SSCP Cryptography Practice Question
An organization wants to implement a hashing algorithm for integrity checks. Which of the following should be avoided due to known vulnerabilities? (Select TWO)
⚠ Common exam trap
It's easy for candidates to assume SHA-1 is still acceptable because it was once widely used, but the SSCP exam expects you to know that both MD5 and SHA-1 are broken for collision resistance and should be avoided.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MD5
MD5 (C) must be avoided because it is cryptographically broken: practical collision attacks (e.g., the 2004 Wang attacks and later chosen-prefix collisions) allow two different inputs to produce the same 128-bit digest, so it cannot reliably detect malicious modification. SHA-1 (E) must also be avoided because collision attacks are practical (the 2017 SHAttered attack produced two colliding PDFs), making its 160-bit digest unsuitable for integrity checks against adversaries. SHA-3 (A) and SHA-256 (B) are unmarked because they are current, collision-resistant hash functions from the SHA-2/SHA-3 families and are appropriate for integrity verification. HMAC-SHA256 (D) is unmarked because it is a keyed MAC built on SHA-256 that provides both integrity and authenticity and has no known practical breaks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SHA-3
Why it's wrong here
SHA-3 is the newest NIST standard, using the Keccak sponge construction, and has no known practical vulnerabilities. It is tempting to avoid because it is less widely deployed than SHA-2, but deployment maturity is not a cryptographic weakness. SHA-3 is correct when a modern, secure hash is required; MD5 and SHA-1 are the flawed choices.
- ✗
SHA-256
Why it's wrong here
SHA-256 is a current, collision-resistant member of the SHA-2 family and is recommended for integrity checks. It is tempting to avoid because it is older than SHA-3, but age is not a vulnerability. SHA-256 is correct when a widely supported, secure hash is required; the flawed options are MD5 and SHA-1.
- ✓
MD5
Why this is correct
MD5 produces 128-bit digests with practical collision attacks demonstrated, so it cannot assure integrity. Its weakness against chosen-prefix collisions directly satisfies the stem's criterion of an algorithm to avoid for integrity checks due to known vulnerabilities.
- ✗
HMAC-SHA256
Why it's wrong here
HMAC-SHA256 combines SHA-256 with a secret key to provide integrity and authenticity, and remains secure. It is tempting to avoid because it shares SHA-256's name, but HMAC strengthens rather than weakens it. HMAC-SHA256 is correct when message authentication is required; MD5 and SHA-1 are the vulnerable algorithms to avoid.
- ✓
SHA-1
Why this is correct
SHA-1 generates 160-bit digests and is vulnerable to collision attacks, demonstrated by the SHAttered effort, making it unsuitable for integrity verification. This known cryptographic weakness satisfies the stem's requirement to identify an algorithm to avoid.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.