SSCP Cryptography Practice Question
A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?
⚠ Common exam trap
SSCP often tests the difference between true random and pseudorandom sources — candidates pick a PRNG seeded with a timestamp or password because it sounds random, but cryptographic keys require a truly random source like a hardware RNG.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hardware random number generator
A hardware random number generator (HRNG) uses a physical entropy source (e.g., thermal noise, quantum effects) to produce truly random numbers, making it the most appropriate for generating cryptographic keys. Cryptographic keys require high entropy and unpredictability; HRNGs provide true randomness, unlike deterministic PRNGs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hardware random number generator
Why this is correct
A hardware random number generator derives entropy from physical phenomena, producing non-deterministic output. Software generators are deterministic algorithms, so only a hardware source satisfies the requirement for a truly random seed for cryptographic key generation.
- ✗
Cryptographically secure PRNG seeded with a static password
Why it's wrong here
A static password seed makes output reproducible, so an attacker who learns the password regenerates every key; true randomness requires an entropy source such as a hardware RNG. It tempts because CSPRNGs are cryptographically strong, and would be correct where a securely stored, high-entropy seed is available and determinism is required.
- ✗
Pseudorandom number generator (PRNG) seeded with current timestamp
Why it's wrong here
A timestamp seed is predictable and low-entropy, so keys can be brute-forced by enumerating plausible generation times; true randomness needs a hardware entropy source. It tempts because PRNGs are fast and convenient for bulk key generation, and would be correct only when seeded from a genuinely unpredictable source.
- ✗
User-memorized passphrase
Why it's wrong here
Human-chosen passphrases carry dictionary and pattern bias, giving far less entropy than a hardware random source, so derived keys are guessable. It tempts because passphrases are memorable and usable for key derivation, and would be correct for protecting a keystore or deriving keys via a slow KDF, not for true randomness.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.