
EC-CouncilCertified Encryption Specialist
Domain 2Objective 3
Hashing Algorithms (MD5, SHA, RIPEMD, Tiger, Whirlpool) and HMAC ECES Practice Questions (Page 7)
Part of the Symmetric Cryptography and Hashing domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
9concepts
Questions 31–35
- 31
A compliance framework requires that all stored password hashes use an algorithm that is resistant to brute-force attacks. The current system uses unsalted SHA-256. Which change best meets the requirement?
Select an answer first - 32
Which of the following hash algorithms is considered insecure for general use due to known collision attacks?
Select an answer first - 33
A software company wants to ensure that its downloadable installers are authentic and have not been modified. They already publish a SHA-256 hash. What additional step would provide the strongest assurance of authenticity?
Select an answer first - 34
A security team is assessing a legacy system that uses MD5 for both password storage and file-integrity checks. The system is air-gapped and will be decommissioned in six months. The team must decide whether to invest in migrating to SHA-256. What is the most appropriate decision?
Select an answer first - 35
Which property of a cryptographic hash function ensures that it is infeasible to find any two different messages that produce the same hash?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.