
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 2
Weak Cryptographic Algorithms or Protocols WAHS Practice Questions (Page 3)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
5concepts
Questions 11–15
- 11
A security auditor is reviewing a web application that uses a custom encryption scheme for session tokens. The scheme uses a 64-bit key with a proprietary algorithm that is not publicly reviewed. The auditor also finds that the application uses RC4 for TLS connections. Which recommendation should the auditor make?
Select an answer first - 12
A company is deploying a new web application and must support clients that use a variety of TLS versions. The security policy requires that all data be encrypted with at least 128-bit security and that the system be resistant to known attacks. The application will be accessed by both modern browsers and legacy embedded devices that only support TLS 1.1. What is the best approach?
Select an answer first - 13
A security auditor is reviewing a web server's TLS configuration and finds that it supports TLS 1.2 with the cipher suite TLS_RSA_WITH_AES_128_GCM_SHA256. The auditor notes that the server does not support any ECDHE or DHE key exchange. What is the primary concern?
Select an answer first - 14
A security analyst is using Wireshark to capture traffic from a web application that uses HTTPS. The analyst sees that the ClientHello message lists several cipher suites, including TLS_RSA_WITH_3DES_EDE_CBC_SHA. What should the analyst conclude?
Select an answer first - 15
A network administrator is configuring a load balancer that terminates TLS for a set of internal applications. The applications are accessed by a mix of modern browsers and legacy clients. The security policy requires that all traffic be encrypted with at least TLS 1.2. What is the best approach to support legacy clients while meeting the policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.