SSCP Cryptography Practice Question
Which of the following protocols is used to securely transfer files over SSH and is considered a replacement for FTP?
⚠ Common exam trap
SSCP often tests the confusion between SFTP, FTPS, and SCP — candidates see 'secure FTP' and pick FTPS or SCP, missing that the question specifies 'over SSH' and 'replacement for FTP,' which is SFTP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SFTP
SFTP (SSH File Transfer Protocol) is the protocol that runs over SSH to securely transfer files and is widely regarded as the secure replacement for FTP. It encrypts both commands and data within a single SSH connection, typically on port 22. HTTPS, IPsec, and SMTPS serve different purposes and are not FTP replacements over SSH.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPsec
Why it's wrong here
IPsec operates at the network layer, encrypting IP packets between gateways or hosts, and cannot itself transfer files or authenticate users. SFTP provides SSH-based file transfer. IPsec would be correct for building a VPN tunnel protecting all traffic between two sites, not for replacing FTP.
- ✗
HTTPS
Why it's wrong here
HTTPS secures web traffic between browsers and servers, transferring web content rather than providing an interactive file-transfer service over SSH. SFTP runs inside an SSH session for file operations. HTTPS would be the right answer for securing a web application or REST API, not for replacing FTP.
- ✓
SFTP
Why this is correct
SFTP tunnels file transfers through SSH on port 22, encrypting both commands and data in a single connection. This satisfies the stem's requirement for a secure FTP replacement, unlike FTPS, which wraps standard FTP in TLS across separate control and data channels. SFTP's SSH foundation delivers the confidentiality and integrity the scenario demands.
- ✗
SMTPS
Why it's wrong here
SMTPS secures email submission and relay over TLS, carrying messages between mail clients and servers, not files. SFTP is the SSH-based file transfer replacement for FTP. SMTPS would be correct when the requirement is encrypted SMTP mail transport, such as authenticated message submission on port 465.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.