SSCP Cryptography Practice Question
An organization is designing a secure email system using S/MIME. Which of the following are essential components of the PKI that must be in place? (Select THREE)
⚠ Common exam trap
In the SSCP exam, candidates often mistakenly select a KDC or TSA as essential for S/MIME, but these are auxiliary services, not core PKI components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
X.509 digital certificates for each user
Option B is correct because S/MIME binds each user's public key to their identity through an X.509 digital certificate, which is required for encrypting messages and verifying digital signatures. Option C is correct because the PKI must provide a way to check certificate revocation status, typically via CRL or OCSP, so recipients can reject messages signed with compromised or expired certificates. Option E is correct because a certificate authority (CA) is needed to issue and digitally sign the X.509 certificates that S/MIME relies on for trust. Option A is not correct because a symmetric key distribution center (KDC) is associated with Kerberos-style symmetric key management, not with S/MIME's certificate-based public key infrastructure. Option D is not correct because a timestamp authority (TSA) supports trusted time-stamping for non-repudiation and is not an essential PKI component for basic S/MIME encryption and signing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A symmetric key distribution center (KDC)
Why it's wrong here
S/MIME relies on X.509 certificates and a certification authority; a symmetric KDC belongs to Kerberos, which distributes session keys rather than issuing public key certificates. It is tempting because Kerberos underpins authentication in many directories, but S/MIME encryption and signing require asymmetric key pairs.
- ✓
X.509 digital certificates for each user
Why this is correct
S/MIME binds each user's public key to their email identity through an X.509 certificate, satisfying the PKI requirement for verified sender and recipient identities. Without per-user certificates, signing and encryption cannot be tied to a trusted identity.
- ✓
A method to check certificate revocation (e.g., CRL or OCSP)
Why this is correct
Revocation checking via CRL or OCSP lets recipients verify that a sender's certificate has not been revoked before trusting a signature or encrypting to it. This satisfies the PKI requirement for timely invalidation of compromised or expired credentials.
- ✗
A timestamp authority (TSA)
Why it's wrong here
A TSA proves when a signature was created, supporting long-term non-repudiation, but S/MIME signing and encryption operate without one. It is tempting because timestamping strengthens evidence in legal disputes, yet the essential PKI components are the certification authority, registration authority and certificate repository.
- ✓
A certificate authority (CA) to sign certificates
Why this is correct
S/MIME relies on X.509 certificates to bind public keys to email identities, so a CA must issue and sign those certificates. Without a trusted CA, recipients cannot validate sender certificates or build a chain of trust, breaking the PKI requirement the scenario demands.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.