Courseiva

SSCP · topic practice

Cryptography practice questions

Cryptography is 9% of the SSCP exam, covering symmetric and asymmetric encryption, hashing, PKI, digital certificates, and secure protocols. Questions are scenario-based: you pick the right algorithm, mode, or protocol for a stated goal such as confidentiality, integrity, authentication, or nonrepudiation, and you distinguish closely related technologies.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cryptography

What the exam tests

What to know about Cryptography

Be able to match a security goal to the correct cryptographic tool: symmetric or asymmetric encryption for confidentiality, hashing or HMAC for integrity, and PKI services such as OCSP for certificate status. The key skill is selecting the right algorithm, mode, or protocol for the scenario.

Symmetric algorithms (AES, 3DES) versus asymmetric algorithms (RSA, ECC) and when each applies

Hashing (SHA-2, SHA-3) for integrity and HMAC for authenticated integrity checks

PKI components: CA, RA, CRL, OCSP, and certificate lifecycle and validation

Secure transport and email protocols: TLS, IPsec, S/MIME, PGP, SFTP, and SSH

Watch out for

Common Cryptography exam traps

  • ▸Confusing encryption with hashing: hashing provides integrity, not confidentiality, and is not reversible.
  • ▸Assuming a CRL is required to check revocation when OCSP provides online, real-time status without the full list.
  • ▸Mixing up encryption modes, such as choosing CBC or ECB when authenticated encryption like GCM is required.

Practice set

Cryptography questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full Cryptography explanation →

A security administrator is configuring a web server to use TLS. They want to optimize performance while maintaining strong security. Which cipher suite should they prioritize?

Question 2mediummulti select
Read the full Cryptography explanation →

A security team is evaluating hashing algorithms for use in a new system. Which of the following are considered currently secure for general use? (Select TWO)

Question 3mediummultiple choice
Read the full Cryptography explanation →

An organization is moving away from legacy encryption and wants to avoid stream ciphers due to known vulnerabilities. Which of the following algorithms should be avoided because it is a stream cipher with known weaknesses like the BEAST attack?

Question 4mediummulti select
Read the full Cryptography explanation →

An organization is implementing a digital signature solution to ensure non-repudiation and integrity of documents. Which three of the following are true regarding digital signatures?

Question 5hardmultiple choice
Read the full Cryptography explanation →

A security engineer is designing a system that must securely store encryption keys used for data-at-rest encryption. The keys must be protected against extraction even if the host is compromised, and the solution must support hardware-based key generation and storage. Which technology should the engineer implement?

Question 6mediummultiple choice
Read the full Cryptography explanation →

A financial institution wants to ensure that a large file transferred between two branches has not been altered in transit. The security team decides to use a cryptographic hash function. Which of the following properties of the hash function is most critical for detecting accidental or malicious modifications?

Question 7mediummulti select
Read the full VPN explanation →

A security team is deploying a VPN that uses IPsec in tunnel mode. The team must ensure the VPN provides confidentiality, integrity, and authentication of data in transit. Which two of the following components should be used to meet these requirements? (Choose two.)

Question 8mediummultiple choice
Read the full Cryptography explanation →

A healthcare organization must ensure that stored patient records remain confidential even if an attacker gains physical access to the storage array and removes the disks. The security team wants to use full-disk encryption with a hardware module that protects the encryption keys and performs cryptographic operations independently of the host CPU. Which technology BEST meets these requirements?

Question 9mediummulti select
Read the full Cryptography explanation →

A security administrator is implementing cryptographic controls for a new application that stores sensitive customer data. The administrator must ensure that data at rest is encrypted and that any tampering can be detected. Which two of the following should the administrator implement to meet these requirements? (Choose two.)

Question 10easymultiple choice
Read the full Cryptography explanation →

A security analyst is recommending a symmetric encryption algorithm for a new application that requires both confidentiality and authentication. Which algorithm and mode combination should they select?

Question 11mediummultiple choice
Read the full Cryptography explanation →

An organization is implementing a digital signature solution to ensure non-repudiation of documents. Which combination of keys is used during the signing process?

Question 12mediummultiple choice
Read the full VPN explanation →

A company is deploying a VPN using IPsec. They want to ensure that even if the private key of the server is compromised, past session keys cannot be derived. Which key exchange method should they use?

Question 13easymultiple choice
Read the full Cryptography explanation →

Which of the following hash algorithms is considered cryptographically broken and should be avoided due to collision attacks?

Question 14mediummultiple choice
Read the full Cryptography explanation →

An organization uses a PKI with a root CA that issues certificates to intermediate CAs, which then issue end-entity certificates. A client receives an end-entity certificate signed by an intermediate CA. During validation, which certificates are required to build the chain of trust?

Question 15mediummultiple choice
Read the full Cryptography explanation →

A security engineer needs to choose an asymmetric algorithm for a system with limited computational resources, such as an IoT device. The algorithm must provide equivalent security to RSA 2048-bit while using smaller key sizes. Which algorithm should they choose?

Question 16hardmultiple choice
Read the full Cryptography explanation →

A security auditor reviews a system that uses HMAC-SHA256 for message authentication. Which property does HMAC provide that a simple hash of the message does not?

Question 17easymultiple choice
Read the full Cryptography explanation →

Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?

Question 18mediummultiple choice
Read the full Cryptography explanation →

A company wants to implement a key management system. They need to generate cryptographic keys that are unpredictable. Which source of randomness should be used?

Question 19hardmultiple choice
Read the full Cryptography explanation →

A certificate authority (CA) issues a certificate with the extended key usage (EKU) extension specifying 'serverAuth'. Which of the following is this certificate allowed to do?

Question 20easymultiple choice
Read the full Cryptography explanation →

Which of the following is a method to check the revocation status of a digital certificate in real-time without the client downloading a full list?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cryptography sessions

Start a Cryptography only practice session

Every question in these sessions is drawn from the Cryptography domain — nothing else.

Related practice questions

Related SSCP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SSCP exam test about Cryptography?
Be able to match a security goal to the correct cryptographic tool: symmetric or asymmetric encryption for confidentiality, hashing or HMAC for integrity, and PKI services such as OCSP for certificate status. The key skill is selecting the right algorithm, mode, or protocol for the scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cryptography questions in a focused session?
Yes — the session launcher on this page draws every question from the Cryptography domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SSCP topics?
Use the topic links above to move to related areas, or go back to the SSCP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SSCP exam covers. They are not copied from any real exam or dump site.