SSCP Cryptography Practice Question
A security analyst is reviewing the cryptographic controls for a new messaging application. The application must ensure that messages are encrypted in transit and that the sender cannot later deny having sent a message. Which two of the following cryptographic mechanisms should be implemented to meet these requirements? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse integrity mechanisms like HMAC or hashing with non-repudiation, which requires asymmetric cryptography.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Digital signatures using the sender's private key
To encrypt messages in transit, TLS is appropriate as it provides confidentiality and integrity for data in transit. To ensure non-repudiation, digital signatures using the sender's private key are required because they uniquely bind the sender to the message. Symmetric encryption, hashing, and HMAC do not provide non-repudiation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Digital signatures using the sender's private key
Why this is correct
Digital signatures provide non-repudiation because they are generated with the sender's private key, which only the sender possesses. Anyone can verify the signature using the sender's public key, proving that the message originated from the sender and has not been altered. This directly meets the requirement that the sender cannot deny sending the message.
- ✗
Keyed-hash message authentication code (HMAC)
Why it's wrong here
HMAC provides integrity and authentication using a shared secret key, but it does not provide non-repudiation because the shared key is known to both parties. Either party could generate the HMAC, so it cannot prove the sender's identity. It also does not provide encryption for confidentiality.
- ✓
TLS for encrypting messages in transit
Why this is correct
TLS provides encryption for data in transit, ensuring confidentiality and integrity during transmission. It uses asymmetric cryptography for key exchange and symmetric encryption for bulk data. This meets the requirement that messages are encrypted in transit. However, TLS alone does not provide non-repudiation at the application layer.
- ✗
Hashing messages with SHA-256
Why it's wrong here
Hashing provides integrity by producing a fixed-size digest that can detect accidental or malicious changes. However, a hash alone does not provide confidentiality or non-repudiation. It must be combined with other mechanisms, such as digital signatures, to achieve non-repudiation. Therefore, it does not meet the stated requirements by itself.
- ✗
Symmetric encryption using a shared secret key
Why it's wrong here
Symmetric encryption provides confidentiality but not non-repudiation. Because both parties share the same key, either could have created the message. Therefore, it cannot prove the sender's identity or prevent the sender from denying having sent the message. It does not meet the non-repudiation requirement.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.