hardMultiple Choice
SSCP Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. crypto isakmp policy 10 authentication pre-share encryption aes 256 hash sha group 14 lifetime 3600 crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0
Refer to the exhibit. A network administrator is reviewing the VPN configuration on a site-to-site VPN hub. Which of the following is the most significant security vulnerability in this configuration?
⚠ Common exam trap
SSCP often tests the identification of misconfigurations that lead to security vulnerabilities, and candidates may focus on encryption algorithms or key length while missing the overly permissive peer address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pre-shared key is applied to all potential peers due to the wildcard address
The most significant security vulnerability is that the pre-shared key is applied to all potential peers due to the wildcard address. This means any peer with the correct PSK can establish a VPN connection, potentially allowing unauthorized access. The wildcard address (0.0.0.0/0) in the peer configuration is overly permissive and should be restricted to specific IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The encryption algorithm AES-256 is too weak
Why it's wrong here
AES-256 is a strong symmetric cipher, so labelling it weak misreads the exhibit. This option tempts candidates who assume any listed algorithm is suspect. AES-256 would be questioned only if the exhibit showed a deprecated mode such as ECB or a truncated key length.
- ✓
The pre-shared key is applied to all potential peers due to the wildcard address
Why this is correct
A wildcard peer address combined with one shared pre-shared key means any remote endpoint matching that wildcard can authenticate using the same secret. This collapses peer identity into a single credential, so compromise of one site's key grants access to every tunnel, defeating per-peer authentication.
- ✗
The hash algorithm SHA is insecure
Why it's wrong here
SHA (Secure Hash Algorithm) is a family of secure cryptographic hash functions. The specific version (SHA-1 or SHA-2) is not specified, but SHA in general is considered secure for IKE. The vulnerability is not in the hash algorithm.
- ✗
The pre-shared key is too short and easily guessable
Why it's wrong here
A short pre-shared key weakens authentication, but the exhibit's configuration flaw concerns the tunnel's encryption or integrity settings. Key length matters where PSK strength is the only authentication control; here the more significant vulnerability lies in the protocol parameters shown.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.