SSCP Network and Communications Security Practice Question
Which protocol is used to securely transfer files between a client and server, typically over TCP port 22?
⚠ Common exam trap
SSCP often tests the port-to-protocol mapping and the secure-vs-insecure distinction — candidates may pick FTP because it is the 'file transfer' protocol, missing that the question specifies 'securely' and 'port 22'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH
SSH (Secure Shell) operates over TCP port 22 and provides an encrypted channel for secure file transfer (via SFTP or SCP) as well as remote shell access. Its encryption and host authentication replace the cleartext credentials and data of legacy protocols like FTP and Telnet. This makes SSH the correct answer for secure file transfer on port 22.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SMTP
Why it's wrong here
SMTP carries email between mail servers on TCP port 25, not encrypted file transfers on port 22. It tempts because it does move data between hosts, but that data is mail messages, not files, and no SSH tunnel or SFTP subsystem is involved.
- ✗
TFTP
Why it's wrong here
TFTP moves files over UDP port 69 with no authentication or encryption, so it cannot satisfy the secure, TCP port 22 requirement. It tempts as a genuine file-transfer protocol, and would fit trivial firmware or configuration pushes on a trusted LAN.
- ✓
SSH
Why this is correct
SSH provides an encrypted channel over TCP port 22 and includes SFTP and SCP for secure file transfer. Unlike FTPS, which uses TLS on different ports, SSH natively satisfies the port 22 and encryption requirements stated in the question.
- ✗
FTP
Why it's wrong here
FTP transmits credentials and data in cleartext and listens on port 21, not 22; SFTP over SSH satisfies the port 22 requirement. FTP is tempting for legacy scripted transfers, but it provides no encryption, so it fails the secure-transfer criterion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.