hardMultiple Select
SSCP Practice Question: Which TWO protocols are used to secure email…
Which TWO protocols are used to secure email communication at the message level?
⚠ Common exam trap
ISC2 often tests the distinction between transport-layer security (SSL/TLS) and message-level security (PGP/SMIME), so candidates mistakenly choose SSL/TLS because they associate it with email security (e.g., SMTPS), but it does not provide end-to-end message encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PGP
PGP (Pretty Good Privacy) and S/MIME (Secure/Multipurpose Internet Mail Extensions) are the two primary protocols that secure email at the message level. They encrypt the entire email body and attachments, ensuring end-to-end confidentiality and integrity regardless of the transport path. PGP uses a web of trust model, while S/MIME relies on a hierarchical public key infrastructure (PKI) with X.509 certificates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPsec
Why it's wrong here
IPsec operates at the network layer, encrypting all traffic between gateways or hosts, so it cannot selectively protect individual email messages across diverse mail relays. It is tempting because IPsec genuinely secures VPN tunnels and site-to-site links, which would be the right answer if the question asked about network-layer transport protection rather than message-level email security.
- ✓
PGP
Why this is correct
PGP provides message-level email security through encryption and digital signatures applied to the message content using a web-of-trust key model. This satisfies the stem's message-level constraint, since the payload remains protected end-to-end, unlike transport-layer mechanisms such as TLS that secure only the delivery channel.
- ✓
S/MIME
Why this is correct
S/MIME secures email at the message level by signing and encrypting the message body itself using X.509 certificates, so protection persists regardless of transport. This satisfies the stem's message-level constraint, unlike transport-layer protocols such as TLS or STARTTLS that only secure the connection between servers.
- ✗
SSL/TLS
Why it's wrong here
SSL/TLS secures the transport channel between mail clients and servers or between relays, leaving the message itself unprotected once it leaves that hop. It is tempting because TLS is widely deployed for SMTP transport encryption, and it would be correct if the question asked about channel-level rather than message-level email security.
- ✗
SSH
Why it's wrong here
SSH provides encrypted remote shell and file-transfer sessions, not message-level email protection, so it never secures SMTP message content between mail servers. It is tempting because SSH tunnelling can encrypt arbitrary traffic, and it would be the correct choice if the scenario required secure administrative access or port-forwarded transport rather than per-message email signing and encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.