
EC-CouncilCertified Encryption Specialist
Domain 5Objective 3
Modern Cryptographic Attacks ECES Practice Questions (Page 4)
Part of the Cryptanalysis domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 16–20
- 16
A developer implements RSA encryption using the public exponent e=3 and does not use any padding scheme. What is the most significant vulnerability?
Select an answer first - 17
A security team is designing a new authentication system for a high-security facility. The system must use smart cards with PIN entry. The team is considering two designs: Design A uses a constant-time PIN comparison but is vulnerable to power analysis because the card's processor draws different power when processing different PIN digits. Design B uses a masked AES implementation to equalize power consumption but has a variable-time PIN comparison. The team must choose one design. Which design is the better choice, and why?
Select an answer first - 18
Which of the following is considered a protocol-level attack surface in a cryptographic system?
Select an answer first - 19
A security team suspects that a cryptographic key is leaking through cache-timing behavior on a shared server. The application uses AES with a software implementation. Which mitigation is most appropriate?
Select an answer first - 20
A developer is implementing a file encryption feature. The code uses the same AES key and IV for every file encrypted. A security reviewer identifies this as a critical flaw. Which attack is the system most vulnerable to, and what is the correct fix?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.