Courseiva
Cryptography →hardMultiple Select

SSCP Cryptography Practice Question

A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?

⚠ Common exam trap

SSCP often tests key management fundamentals, catching candidates who choose convenience (emailing keys, single key for all purposes) over security best practices like HSM storage and rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store keys in dedicated hardware security modules (HSMs).

Option A is correct because dedicated hardware security modules (HSMs) provide tamper-resistant, FIPS 140-2/140-3 validated storage and cryptographic processing, ensuring keys are generated, used, and stored in a protected boundary and never exposed in plaintext on general-purpose systems. Option E is correct because regular key rotation limits the amount of data protected by any single key (cryptoperiod) and reduces the blast radius of a compromise, while rotation upon suspected or confirmed compromise ensures the exposed key is retired and replaced immediately. Options B, C, and D are not appropriate: reusing one key across encryption, digital signatures, and key exchange violates key-separation principles and increases the impact of any single key compromise; emailing keys exposes them to interception and unauthorized access; and storing keys alongside the encrypted data means a single database breach compromises both the ciphertext and the key needed to decrypt it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store keys in dedicated hardware security modules (HSMs).

    Why this is correct

    HSMs provide tamper-resistant hardware that generates and stores keys so private material never exists in plaintext on general-purpose systems, satisfying the lifecycle requirement for secure generation, storage and protection. Keys are used inside the module, preventing extraction even if the host is compromised.

  • ✗

    Use the same key for encryption, digital signatures, and key exchange.

    Why it's wrong here

    Key reuse across encryption, signing and key exchange lets compromise of one key undermine every function, and algorithm requirements differ per purpose. It tempts as a simplification to reduce key count, yet the correct practise is separate keys per cryptographic purpose, limiting blast radius.

  • ✗

    Email keys to authorized users for convenience.

    Why it's wrong here

    Email transports keys through unencrypted, retained channels, exposing them to interception and archiving outside the system's control. It tempts because distributing keys to users is necessary, but the correct practise is secure out-of-band delivery or key wrapping, never plain email.

  • ✗

    Store keys in the same database as encrypted data.

    Why it's wrong here

    Co-locating keys with ciphertext means one database breach yields both, defeating encryption entirely. It tempts because storing keys alongside data simplifies application access, yet the correct practise is separate key storage, ideally a hardware security module or dedicated key vault.

  • ✓

    Rotate keys regularly and upon compromise.

    Why this is correct

    Regular rotation limits the data exposed if a key is compromised, and immediate rotation after compromise restores security. This lifecycle practise directly satisfies the stem's requirement for securing keys, alongside secure generation, storage and destruction.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.