Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 5Objective 2

Weak Cryptographic Algorithms or Protocols WAHS Practice Questions (Page 2)

Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
5concepts

Questions 6–10

  1. 6application · medium

    A company's web application is accessible over the internet and uses a certificate signed with SHA-1. The certificate authority has announced that SHA-1 certificates are no longer trusted by modern browsers. What is the immediate action required?

    Select an answer first
  2. 7application · medium

    An organization is evaluating a new web application that uses a 2048-bit RSA certificate and supports TLS 1.3. However, the application also accepts connections using a cipher suite that uses RC4. What should the security team do?

    Select an answer first
  3. 8application · medium

    A company is migrating its public web application to a new server and wants to ensure that only strong cryptographic protocols are supported. The current configuration allows SSLv3, TLS 1.0, TLS 1.1, and TLS 1.2. The compliance team requires that all traffic be protected against known protocol-level attacks. Which configuration should be applied?

    Select an answer first
  4. 9application · medium

    A penetration tester is assessing a web application that uses a custom encryption library. The library uses DES with a 56-bit key to encrypt sensitive data in transit. The tester also notices that the application accepts SHA-1 certificates for TLS connections. Which action should the tester recommend?

    Select an answer first
  5. 10expert · hard

    A cloud-based application uses a load balancer to terminate TLS. The security team needs to ensure that the encryption strength meets PCI DSS requirements, which mandate strong cryptography. The load balancer currently supports TLS 1.2 with AES-128-CBC and TLS 1.3 with AES-256-GCM. What is the best configuration to meet PCI DSS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.