
EC-CouncilCertified Encryption Specialist
Domain 5Objective 3
Modern Cryptographic Attacks ECES Practice Questions (Page 8)
Part of the Cryptanalysis domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 36–39
- 36
A security team is investigating a breach where an attacker was able to decrypt traffic between a client and server. The server supports both RSA key exchange and ephemeral Diffie-Hellman (DHE). The attacker is suspected of having recorded all encrypted traffic and later obtained the server's private key. Which key exchange method is most likely to have been used, and why?
Select an answer first - 37
A security researcher is analyzing a smart card that uses RSA decryption. The researcher notices that the time taken to decrypt a message varies depending on the private key bits. The researcher also has physical access to the card and can measure its power consumption. Which side-channel attack is the researcher most likely to succeed with, and what is the best mitigation?
Select an answer first - 38
A developer is implementing password storage for a new application. The developer uses SHA-256 without a salt to hash passwords. A security reviewer flags this as a serious flaw. Which attack is the developer's approach most vulnerable to, and what is the recommended fix?
Select an answer first - 39
Which of the following is a common implementation flaw that weakens a cryptographic system?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECES
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECES” is a trademark of its owner, used for identification only.