality and integrity, but the analyst notices that the same nonce is generated for multiple messages under the same key. What is the MOST likely security consequence of this flaw?

⚠ Common exam trap

The trap here is focusing only on confidentiality loss from keystream reuse and overlooking that nonce reuse in GCM destroys integrity by enabling tag forgery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The integrity protection is broken, allowing an attacker to forge authentication tags and inject messages.

In AES-GCM, the nonce must be unique for each encryption under a given key. Reusing a nonce allows an attacker to recover the GHASH subkey H and forge authentication tags, completely breaking integrity and authenticity. Although confidentiality is also weakened because the keystream repeats, the most critical consequence is the ability to inject undetected messages, which invalidates the application's trust model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The integrity protection is broken, allowing an attacker to forge authentication tags and inject messages.

    Why this is correct

    In GCM, nonce reuse under the same key is catastrophic because it allows an attacker to recover the authentication subkey H and forge valid tags. This breaks integrity and authenticity, enabling injection of arbitrary messages without detection. While confidentiality is also compromised, the primary and most severe consequence is the loss of integrity, which undermines the entire security guarantee of the messaging application.

  • ✗

    The performance of the encryption degrades because the nonce is used to seed the counter, causing counter collisions.

    Why it's wrong here

    Nonce reuse does cause counter block collisions, but the effect is not performance degradation. The security impact is the loss of confidentiality and integrity. Counter collisions mean the same keystream blocks are used, which is a security failure, not a performance issue. This option mischaracterizes the consequence and does not address the cryptographic break.

  • ✗

    The confidentiality of the messages is lost because the keystream is reused, allowing XOR-based plaintext recovery.

    Why it's wrong here

    While nonce reuse in GCM does compromise confidentiality because the same keystream is used, the more severe and immediate consequence is the loss of integrity protection. GCM's authentication tag depends on the nonce and key; reusing a nonce allows an attacker to forge valid tags more easily. Confidentiality loss is a real issue, but the catastrophic failure is the ability to forge messages, making this option incomplete.

  • ✗

    The encryption key is immediately exposed, requiring rekeying of all sessions.

    Why it's wrong here

    Nonce reuse does not directly reveal the AES key. It reveals the keystream and weakens the authentication mechanism, but the key itself remains secret. An attacker cannot trivially recover the key from nonce reuse alone; they would need additional cryptanalysis. Therefore, claiming immediate key exposure overstates the consequence and misidentifies the primary risk.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.