Courseiva
Cryptography →hardMultiple Choice

SSCP Cryptography Practice Question

A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?

⚠ Common exam trap

SSCP often tests the difference between true random and pseudorandom sources — candidates pick a PRNG seeded with a timestamp or password because it sounds random, but cryptographic keys require a truly random source like a hardware RNG.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hardware random number generator

A hardware random number generator (HRNG) uses a physical entropy source (e.g., thermal noise, quantum effects) to produce truly random numbers, making it the most appropriate for generating cryptographic keys. Cryptographic keys require high entropy and unpredictability; HRNGs provide true randomness, unlike deterministic PRNGs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hardware random number generator

    Why this is correct

    A hardware random number generator derives entropy from physical phenomena, producing non-deterministic output. Software generators are deterministic algorithms, so only a hardware source satisfies the requirement for a truly random seed for cryptographic key generation.

  • ✗

    Cryptographically secure PRNG seeded with a static password

    Why it's wrong here

    A static password seed makes output reproducible, so an attacker who learns the password regenerates every key; true randomness requires an entropy source such as a hardware RNG. It tempts because CSPRNGs are cryptographically strong, and would be correct where a securely stored, high-entropy seed is available and determinism is required.

  • ✗

    Pseudorandom number generator (PRNG) seeded with current timestamp

    Why it's wrong here

    A timestamp seed is predictable and low-entropy, so keys can be brute-forced by enumerating plausible generation times; true randomness needs a hardware entropy source. It tempts because PRNGs are fast and convenient for bulk key generation, and would be correct only when seeded from a genuinely unpredictable source.

  • ✗

    User-memorized passphrase

    Why it's wrong here

    Human-chosen passphrases carry dictionary and pattern bias, giving far less entropy than a hardware random source, so derived keys are guessable. It tempts because passphrases are memorable and usable for key derivation, and would be correct for protecting a keystore or deriving keys via a slow KDF, not for true randomness.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.