
EC-CouncilCertified Encryption Specialist
Domain 2Objective 3
Hashing Algorithms (MD5, SHA, RIPEMD, Tiger, Whirlpool) and HMAC ECES Practice Questions (Page 3)
Part of the Symmetric Cryptography and Hashing domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
9concepts
Questions 11–15
- 11
How does RIPEMD-160 compare to SHA-1 in terms of security and design?
Select an answer first - 12
A cryptography consultant is reviewing a system that must interoperate with a legacy European payment gateway. The gateway only supports RIPEMD-160 for integrity checks. The consultant must decide whether this is acceptable for a new high-security deployment. What is the most accurate recommendation?
Select an answer first - 13
A forensic analyst is investigating a data breach. The attacker replaced a legitimate file with a malicious one that has the same MD5 hash. The analyst must determine whether this indicates a collision attack or a second preimage attack. What is the key distinction?
Select an answer first - 14
A security architect is designing an API authentication scheme. The team wants to use HMAC-SHA256, but a junior engineer suggests using plain SHA-256 of the message with the secret appended. The architect must decide. Which statement best justifies the architect's decision to use HMAC?
Select an answer first - 15
What does preimage resistance mean for a cryptographic hash function?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.