
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 1
Weak SSL/TLS Ciphers WAHS Practice Questions (Page 1)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 1–5
- 1
Which compliance standard explicitly requires the use of strong cryptography and prohibits the use of SSL and early TLS versions for transmitting cardholder data?
Select an answer first - 2
Why is the RC4 stream cipher considered weak and deprecated in modern TLS configurations?
Select an answer first - 3
A security audit of a government website finds that the server supports TLS_RSA_WITH_3DES_EDE_CBC_SHA. The site is not required to support legacy clients. What is the primary reason this cipher suite should be disabled?
Select an answer first - 4
Which command-line tool can be used to enumerate the SSL/TLS cipher suites supported by a remote server?
Select an answer first - 5
A security analyst is investigating a potential man-in-the-middle attack on a web application. The analyst suspects that the server supports export-grade cipher suites. Which attack is most directly enabled by export-grade ciphers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.