
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 1
Weak SSL/TLS Ciphers WAHS Practice Questions (Page 4)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 16–20
- 16
A security analyst is investigating a potential downgrade attack on a web server. The server supports TLS 1.2 with strong ciphers, but also supports TLS 1.0 with RC4. The analyst suspects that an attacker is forcing clients to downgrade to TLS 1.0. Which attack technique is most likely being used?
Select an answer first - 17
A security team is reviewing the TLS configuration of a web application. The server supports TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA and TLS_RSA_WITH_AES_128_GCM_SHA256. Which suite is more resistant to a BEAST attack?
Select an answer first - 18
An organization is hardening its web server and wants to disable all export-grade cipher suites. Which configuration change is most effective?
Select an answer first - 19
A penetration tester is assessing a web server and needs to identify which cipher suites are supported. The tester wants to determine if any export-grade ciphers are enabled, which could allow FREAK attacks. Which tool or technique is most appropriate for this task?
Select an answer first - 20
Which of the following is a recommended practice when configuring TLS on a web server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.