Courseiva
Cryptography →easyMultiple Choice

SSCP Cryptography Practice Question

Which of the following is a secure protocol for remote administration of a server, replacing insecure protocols like Telnet?

⚠ Common exam trap

Candidates often confuse Telnet with SSH or think that FTP or HTTP can be used for remote administration, but the question specifically asks for a secure replacement for Telnet, which is SSH.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH

SSH (Secure Shell) is the correct answer because it provides encrypted remote administration capabilities, replacing insecure protocols like Telnet that transmit data in plaintext. SSH uses public-key cryptography for authentication and symmetric encryption (e.g., AES, ChaCha20) for session confidentiality, protecting against eavesdropping and man-in-the-middle attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FTP

    Why it's wrong here

    FTP sends credentials and file contents unencrypted and provides file transfer, not interactive remote command execution. It is tempting because it is a standard administrative file-transfer tool, and would be correct when replaced by FTPS or SFTP for encrypted bulk file movement to a server.

  • ✓

    SSH

    Why this is correct

    SSH encrypts the entire session, including authentication credentials and commands, over TCP port 22. Telnet transmits everything in cleartext, exposing passwords to sniffing. SSH's host key verification and encrypted channel satisfy the requirement for secure remote administration.

  • ✗

    HTTP

    Why it's wrong here

    HTTP carries no transport encryption, so credentials and commands cross the network in cleartext; it also lacks a remote shell mechanism. It is tempting because HTTP underpins web-based management consoles, and would be right when secured as HTTPS for browser administration rather than command-line access.

  • ✗

    Telnet

    Why it's wrong here

    Telnet transmits credentials and session data in cleartext, so it is the insecure protocol being replaced, not a secure alternative. It is tempting because Telnet genuinely provides remote shell administration, and would be acceptable only on an isolated, trusted management network where encryption is handled by another layer.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.