Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 5Objective 1

Weak SSL/TLS Ciphers WAHS Practice Questions (Page 1)

Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    Which compliance standard explicitly requires the use of strong cryptography and prohibits the use of SSL and early TLS versions for transmitting cardholder data?

    Select an answer first
  2. 2foundation · easy

    Why is the RC4 stream cipher considered weak and deprecated in modern TLS configurations?

    Select an answer first
  3. 3application · medium

    A security audit of a government website finds that the server supports TLS_RSA_WITH_3DES_EDE_CBC_SHA. The site is not required to support legacy clients. What is the primary reason this cipher suite should be disabled?

    Select an answer first
  4. 4foundation · easy

    Which command-line tool can be used to enumerate the SSL/TLS cipher suites supported by a remote server?

    Select an answer first
  5. 5application · medium

    A security analyst is investigating a potential man-in-the-middle attack on a web application. The analyst suspects that the server supports export-grade cipher suites. Which attack is most directly enabled by export-grade ciphers?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.