SSCP Cryptography Practice Question
Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?
⚠ Common exam trap
Candidates often confuse Telnet with SSH or think that FTP or HTTP can be used for remote administration, but the question specifically asks for a secure replacement for Telnet, which is SSH.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH
SSH (Secure Shell) is the correct answer because it provides encrypted remote administration capabilities, replacing insecure protocols like Telnet that transmit data in plaintext. SSH uses public-key cryptography for authentication and symmetric encryption (e.g., AES, ChaCha20) for session confidentiality, protecting against eavesdropping and man-in-the-middle attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FTP
Why it's wrong here
FTP sends credentials and file contents unencrypted and provides file transfer, not interactive remote command execution. It is tempting because it is a standard administrative file-transfer tool, and would be correct when replaced by FTPS or SFTP for encrypted bulk file movement to a server.
- ✓
SSH
Why this is correct
SSH encrypts the entire session, including authentication credentials and commands, over TCP port 22. Telnet transmits everything in cleartext, exposing passwords to sniffing. SSH's host key verification and encrypted channel satisfy the requirement for secure remote administration.
- ✗
HTTP
Why it's wrong here
HTTP carries no transport encryption, so credentials and commands cross the network in cleartext; it also lacks a remote shell mechanism. It is tempting because HTTP underpins web-based management consoles, and would be right when secured as HTTPS for browser administration rather than command-line access.
- ✗
Telnet
Why it's wrong here
Telnet transmits credentials and session data in cleartext, so it is the insecure protocol being replaced, not a secure alternative. It is tempting because Telnet genuinely provides remote shell administration, and would be acceptable only on an isolated, trusted management network where encryption is handled by another layer.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.