Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Encryption Specialist

Domain 5Objective 3

Modern Cryptographic Attacks ECES Practice Questions (Page 3)

Part of the Cryptanalysis domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 11–15

  1. 11application · medium

    A penetration tester is assessing a legacy TLS 1.0 server that supports an outdated cipher suite. The tester successfully forces the client and server to negotiate the legacy protocol instead of the modern TLS 1.3 that both support. Which protocol-level weakness is being exploited, and what is the recommended remediation?

    Select an answer first
  2. 12application · medium

    A VPN gateway supports both IKEv1 and IKEv2. A security assessment finds that an attacker can force the gateway to negotiate IKEv1 with a weak Diffie-Hellman group. Which attack is this, and what is the recommended configuration change?

    Select an answer first
  3. 13expert · hard

    A security auditor is reviewing a system that uses TLS 1.2 with a cipher suite that supports forward secrecy. The auditor must decide whether to recommend upgrading to TLS 1.3. The system must support legacy clients that do not support TLS 1.3. What is the most appropriate recommendation?

    Select an answer first
  4. 14expert · hard

    A startup is building a password manager. The developers want to use a strong key-derivation function (KDF) to protect user master passwords. They are considering PBKDF2 with a high iteration count, bcrypt, and Argon2id. The company must balance security against performance on a variety of user devices, including low-end mobile phones. Which choice is most appropriate?

    Select an answer first
  5. 15foundation · easy

    Which of the following is an example of a key management flaw that can compromise cryptographic security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.