SSCP Cryptography Practice Question
Which of the following is a secure alternative to RC4 for stream ciphers?
⚠ Common exam trap
A common mistake in this exam is confusing block cipher modes like ECB or hash functions like MD5 with stream ciphers. The correct answer must be a dedicated stream cipher that operates similarly to RC4, such as ChaCha20.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ChaCha20
ChaCha20 is a modern, high-speed stream cipher designed by Daniel J. Bernstein as a secure alternative to RC4, which has known vulnerabilities such as biases in its keystream and susceptibility to attacks like the Fluhrer-Mantin-Shamir attack. ChaCha20 is standardized in RFC 8439 and is widely used in TLS 1.3 and SSH, offering strong security and performance without the weaknesses of RC4.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MD5
Why it's wrong here
MD5 is a 128-bit hash producing a fixed digest, not a cipher; it has no key or keystream and cannot encrypt data at all. It would be selected for integrity checking or password storage, never as a confidentiality mechanism replacing RC4 in a stream context.
- ✗
AES in ECB mode
Why it's wrong here
AES is a block cipher, and ECB mode encrypts each 16-byte block independently with no keystream or chaining, so it is not a stream cipher and leaks identical plaintext blocks. It suits bulk data at rest where parallel block processing is wanted, not RC4's byte-wise streaming role.
- ✓
ChaCha20
Why this is correct
ChaCha20 is a modern stream cipher offering strong resistance to cryptanalysis, unlike RC4 whose keystream biases render it insecure. It satisfies the stem's demand for a secure stream cipher alternative, and is standardised for use in TLS.
- ✗
3DES
Why it's wrong here
3DES is a 64-bit block cipher built from DES's Feistel network, so it processes fixed blocks with padding rather than a continuous keystream. It cannot substitute for a stream cipher in byte-oriented or real-time pipelines. It would be chosen to extend legacy DES deployments, not to replace RC4's streaming behaviour.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.