SSCP Cryptography Practice Question
A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?
⚠ Common exam trap
SSCP often tests key management fundamentals, catching candidates who choose convenience (emailing keys, single key for all purposes) over security best practices like HSM storage and rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store keys in dedicated hardware security modules (HSMs).
Option A is correct because dedicated hardware security modules (HSMs) provide tamper-resistant, FIPS 140-2/140-3 validated storage and cryptographic processing, ensuring keys are generated, used, and stored in a protected boundary and never exposed in plaintext on general-purpose systems. Option E is correct because regular key rotation limits the amount of data protected by any single key (cryptoperiod) and reduces the blast radius of a compromise, while rotation upon suspected or confirmed compromise ensures the exposed key is retired and replaced immediately. Options B, C, and D are not appropriate: reusing one key across encryption, digital signatures, and key exchange violates key-separation principles and increases the impact of any single key compromise; emailing keys exposes them to interception and unauthorized access; and storing keys alongside the encrypted data means a single database breach compromises both the ciphertext and the key needed to decrypt it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store keys in dedicated hardware security modules (HSMs).
Why this is correct
HSMs provide tamper-resistant hardware that generates and stores keys so private material never exists in plaintext on general-purpose systems, satisfying the lifecycle requirement for secure generation, storage and protection. Keys are used inside the module, preventing extraction even if the host is compromised.
- ✗
Use the same key for encryption, digital signatures, and key exchange.
Why it's wrong here
Key reuse across encryption, signing and key exchange lets compromise of one key undermine every function, and algorithm requirements differ per purpose. It tempts as a simplification to reduce key count, yet the correct practise is separate keys per cryptographic purpose, limiting blast radius.
- ✗
Email keys to authorized users for convenience.
Why it's wrong here
Email transports keys through unencrypted, retained channels, exposing them to interception and archiving outside the system's control. It tempts because distributing keys to users is necessary, but the correct practise is secure out-of-band delivery or key wrapping, never plain email.
- ✗
Store keys in the same database as encrypted data.
Why it's wrong here
Co-locating keys with ciphertext means one database breach yields both, defeating encryption entirely. It tempts because storing keys alongside data simplifies application access, yet the correct practise is separate key storage, ideally a hardware security module or dedicated key vault.
- ✓
Rotate keys regularly and upon compromise.
Why this is correct
Regular rotation limits the data exposed if a key is compromised, and immediate rotation after compromise restores security. This lifecycle practise directly satisfies the stem's requirement for securing keys, alongside secure generation, storage and destruction.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.