Courseiva
hardMultiple Choice

SSCP Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.

crypto isakmp policy 10
 authentication pre-share
 encryption aes 256
 hash sha
 group 14
 lifetime 3600
crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0

Refer to the exhibit. A network administrator is reviewing the VPN configuration on a site-to-site VPN hub. Which of the following is the most significant security vulnerability in this configuration?

⚠ Common exam trap

SSCP often tests the identification of misconfigurations that lead to security vulnerabilities, and candidates may focus on encryption algorithms or key length while missing the overly permissive peer address.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pre-shared key is applied to all potential peers due to the wildcard address

The most significant security vulnerability is that the pre-shared key is applied to all potential peers due to the wildcard address. This means any peer with the correct PSK can establish a VPN connection, potentially allowing unauthorized access. The wildcard address (0.0.0.0/0) in the peer configuration is overly permissive and should be restricted to specific IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The encryption algorithm AES-256 is too weak

    Why it's wrong here

    AES-256 is a strong symmetric cipher, so labelling it weak misreads the exhibit. This option tempts candidates who assume any listed algorithm is suspect. AES-256 would be questioned only if the exhibit showed a deprecated mode such as ECB or a truncated key length.

  • ✓

    The pre-shared key is applied to all potential peers due to the wildcard address

    Why this is correct

    A wildcard peer address combined with one shared pre-shared key means any remote endpoint matching that wildcard can authenticate using the same secret. This collapses peer identity into a single credential, so compromise of one site's key grants access to every tunnel, defeating per-peer authentication.

  • ✗

    The hash algorithm SHA is insecure

    Why it's wrong here

    SHA (Secure Hash Algorithm) is a family of secure cryptographic hash functions. The specific version (SHA-1 or SHA-2) is not specified, but SHA in general is considered secure for IKE. The vulnerability is not in the hash algorithm.

  • ✗

    The pre-shared key is too short and easily guessable

    Why it's wrong here

    A short pre-shared key weakens authentication, but the exhibit's configuration flaw concerns the tunnel's encryption or integrity settings. Key length matters where PSK strength is the only authentication control; here the more significant vulnerability lies in the protocol parameters shown.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.