
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 1
Weak SSL/TLS Ciphers WAHS Practice Questions (Page 3)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 11–15
- 11
Which of the following is the most effective way to mitigate the POODLE attack?
Select an answer first - 12
Which of the following is a web-based service that can be used to test a website's SSL/TLS configuration for weak ciphers and other vulnerabilities?
Select an answer first - 13
A security analyst is reviewing a web application that supports TLS 1.0 with CBC-mode ciphers. The analyst is concerned about the BEAST attack. What is the primary risk associated with BEAST?
Select an answer first - 14
An administrator suspects that a web server is accepting RC4 cipher suites. Which command-line tool can be used to confirm this by attempting a connection with a specific RC4 cipher?
Select an answer first - 15
Which component of an SSL/TLS cipher suite is responsible for ensuring that data has not been altered during transmission?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.