SSCP Cryptography Practice Question
A security engineer is implementing a cryptographic system that requires both confidentiality and integrity. The engineer decides to use AES-256 in Galois/Counter Mode (GCM). Which of the following statements about GCM is true?
⚠ Common exam trap
The trap here is assuming that GCM, like CBC, is vulnerable to padding oracle attacks or that it does not provide confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GCM requires a unique nonce for each encryption operation under the same key.
GCM is an authenticated encryption mode that provides confidentiality and integrity. It requires a unique nonce for each encryption under the same key; nonce reuse compromises the authentication key and allows forgery. GCM does not use padding, so it is not susceptible to padding oracle attacks. It is designed for 128-bit block ciphers like AES.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GCM provides authentication but not confidentiality.
Why it's wrong here
GCM is an authenticated encryption mode that provides both confidentiality and integrity. It uses AES in counter mode for encryption and a universal hash function for authentication. Therefore, it does provide confidentiality, so this statement is incorrect.
- ✗
GCM is vulnerable to padding oracle attacks.
Why it's wrong here
Padding oracle attacks typically target CBC mode with PKCS#7 padding, where an attacker can distinguish between padding errors and other errors. GCM does not use padding; it is a stream-like mode that operates on arbitrary-length data. Therefore, GCM is not vulnerable to padding oracle attacks.
- ✗
GCM can only be used with block sizes of 128 bits.
Why it's wrong here
GCM is specifically defined for block ciphers with a 128-bit block size, such as AES. However, the statement as phrased is misleading because it implies a limitation, but in practice GCM is used with AES which has a 128-bit block size. The other options are more accurate descriptions of GCM's properties.
- ✓
GCM requires a unique nonce for each encryption operation under the same key.
Why this is correct
GCM is a nonce-based authenticated encryption mode. Reusing a nonce with the same key is catastrophic: it allows an attacker to recover the authentication key and potentially forge messages. Therefore, it is critical that each encryption operation uses a unique nonce. This is a fundamental requirement for the security of GCM.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.