Courseiva
hardMultiple SelectObjective-mapped

SSCP Practice Question: Which TWO are security implications of using…

Which TWO are security implications of using deprecated cryptographic protocols such as SSL 3.0 and TLS 1.0?

⚠ Common exam trap

ISC2 often tests the misconception that deprecated protocols are 'still secure enough' or that their only downside is performance overhead, but the real trap is that candidates confuse 'interoperability issues' (which are a practical concern) with 'security implications' (which are the core focus of the question).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Susceptibility to downgrade attacks

Deprecated protocols such as SSL 3.0 and TLS 1.0 have well-known security vulnerabilities. Option A is correct because these protocols are susceptible to downgrade attacks (e.g., POODLE) where an attacker forces the use of the weaker protocol. Option D is correct because they often employ weak key exchange algorithms, making encrypted communications easier to decrypt. Option E is incorrect because interoperability issues are a practical concern, not a direct security implication; the question specifically asks for security implications. Options B and C are not security implications: increased computational overhead is a performance issue, and compliance with regulations refers to legal requirements, not inherent security flaws.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Susceptibility to downgrade attacks

    Why this is correct

    Correct. Deprecated protocols like SSL 3.0 and TLS 1.0 are vulnerable to downgrade attacks (e.g., POODLE), where an active attacker forces the client and server to negotiate a weaker protocol, exploiting known weaknesses.

  • Increased computational overhead

    Why it's wrong here

    Incorrect. Increased computational overhead is a performance concern, not a direct security implication. It may result from inefficiencies but does not represent a security flaw.

  • Compliance with regulations

    Why it's wrong here

    Incorrect. Compliance with regulations is a legal/regulatory matter; while using deprecated protocols may violate compliance standards, the question asks for security implications of the protocols themselves.

  • Weak key exchange

    Why this is correct

    Correct. Weak key exchange mechanisms in deprecated protocols allow attackers to decrypt traffic more easily, compromising confidentiality.

  • Interoperability issues with modern systems

    Why it's wrong here

    Incorrect. Interoperability issues with modern systems are a practical concern, not a security implication. The question specifically asks for security implications, so this option does not apply.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.