Question

Which Security Modes does an OPC UA SecureChannel support per the standard?

OPC UAMock examSecurityHard
Answer

C — None, Sign and SignAndEncrypt

The OPC UA specification defines exactly three Security Modes on a SecureChannel: None (no protection, dev/test only), Sign (authentication and integrity via HMAC, no confidentiality), and SignAndEncrypt (sign plus AES encryption). Option A is wrong because "Encrypt" without signing is not a defined mode; you cannot encrypt without also signing in OPC UA. Option B is wrong because it omits the mandatory SignAndEncrypt mode used in production. Option D is wrong because it removes the None mode, which is legally part of the standard even though it is unsuitable for production. In production you should always choose SignAndEncrypt with a strong Security Policy such as Basic256Sha256, Aes128_Sha256_RsaOaep or Aes256_Sha256_RsaPss.

Preparation tip

Treat SecurityMode=None as a red flag in any production audit: it is acceptable only on a strictly isolated commissioning network, never on a routed plant network.

All proposed choices (exam context)
  1. A.None and Encrypt
  2. B.None and Sign
  3. C.None, Sign and SignAndEncrypt
  4. D.Sign and SignAndEncrypt only
Waitlist

OPC UA bank in preparation

The full OPC UA bank isn't available yet. Drop your email to get notified at launch and grab an early-bird discount.

Join the waitlist
Want more?

See the 9 other OPC UA practice questions

Related questions

Question from our independent practice bank. OPC UA is a registered trademark of OPC Foundation, not affiliated with CertifBus.

Last updated: 19 May 2026

Join the waitlist
OPC UA waitlist