
EC-CouncilCertified Cybersecurity Technician
Domain 5Objective 1
Cryptography CCT Practice Questions (Page 8)
Part of the Cryptography and Data Security domain, which makes up ~9% of our current practice bank.
45questions here
9free pages
8concepts
Questions 36–40
- 36
A company operates a private CA. An employee's private key is suspected of being compromised. The certificate is still valid for another year. What is the most appropriate immediate action?
Select an answer first - 37
A small company uses a legacy application that only supports 3DES for encrypting data at rest. The security team wants to migrate to a modern symmetric algorithm without changing the application's encryption interface. Which action best addresses the migration while maintaining compatibility?
Select an answer first - 38
A company's public-facing website uses a certificate from a public CA. The CA's root certificate is compromised. What is the immediate security concern for the website?
Select an answer first - 39
A database administrator stores user passwords as unsalted SHA-256 hashes. After a breach, an attacker quickly recovers many plaintext passwords. Which improvement would most directly mitigate this type of attack?
Select an answer first - 40
Which property of a cryptographic hash function ensures that it is computationally infeasible to find two different inputs that produce the same hash value?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.