StudyToCert

All certifications / SSCP / Lessons

ISC2 SSCP Oct 2025 outline · Domain 5: Cryptography

Forward secrecy and cipher suite choices

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Imagine an attacker records all of your organization's encrypted traffic for a year, then later steals the web server's private key. If the session keys were derived in a way that depends only on that long-term key, the attacker could go back and decrypt the whole archive. Forward secrecy, often called perfect forward secrecy (PFS), prevents this. With forward secrecy, each session uses a fresh, temporary key pair that is discarded afterward, so compromising the long-term key later does not reveal past session keys.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SSCP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SSCP study plan