
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 2
Weak Cryptographic Algorithms or Protocols WAHS Practice Questions (Page 6)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
5concepts
Questions 26–30
- 26
A security consultant is reviewing a web application that uses a custom encryption scheme for session cookies. The scheme uses a 64-bit key with the DES algorithm. The application is being updated to use a stronger algorithm, but the development team wants to minimize changes to the cookie format. What is the best recommendation?
Select an answer first - 27
During a security review of a legacy web application, a penetration tester captures traffic and observes that the server negotiates TLS 1.0 with an RSA key exchange using a 1024-bit certificate. The application also uses MD5 for password hashing. Which finding should be prioritized as the most critical to remediate?
Select an answer first - 28
A security analyst is reviewing a web application's configuration and finds that it uses a hash function to store passwords. The analyst notes that the hash function is known to be vulnerable to collision attacks and can be computed extremely quickly, allowing attackers to brute-force passwords at high speed. Which hash algorithm is the analyst most likely reviewing?
Select an answer first - 29
A developer is updating a web application's authentication system. The current code uses SHA-1 to hash passwords. The security team has mandated that all password hashes must be resistant to brute-force attacks and use a salt. Which algorithm should the developer choose?
Select an answer first - 30
An auditor is reviewing a web server's SSL/TLS configuration. The server supports TLS 1.0, TLS 1.1, and TLS 1.2, and the cipher suite list includes 3DES, RC4, and AES-128-CBC. The application is a public-facing e-commerce site. Which finding should be reported as the highest risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.