Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 5Objective 1

Weak SSL/TLS Ciphers WAHS Practice Questions (Page 9)

Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 41–43

  1. 41foundation · easy

    What is the primary security risk when a web server supports export-grade cipher suites?

    Select an answer first
  2. 42expert · hard

    A large organization runs a legacy web application that must support a custom client built on an old TLS stack. The client only supports TLS 1.0 with CBC-mode ciphers and RC4. The security team must balance compliance with PCI DSS and the operational need to keep the client working. Which approach best addresses the conflict?

    Select an answer first
  3. 43application · medium

    A security analyst is investigating a suspected man-in-the-middle attack on a web application. The server logs show that a client negotiated TLS_RSA_WITH_RC4_128_SHA. Which attack is most directly enabled by this cipher suite?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to WAHS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.