SSCP Cryptography Practice Question
An analyst is comparing symmetric and asymmetric encryption. Which statement accurately describes a typical use case?
⚠ Common exam trap
A common pitfall in this context is the misconception that symmetric encryption is used for key exchange or that asymmetric encryption is faster for bulk data. In reality, asymmetric encryption is slow and reserved for secure key exchange, while symmetric encryption is fast and used for bulk data encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Asymmetric encryption is used to securely exchange a symmetric key.
Asymmetric encryption (e.g., RSA, ECDH) is computationally expensive and slow, making it unsuitable for bulk data encryption. Instead, it is commonly used to securely exchange a symmetric session key (e.g., an AES key) over an insecure channel. Once both parties have the symmetric key, they can switch to symmetric encryption (e.g., AES-GCM) for efficient bulk data encryption. This hybrid approach combines the secure key distribution of asymmetric encryption with the speed of symmetric encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Symmetric encryption is used for key exchange over insecure channels.
Why it's wrong here
Key exchange over insecure channels relies on asymmetric cryptography, such as Diffie-Hellman or RSA-wrapped keys, since symmetric keys cannot be shared safely without a prior secure channel. Symmetric ciphers suit bulk data once a shared secret already exists.
- ✓
Asymmetric encryption is used to securely exchange a symmetric key.
Why this is correct
Asymmetric encryption, using public and private key pairs, is slower but solves key distribution; it typically encrypts a randomly generated symmetric session key, which then protects bulk data. This hybrid approach combines asymmetric key exchange with symmetric throughput.
- ✗
Symmetric encryption is used to sign documents to provide non-repudiation.
Why it's wrong here
Non-repudiation requires a private key held by one party, so signing uses asymmetric cryptography, not symmetric. Symmetric encryption is tempting because it can produce a MAC, but that only proves shared-secret knowledge, not unique origin.
- ✗
Asymmetric encryption is used for bulk data encryption because it is faster.
Why it's wrong here
Asymmetric encryption is computationally slow and is used to protect small payloads such as keys or signatures; bulk data is encrypted with symmetric ciphers. The speed claim inverts the actual performance relationship between the two families.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.