Courseiva

SSCP · domain

Cryptography

Practise Systems Security Certified Practitioner SSCP Cryptography practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

36 questions7 easy19 medium10 hard

Focused practice

Practice Cryptography questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cryptography

Cryptography questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Cryptography exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Cryptography questions (36)

Click any question to see the full explanation, or start a practice session above.

1

A security team is implementing a PKI for a large enterprise. Which TWO of the following are commonly used methods for certificate revocation checking? (Select TWO.)

Medium
2

A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?

Medium
3

An organization is migrating from 3DES to AES-256 for encrypting data at rest. Which mode of AES is recommended for authenticated encryption?

Medium
4

Which of the following protocols is used to securely transfer files over SSH and is considered a replacement for FTP?

Medium
5

An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?

Medium
6

A certificate authority (CA) issues a certificate with the extended key usage (EKU) extension specifying 'serverAuth'. Which of the following is this certificate allowed to do?

Hard
7

An organization wants to implement a key exchange mechanism that provides forward secrecy. Which of the following should be used?

Medium
8

An organization is configuring a VPN using IPsec. To ensure forward secrecy, which key exchange method should be used?

Hard
9

Which of the following is a method to check the revocation status of a digital certificate in real-time without the client downloading a full list?

Easy
10

A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)

Medium
11

Which of the following best describes the difference between HMAC and a simple hash function like SHA-256 when used for message authentication?

Hard
12

A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?

Medium
13

An organization is moving away from legacy encryption and wants to avoid stream ciphers due to known vulnerabilities. Which of the following algorithms should be avoided because it is a stream cipher with known weaknesses like the BEAST attack?

Medium
14

A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?

Medium
15

In X.509 certificate format, which field is used to specify the fully qualified domain name(s) for which the certificate is valid?

Medium
16

An organization is designing a secure email system using S/MIME. Which of the following are essential components of the PKI that must be in place? (Select THREE)

Hard
17

A security analyst is reviewing a digital signature implementation. The signer uses their private key to encrypt the hash of a message. What does the recipient use to verify the signature?

Medium
18

A security auditor reviews a system that uses HMAC-SHA256 for message authentication. Which property does HMAC provide that a simple hash of the message does not?

Hard
19

Which of the following best describes the purpose of a Hardware Security Module (HSM) in key management?

Medium
20

Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?

Easy
21

A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?

Medium
22

A security administrator is setting up a public key infrastructure (PKI) for internal use. Which two of the following components are essential for establishing a chain of trust from the root CA to end-entity certificates?

Easy
23

A PKI administrator needs to check the revocation status of a digital certificate without requiring the client to download the entire CRL. Which method is designed for online, real-time certificate status checking?

Hard
24

A company wants to implement a key management system. They need to generate cryptographic keys that are unpredictable. Which source of randomness should be used?

Medium
25

A security analyst is evaluating encryption modes for a new system that requires authenticated encryption to ensure both confidentiality and integrity of data in transit. Which AES mode should the analyst recommend?

Medium
26

Which of the following is a secure hash algorithm currently recommended by NIST?

Easy
27

A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?

Hard
28

A company is upgrading its legacy systems to use modern cryptographic standards. Which two of the following algorithms should be avoided due to known weaknesses or deprecation?

Medium
29

Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?

Easy
30

Which TWO of the following are considered secure cryptographic hash functions as of current standards? (Select TWO.)

Easy
31

A company is selecting a cryptographic algorithm for digital signatures. Which THREE of the following algorithms can be used for digital signatures? (Select THREE.)

Hard
32

A security administrator is configuring a web server to use TLS. They want to optimize performance while maintaining strong security. Which cipher suite should they prioritize?

Hard
33

A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?

Hard
34

An organization is implementing a digital signature solution to ensure non-repudiation and integrity of documents. Which three of the following are true regarding digital signatures?

Medium
35

An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?

Medium
36

A security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?

Easy

Frequently asked questions

What does the Cryptography domain cover on the SSCP exam?
Cryptography questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 36 Cryptography questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cryptography questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp cryptography Practice Questions