
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 1
Weak SSL/TLS Ciphers WAHS Practice Questions (Page 8)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 36–40
- 36
A company processes credit card transactions and is subject to PCI DSS. Their web server currently supports TLS 1.2 with ECDHE-RSA-AES128-GCM-SHA256 and also TLS 1.0 with RC4 for an old point-of-sale system. The POS system cannot be upgraded immediately. Which action is the most appropriate to maintain compliance while keeping the POS system operational?
Select an answer first - 37
In an SSL/TLS cipher suite, what is the role of the key exchange algorithm?
Select an answer first - 38
An organization is migrating from a legacy TLS configuration to a more secure one. They currently support TLS 1.0, 1.1, and 1.2. They want to maintain compatibility with older clients while improving security. Which approach is the most balanced?
Select an answer first - 39
Which attack exploits the use of CBC-mode ciphers in SSL/TLS to decrypt encrypted cookies or other sensitive data?
Select an answer first - 40
A developer is configuring a web server and needs to choose a cipher suite that provides forward secrecy. Which cipher suite should the developer select?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.