hardMultiple SelectObjective-mapped
SSCP Practice Question: Which TWO are security implications of using…
Which TWO are security implications of using deprecated cryptographic protocols such as SSL 3.0 and TLS 1.0?
⚠ Common exam trap
ISC2 often tests the misconception that deprecated protocols are 'still secure enough' or that their only downside is performance overhead, but the real trap is that candidates confuse 'interoperability issues' (which are a practical concern) with 'security implications' (which are the core focus of the question).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Susceptibility to downgrade attacks
Deprecated protocols such as SSL 3.0 and TLS 1.0 have well-known security vulnerabilities. Option A is correct because these protocols are susceptible to downgrade attacks (e.g., POODLE) where an attacker forces the use of the weaker protocol. Option D is correct because they often employ weak key exchange algorithms, making encrypted communications easier to decrypt. Option E is incorrect because interoperability issues are a practical concern, not a direct security implication; the question specifically asks for security implications. Options B and C are not security implications: increased computational overhead is a performance issue, and compliance with regulations refers to legal requirements, not inherent security flaws.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Susceptibility to downgrade attacks
Why this is correct
Correct. Deprecated protocols like SSL 3.0 and TLS 1.0 are vulnerable to downgrade attacks (e.g., POODLE), where an active attacker forces the client and server to negotiate a weaker protocol, exploiting known weaknesses.
- ✗
Increased computational overhead
Why it's wrong here
Incorrect. Increased computational overhead is a performance concern, not a direct security implication. It may result from inefficiencies but does not represent a security flaw.
- ✗
Compliance with regulations
Why it's wrong here
Incorrect. Compliance with regulations is a legal/regulatory matter; while using deprecated protocols may violate compliance standards, the question asks for security implications of the protocols themselves.
- ✓
Weak key exchange
Why this is correct
Correct. Weak key exchange mechanisms in deprecated protocols allow attackers to decrypt traffic more easily, compromising confidentiality.
- ✗
Interoperability issues with modern systems
Why it's wrong here
Incorrect. Interoperability issues with modern systems are a practical concern, not a security implication. The question specifically asks for security implications, so this option does not apply.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.