easyMultiple Select
SSCP Practice Question: Which TWO of the following are common weaknesses…
Which TWO of the following are common weaknesses in cryptographic implementations that an SSCP should be aware of? (Select exactly 2.)
⚠ Common exam trap
ISC2 often tests the misconception that 'using strong algorithms' or 'following standards' automatically guarantees security, when in fact implementation flaws like weak randomness or poor key management are the real vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Weak random number generation
Option A (Weak random number generation) is correct because cryptographic security depends on unpredictable entropy for generating keys, IVs, and nonces; if a weak or predictable PRNG (e.g., a non-cryptographic RNG or insufficient entropy source) is used, attackers can predict keys or nonces and break confidentiality or integrity. Option B (Improper key storage) is correct because even strong algorithms fail if keys are stored insecurely — for example, hard-coded in source, kept in plaintext, or left unprotected in memory or on disk — allowing attackers to recover keys and decrypt or forge data. The unmarked options do not represent weaknesses: frequent rekeying (C) actually limits exposure from key compromise, using proven algorithms like AES (D) is a recommended practice rather than a flaw, and following NIST guidelines (E) is a security best practice, not a common implementation weakness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Weak random number generation
Why this is correct
Weak random number generation undermines cryptographic strength because predictable or low-entropy values let attackers derive keys, nonces and session tokens. This satisfies the stem's focus on implementation weaknesses rather than algorithm design flaws, since even sound ciphers such as AES fail when their random inputs are guessable.
- ✓
Improper key storage
Why this is correct
Improper key storage exposes cryptographic keys to unauthorised parties, so encryption and signatures provide no protection once keys are read from unprotected files, memory or backups. The algorithm's strength is irrelevant when the secret itself is compromised.
- ✗
Frequent rekeying
Why it's wrong here
Rekeying at frequent intervals limits the data exposed per key, so it strengthens rather than weakens a cryptographic implementation. It is tempting because key rotation is a genuine control, and it would be the right answer if the question asked how to limit the impact of a compromised session key.
- ✗
Using proven encryption algorithms like AES
Why it's wrong here
AES is a vetted, publicly analysed block cipher, so selecting it removes algorithm weakness rather than introducing it. It is tempting because algorithm choice is a genuine implementation decision, and AES would be correct if the question asked which cipher to use for symmetric encryption of data at rest.
- ✗
Following NIST guidelines
Why it's wrong here
Adhering to NIST guidance hardens an implementation; it is the recommended baseline, not a weakness. It is tempting because standards documents do get applied incorrectly, and following NIST would be correct if the question asked how to select approved algorithms and key lengths for a system.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.