
EC-CouncilCertified Encryption Specialist
Domain 5Objective 3
Modern Cryptographic Attacks ECES Practice Questions (Page 6)
Part of the Cryptanalysis domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 26–30
- 26
Which of the following is an example of a side-channel attack surface in a cryptographic system?
Select an answer first - 27
What is the primary goal of a padding oracle attack?
Select an answer first - 28
A developer reuses the same nonce for multiple messages encrypted with AES-GCM. What is the most important consequence and the correct remediation?
Select an answer first - 29
Your company's IoT devices use a custom protocol that encrypts each message with AES-CBC using a static key and a predictable initialization vector (IV) that increments by one for each message. What is the most critical risk?
Select an answer first - 30
A developer is reviewing a web application that uses RSA encryption for sensitive form data. The code generates a new RSA key pair on every server restart and stores the private key in a world-readable configuration file. Which two implementation flaws are most directly exposed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.