
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 2
Weak Cryptographic Algorithms or Protocols WAHS Practice Questions (Page 4)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
5concepts
Questions 16–20
- 16
A security architect is reviewing a legacy web application that uses a combination of MD5 for password hashing and DES for encrypting session tokens. The application is being migrated to a cloud environment, and the architect must ensure compliance with PCI DSS, which requires strong cryptography. The migration team wants to minimize changes to the application code. Which approach should the architect recommend?
Select an answer first - 17
A developer is implementing a file integrity monitoring system and needs to generate checksums for files. The current system uses MD5. The security team requires that the checksums be collision-resistant. Which algorithm should be used?
Select an answer first - 18
A system administrator is updating the TLS configuration of a web server. The server currently supports SSLv3 and TLS 1.0. The administrator wants to disable weak protocols while ensuring that the web application remains accessible to all current browsers. Which action should be taken?
Select an answer first - 19
A development team is building a web application that will store sensitive user data. The team is considering using AES-128 for encryption and SHA-256 for hashing. A security consultant recommends using AES-256 and SHA-512 instead. The team is concerned about performance and cost. Which decision is most appropriate?
Select an answer first - 20
A development team is building a new web application and needs to store API keys securely. They plan to use a hardware security module (HSM) to manage encryption keys. Which practice is essential for the secure use of the HSM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.