Courseiva
Cryptography →mediumMultiple Select

SSCP Cryptography Practice Question

An organization wants to implement a hashing algorithm for integrity checks. Which of the following should be avoided due to known vulnerabilities? (Select TWO)

⚠ Common exam trap

It's easy for candidates to assume SHA-1 is still acceptable because it was once widely used, but the SSCP exam expects you to know that both MD5 and SHA-1 are broken for collision resistance and should be avoided.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MD5

MD5 (C) must be avoided because it is cryptographically broken: practical collision attacks (e.g., the 2004 Wang attacks and later chosen-prefix collisions) allow two different inputs to produce the same 128-bit digest, so it cannot reliably detect malicious modification. SHA-1 (E) must also be avoided because collision attacks are practical (the 2017 SHAttered attack produced two colliding PDFs), making its 160-bit digest unsuitable for integrity checks against adversaries. SHA-3 (A) and SHA-256 (B) are unmarked because they are current, collision-resistant hash functions from the SHA-2/SHA-3 families and are appropriate for integrity verification. HMAC-SHA256 (D) is unmarked because it is a keyed MAC built on SHA-256 that provides both integrity and authenticity and has no known practical breaks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SHA-3

    Why it's wrong here

    SHA-3 is the newest NIST standard, using the Keccak sponge construction, and has no known practical vulnerabilities. It is tempting to avoid because it is less widely deployed than SHA-2, but deployment maturity is not a cryptographic weakness. SHA-3 is correct when a modern, secure hash is required; MD5 and SHA-1 are the flawed choices.

  • ✗

    SHA-256

    Why it's wrong here

    SHA-256 is a current, collision-resistant member of the SHA-2 family and is recommended for integrity checks. It is tempting to avoid because it is older than SHA-3, but age is not a vulnerability. SHA-256 is correct when a widely supported, secure hash is required; the flawed options are MD5 and SHA-1.

  • ✓

    MD5

    Why this is correct

    MD5 produces 128-bit digests with practical collision attacks demonstrated, so it cannot assure integrity. Its weakness against chosen-prefix collisions directly satisfies the stem's criterion of an algorithm to avoid for integrity checks due to known vulnerabilities.

  • ✗

    HMAC-SHA256

    Why it's wrong here

    HMAC-SHA256 combines SHA-256 with a secret key to provide integrity and authenticity, and remains secure. It is tempting to avoid because it shares SHA-256's name, but HMAC strengthens rather than weakens it. HMAC-SHA256 is correct when message authentication is required; MD5 and SHA-1 are the vulnerable algorithms to avoid.

  • ✓

    SHA-1

    Why this is correct

    SHA-1 generates 160-bit digests and is vulnerable to collision attacks, demonstrated by the SHAttered effort, making it unsuitable for integrity verification. This known cryptographic weakness satisfies the stem's requirement to identify an algorithm to avoid.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.