Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 5Objective 1

Weak SSL/TLS Ciphers WAHS Practice Questions (Page 6)

Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 26–30

  1. 26expert · hard

    A security engineer is reviewing a proposed TLS configuration for a new web service. The configuration includes TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 and TLS_RSA_WITH_AES_128_GCM_SHA256. The engineer wants to ensure that the service provides forward secrecy for all sessions. What should the engineer do?

    Select an answer first
  2. 27application · medium

    A security consultant is reviewing a client's TLS configuration and finds that the server supports TLS 1.0 with CBC-mode ciphers. The client is not subject to PCI DSS but wants to align with NIST guidelines. Which recommendation is most appropriate?

    Select an answer first
  3. 28expert · hard

    A system administrator is configuring a web server that must support a legacy application used by a small number of internal users. The application only works with TLS 1.0 and RC4. The administrator wants to minimize the risk while keeping the application functional. Which approach is the most appropriate?

    Select an answer first
  4. 29expert · hard

    A large enterprise runs a legacy web application that is critical to operations. The application is used by both internal employees and external partners, some of whom use very old browsers that only support TLS 1.0 with RC4. The enterprise must comply with PCI DSS because the application processes credit card payments. The security team is tasked with remediating the weak cipher usage without causing a business outage. Which approach is the most appropriate?

    Select an answer first
  5. 30application · medium

    A security engineer is reviewing the TLS configuration of a legacy web application that must remain compatible with older embedded devices. The current configuration supports TLS 1.0 with CBC-mode ciphers and RC4. The engineer needs to reduce the risk of BEAST and other CBC-related attacks while maintaining compatibility with the legacy devices. Which action is the most appropriate first step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.