Courseiva
Cryptography →easyMultiple Choice

SSCP Cryptography Practice Question

What is the minimum recommended RSA key size for secure use as of current best practices?

⚠ Common exam trap

Candidates often mistake that larger keys are always better, leading them to choose 4096 bits as the minimum, when in fact 2048 bits is the officially recommended baseline for secure use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

2048 bits

(2048 bits) is correct because current best practices, as recommended by NIST SP 800-57 and other cryptographic standards, consider 2048-bit RSA keys as the minimum secure size for protecting data through 2030. This key length provides a sufficient security margin against known factoring attacks, balancing computational efficiency with cryptographic strength.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    1024 bits

    Why it's wrong here

    1024-bit RSA is deprecated and factorable with sufficient resources, falling below the 2048-bit minimum in NIST SP 800-57. It is tempting because legacy systems and older certificates still use it, and it would satisfy compatibility requirements only where no current security standard applies.

  • ✗

    4096 bits

    Why it's wrong here

    4096-bit RSA exceeds the 2048-bit minimum, so it is stronger than required rather than the minimum itself. It is tempting because larger keys are perceived as safer, and 4096 bits would be the right choice for long-lived root CA keys or high-assurance environments.

  • ✗

    3072 bits

    Why it's wrong here

    3072-bit RSA provides roughly 128-bit security, matching the minimum for new systems only from 2031 onward; current guidance sets 2048 bits as the floor. It is tempting because 3072 bits is the recommended size for a longer lifespan, and it would be correct for keys intended to remain secure beyond 2030.

  • ✓

    2048 bits

    Why this is correct

    2048-bit RSA is the current minimum recommended size; smaller keys such as 1024-bit are considered cryptographically weak against modern factoring attacks. This satisfies the stem's requirement for the minimum secure key length under current best practise.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.