🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An enterprise is setting up an offline root CA to issue code-signing certificates. Compliance demands that the CA's private key be resistant to disclosure and generated with high-quality entropy. Which approach BEST meets secure key generation and composition requirements for this scenario?

  • Generate a 2048-bit RSA key pair on an administrator's workstation using OpenSSL, then transfer the private key to the CA over an encrypted SSH session.

  • Derive the private key from a strong passphrase with PBKDF2 and archive the resulting key in an encrypted ZIP file on a network share.

  • Accept the CA software's default 1024-bit RSA key pair created during installation and store the private key on the system drive of the CA server.

  • Generate a 2048-bit RSA key pair entirely within an offline FIPS 140-2 Level 3 HSM and escrow the private key by cloning it to a second HSM stored securely off-site.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot