Courseiva

SSCP · domain

Cryptography

Cryptography is 9% of the SSCP exam, covering symmetric and asymmetric encryption, hashing, PKI, digital certificates, and secure protocols. Questions are scenario-based: you pick the right algorithm, mode, or protocol for a stated goal such as confidentiality, integrity, authentication, or nonrepudiation, and you distinguish closely related technologies.

65 questions14 easy30 medium21 hard

Focused practice

Practice Cryptography questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cryptography

Be able to match a security goal to the correct cryptographic tool: symmetric or asymmetric encryption for confidentiality, hashing or HMAC for integrity, and PKI services such as OCSP for certificate status. The key skill is selecting the right algorithm, mode, or protocol for the scenario.

Symmetric algorithms (AES, 3DES) versus asymmetric algorithms (RSA, ECC) and when each applies

Hashing (SHA-2, SHA-3) for integrity and HMAC for authenticated integrity checks

PKI components: CA, RA, CRL, OCSP, and certificate lifecycle and validation

Secure transport and email protocols: TLS, IPsec, S/MIME, PGP, SFTP, and SSH

Watch out for

Common Cryptography exam traps

  • ▸Confusing encryption with hashing: hashing provides integrity, not confidentiality, and is not reversible.
  • ▸Assuming a CRL is required to check revocation when OCSP provides online, real-time status without the full list.
  • ▸Mixing up encryption modes, such as choosing CBC or ECB when authenticated encryption like GCM is required.

Question index

All Cryptography questions (65)

Click any question to see the full explanation, or start a practice session above.

1

A security team is implementing a PKI for a large enterprise. Which TWO of the following are commonly used methods for certificate revocation checking? (Select TWO.)

Medium
2

A security analyst is reviewing a proposed solution that uses a stream cipher to encrypt real-time voice traffic. Which property of stream ciphers makes them well suited for this scenario?

Easy
3

A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?

Medium
4

An organization is migrating from 3DES to AES-256 for encrypting data at rest. Which mode of AES is recommended for authenticated encryption?

Medium
5

A security administrator is configuring a VPN gateway that must support perfect forward secrecy for IPsec connections. Which key establishment method should be enabled to ensure that compromise of a long-term key does not expose previously established session keys?

Medium
6

Which of the following protocols is used to securely transfer files over SSH and is considered a replacement for FTP?

Medium
7

An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?

Medium
8

A certificate authority (CA) issues a certificate with the extended key usage (EKU) extension specifying 'serverAuth'. Which of the following is this certificate allowed to do?

Hard
9

An organization wants to implement a key exchange mechanism that provides forward secrecy. Which of the following should be used?

Medium
10

An organization is configuring a VPN using IPsec. To ensure forward secrecy, which key exchange method should be used?

Hard
11

Which of the following is a method to check the revocation status of a digital certificate in real-time without the client downloading a full list?

Easy
12

A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)

Medium
13

An organization is planning to implement ECC for digital signatures. Which key size provides a security level equivalent to a 3072-bit RSA key?

Hard
14

Which of the following best describes the difference between HMAC and a simple hash function like SHA-256 when used for message authentication?

Hard
15

Which of the following are considered secure cryptographic practices for key management? (Select THREE)

Hard
16

A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?

Medium
17

A security engineer is implementing a digital signature scheme to ensure non-repudiation. Which process correctly describes how a digital signature is created and verified?

Hard
18

A financial institution is deploying a hardware security module (HSM) to protect cryptographic keys used for payment transactions. The security team must ensure that the HSM provides strong logical and physical protection. Which two of the following characteristics are MOST important to validate when selecting the HSM? (Choose two.)

Hard
19

A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?

Medium
20

In X.509 certificate format, which field is used to specify the fully qualified domain name(s) for which the certificate is valid?

Medium
21

An organization is designing a secure email system using S/MIME. Which of the following are essential components of the PKI that must be in place? (Select THREE)

Hard
22

A security analyst is reviewing a digital signature implementation. The signer uses their private key to encrypt the hash of a message. What does the recipient use to verify the signature?

Medium
23

A security auditor reviews a system that uses HMAC-SHA256 for message authentication. Which property does HMAC provide that a simple hash of the message does not?

Hard
24

An organization wants to implement a hashing algorithm for integrity checks. Which of the following should be avoided due to known vulnerabilities? (Select TWO)

Medium
25

Which of the following best describes the purpose of a Hardware Security Module (HSM) in key management?

Medium
26

Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?

Easy
27

A security administrator is configuring a web server to use TLS 1.3. The administrator wants to ensure that the server supports forward secrecy for all connections. Which of the following key exchange mechanisms should be used?

Easy
28

What is the minimum recommended RSA key size for secure use as of current best practices?

Easy
29

Which of the following is a cryptographic hash function that is considered cryptographically broken due to collision attacks and should not be used for security purposes?

Medium
30

A company is deploying a hardware security module (HSM) to protect the root keys of its certificate authority. Which two practices are essential for maintaining the security of the CA's private keys? (Choose two.)

Hard
31

In a PKI, what is the role of the root Certificate Authority (CA)?

Medium
32

A healthcare provider must protect the confidentiality of patient records stored on a shared network drive. The compliance officer mandates that the encryption solution use a symmetric algorithm with a 256-bit key and operate as a block cipher. Which of the following should the security administrator select to meet these requirements?

Medium
33

A financial institution is implementing a digital signature solution to ensure the integrity and authenticity of wire transfer instructions. The solution must provide non-repudiation and use a NIST-approved algorithm. Which of the following should the security architect select?

Hard
34

A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?

Medium
35

An analyst is comparing symmetric and asymmetric encryption. Which statement accurately describes a typical use case?

Hard
36

A security engineer is configuring a TLS 1.3 server for an e-commerce site. The engineer wants to ensure that the cipher suite provides both confidentiality and integrity for application data. Which of the following cipher suites should the engineer select?

Hard
37

A security administrator is setting up a public key infrastructure (PKI) for internal use. Which two of the following components are essential for establishing a chain of trust from the root CA to end-entity certificates?

Easy
38

A software vendor distributes patches over the internet. Customers must be able to verify that a patch came from the vendor and was not altered in transit. The vendor wants to use a digital signature. Which key should the vendor use to create the signature?

Hard
39

A PKI administrator needs to check the revocation status of a digital certificate without requiring the client to download the entire CRL. Which method is designed for online, real-time certificate status checking?

Hard
40

A company wants to implement a key management system. They need to generate cryptographic keys that are unpredictable. Which source of randomness should be used?

Medium
41

Which of the following encryption algorithms is classified as a symmetric block cipher and is the current standard recommended by NIST, supporting key sizes of 128, 192, and 256 bits?

Easy
42

A healthcare company must store backup tapes offsite for seven years. The tapes contain patient records, and the company wants a symmetric encryption algorithm that is fast, widely supported, and approved by NIST for protecting data at rest. Which algorithm best meets these requirements?

Medium
43

A security analyst is reviewing the cryptographic controls for a new messaging application. The application must ensure that messages are encrypted in transit and that the sender cannot later deny having sent a message. Which two of the following cryptographic mechanisms should be implemented to meet these requirements? (Choose two.)

Medium
44

A financial services company is deploying a new VPN concentrator that must support perfect forward secrecy (PFS) for all client sessions. The security team is configuring the IPsec phase 2 (Quick Mode) proposals. Which of the following should be configured to achieve PFS?

Medium
45

A security analyst is evaluating encryption modes for a new system that requires authenticated encryption to ensure both confidentiality and integrity of data in transit. Which AES mode should the analyst recommend?

Medium
46

Which of the following is a secure hash algorithm currently recommended by NIST?

Easy
47

A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?

Hard
48

A company is upgrading its legacy systems to use modern cryptographic standards. Which two of the following algorithms should be avoided due to known weaknesses or deprecation?

Medium
49

Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?

Easy
50

A security administrator needs to verify the integrity and authenticity of a downloaded software package. The vendor provides a separate file containing a cryptographic hash of the package, but the hash file itself is not signed. Which action BEST mitigates the risk of a modified package being accepted?

Easy
51

Which TWO of the following are considered secure cryptographic hash functions as of current standards? (Select TWO.)

Easy
52

A company is selecting a cryptographic algorithm for digital signatures. Which THREE of the following algorithms can be used for digital signatures? (Select THREE.)

Hard
53

A company is deploying a VPN that uses IPsec in tunnel mode. The security engineer must choose a key exchange method that provides perfect forward secrecy (PFS) so that compromise of a long-term key does not expose past session keys. Which configuration should the engineer select?

Medium
54

A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?

Hard
55

A company deploys a VPN gateway that uses Diffie-Hellman key exchange to establish session keys. A security auditor warns that the gateway is vulnerable to a man-in-the-middle attack during key agreement. Which of the following should the administrator implement to mitigate this risk?

Hard
56

Which of the following is a secure alternative to RC4 for stream ciphers?

Easy
57

A security administrator is configuring a new wireless network that must use a protocol providing strong encryption and mutual authentication. The organization requires that the solution support AES-CCMP and be based on the IEEE 802.11i standard. Which protocol should the administrator implement?

Medium
58

An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?

Medium
59

A security engineer is implementing a cryptographic system that requires both confidentiality and integrity. The engineer decides to use AES-256 in Galois/Counter Mode (GCM). Which of the following statements about GCM is true?

Hard
60

A security analyst is reviewing a proposed cryptographic design for a new messaging application. The design uses AES-256 in Galois/Counter Mode (GCM) for confidentiality and integrity, but the analyst notices that the same nonce is generated for multiple messages under the same key. What is the MOST likely security consequence of this flaw?

Hard
61

Which protocol is used to provide secure remote shell access and replace Telnet?

Easy
62

A security administrator is evaluating encryption protocols for email communication. Which of the following protocols can secure email in transit? (Select TWO)

Medium
63

A security engineer is designing a system that requires non-repudiation of data origin. Which cryptographic technique should be used?

Medium
64

A security engineer is deploying a new VPN concentrator that must use a symmetric encryption algorithm approved by NIST for protecting sensitive government data. The algorithm must operate as a block cipher with a 128-bit block size and support key sizes of 128, 192, and 256 bits. Which algorithm should the engineer select?

Medium
65

A security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?

Easy

Frequently asked questions

What does the Cryptography domain cover on the SSCP exam?
Be able to match a security goal to the correct cryptographic tool: symmetric or asymmetric encryption for confidentiality, hashing or HMAC for integrity, and PKI services such as OCSP for certificate status. The key skill is selecting the right algorithm, mode, or protocol for the scenario.
How many questions are in this domain?
This page lists all 65 Cryptography questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cryptography questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp cryptography Practice Questions