Courseiva

CCNA Cryptography Questions

65 questions · Cryptography · All types, answers revealed

1
Multi-Selectmedium

A security team is implementing a PKI for a large enterprise. Which TWO of the following are commonly used methods for certificate revocation checking? (Select TWO.)

Select 2 answers
A.Certificate Signing Request (CSR)
B.Online Certificate Status Protocol (OCSP)
C.Certificate Revocation List (CRL)
D.Key Escrow
E.Digital Signature Algorithm (DSA)
AnswersB, C

OCSP queries a responder for the real-time revocation status of a specific certificate, returning good, revoked or unknown. This satisfies the enterprise PKI requirement for a commonly used revocation checking method, offering lower latency than downloading a full list.

Why this answer

Option B, Online Certificate Status Protocol (OCSP), is correct because it is a standard protocol defined in RFC 6960 that allows a client to query a dedicated OCSP responder in real time to determine whether a specific certificate has been revoked, returning a status of good, revoked, or unknown. Option C, Certificate Revocation List (CRL), is correct because it is a signed list published by the Certificate Authority (typically distributed via HTTP, LDAP, or FTP at the CDP extension URL) that enumerates the serial numbers of certificates that have been revoked before their expiration date. The remaining options are not revocation-checking methods: a Certificate Signing Request (A) is a message sent to a CA to request issuance of a certificate, Key Escrow (D) is the practice of storing private keys with a third party for recovery purposes, and the Digital Signature Algorithm (E) is a signing algorithm used to create and verify digital signatures, not to check revocation status.

Exam trap

The trap is confusing certificate lifecycle elements like CSR or key escrow with revocation checking mechanisms, or picking cryptographic algorithms like DSA that are unrelated to revocation.

2
MCQeasy

A security analyst is reviewing a proposed solution that uses a stream cipher to encrypt real-time voice traffic. Which property of stream ciphers makes them well suited for this scenario?

A.They require a unique public/private key pair for every call.
B.They encrypt data one bit or byte at a time, avoiding the need to pad to a block boundary.
C.They provide built-in non-repudiation for each voice packet.
D.They automatically compress voice data before encryption.
AnswerB

Stream ciphers generate a keystream and combine it with plaintext one unit at a time, so they do not require padding and can handle continuous data streams. This is advantageous for real-time voice, where traffic is generated continuously and buffering to fill a block could introduce latency. The absence of padding also avoids ciphertext expansion.

Why this answer

Stream ciphers operate on small units of data, such as bits or bytes, and do not require padding to a block boundary. This makes them efficient for continuous, low-latency traffic like real-time voice, where waiting for a full block would add delay. They are symmetric and provide confidentiality only, so properties such as non-repudiation, per-call key pairs, and compression are not inherent to them.

Exam trap

The trap here is attributing asymmetric or compression features to stream ciphers, or overlooking that their main advantage for voice is low latency and no padding.

3
MCQmedium

A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?

A.Pre-shared key (PSK)
B.RSA key exchange
C.Ephemeral Diffie-Hellman (DHE or ECDHE)
D.Diffie-Hellman with static keys
AnswerC

Ephemeral Diffie-Hellman generates a fresh key pair per session, so the derived shared secret is never transmitted and cannot be recovered from the server's long-term private key. This satisfies the forward secrecy constraint: compromise of that key leaves previously negotiated session keys underivable.

Why this answer

Ephemeral Diffie-Hellman (DHE or ECDHE) provides perfect forward secrecy (PFS) because it generates a unique, temporary session key for each session using ephemeral key pairs. Even if the server's long-term private key is compromised, past session keys cannot be derived because they were created from ephemeral keys that are discarded after each session. This ensures that historical encrypted traffic remains secure.

Exam trap

The trap here is that candidates confuse authentication with key exchange, assuming that RSA or static DH provides PFS because they involve public-key cryptography, but only ephemeral DH ensures that session keys are not derived from long-term secrets.

How to eliminate wrong answers

Option A is wrong because pre-shared keys (PSK) are static and do not provide PFS; if the PSK is compromised, all past session keys can be derived. Option B is wrong because RSA key exchange uses the server's static private key to encrypt the session key, so compromising that private key allows decryption of all past session keys. Option D is wrong because Diffie-Hellman with static keys uses long-term Diffie-Hellman keys that do not change per session, so compromising the static private key enables recovery of all past session keys.

4
MCQmedium

An organization is migrating from 3DES to AES-256 for encrypting data at rest. Which mode of AES is recommended for authenticated encryption?

A.ECB
B.GCM
C.CBC
D.CTR
AnswerB

GCM provides authenticated encryption with associated data, combining AES-CTR confidentiality with a GHASH authentication tag in one pass. This satisfies the stem's requirement for authenticated encryption, unlike CBC or ECB, which supply confidentiality only and need a separate MAC.

Why this answer

GCM (Galois/Counter Mode) is the correct choice because it provides both confidentiality and authenticity in a single, efficient mode. For data at rest, authenticated encryption ensures that encrypted data cannot be tampered with undetected, which is critical for integrity. AES-256-GCM is widely recommended and standardized (NIST SP 800-38D) for this purpose.

Exam trap

ISC2 SSCP often tests the misconception that any mode providing confidentiality (like CBC or CTR) is sufficient for secure encryption, but the trap here is that authenticated encryption specifically requires a mode that also guarantees integrity, which only GCM (or CCM) provides among the listed options.

How to eliminate wrong answers

Option A is wrong because ECB (Electronic Codebook) mode encrypts each block independently, producing identical ciphertext for identical plaintext blocks, which leaks patterns and provides no authentication. Option C is wrong because CBC (Cipher Block Chaining) mode provides only confidentiality, not authentication; it requires a separate MAC (e.g., HMAC) to achieve authenticated encryption, and it is vulnerable to padding oracle attacks if not implemented carefully. Option D is wrong because CTR (Counter) mode provides only confidentiality and no integrity protection; it is a stream cipher mode that can be combined with a MAC but does not itself offer authenticated encryption.

5
MCQmedium

A security administrator is configuring a VPN gateway that must support perfect forward secrecy for IPsec connections. Which key establishment method should be enabled to ensure that compromise of a long-term key does not expose previously established session keys?

A.RSA key transport with the gateway's static RSA key pair
B.Pre-shared key authentication with a static PSK
C.HMAC-SHA-256 for integrity protection of IKE messages
D.Internet Key Exchange with ephemeral Diffie-Hellman (DHE)
AnswerD

Ephemeral Diffie-Hellman generates a fresh key pair for each session and discards it afterward, so compromise of the long-term authentication key does not reveal past session keys. This property is exactly what perfect forward secrecy requires. Enabling DHE in IKE allows the VPN gateway to derive unique session keys per connection, protecting previously recorded traffic.

Why this answer

Perfect forward secrecy requires that session keys cannot be recovered from a long-term secret. Ephemeral Diffie-Hellman achieves this by generating temporary key pairs for each session and deleting them after use. Static PSK and static RSA key transport reuse long-term secrets, so compromise of those secrets can expose past sessions.

HMAC provides integrity, not key establishment, and is therefore not the correct control.

Exam trap

The trap here is assuming that any strong authentication method, such as a PSK or RSA key transport, automatically provides perfect forward secrecy.

6
MCQmedium

Which of the following protocols is used to securely transfer files over SSH and is considered a replacement for FTP?

A.IPsec
B.HTTPS
C.SFTP
D.SMTPS
AnswerC

SFTP tunnels file transfers through SSH on port 22, encrypting both commands and data in a single connection. This satisfies the stem's requirement for a secure FTP replacement, unlike FTPS, which wraps standard FTP in TLS across separate control and data channels. SFTP's SSH foundation delivers the confidentiality and integrity the scenario demands.

Why this answer

SFTP (SSH File Transfer Protocol) is the protocol that runs over SSH to securely transfer files and is widely regarded as the secure replacement for FTP. It encrypts both commands and data within a single SSH connection, typically on port 22. HTTPS, IPsec, and SMTPS serve different purposes and are not FTP replacements over SSH.

Exam trap

SSCP often tests the confusion between SFTP, FTPS, and SCP — candidates see 'secure FTP' and pick FTPS or SCP, missing that the question specifies 'over SSH' and 'replacement for FTP,' which is SFTP.

How to eliminate wrong answers

Option A is wrong because IPsec is a network-layer suite for securing IP packets (VPNs), not a file transfer protocol. Option B is wrong because HTTPS secures web traffic over TLS, not a file transfer replacement for FTP over SSH. Option D is wrong because SMTPS is SMTP over TLS for sending email, not file transfer.

7
MCQmedium

An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?

A.Recipient's public key to sign, recipient's private key to verify
B.Sender's private key to sign, sender's public key to verify
C.Sender's public key to sign, recipient's private key to verify
D.A shared symmetric key for both signing and verification
AnswerB

Non-repudiation requires the signer to use their private key, which only they hold, and verifiers to use the corresponding public key. This asymmetric pairing proves origin and prevents the sender denying authorship of the signed document.

Why this answer

Digital signatures use asymmetric cryptography where the sender creates a signature with their private key, and the recipient verifies it with the sender's public key. This ensures non-repudiation because only the sender possesses their private key, so they cannot deny having signed the document. The process typically involves hashing the document and encrypting the hash with the sender's private key.

Exam trap

ISC2 SSCP often tests the misconception that signing uses a public key or that verification uses a private key, leading candidates to confuse the roles of keys in encryption versus signing.

How to eliminate wrong answers

Option A is wrong because the recipient's public key is used for encrypting messages to the recipient, not for signing; signing requires the sender's private key, and verification uses the sender's public key, not the recipient's private key. Option C is wrong because the sender's public key cannot sign (signing requires a private key), and the recipient's private key is never used for verification of a sender's signature. Option D is wrong because symmetric keys do not provide non-repudiation; they are shared secrets and cannot uniquely tie a signature to a single sender, as both parties possess the same key.

8
MCQhard

A certificate authority (CA) issues a certificate with the extended key usage (EKU) extension specifying 'serverAuth'. Which of the following is this certificate allowed to do?

A.Encrypt email
B.Authenticate a TLS server
C.Sign code
D.Issue subordinate CA certificates
AnswerB

The serverAuth EKU value permits the certificate's public key to authenticate a TLS server during the handshake, proving the server's identity to clients. This satisfies the stem's specified extension, restricting usage to server authentication rather than clientAuth, code signing or email protection.

Why this answer

The Extended Key Usage (EKU) extension specifies the intended purpose of a certificate. The 'serverAuth' OID (1.3.6.1.5.5.7.3.1) explicitly permits the certificate to be used for authenticating a TLS server during the SSL/TLS handshake, such as in HTTPS. This is defined in RFC 5280 and is enforced by TLS clients to ensure the certificate is used only for its designated purpose.

Exam trap

A common pitfall is assuming that a certificate with 'serverAuth' can also be used for client authentication or other purposes, but the EKU extension strictly limits usage. Candidates often confuse 'serverAuth' with other EKUs like 'clientAuth' or 'emailProtection'.

How to eliminate wrong answers

Option A is wrong because encrypting email requires the 'emailProtection' EKU (1.3.6.1.5.5.7.3.4), not 'serverAuth'. Option C is wrong because signing code requires the 'codeSigning' EKU (1.3.6.1.5.5.7.3.3), which is a separate purpose. Option D is wrong because issuing subordinate CA certificates requires the 'keyCertSign' key usage extension and often the 'CA:TRUE' basic constraint, not the 'serverAuth' EKU; 'serverAuth' is for end-entity certificates, not for CA certificates.

9
MCQmedium

An organization wants to implement a key exchange mechanism that provides forward secrecy. Which of the following should be used?

A.Pre-shared key
B.Ephemeral Diffie-Hellman
C.RSA key exchange
D.Static Diffie-Hellman
AnswerB

Ephemeral Diffie-Hellman generates a fresh, temporary key pair for each session, so compromising a long-term private key cannot decrypt previously captured traffic. This property is forward secrecy, exactly the mechanism the organisation requires, whereas static Diffie-Hellman or RSA key transport reuse persistent keys and lack it.

Why this answer

Ephemeral Diffie-Hellman (DHE or ECDHE) generates a fresh key pair for each session, so even if the long-term private key is compromised later, past session keys cannot be derived. This property is forward secrecy. It is the standard mechanism used in TLS 1.3 and modern cipher suites (e.g., ECDHE-RSA-AES256-GCM-SHA384).

Exam trap

SSCP often tests the misconception that any Diffie-Hellman provides forward secrecy — candidates must distinguish ephemeral DH (fresh keys per session) from static DH (reused keys), and recognize that RSA key exchange lacks forward secrecy entirely.

How to eliminate wrong answers

Option A is wrong because a pre-shared key is a static secret shared in advance; compromise of the PSK compromises all past and future sessions, providing no forward secrecy. Option C is wrong because RSA key exchange encrypts the session key with the server's long-term RSA private key — if that key is later compromised, all recorded sessions can be decrypted, so no forward secrecy. Option D is wrong because static Diffie-Hellman reuses the same DH key pair across sessions, so compromise of the static private key compromises all sessions, again lacking forward secrecy.

10
MCQhard

An organization is configuring a VPN using IPsec. To ensure forward secrecy, which key exchange method should be used?

A.Ephemeral Diffie-Hellman (DHE or ECDHE)
B.RSA key exchange
C.Pre-shared key (PSK)
D.Static Diffie-Hellman
AnswerA

Ephemeral Diffie-Hellman generates a fresh, single-use key pair for each session, then discards it. Compromise of one session key therefore cannot expose past or future traffic, satisfying the forward secrecy requirement. Static Diffie-Hellman or pre-shared keys reuse the same secret, so they cannot provide this property.

Why this answer

Ephemeral Diffie-Hellman (DHE or ECDHE) provides forward secrecy because it generates a temporary, one-time key pair for each session. If the long-term private key is compromised, past session keys cannot be derived, as the ephemeral keys are discarded after use. This ensures that even if an attacker records encrypted traffic and later obtains the private key, they cannot decrypt past sessions.

Exam trap

The trap here is that candidates often confuse 'Diffie-Hellman' in general with forward secrecy, not realizing that only the ephemeral variant (DHE/ECDHE) provides it, while static Diffie-Hellman does not.

How to eliminate wrong answers

Option B (RSA key exchange) is wrong because RSA uses the server's static private key to encrypt the pre-master secret; if the private key is later compromised, all past session keys can be decrypted, providing no forward secrecy. Option C (Pre-shared key (PSK)) is wrong because PSK relies on a static shared secret that does not change per session; if the PSK is compromised, all past and future sessions can be decrypted. Option D (Static Diffie-Hellman) is wrong because it uses fixed, long-term Diffie-Hellman keys that do not change per session; compromise of the static private key allows an attacker to derive all past session keys, violating forward secrecy.

11
MCQeasy

Which of the following is a method to check the revocation status of a digital certificate in real-time without the client downloading a full list?

A.Certificate Revocation List (CRL)
B.Self-signed certificate validation
C.Online Certificate Status Protocol (OCSP)
D.Certificate Transparency (CT)
AnswerC

OCSP queries a responder directly about a single certificate's status, returning good, revoked or unknown in real time. Unlike a CRL, the client never downloads the full revocation list, which satisfies the requirement for immediate status checking without bulk list retrieval.

Why this answer

OCSP (Online Certificate Status Protocol) lets a client query a responder in real time for the revocation status of a specific certificate, returning 'good,' 'revoked,' or 'unknown' without downloading the entire CRL. It is defined in RFC 6960 and is the standard real-time alternative to CRLs. This matches the requirement exactly.

Exam trap

SSCP often tests the difference between CRL (batch, download-heavy) and OCSP (real-time, per-certificate) — candidates pick CRL because it's the more familiar revocation concept, missing the 'real-time without downloading a full list' qualifier.

How to eliminate wrong answers

Option A is wrong because a CRL is a full list of revoked certificates that the client must download and parse — the opposite of real-time, per-certificate checking. Option B is wrong because self-signed certificate validation is about trust anchors, not revocation status. Option D is wrong because Certificate Transparency is a logging framework for issuing certificates to detect mis-issuance; it does not provide real-time revocation status.

12
Multi-Selectmedium

A company is migrating from 3DES to a modern encryption algorithm. Which of the following are acceptable choices? (Select TWO)

Select 2 answers
A.DES
B.ChaCha20
C.AES
D.RC4
E.Blowfish
AnswersB, C

ChaCha20 is a modern stream cipher using a 256-bit key and 96-bit nonce, avoiding 3DES's small block size and short effective key. It provides strong confidentiality, particularly in software without AES hardware acceleration, making it an acceptable replacement.

Why this answer

Option B (ChaCha20) is correct because it is a modern, secure stream cipher standardized by the IETF in RFC 8439, offering strong 256-bit security and excellent performance in software without hardware acceleration. Option C (AES) is correct because it is the current NIST-approved symmetric block cipher, available in 128-, 192-, and 256-bit key sizes, and is the standard replacement for deprecated algorithms like 3DES. Option A (DES) is not acceptable because its 56-bit key is trivially brute-forced and it has been obsolete for decades.

Option D (RC4) is not acceptable because it is a broken stream cipher with well-known biases (e.g., in WEP/TLS) and is prohibited by RFC 7465. Option E (Blowfish) is not acceptable as a modern choice because its 64-bit block size makes it vulnerable to birthday attacks (e.g., SWEET32) and it has been superseded by Twofish/AES.

Exam trap

The trap is that Blowfish sounds modern and 'strong' to candidates who recall it as a successor to DES, but its 64-bit block size disqualifies it; the exam expects you to recognize AES and ChaCha20 as the two current standard symmetric ciphers.

13
MCQhard

An organization is planning to implement ECC for digital signatures. Which key size provides a security level equivalent to a 3072-bit RSA key?

A.192-bit ECC
B.256-bit ECC
C.1024-bit ECC
D.384-bit ECC
AnswerB

ECC delivers roughly half the key length of RSA for equivalent strength: a 256-bit ECC key matches 3072-bit RSA. This satisfies the stem's requirement for a 3072-bit RSA security equivalence, giving the same protection with far smaller keys and faster computation.

Why this answer

The National Institute of Standards and Technology (NIST) recommends that a 256-bit elliptic curve (e.g., P-256) provides a security strength of 128 bits, which is equivalent to a 3072-bit RSA key. This equivalence is based on the computational difficulty of the discrete logarithm problem in elliptic curve groups versus integer factorization, where ECC requires significantly smaller key sizes for the same security level.

Exam trap

The trap here is that candidates often confuse symmetric key equivalence (e.g., 256-bit ECC matches 128-bit symmetric) with RSA equivalence, or mistakenly think larger ECC keys (like 384-bit) are needed to match 3072-bit RSA, when in fact 256-bit ECC is the correct match per NIST guidelines.

How to eliminate wrong answers

Option A is wrong because a 192-bit ECC key provides only 96 bits of security strength, which is equivalent to a 2048-bit RSA key, not 3072-bit. Option C is wrong because 1024-bit ECC is not a standard key size; ECC key sizes are typically much smaller (e.g., 256-bit) and a 1024-bit ECC key would provide far more security than needed, but the question asks for the equivalent to 3072-bit RSA, which is 256-bit ECC. Option D is wrong because a 384-bit ECC key provides 192 bits of security strength, equivalent to a 7680-bit RSA key, which is stronger than required for 3072-bit RSA.

14
MCQhard

Which of the following best describes the difference between HMAC and a simple hash function like SHA-256 when used for message authentication?

A.HMAC is faster than SHA-256
B.SHA-256 produces a larger digest than HMAC
C.HMAC provides integrity and authentication; SHA-256 provides only integrity
D.HMAC is used for encryption, not hashing
AnswerC

HMAC applies a secret key within its construction, so verification proves both that the message was unaltered and that the sender held the key. A plain SHA-256 digest detects modification only, since anyone can recompute it without any shared secret.

Why this answer

HMAC incorporates a secret key into the hash process, providing authentication that a simple hash cannot.

15
Multi-Selecthard

Which of the following are considered secure cryptographic practices for key management? (Select THREE)

Select 3 answers
A.Storing keys in plaintext configuration files
B.Implementing regular key rotation
C.Using a Hardware Security Module (HSM) for key storage
D.Sharing keys over email for convenience
E.Securely destroying keys when no longer needed
AnswersB, C, E

Key rotation limits the impact of a key compromise.

Why this answer

Secure key management practices include: (B) implementing regular key rotation, which limits the amount of data protected by a single key and reduces the impact of a key compromise, consistent with guidance such as NIST SP 800-57; (C) using a Hardware Security Module (HSM) for key storage, since HSMs provide tamper-resistant hardware protection and keep keys out of general-purpose systems; and (E) securely destroying keys when they are no longer needed, so that retired or compromised keys cannot be recovered and misused. In contrast, storing keys in plaintext configuration files (A) and sharing keys over email (D) are insecure practices that expose keys to unauthorized disclosure.

Exam trap

In the SSCP exam, a common trap is the misconception that convenience (e.g., email sharing or plaintext storage) can be acceptable in secure environments, but the exam strictly enforces that keys must never be transmitted or stored in an insecure manner.

16
MCQmedium

A company is implementing a PKI for internal use. What is the primary purpose of a Certificate Revocation List (CRL)?

A.To validate certificate chains
B.To encrypt certificate requests
C.To store all issued certificates
D.To publish revoked certificates
AnswerD

A CRL is a signed, timestamped list issued by the certificate authority enumerating serial numbers of certificates revoked before their expiry. Validators check it during path validation so revoked certificates are rejected, satisfying the PKI requirement to publish revocation status.

Why this answer

The primary purpose of a Certificate Revocation List (CRL) is to publish a list of certificates that have been revoked by the Certificate Authority (CA) before their scheduled expiration. This allows relying parties to verify that a certificate is still valid and has not been compromised, ensuring trust in the PKI.

Exam trap

The trap here is that candidates confuse the CRL's purpose with certificate validation or storage, mistakenly thinking it validates chains or stores all certificates, when in fact it only publishes revoked certificates for status checking.

How to eliminate wrong answers

Option A is wrong because validating certificate chains is performed using the CA's public key and checking signatures, not by consulting a CRL; CRLs are used only to check revocation status. Option B is wrong because encrypting certificate requests is the role of protocols like PKCS#10 or CMP, not the CRL, which is a signed list of revoked certificates. Option C is wrong because storing all issued certificates is the function of a certificate repository or database, whereas a CRL only contains certificates that have been revoked, not all issued ones.

17
MCQhard

A security engineer is implementing a digital signature scheme to ensure non-repudiation. Which process correctly describes how a digital signature is created and verified?

A.Sign with private key, verify with public key
B.Sign with public key, verify with private key
C.Sign with symmetric key, verify with asymmetric key
D.Sign with hash, verify with private key
AnswerA

The signer hashes the message and encrypts that digest with their private key; the verifier decrypts it with the signer's public key and compares digests. Only the private-key holder could produce it, so this binds identity and delivers non-repudiation.

Why this answer

A digital signature is created by hashing the message and then encrypting that hash with the signer's private key. Verification is performed by decrypting the signature with the signer's public key and comparing the result to a freshly computed hash of the message. This asymmetric process ensures non-repudiation because only the private key holder could have created the signature, while anyone with the public key can verify it.

Exam trap

ISC2 often tests the misconception that the public key is used for signing because it is 'publicly available,' but the trap is that signing requires the private key to ensure only the claimed signer could have produced the signature.

How to eliminate wrong answers

Option B is wrong because signing with a public key would allow anyone to create a signature, destroying non-repudiation; the public key is used only for verification, not signing. Option C is wrong because symmetric keys are shared secrets and cannot provide non-repudiation—both parties could create the same signature, making it impossible to prove origin. Option D is wrong because signing with a hash is meaningless without a key; the hash is an intermediate step, and verification uses the public key, not the private key.

18
Multi-Selecthard

A financial institution is deploying a hardware security module (HSM) to protect cryptographic keys used for payment transactions. The security team must ensure that the HSM provides strong logical and physical protection. Which two of the following characteristics are MOST important to validate when selecting the HSM? (Choose two.)

Select 2 answers
A.The HSM enforces role-based access control and requires multiple physical or logical credentials for administrative actions.
B.The HSM includes a built-in UPS to maintain power during outages.
C.The HSM firmware can be updated automatically over the network without manual intervention.
D.The HSM has a FIPS 140-2 or FIPS 140-3 validation at an appropriate security level.
E.The HSM supports the largest possible number of symmetric key slots to avoid future purchases.
AnswersA, D

Strong access control, especially multi-person integrity (split knowledge) for sensitive operations, prevents a single insider from extracting or misusing keys. This directly supports logical protection. Combined with physical tamper safeguards, role-based access with dual control is a critical capability to validate, because it limits the attack surface from authorized users and satisfies common audit requirements.

Why this answer

Validating a FIPS 140-2/140-3 certificate at an appropriate level confirms that the HSM meets stringent security requirements, including tamper resistance and key protection. Enforcing role-based access with multi-person control ensures that no single individual can compromise keys. Together, these characteristics provide the logical and physical safeguards needed for payment transaction keys, whereas capacity, automatic updates, and power backup do not directly address security.

Exam trap

The trap here is confusing operational features such as scalability, automatic updates, or power redundancy with the core security validations that actually protect cryptographic keys.

19
MCQmedium

A security analyst is evaluating the cryptographic settings for a new application that requires both confidentiality and integrity for data in transit. The analyst needs to choose a symmetric cipher that provides authenticated encryption. Which of the following is the best choice?

A.RC4 stream cipher
B.AES in ECB mode
C.AES in GCM mode
D.AES in CBC mode
AnswerC

AES in GCM mode provides authenticated encryption, combining confidentiality with an authentication tag that detects tampering, which meets both stated requirements for data in transit. Other AES modes such as CBC supply confidentiality only and need a separate MAC.

Why this answer

AES in GCM mode provides authenticated encryption, offering both confidentiality and integrity/authenticity in a single operation. GCM (Galois/Counter Mode) is an AEAD (Authenticated Encryption with Associated Data) mode, making it the best choice for data in transit requiring both properties.

Exam trap

The trap is assuming that any AES mode provides integrity; candidates may pick CBC or ECB thinking they are secure, but only GCM (and other AEAD modes like CCM) provide authenticated encryption natively.

How to eliminate wrong answers

Option A is wrong because RC4 is a stream cipher that provides confidentiality but not integrity; it is also deprecated due to vulnerabilities. Option B is wrong because AES in ECB mode provides confidentiality but not integrity, and it is insecure due to pattern leakage. Option D is wrong because AES in CBC mode provides confidentiality but not integrity; it requires a separate MAC for authentication and is vulnerable to padding oracle attacks if not implemented correctly.

20
MCQmedium

In X.509 certificate format, which field is used to specify the fully qualified domain name(s) for which the certificate is valid?

A.Key Usage
B.Issuer
C.Subject
D.Subject Alternative Name
AnswerD

The Subject Alternative Name extension lists the DNS names, and optionally IP addresses, for which the certificate is valid. Modern clients validate identity against SAN rather than the Common Name, making it the field that specifies fully qualified domain names.

Why this answer

The Subject Alternative Name (SAN) extension in an X.509 certificate explicitly lists the fully qualified domain names (FQDNs), IP addresses, or other identifiers for which the certificate is valid. Modern browsers and TLS libraries primarily check the SAN field to validate a server's identity, ignoring the Common Name (CN) in the Subject field. The SAN is defined in RFC 5280 and is critical for multi-domain (SAN) certificates and wildcard certificates.

Exam trap

SSCP often tests the misconception that the Common Name (CN) in the Subject field is still used for hostname verification, but modern standards and browsers rely exclusively on the Subject Alternative Name extension.

How to eliminate wrong answers

Option A is wrong because Key Usage specifies the cryptographic purposes of the public key (e.g., digital signature, key encipherment) and does not contain domain names. Option B is wrong because Issuer identifies the Certificate Authority (CA) that signed and issued the certificate, not the domain it protects. Option C is wrong because Subject contains the entity's distinguished name (DN), including the Common Name (CN), but the CN is deprecated for hostname verification and does not reliably list all valid FQDNs.

21
Multi-Selecthard

An organization is designing a secure email system using S/MIME. Which of the following are essential components of the PKI that must be in place? (Select THREE)

Select 3 answers
A.A symmetric key distribution center (KDC)
B.X.509 digital certificates for each user
C.A method to check certificate revocation (e.g., CRL or OCSP)
D.A timestamp authority (TSA)
E.A certificate authority (CA) to sign certificates
AnswersB, C, E

S/MIME binds each user's public key to their email identity through an X.509 certificate, satisfying the PKI requirement for verified sender and recipient identities. Without per-user certificates, signing and encryption cannot be tied to a trusted identity.

Why this answer

Option B is correct because S/MIME binds each user's public key to their identity through an X.509 digital certificate, which is required for encrypting messages and verifying digital signatures. Option C is correct because the PKI must provide a way to check certificate revocation status, typically via CRL or OCSP, so recipients can reject messages signed with compromised or expired certificates. Option E is correct because a certificate authority (CA) is needed to issue and digitally sign the X.509 certificates that S/MIME relies on for trust.

Option A is not correct because a symmetric key distribution center (KDC) is associated with Kerberos-style symmetric key management, not with S/MIME's certificate-based public key infrastructure. Option D is not correct because a timestamp authority (TSA) supports trusted time-stamping for non-repudiation and is not an essential PKI component for basic S/MIME encryption and signing.

Exam trap

In the SSCP exam, candidates often mistakenly select a KDC or TSA as essential for S/MIME, but these are auxiliary services, not core PKI components.

22
MCQmedium

A security analyst is reviewing a digital signature implementation. The signer uses their private key to encrypt the hash of a message. What does the recipient use to verify the signature?

A.The recipient's private key
B.The signer's private key
C.The recipient's public key
D.The signer's public key
AnswerD

The recipient decrypts the signature with the signer's public key, recovering the hash, then compares it against a hash they compute over the message. Matching hashes confirm integrity and that only the private key holder could have signed.

Why this answer

Digital signatures use asymmetric cryptography where the signer encrypts the message hash with their private key. The recipient decrypts that encrypted hash using the signer's public key, then compares it to a locally computed hash of the received message. If they match, the signature is verified, proving both authenticity and integrity.

Exam trap

Candidates often confuse the roles of keys in digital signatures, mistakenly thinking the recipient uses their own private key or the signer's private key for verification. In asymmetric cryptography, signature verification always uses the signer's public key.

How to eliminate wrong answers

Option A is wrong because the recipient's private key is used for decryption of data encrypted with the recipient's public key, not for verifying a signature from another party. Option B is wrong because the signer's private key is kept secret and used only by the signer to create the signature; sharing it would compromise the entire system. Option C is wrong because the recipient's public key is used by others to encrypt data for the recipient, not to verify a signature created by a different entity.

23
MCQhard

A security auditor reviews a system that uses HMAC-SHA256 for message authentication. Which property does HMAC provide that a simple hash of the message does not?

A.Confidentiality
B.Non-repudiation
C.Integrity and authentication using a shared secret
D.Forward secrecy
AnswerC

HMAC mixes the message with a shared secret key before hashing, so it verifies both integrity and origin authenticity between parties holding that key. A plain hash provides integrity checking only, and anyone can recompute it, giving no authentication.

Why this answer

HMAC-SHA256 uses a shared secret key combined with the message before hashing, which provides both integrity (detecting tampering) and authentication (verifying the sender knows the secret). A simple hash of the message alone offers integrity but no authentication, because anyone can compute the same hash without a secret. Thus, HMAC adds authentication via the shared secret, making option C correct.

Exam trap

The trap here is that candidates confuse integrity (provided by any hash) with authentication (which requires a shared secret), leading them to think a simple hash is sufficient for message authentication, but HMAC specifically adds the keyed property.

How to eliminate wrong answers

Option A is wrong because HMAC does not provide confidentiality; it does not encrypt the message, only authenticates it. Option B is wrong because non-repudiation requires asymmetric cryptography (e.g., digital signatures) to bind a message to a specific entity, whereas HMAC uses a shared symmetric key and cannot prove which party created it. Option D is wrong because forward secrecy is a property of key exchange protocols (e.g., Diffie-Hellman ephemeral) that ensures session keys are not compromised if long-term keys are leaked; HMAC does not provide forward secrecy.

24
Multi-Selectmedium

An organization wants to implement a hashing algorithm for integrity checks. Which of the following should be avoided due to known vulnerabilities? (Select TWO)

Select 2 answers
A.SHA-3
B.SHA-256
C.MD5
D.HMAC-SHA256
E.SHA-1
AnswersC, E

MD5 produces 128-bit digests with practical collision attacks demonstrated, so it cannot assure integrity. Its weakness against chosen-prefix collisions directly satisfies the stem's criterion of an algorithm to avoid for integrity checks due to known vulnerabilities.

Why this answer

MD5 (C) must be avoided because it is cryptographically broken: practical collision attacks (e.g., the 2004 Wang attacks and later chosen-prefix collisions) allow two different inputs to produce the same 128-bit digest, so it cannot reliably detect malicious modification. SHA-1 (E) must also be avoided because collision attacks are practical (the 2017 SHAttered attack produced two colliding PDFs), making its 160-bit digest unsuitable for integrity checks against adversaries. SHA-3 (A) and SHA-256 (B) are unmarked because they are current, collision-resistant hash functions from the SHA-2/SHA-3 families and are appropriate for integrity verification.

HMAC-SHA256 (D) is unmarked because it is a keyed MAC built on SHA-256 that provides both integrity and authenticity and has no known practical breaks.

Exam trap

The trap here is that candidates often assume SHA-1 is still acceptable because it was once widely used, but the SSCP exam expects you to know that both MD5 and SHA-1 are broken for collision resistance and should be avoided.

25
MCQmedium

Which of the following best describes the purpose of a Hardware Security Module (HSM) in key management?

A.To store cryptographic keys in a secure, tamper-resistant environment
B.To replace public key infrastructure (PKI)
C.To accelerate network traffic encryption
D.To generate random numbers for non-cryptographic use
AnswerA

An HSM is a dedicated physical device that generates, stores and processes cryptographic keys inside tamper-resistant hardware, never exposing them in plaintext. This satisfies the key management requirement by protecting keys from extraction, satisfying compliance mandates such as FIPS 140-2.

Why this answer

A Hardware Security Module (HSM) is a dedicated, tamper-resistant hardware appliance designed to securely generate, store, and manage cryptographic keys throughout their lifecycle. By keeping keys within the HSM's physical and logical boundaries, it prevents unauthorized extraction even if the host system is compromised, which is the core purpose of an HSM in key management.

Exam trap

The trap here is that candidates confuse an HSM's ability to perform cryptographic operations (like encryption or signing) with its primary purpose, which is secure key storage and lifecycle management, not performance acceleration or replacing PKI.

How to eliminate wrong answers

Option B is wrong because an HSM does not replace Public Key Infrastructure (PKI); PKI is a framework of policies, roles, and software (e.g., Certificate Authorities) for managing digital certificates, while an HSM is a hardware device that can be used to protect the private keys within a PKI. Option C is wrong because accelerating network traffic encryption is not the primary purpose of an HSM; that function is typically performed by dedicated cryptographic accelerators or offload engines (e.g., Intel QAT), whereas an HSM focuses on secure key storage and limited cryptographic operations. Option D is wrong because while HSMs can generate random numbers, they are used for cryptographic purposes (e.g., key generation, nonces) and not for non-cryptographic use; general random number generation for non-cryptographic tasks is done by simpler PRNGs like those in standard OS libraries.

26
MCQeasy

Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?

A.SHA-3
B.SHA-256
C.MD5
D.HMAC-SHA256
AnswerC

MD5 produces a 128-bit digest and is vulnerable to practical collision attacks, so distinct inputs can yield identical hashes. This breaks integrity guarantees, making it unsuitable where collision resistance is required, unlike SHA-256 or SHA-3.

Why this answer

MD5 is considered cryptographically broken because collision attacks can easily generate two different inputs with the same hash value. This undermines its use for digital signatures, certificates, and integrity checks. SHA-3, SHA-256, and HMAC-SHA256 are still considered secure for cryptographic purposes.

Exam trap

SSCP often tests hash algorithm security; candidates might think SHA-1 is the only broken one, but MD5 is also broken and frequently appears as a distractor.

How to eliminate wrong answers

Option A is wrong because SHA-3 is a secure hash algorithm standardized by NIST, resistant to collision attacks. Option B is wrong because SHA-256 is part of the SHA-2 family and remains secure for cryptographic use. Option D is wrong because HMAC-SHA256 is a keyed-hash message authentication code using SHA-256, which is secure and not affected by MD5's vulnerabilities.

27
MCQeasy

A security administrator is configuring a web server to use TLS 1.3. The administrator wants to ensure that the server supports forward secrecy for all connections. Which of the following key exchange mechanisms should be used?

A.Pre-shared key (PSK) exchange
B.Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Ephemeral Diffie-Hellman (ECDHE)
C.Static Diffie-Hellman (DH)
D.RSA key exchange
AnswerB

Ephemeral Diffie-Hellman (DHE) and its elliptic curve variant (ECDHE) generate a unique, temporary key pair for each session. The private keys are discarded after the session, so even if the server's long-term private key is compromised, past session keys cannot be recovered. TLS 1.3 mandates the use of ephemeral key exchanges like ECDHE for forward secrecy.

Why this answer

TLS 1.3 requires forward secrecy, which is achieved by using ephemeral key exchanges such as DHE or ECDHE. These generate a unique session key that is not derivable from the server's long-term private key. RSA and static DH key exchanges lack forward secrecy and are not supported in TLS 1.3.

PSK alone also does not provide forward secrecy.

Exam trap

The trap here is assuming that any key exchange method in TLS provides forward secrecy, when in fact only ephemeral methods do.

28
MCQeasy

What is the minimum recommended RSA key size for secure use as of current best practices?

A.1024 bits
B.4096 bits
C.3072 bits
D.2048 bits
AnswerD

2048-bit RSA is the current minimum recommended size; smaller keys such as 1024-bit are considered cryptographically weak against modern factoring attacks. This satisfies the stem's requirement for the minimum secure key length under current best practise.

Why this answer

(2048 bits) is correct because current best practices, as recommended by NIST SP 800-57 and other cryptographic standards, consider 2048-bit RSA keys as the minimum secure size for protecting data through 2030. This key length provides a sufficient security margin against known factoring attacks, balancing computational efficiency with cryptographic strength.

Exam trap

Candidates often mistake that larger keys are always better, leading them to choose 4096 bits as the minimum, when in fact 2048 bits is the officially recommended baseline for secure use.

How to eliminate wrong answers

Option A is wrong because 1024-bit RSA keys are deprecated and considered insecure due to advances in factoring algorithms and computational power; they provide only about 80 bits of security, which is below the recommended 112-bit minimum. Option B is wrong because 4096-bit RSA keys, while secure, are not the minimum recommended size; they offer excessive security margin (about 140 bits) at the cost of significantly slower performance, making them unnecessary for most applications. Option C is wrong because 3072-bit RSA keys, though providing a higher security level (128 bits), are not the minimum recommended size; 2048 bits is the established baseline per NIST and industry standards.

29
MCQmedium

Which of the following is a cryptographic hash function that is considered cryptographically broken due to collision attacks and should not be used for security purposes?

A.SHA-1
B.SHA-256
C.SHA-3
D.SHA-512
AnswerA

SHA-1 is vulnerable to collision attacks and is considered broken.

Why this answer

SHA-1 is considered cryptographically broken due to collision attacks and should not be used for security purposes. SHA-256, SHA-3, and SHA-512 are still considered secure.

30
Multi-Selecthard

A company is deploying a hardware security module (HSM) to protect the root keys of its certificate authority. Which two practices are essential for maintaining the security of the CA's private keys? (Choose two.)

Select 2 answers
A.Enable remote administration of the HSM over the public internet for convenience.
B.Store the CA private keys in the HSM and configure it to prevent export of the keys in plaintext.
C.Back up the CA private keys by exporting them to an encrypted file on a network share.
D.Require multiple authorized administrators to authenticate before the HSM performs a signing operation.
E.Use the same HSM partition for the root CA and for issuing subordinate certificates to simplify management.
AnswersB, D

Keeping the CA private keys inside the HSM and preventing plaintext export ensures that the keys never exist in an unprotected form on general-purpose systems. This reduces the risk of theft or accidental disclosure and is a fundamental requirement for protecting a root CA. The HSM's tamper-resistant design provides additional safeguards against physical and logical attacks.

Why this answer

Protecting a CA's private keys requires keeping them inside a tamper-resistant HSM and preventing plaintext export, as well as enforcing multi-person control over signing operations. Exporting keys to a file, exposing administration to the internet, or merging root and issuing roles all increase the risk of key compromise. These practices reflect standard CA hardening guidance.

Exam trap

The trap here is treating encrypted key backups or convenient remote administration as acceptable for a root CA, when they actually expand the attack surface.

31
MCQmedium

In a PKI, what is the role of the root Certificate Authority (CA)?

A.To be the trust anchor for the entire PKI hierarchy
B.To issue certificates directly to end users
C.To generate private keys for all users
D.To revoke certificates and publish CRLs
AnswerA

The root CA sits at the top of the hierarchy and self-signs its own certificate, so every subordinate CA and end-entity certificate chains back to it. That position makes it the trust anchor, and its private key must be strictly offline-protected.

Why this answer

The root Certificate Authority (CA) is the trust anchor in a Public Key Infrastructure (PKI) hierarchy. Its self-signed root certificate is the ultimate trust point from which all subordinate CA certificates and end-entity certificates derive their trust. Without a trusted root, the entire chain of trust collapses, as no certificate can be validated back to a trusted source.

Exam trap

The trap here is that candidates often assume the root CA directly issues end-user certificates or handles revocation, but the SSCP exam tests the understanding that the root CA's primary role is to serve as the immutable trust anchor, with operational tasks delegated to subordinate CAs.

How to eliminate wrong answers

Option B is wrong because the root CA typically does not issue certificates directly to end users; that task is delegated to subordinate or intermediate CAs to limit exposure of the root key. Option C is wrong because the root CA does not generate private keys for users; private keys are generated by the user or their client software and should never be known to the CA. Option D is wrong because while the root CA can theoretically revoke certificates and publish CRLs, in practice this is usually handled by subordinate CAs or a dedicated CRL issuer to reduce operational load on the root.

32
MCQmedium

A healthcare provider must protect the confidentiality of patient records stored on a shared network drive. The compliance officer mandates that the encryption solution use a symmetric algorithm with a 256-bit key and operate as a block cipher. Which of the following should the security administrator select to meet these requirements?

A.AES-256
B.RSA-2048
C.SHA-256
D.3DES
AnswerA

AES-256 is a symmetric block cipher standardized by NIST with a 256-bit key and a 128-bit block size. It satisfies the requirement for strong symmetric encryption and is widely supported in both hardware and software for protecting data at rest, including patient records on shared storage.

Why this answer

AES-256 is the correct choice because it is a symmetric block cipher with a 256-bit key, exactly matching the compliance requirement. RSA is asymmetric and too slow for bulk data, 3DES lacks the required key size and is deprecated, and SHA-256 is a hash function that provides no confidentiality. Only AES-256 satisfies all stated conditions for protecting stored records.

Exam trap

The trap here is confusing hash functions such as SHA-256 with encryption algorithms, or assuming any symmetric cipher like 3DES meets a 256-bit key requirement.

33
MCQhard

A financial institution is implementing a digital signature solution to ensure the integrity and authenticity of wire transfer instructions. The solution must provide non-repudiation and use a NIST-approved algorithm. Which of the following should the security architect select?

A.HMAC-SHA256
B.AES-256-GCM
C.ECDSA with SHA-256
D.RSA-1024 with SHA-1
AnswerC

ECDSA (Elliptic Curve Digital Signature Algorithm) with SHA-256 is a NIST-approved digital signature algorithm (FIPS 186-4) that provides integrity, authenticity, and non-repudiation. It uses elliptic curve cryptography, which offers strong security with smaller key sizes compared to RSA. This meets the financial institution's requirements for a NIST-approved algorithm.

Why this answer

ECDSA with SHA-256 is a NIST-approved digital signature algorithm that provides non-repudiation, integrity, and authenticity. It is based on elliptic curve cryptography, which is efficient and secure with smaller key sizes. The other options either lack non-repudiation (HMAC, AES-GCM) or use deprecated algorithms (RSA-1024 with SHA-1).

Exam trap

The trap here is confusing message authentication codes or symmetric encryption with digital signatures, which are the only cryptographic mechanisms that provide non-repudiation.

34
MCQmedium

A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?

A.RSA with 2048-bit keys
B.Elliptic Curve Cryptography (ECC) with 256-bit keys
C.Diffie-Hellman with 2048-bit keys
D.3DES with 168-bit keys
AnswerB

ECC achieves equivalent security with far smaller keys because its security rests on the elliptic curve discrete logarithm problem, which resists known sub-exponential attacks. A 256-bit ECC key matches RSA 2048-bit strength, satisfying the IoT constraint of limited computational resources and smaller key sizes.

Why this answer

Elliptic Curve Cryptography (ECC) with 256-bit keys provides equivalent security to RSA 2048-bit because the elliptic curve discrete logarithm problem is significantly harder to solve than the integer factorization problem for the same key length. This allows ECC to achieve strong security with much smaller key sizes, making it ideal for resource-constrained IoT devices where memory, power, and processing are limited.

Exam trap

The SSCP exam often tests the misconception that larger key sizes always mean stronger security, leading candidates to pick RSA 2048-bit or Diffie-Hellman 2048-bit, while the trap is that ECC with much smaller key sizes (e.g., 256-bit) provides equivalent security with lower computational overhead, which is the exact requirement for IoT devices.

How to eliminate wrong answers

Option A is wrong because RSA with 2048-bit keys is the baseline for comparison, not a smaller key size alternative, and it requires significantly more computational resources than ECC for equivalent security. Option C is wrong because Diffie-Hellman with 2048-bit keys is a symmetric-key-agreement protocol that also uses large key sizes for security, not a smaller key size alternative, and it does not provide the same key-size efficiency as ECC. Option D is wrong because 3DES with 168-bit keys is a symmetric encryption algorithm, not an asymmetric algorithm, and it provides only about 112 bits of security, far less than RSA 2048-bit, while also being computationally heavy and deprecated in modern standards.

35
MCQhard

An analyst is comparing symmetric and asymmetric encryption. Which statement accurately describes a typical use case?

A.Symmetric encryption is used for key exchange over insecure channels.
B.Asymmetric encryption is used to securely exchange a symmetric key.
C.Symmetric encryption is used to sign documents to provide non-repudiation.
D.Asymmetric encryption is used for bulk data encryption because it is faster.
AnswerB

Asymmetric encryption, using public and private key pairs, is slower but solves key distribution; it typically encrypts a randomly generated symmetric session key, which then protects bulk data. This hybrid approach combines asymmetric key exchange with symmetric throughput.

Why this answer

Asymmetric encryption (e.g., RSA, ECDH) is computationally expensive and slow, making it unsuitable for bulk data encryption. Instead, it is commonly used to securely exchange a symmetric session key (e.g., an AES key) over an insecure channel. Once both parties have the symmetric key, they can switch to symmetric encryption (e.g., AES-GCM) for efficient bulk data encryption.

This hybrid approach combines the secure key distribution of asymmetric encryption with the speed of symmetric encryption.

Exam trap

A common pitfall in this context is the misconception that symmetric encryption is used for key exchange or that asymmetric encryption is faster for bulk data. In reality, asymmetric encryption is slow and reserved for secure key exchange, while symmetric encryption is fast and used for bulk data encryption.

How to eliminate wrong answers

Option A is wrong because symmetric encryption uses a single shared key and cannot securely exchange that key over an insecure channel without a pre-existing secure method; key exchange is a primary use case for asymmetric encryption (e.g., Diffie-Hellman, RSA key transport). Option C is wrong because symmetric encryption does not provide non-repudiation; digital signatures, which use asymmetric encryption (e.g., RSA or ECDSA with a private key), are required to provide non-repudiation by binding the signer's identity to the document. Option D is wrong because asymmetric encryption is significantly slower than symmetric encryption (e.g., RSA is hundreds to thousands of times slower than AES for equivalent security levels) and is therefore not used for bulk data encryption; symmetric encryption (e.g., AES-256) is the standard for encrypting large volumes of data.

36
MCQhard

A security engineer is configuring a TLS 1.3 server for an e-commerce site. The engineer wants to ensure that the cipher suite provides both confidentiality and integrity for application data. Which of the following cipher suites should the engineer select?

A.TLS_RSA_WITH_3DES_EDE_CBC_SHA
B.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
C.TLS_AES_128_GCM_SHA256
D.TLS_AES_256_CBC_SHA384
AnswerC

TLS_AES_128_GCM_SHA256 uses AES-128 in Galois/Counter Mode, which is an authenticated encryption with associated data (AEAD) cipher. GCM provides both confidentiality and integrity in a single operation, and SHA256 is used for the handshake hash. This suite meets the requirement for protecting application data.

Why this answer

TLS_AES_128_GCM_SHA256 is the only valid TLS 1.3 cipher suite listed that uses an AEAD algorithm. GCM provides authenticated encryption, ensuring both confidentiality and integrity of application data. The other options are either legacy TLS 1.2 suites with CBC and separate MACs or an invalid TLS 1.3 suite name, so they do not meet the requirement.

Exam trap

The trap here is selecting a cipher suite based on key size or familiarity without recognizing that TLS 1.3 mandates AEAD ciphers and disallows CBC mode.

37
Multi-Selecteasy

A security administrator is setting up a public key infrastructure (PKI) for internal use. Which two of the following components are essential for establishing a chain of trust from the root CA to end-entity certificates?

Select 2 answers
A.An intermediate (subordinate) CA certificate signed by the root CA
B.A certificate signing request (CSR)
C.A self-signed root CA certificate
D.An online certificate status protocol (OCSP) responder
E.A certificate revocation list (CRL)
AnswersA, C

An intermediate CA certificate, signed by the root CA, extends the trust anchor so end-entity certificates chain upward to the root. This satisfies the stem's requirement for establishing a verifiable chain of trust from root CA to end-entity certificates.

Why this answer

The chain of trust must begin with a self-signed root CA certificate (C), which is the trust anchor that is inherently trusted and whose private key signs the certificates below it. To extend that trust to end-entity certificates without exposing the root's private key, an intermediate (subordinate) CA certificate signed by the root CA (A) is required, forming the hierarchical path root CA → intermediate CA → leaf certificate. A CSR (B) is only a request containing a public key and identity information that a CA uses to issue a certificate; it is not itself a link in the trust chain.

An OCSP responder (D) and a CRL (E) are revocation-checking mechanisms that report certificate status, but they do not establish the chain of trust from the root CA to end-entity certificates.

38
MCQhard

A software vendor distributes patches over the internet. Customers must be able to verify that a patch came from the vendor and was not altered in transit. The vendor wants to use a digital signature. Which key should the vendor use to create the signature?

A.The vendor's private key
B.The customer's private key
C.A symmetric session key shared with each customer
D.The vendor's public key
AnswerA

A digital signature is created by signing a hash of the patch with the signer's private key. Only the vendor possesses this private key, so a successful verification with the corresponding public key proves origin and integrity. This directly satisfies the requirement that customers can confirm the patch came from the vendor and was not modified in transit.

Why this answer

Digital signatures rely on asymmetric cryptography: the signer uses its private key to sign a hash of the data, and verifiers use the signer's public key to check the signature. Because only the vendor holds its private key, a valid signature proves the patch originated from the vendor and was not altered. Public keys, symmetric keys, and customer keys cannot provide this combination of authenticity and integrity.

Exam trap

The trap here is reversing the roles of public and private keys, or assuming a shared symmetric key can provide non-repudiation for a publicly distributed patch.

39
MCQhard

A PKI administrator needs to check the revocation status of a digital certificate without requiring the client to download the entire CRL. Which method is designed for online, real-time certificate status checking?

A.OCSP
B.OCSP stapling
C.CRL
D.Certificate transparency
AnswerA

OCSP queries a responder for a single certificate's status in real time, returning a signed good, revoked, or unknown response. This avoids the client downloading and parsing the full CRL, directly meeting the stem's online, real-time revocation checking constraint.

Why this answer

OCSP (Online Certificate Status Protocol) is designed for online, real-time certificate status checking. It allows a client to query an OCSP responder for the revocation status of a specific certificate without downloading the entire CRL.

Exam trap

SSCP often tests the difference between OCSP and CRL, and candidates might confuse OCSP stapling as a separate protocol rather than an optimization of OCSP.

How to eliminate wrong answers

Option B is wrong because OCSP stapling is a method where the server staples the OCSP response to the TLS handshake, but it still relies on OCSP; the question asks for the method designed for online checking, which is OCSP itself. Option C is wrong because CRL (Certificate Revocation List) requires downloading the entire list, which is not real-time and can be large. Option D is wrong because Certificate Transparency is a logging framework for certificates, not for revocation checking.

40
MCQmedium

A company wants to implement a key management system. They need to generate cryptographic keys that are unpredictable. Which source of randomness should be used?

A.Hardware random number generator (HRNG)
B.Random numbers from a website
C.Linear congruential generator (LCG)
D.Pseudorandom number generator (PRNG) seeded with current timestamp
AnswerA

An HRNG derives randomness from a physical entropy source, such as thermal or quantum noise, so its output cannot be predicted or reproduced. This satisfies the requirement for unpredictable key material, unlike deterministic software PRNGs, whose sequences are reproducible once the seed is known.

Why this answer

A hardware random number generator (HRNG) is the correct choice because it derives randomness from physical processes (e.g., thermal noise, quantum effects) that are inherently unpredictable and non-deterministic. Cryptographic key generation requires true entropy to resist brute-force and prediction attacks, which software-based deterministic methods cannot guarantee.

Exam trap

ISC2 SSCP often tests the misconception that a PRNG seeded with a timestamp is sufficient for cryptography, but the trap is that timestamps are predictable or guessable, making the output deterministic and insecure for key generation.

How to eliminate wrong answers

Option B is wrong because random numbers from a website are sourced over an untrusted network and may be intercepted, reused, or generated by a pseudorandom algorithm, offering no verifiable entropy. Option C is wrong because a linear congruential generator (LCG) is a deterministic, predictable algorithm with a short period, making it unsuitable for cryptographic key generation. Option D is wrong because a pseudorandom number generator (PRNG) seeded with a current timestamp is deterministic; if the timestamp is guessed or observed, all outputs become predictable, violating the unpredictability requirement.

41
MCQeasy

Which of the following encryption algorithms is classified as a symmetric block cipher and is the current standard recommended by NIST, supporting key sizes of 128, 192, and 256 bits?

A.AES
B.RSA
C.3DES
D.ChaCha20
AnswerA

AES is a symmetric block cipher operating on 128-bit blocks, with key sizes of 128, 192, and 256 bits, exactly matching the stem's requirements. NIST adopted it as the current standard (FIPS 197), replacing DES and 3DES. Its substitution-permutation network resists linear and differential cryptanalysis far better than legacy ciphers.

Why this answer

AES (Advanced Encryption Standard) is a symmetric block cipher that encrypts data in fixed 128-bit blocks and is the current standard recommended by NIST (FIPS 197). It supports key sizes of 128, 192, and 256 bits, making it the correct answer for a symmetric block cipher with those specific key lengths.

Exam trap

Candidates often confuse symmetric with asymmetric algorithms, or mistakenly think 3DES is still the current standard. In the SSCP exam, remember that AES is the only symmetric block cipher recommended by NIST that supports 128, 192, and 256-bit keys.

How to eliminate wrong answers

Option B (RSA) is wrong because it is an asymmetric (public-key) cipher, not a symmetric block cipher, and it does not use fixed block sizes or the specified key sizes. Option C (3DES) is wrong because, while it is a symmetric block cipher, it is deprecated by NIST due to its small 64-bit block size and slow performance, and it supports key sizes of 56, 112, or 168 bits, not 128, 192, or 256 bits. Option D (ChaCha20) is wrong because it is a stream cipher, not a block cipher, and although it is a symmetric algorithm, it does not use the specified key sizes in the context of a block cipher standard.

42
MCQmedium

A healthcare company must store backup tapes offsite for seven years. The tapes contain patient records, and the company wants a symmetric encryption algorithm that is fast, widely supported, and approved by NIST for protecting data at rest. Which algorithm best meets these requirements?

A.Diffie-Hellman key exchange with a 2048-bit group
B.AES with a 256-bit key
C.RSA with a 2048-bit key
D.SHA-256 hashing of each backup file
AnswerB

AES is a symmetric block cipher standardized by NIST and is the current approved algorithm for protecting sensitive data at rest. A 256-bit key provides a strong security margin, and AES performs efficiently on modern hardware, making it suitable for encrypting large backup tapes. It is widely supported across storage and backup platforms, matching the healthcare company's operational needs.

Why this answer

AES is a NIST-approved symmetric block cipher that provides strong confidentiality with high performance, which is essential for encrypting large volumes of backup data. A 256-bit key offers a conservative security margin for long-term storage. Hashing provides integrity only, RSA and Diffie-Hellman are asymmetric mechanisms not suited to bulk data-at-rest encryption, so AES is the appropriate choice.

Exam trap

The trap here is confusing integrity mechanisms such as hashing with confidentiality mechanisms, or assuming that any NIST-approved algorithm works for bulk encryption regardless of whether it is symmetric or asymmetric.

43
Multi-Selectmedium

A security analyst is reviewing the cryptographic controls for a new messaging application. The application must ensure that messages are encrypted in transit and that the sender cannot later deny having sent a message. Which two of the following cryptographic mechanisms should be implemented to meet these requirements? (Choose two.)

Select 2 answers
A.Digital signatures using the sender's private key
B.Keyed-hash message authentication code (HMAC)
C.TLS for encrypting messages in transit
D.Hashing messages with SHA-256
E.Symmetric encryption using a shared secret key
AnswersA, C

Digital signatures provide non-repudiation because they are generated with the sender's private key, which only the sender possesses. Anyone can verify the signature using the sender's public key, proving that the message originated from the sender and has not been altered. This directly meets the requirement that the sender cannot deny sending the message.

Why this answer

To encrypt messages in transit, TLS is appropriate as it provides confidentiality and integrity for data in transit. To ensure non-repudiation, digital signatures using the sender's private key are required because they uniquely bind the sender to the message. Symmetric encryption, hashing, and HMAC do not provide non-repudiation.

Exam trap

The trap here is confusing integrity mechanisms like HMAC or hashing with non-repudiation, which requires asymmetric cryptography.

44
MCQmedium

A financial services company is deploying a new VPN concentrator that must support perfect forward secrecy (PFS) for all client sessions. The security team is configuring the IPsec phase 2 (Quick Mode) proposals. Which of the following should be configured to achieve PFS?

A.Set the phase 1 lifetime to be shorter than the phase 2 lifetime.
B.Configure the phase 1 proposal to use RSA signatures for authentication.
C.Enable Diffie-Hellman group 14 in the phase 2 proposal.
D.Use AES-256-GCM for the phase 2 encryption algorithm.
AnswerC

Perfect forward secrecy in IPsec is achieved by performing a new Diffie-Hellman key exchange during phase 2 (Quick Mode). Specifying a DH group such as group 14 (2048-bit MODP) in the phase 2 proposal ensures that a fresh key is generated for each session, so compromise of one session key does not expose past or future session keys.

Why this answer

Perfect forward secrecy in IPsec is achieved by including a Diffie-Hellman group in the phase 2 (Quick Mode) proposal. This forces a new key exchange for each session, ensuring that compromise of one session key does not compromise other sessions. Encryption algorithms and authentication methods do not provide PFS; they serve different purposes.

Exam trap

The trap here is confusing authentication or encryption algorithms with key exchange mechanisms, assuming that strong encryption alone provides perfect forward secrecy.

45
MCQmedium

A security analyst is evaluating encryption modes for a new system that requires authenticated encryption to ensure both confidentiality and integrity of data in transit. Which AES mode should the analyst recommend?

A.ECB
B.CBC
C.CTR
D.GCM
AnswerD

GCM combines AES counter-mode encryption with GHASH authentication, producing a tag that verifies integrity alongside confidentiality in a single pass. This satisfies the authenticated encryption requirement, unlike CBC or CTR, which provide confidentiality only and need a separate MAC.

Why this answer

GCM (Galois/Counter Mode) is the correct choice because it provides authenticated encryption, combining the confidentiality of CTR mode with integrity verification via a Galois field authentication tag. This makes it ideal for securing data in transit, as it ensures both privacy and tamper detection in a single, efficient operation.

Exam trap

The trap here is that candidates often confuse confidentiality-only modes (like CBC or CTR) with authenticated encryption, overlooking that GCM is the only option listed that natively provides both encryption and integrity in a single mode.

How to eliminate wrong answers

Option A is wrong because ECB (Electronic Codebook) mode encrypts each block independently, producing identical ciphertext for identical plaintext blocks, which leaks patterns and provides no integrity protection. Option B is wrong because CBC (Cipher Block Chaining) mode ensures confidentiality through chaining but does not inherently provide authentication or integrity; it requires a separate MAC (e.g., HMAC) for authenticated encryption. Option C is wrong because CTR (Counter) mode offers confidentiality by encrypting a counter value, but like CBC, it lacks built-in integrity verification and is vulnerable to bit-flipping attacks without an additional authentication mechanism.

46
MCQeasy

Which of the following is a secure hash algorithm currently recommended by NIST?

A.SHA-1
B.RC4
C.MD5
D.SHA-256
AnswerD

SHA-256 belongs to the SHA-2 family, which NIST specifies in FIPS 180-4 for cryptographic hashing. It resists the collision attacks that broke SHA-1 and MD5, satisfying the stem's requirement for a currently recommended secure hash algorithm.

Why this answer

SHA-256 is a member of the SHA-2 family of secure hash algorithms and is currently recommended by NIST for cryptographic use. It produces a 256-bit (32-byte) hash value and is widely deployed in protocols such as TLS, SSH, and IPsec, as well as in digital signatures and certificate validation.

Exam trap

ISC2 SSCP exams often test the distinction between hash algorithms and encryption ciphers, so candidates may mistakenly select RC4 because it is a well-known cryptographic algorithm, but it is not a hash function at all.

How to eliminate wrong answers

Option A is wrong because SHA-1 is no longer considered secure by NIST due to demonstrated collision attacks (e.g., the SHAttered attack in 2017) and is deprecated for most cryptographic applications. Option B is wrong because RC4 is a stream cipher, not a hash algorithm, and it is also deprecated due to severe biases in its output. Option C is wrong because MD5 is a broken hash algorithm with practical collision attacks (e.g., used in the Flame malware) and is explicitly not recommended by NIST for any security purpose.

47
Multi-Selecthard

A security engineer is designing a key management system for a large enterprise. Which two of the following practices are essential for securing cryptographic keys throughout their lifecycle?

Select 2 answers
A.Store keys in dedicated hardware security modules (HSMs).
B.Use the same key for encryption, digital signatures, and key exchange.
C.Email keys to authorized users for convenience.
D.Store keys in the same database as encrypted data.
E.Rotate keys regularly and upon compromise.
AnswersA, E

HSMs provide tamper-resistant hardware that generates and stores keys so private material never exists in plaintext on general-purpose systems, satisfying the lifecycle requirement for secure generation, storage and protection. Keys are used inside the module, preventing extraction even if the host is compromised.

Why this answer

Option A is correct because dedicated hardware security modules (HSMs) provide tamper-resistant, FIPS 140-2/140-3 validated storage and cryptographic processing, ensuring keys are generated, used, and stored in a protected boundary and never exposed in plaintext on general-purpose systems. Option E is correct because regular key rotation limits the amount of data protected by any single key (cryptoperiod) and reduces the blast radius of a compromise, while rotation upon suspected or confirmed compromise ensures the exposed key is retired and replaced immediately. Options B, C, and D are not appropriate: reusing one key across encryption, digital signatures, and key exchange violates key-separation principles and increases the impact of any single key compromise; emailing keys exposes them to interception and unauthorized access; and storing keys alongside the encrypted data means a single database breach compromises both the ciphertext and the key needed to decrypt it.

Exam trap

SSCP often tests key management fundamentals, catching candidates who choose convenience (emailing keys, single key for all purposes) over security best practices like HSM storage and rotation.

48
Multi-Selectmedium

A company is upgrading its legacy systems to use modern cryptographic standards. Which two of the following algorithms should be avoided due to known weaknesses or deprecation?

Select 2 answers
A.SHA-256 for hashing
B.MD5 for hashing
C.AES-256 for encryption
D.ECDH for key exchange
E.3DES for encryption
AnswersB, E

MD5 is cryptographically broken; collision attacks are feasible.

Why this answer

MD5 (option B) must be avoided because it is cryptographically broken: practical collision attacks (e.g., chosen-prefix collisions) make it unsuitable for hashing, digital signatures, or integrity checks, and it has been deprecated by NIST for security use. 3DES (option E) should also be avoided because its 64-bit block size enables Sweet32-style birthday attacks, and its effective key strength is reduced (e.g., 2-key 3DES offers only about 80 bits), leading to its deprecation and removal from standards such as NIST SP 800-131A. SHA-256 (option A) is a current, secure SHA-2 hash and remains approved for hashing. AES-256 (option C) is a strong, modern symmetric cipher with no practical breaks and is widely recommended.

ECDH (option D) is a sound modern elliptic-curve key-exchange method and is not deprecated.

Exam trap

SSCP often tests whether candidates can distinguish deprecated algorithms (MD5, SHA-1, 3DES, RC4) from still-strong ones (SHA-256, AES-256, ECDH) — the trap is assuming 'Triple DES' must be three times stronger than DES and therefore secure.

49
MCQeasy

Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?

A.FTP
B.SSH
C.HTTP
D.Telnet
AnswerB

SSH encrypts the entire session, including authentication credentials and commands, over TCP port 22. Telnet transmits everything in cleartext, exposing passwords to sniffing. SSH's host key verification and encrypted channel satisfy the requirement for secure remote administration.

Why this answer

SSH (Secure Shell) is the correct answer because it provides encrypted remote administration capabilities, replacing insecure protocols like Telnet that transmit data in plaintext. SSH uses public-key cryptography for authentication and symmetric encryption (e.g., AES, ChaCha20) for session confidentiality, protecting against eavesdropping and man-in-the-middle attacks.

Exam trap

The trap here is that candidates may confuse Telnet with SSH or think that FTP or HTTP can be used for remote administration, but the question specifically asks for a secure replacement for Telnet, which is SSH.

How to eliminate wrong answers

Option A (FTP) is wrong because it is a file transfer protocol, not a remote administration protocol, and it transmits credentials and data in plaintext unless secured with FTPS or SFTP. Option C (HTTP) is wrong because it is a web protocol used for transferring hypertext, not for remote server administration, and it lacks encryption by default (HTTPS is the secure variant). Option D (Telnet) is wrong because it is the very insecure protocol that SSH replaces, sending all data including passwords in cleartext over TCP port 23.

50
MCQeasy

A security administrator needs to verify the integrity and authenticity of a downloaded software package. The vendor provides a separate file containing a cryptographic hash of the package, but the hash file itself is not signed. Which action BEST mitigates the risk of a modified package being accepted?

A.Compare the provided hash with a hash computed locally using the same algorithm.
B.Decrypt the package using the vendor's public key before hashing it.
C.Recompute the hash using a different algorithm and compare it to the vendor's hash.
D.Obtain the hash value from a trusted, independent source and compare it to a locally computed hash.
AnswerD

Integrity verification requires a trusted reference. By retrieving the hash from an independent, authenticated channel, the administrator can detect whether the package or the accompanying hash file was altered. A locally computed hash of the downloaded package compared against that trusted value provides assurance of integrity and authenticity, which the unsigned hash file alone cannot.

Why this answer

Hashes alone provide integrity only when the reference value is trusted. Since the provided hash file is unsigned and could be altered alongside the package, the administrator must obtain the expected hash through an independent, authenticated channel. Comparing a locally computed hash against that trusted value detects tampering, whereas using the untrusted file or changing algorithms does not.

Exam trap

The trap here is treating any hash comparison as sufficient for integrity, overlooking that the hash itself must come from a trusted source to provide assurance.

51
Multi-Selecteasy

Which TWO of the following are considered secure cryptographic hash functions as of current standards? (Select TWO.)

Select 2 answers
A.SHA-3
B.RC4
C.SHA-1
D.MD5
E.SHA-256
AnswersA, E

SHA-3 remains collision- and preimage-resistant under current standards, satisfying the stem's requirement for a secure hash function. Its sponge construction (Keccak) differs fundamentally from SHA-2's Merkle–Damgård design, providing an independent security margin should SHA-2 weaknesses emerge. NIST standardised it in FIPS 202, so it meets current cryptographic approval.

Why this answer

SHA-3 (Option A) is correct because it is the latest NIST-standardized hash function family (FIPS 202), based on the Keccak sponge construction, and remains resistant to known collision and preimage attacks. SHA-256 (Option E) is correct because it is part of the SHA-2 family (FIPS 180-4) and is still considered cryptographically secure for collision resistance and preimage resistance in current standards. RC4 (Option B) is a stream cipher, not a hash function, and is deprecated due to biases in its keystream.

SHA-1 (Option C) is no longer considered secure because practical collision attacks (e.g., SHAttered) have been demonstrated. MD5 (Option D) is also broken, with trivial collision generation, so it is unsuitable for security purposes.

Exam trap

SSCP often tests the confusion between deprecated algorithms (MD5, SHA-1) and secure ones, and between hash functions and ciphers (RC4), tempting candidates to pick SHA-1 because it is a SHA family member.

52
Multi-Selecthard

A company is selecting a cryptographic algorithm for digital signatures. Which THREE of the following algorithms can be used for digital signatures? (Select THREE.)

Select 3 answers
A.SHA-256
B.DSA
C.AES
D.RSA
E.ECDSA
AnswersB, D, E

DSA is a FIPS-approved asymmetric algorithm designed solely for digital signatures, relying on the discrete logarithm problem over finite fields. It satisfies the stem's requirement directly, generating signatures through a per-message random value k rather than supporting encryption.

Why this answer

DSA (Option B) is a Digital Signature Algorithm designed specifically to generate and verify digital signatures using discrete logarithms, so it is correct. RSA (Option D) can produce digital signatures by signing a hash with the private key and verifying with the public key, making it a valid signature algorithm. ECDSA (Option E) is the Elliptic Curve Digital Signature Algorithm, which provides digital signatures based on elliptic-curve cryptography and is also correct.

SHA-256 (Option A) is only a hash function used to create message digests, not a signature algorithm by itself, and AES (Option C) is a symmetric block cipher for encryption, not for digital signatures.

Exam trap

SSCP often tests the confusion between hash functions (SHA-256), symmetric ciphers (AES), and asymmetric signature algorithms (DSA, RSA, ECDSA), catching candidates who select SHA-256 thinking it 'signs' data.

53
MCQmedium

A company is deploying a VPN that uses IPsec in tunnel mode. The security engineer must choose a key exchange method that provides perfect forward secrecy (PFS) so that compromise of a long-term key does not expose past session keys. Which configuration should the engineer select?

A.Use static keying with manually configured security associations and AES-256.
B.Use IKEv2 with a Diffie-Hellman group for the IKE SA and a separate Diffie-Hellman group for the CHILD_SA.
C.Use IKEv2 with RSA signatures for authentication and no additional Diffie-Hellman exchange after the initial IKE SA.
D.Use IKEv1 in main mode with pre-shared keys and no DH group for the quick mode.
AnswerB

Perfect forward secrecy is achieved when each session key is derived from a fresh Diffie-Hellman exchange rather than from a long-term key. In IKEv2, using a DH group for the IKE SA and a distinct DH group for the CHILD_SA ensures that compromise of the IKE SA key does not compromise the IPsec session keys. This provides the required PFS.

Why this answer

Perfect forward secrecy requires that each IPsec session key be derived from a fresh, ephemeral Diffie-Hellman exchange. In IKEv2, configuring separate DH groups for the IKE SA and the CHILD_SA ensures that even if the IKE SA key is compromised, past and future child session keys remain protected. Static keys and configurations without a child DH exchange do not provide this property.

Exam trap

The trap here is assuming that using strong authentication or a strong cipher automatically provides perfect forward secrecy, when PFS specifically requires an ephemeral Diffie-Hellman exchange for each session.

54
MCQhard

A security professional is designing a key management system and needs to ensure that keys are generated using a truly random source. Which of the following is the most appropriate method for generating cryptographic keys?

A.Hardware random number generator
B.Cryptographically secure PRNG seeded with a static password
C.Pseudorandom number generator (PRNG) seeded with current timestamp
D.User-memorized passphrase
AnswerA

A hardware random number generator derives entropy from physical phenomena, producing non-deterministic output. Software generators are deterministic algorithms, so only a hardware source satisfies the requirement for a truly random seed for cryptographic key generation.

Why this answer

A hardware random number generator (HRNG) uses a physical entropy source (e.g., thermal noise, quantum effects) to produce truly random numbers, making it the most appropriate for generating cryptographic keys. Cryptographic keys require high entropy and unpredictability; HRNGs provide true randomness, unlike deterministic PRNGs.

Exam trap

SSCP often tests the difference between true random and pseudorandom sources — candidates pick a PRNG seeded with a timestamp or password because it sounds random, but cryptographic keys require a truly random source like a hardware RNG.

How to eliminate wrong answers

Option B is wrong because a cryptographically secure PRNG seeded with a static password is deterministic and the static password is a weak, low-entropy seed, making keys predictable. Option C is wrong because a PRNG seeded with the current timestamp is predictable (timestamps are guessable) and not cryptographically secure. Option D is wrong because a user-memorized passphrase is low-entropy and subject to dictionary attacks; it is not a random source.

55
MCQhard

A company deploys a VPN gateway that uses Diffie-Hellman key exchange to establish session keys. A security auditor warns that the gateway is vulnerable to a man-in-the-middle attack during key agreement. Which of the following should the administrator implement to mitigate this risk?

A.Increase the Diffie-Hellman group to 8192-bit MODP
B.Configure the gateway to use static Diffie-Hellman keys
C.Deploy certificates and use authenticated Diffie-Hellman
D.Enable perfect forward secrecy on the VPN gateway
AnswerC

Authenticated Diffie-Hellman binds the exchange to verified identities using digital certificates, preventing an attacker from substituting keys. By validating each peer's certificate, the VPN gateway ensures it shares a key only with the legitimate party, directly mitigating the man-in-the-middle risk described by the auditor.

Why this answer

The vulnerability exists because unauthenticated Diffie-Hellman allows an attacker to impersonate each party. Using certificates to authenticate the exchange ensures that each side verifies the other's identity before deriving session keys. Larger groups, perfect forward secrecy, or static keys do not by themselves prevent impersonation, so authenticated Diffie-Hellman is the required mitigation.

Exam trap

The trap here is assuming that increasing key size or enabling perfect forward secrecy provides authentication, when these properties are independent of identity verification.

56
MCQeasy

Which of the following is a secure alternative to RC4 for stream ciphers?

A.MD5
B.AES in ECB mode
C.ChaCha20
D.3DES
AnswerC

ChaCha20 is a modern stream cipher offering strong resistance to cryptanalysis, unlike RC4 whose keystream biases render it insecure. It satisfies the stem's demand for a secure stream cipher alternative, and is standardised for use in TLS.

Why this answer

ChaCha20 is a modern, high-speed stream cipher designed by Daniel J. Bernstein as a secure alternative to RC4, which has known vulnerabilities such as biases in its keystream and susceptibility to attacks like the Fluhrer-Mantin-Shamir attack. ChaCha20 is standardized in RFC 8439 and is widely used in TLS 1.3 and SSH, offering strong security and performance without the weaknesses of RC4.

Exam trap

A common mistake in this exam is confusing block cipher modes like ECB or hash functions like MD5 with stream ciphers. The correct answer must be a dedicated stream cipher that operates similarly to RC4, such as ChaCha20.

How to eliminate wrong answers

Option A is wrong because MD5 is a cryptographic hash function, not a stream cipher, and it is broken for collision resistance. Option B is wrong because AES in ECB mode is a block cipher mode that encrypts each block independently, making it deterministic and insecure for patterns, not a stream cipher; it also lacks the keystream generation property of RC4. Option D is wrong because 3DES is a block cipher (not a stream cipher) and is deprecated due to its small 56-bit effective key size and vulnerability to meet-in-the-middle attacks.

57
MCQmedium

A security administrator is configuring a new wireless network that must use a protocol providing strong encryption and mutual authentication. The organization requires that the solution support AES-CCMP and be based on the IEEE 802.11i standard. Which protocol should the administrator implement?

A.WPA-Personal
B.WPA2-Enterprise
C.WEP
D.WPA3-Personal
AnswerB

WPA2-Enterprise implements the IEEE 802.11i standard and mandates AES-CCMP for encryption. It supports mutual authentication through 802.1X and EAP methods, allowing the client and server to authenticate each other. This meets the requirements for strong encryption and mutual authentication in a wireless network.

Why this answer

WPA2-Enterprise is based on IEEE 802.11i and uses AES-CCMP for encryption. It supports mutual authentication through 802.1X and EAP, making it suitable for enterprise wireless networks. The other options either lack mutual authentication (WPA-Personal, WPA3-Personal) or are insecure and outdated (WEP).

Exam trap

The trap here is assuming that any WPA2 or WPA3 variant provides mutual authentication, when only enterprise modes with 802.1X do.

58
MCQmedium

An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?

A.Only the root CA certificate
B.End-entity certificate, intermediate CA certificate, and root CA certificate
C.Only the end-entity certificate and the root CA certificate
D.Only the end-entity certificate and the intermediate CA certificate
AnswerB

Validation requires the full chain from the end-entity certificate up through the issuing intermediate CA to the trusted root CA, because each signature must be verified against its issuer's public key until a trust anchor is reached.

Why this answer

In a PKI hierarchy, the chain of trust requires each certificate in the path to be validated up to a trusted root. The client must have the end-entity certificate, the intermediate CA certificate (to verify the end-entity's signature), and the root CA certificate (to verify the intermediate CA's signature). Without the intermediate CA certificate, the client cannot cryptographically link the end-entity to the root, breaking the chain.

Exam trap

The trap here is that candidates often assume the root CA directly signs all certificates, forgetting that intermediate CAs are used in practice, so they incorrectly select Option C or D, missing the need for the full chain.

How to eliminate wrong answers

Option A is wrong because the root CA certificate alone cannot verify the end-entity certificate's signature, which was issued by the intermediate CA, not the root. Option C is wrong because omitting the intermediate CA certificate leaves a gap in the chain; the client cannot validate the intermediate CA's signature on the end-entity certificate. Option D is wrong because without the root CA certificate, the client cannot verify the intermediate CA certificate's signature, so the chain of trust cannot be anchored to a trusted root.

59
MCQhard

A security engineer is implementing a cryptographic system that requires both confidentiality and integrity. The engineer decides to use AES-256 in Galois/Counter Mode (GCM). Which of the following statements about GCM is true?

A.GCM provides authentication but not confidentiality.
B.GCM is vulnerable to padding oracle attacks.
C.GCM can only be used with block sizes of 128 bits.
D.GCM requires a unique nonce for each encryption operation under the same key.
AnswerD

GCM is a nonce-based authenticated encryption mode. Reusing a nonce with the same key is catastrophic: it allows an attacker to recover the authentication key and potentially forge messages. Therefore, it is critical that each encryption operation uses a unique nonce. This is a fundamental requirement for the security of GCM.

Why this answer

GCM is an authenticated encryption mode that provides confidentiality and integrity. It requires a unique nonce for each encryption under the same key; nonce reuse compromises the authentication key and allows forgery. GCM does not use padding, so it is not susceptible to padding oracle attacks.

It is designed for 128-bit block ciphers like AES.

Exam trap

The trap here is assuming that GCM, like CBC, is vulnerable to padding oracle attacks or that it does not provide confidentiality.

60
MCQhard

A security analyst is reviewing a proposed cryptographic design for a new messaging application. The design uses AES-256 in Galois/Counter Mode (GCM) for confidentiality and integrity, but the analyst notices that the same nonce is generated for multiple messages under the same key. What is the MOST likely security consequence of this flaw?

A.The integrity protection is broken, allowing an attacker to forge authentication tags and inject messages.
B.The performance of the encryption degrades because the nonce is used to seed the counter, causing counter collisions.
C.The confidentiality of the messages is lost because the keystream is reused, allowing XOR-based plaintext recovery.
D.The encryption key is immediately exposed, requiring rekeying of all sessions.
AnswerA

In GCM, nonce reuse under the same key is catastrophic because it allows an attacker to recover the authentication subkey H and forge valid tags. This breaks integrity and authenticity, enabling injection of arbitrary messages without detection. While confidentiality is also compromised, the primary and most severe consequence is the loss of integrity, which undermines the entire security guarantee of the messaging application.

Why this answer

In AES-GCM, the nonce must be unique for each encryption under a given key. Reusing a nonce allows an attacker to recover the GHASH subkey H and forge authentication tags, completely breaking integrity and authenticity. Although confidentiality is also weakened because the keystream repeats, the most critical consequence is the ability to inject undetected messages, which invalidates the application's trust model.

Exam trap

The trap here is focusing only on confidentiality loss from keystream reuse and overlooking that nonce reuse in GCM destroys integrity by enabling tag forgery.

61
MCQeasy

Which protocol is used to provide secure remote shell access and replace Telnet?

A.SFTP
B.SSH
C.IPsec
D.HTTPS
AnswerB

SSH encrypts the entire session, including authentication credentials and commands, whereas Telnet transmits them in cleartext. This satisfies the stem's requirement for secure remote shell access and Telnet replacement. Operating over TCP port 22, SSH provides confidentiality and integrity that Telnet fundamentally lacks.

Why this answer

SSH (Secure Shell) is the correct answer because it provides encrypted remote shell access and command execution, replacing the insecure Telnet protocol which transmits data in cleartext. SSH uses public-key cryptography for authentication and symmetric encryption (e.g., AES, ChaCha20) for session confidentiality, as defined in RFC 4251.

Exam trap

In the SSCP exam, candidates often confuse SSH (remote shell) with SFTP (file transfer), mistakenly thinking SFTP is a replacement for Telnet when it actually relies on SSH for its secure transport.

How to eliminate wrong answers

Option A (SFTP) is wrong because SFTP (SSH File Transfer Protocol) is a file transfer protocol that runs over SSH, not a remote shell access protocol; it is used for secure file operations, not interactive shell sessions. Option C (IPsec) is wrong because IPsec is a network-layer security protocol suite used for encrypting IP packets (e.g., in VPNs), not for providing remote shell access or replacing Telnet. Option D (HTTPS) is wrong because HTTPS is HTTP over TLS, designed for secure web browsing, not for remote shell access or command-line interaction.

62
Multi-Selectmedium

A security administrator is evaluating encryption protocols for email communication. Which of the following protocols can secure email in transit? (Select TWO)

Select 2 answers
A.IMAPS
B.HTTPS
C.SSH
D.SMTPS
E.SFTP
AnswersA, D

IMAPS wraps IMAP within TLS, encrypting mail retrieval between client and server on port 993. This protects credentials and message content in transit, satisfying the requirement to secure email communication against interception during mailbox access.

Why this answer

IMAPS (Option A) is correct because it wraps the IMAP mail-retrieval protocol inside TLS (typically on TCP port 993), encrypting the client-to-server session so credentials and message contents are protected in transit. SMTPS (Option D) is correct because it applies TLS to SMTP (commonly on TCP port 465, or via STARTTLS on 587/25), securing the transport of outgoing email between mail clients and servers or between mail relays. HTTPS (Option B) secures web traffic via TLS but is not an email transport protocol, so it does not directly secure email in transit.

SSH (Option C) provides an encrypted remote-shell/tunneling channel and is not an email protocol, and SFTP (Option E) is a file-transfer protocol over SSH, unrelated to securing email delivery.

Exam trap

A common challenge on the SSCP exam is distinguishing between protocols that secure email in transit (IMAPS, SMTPS) versus protocols that secure other services (HTTPS for web, SSH for remote access, SFTP for file transfer). Candidates may confuse secure versions of unrelated protocols.

63
MCQmedium

A security engineer is designing a system that requires non-repudiation of data origin. Which cryptographic technique should be used?

A.Keyed hash (HMAC)
B.Digital signature using RSA or ECDSA
C.Hash function only
D.Symmetric encryption with a shared key
AnswerB

A digital signature binds the signer's private key to the message, letting any verifier confirm origin and integrity with the public key while the signer cannot later deny signing. RSA and ECDSA both provide this non-repudiation property.

Why this answer

Digital signatures using RSA or ECDSA provide non-repudiation of data origin because they bind the signer's identity to the data through a private key that only the signer possesses. The recipient can verify the signature with the corresponding public key, and the signer cannot later deny having signed the data, as the private key is uniquely under their control. This meets the legal and technical requirement for non-repudiation, unlike symmetric or hash-only methods.

Exam trap

The trap here is that candidates confuse integrity (provided by HMAC or hash) with non-repudiation, or assume a shared secret (HMAC or symmetric encryption) can prove origin, but only asymmetric digital signatures satisfy the legal requirement of non-repudiation.

How to eliminate wrong answers

Option A is wrong because a keyed hash (HMAC) uses a shared secret key between sender and receiver, which cannot prove which party generated the MAC, thus failing to provide non-repudiation. Option C is wrong because a hash function alone provides integrity but no authentication or proof of origin, as anyone can compute the same hash. Option D is wrong because symmetric encryption with a shared key does not provide non-repudiation; both parties possess the same key, so the sender can deny creating the ciphertext.

64
MCQmedium

A security engineer is deploying a new VPN concentrator that must use a symmetric encryption algorithm approved by NIST for protecting sensitive government data. The algorithm must operate as a block cipher with a 128-bit block size and support key sizes of 128, 192, and 256 bits. Which algorithm should the engineer select?

A.RSA
B.Blowfish
C.AES
D.3DES
AnswerC

AES is a symmetric block cipher standardized by NIST (FIPS 197) with a 128-bit block size and supported key sizes of 128, 192, and 256 bits. It is approved for protecting sensitive government data up to Top Secret when used with appropriate key lengths. This matches the engineer's requirements exactly.

Why this answer

AES is the only NIST-approved symmetric block cipher that meets all stated requirements: 128-bit block size and support for 128-, 192-, and 256-bit keys. It is widely implemented in VPN concentrators and is suitable for protecting sensitive government data. The other algorithms either have smaller block sizes, are asymmetric, or lack NIST approval for this use case.

Exam trap

The trap here is assuming that any well-known symmetric cipher is NIST-approved for government data, when only AES meets the block size and key length requirements.

65
MCQeasy

A security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?

A.3DES-CBC
B.AES-ECB
C.RC4
D.AES-GCM
AnswerD

AES-GCM is a block cipher in Galois/Counter Mode, providing authenticated encryption: confidentiality plus an authentication tag verifying integrity and origin. This satisfies the stem's dual requirement for confidentiality and authentication in one symmetric primitive, unlike CBC or CTR, which lack built-in authentication.

Why this answer

AES-GCM (Galois/Counter Mode) is a symmetric encryption algorithm that provides both confidentiality and authentication in a single, efficient operation. It combines AES encryption in counter mode with a Galois field-based message authentication code (GMAC), making it ideal for applications requiring both security properties.

Exam trap

The trap here is that candidates often confuse CBC mode with providing authentication (since it uses an IV), but CBC only offers confidentiality; GCM is the correct choice for combined confidentiality and authentication in symmetric encryption.

How to eliminate wrong answers

Option A is wrong because 3DES-CBC provides only confidentiality, not authentication; CBC mode requires a separate MAC (e.g., HMAC) to ensure integrity and authenticity, and 3DES is deprecated due to its 64-bit block size and slow performance. Option B is wrong because AES-ECB is deterministic and does not provide authentication; it encrypts identical plaintext blocks into identical ciphertext blocks, leaking patterns and lacking any integrity check. Option C is wrong because RC4 is a stream cipher that provides only confidentiality, not authentication, and is considered broken due to biases in its output (e.g., RC4 biases in TLS), making it unsuitable for secure applications.

Ready to test yourself?

Try a timed practice session using only Cryptography questions.