Certified Ethical Hacker (CEH) Practice Question

During a penetration test you capture an SMTP session between the organization's mail server and an external partner. After the EHLO exchange you see the command 'STARTTLS' followed by a TLS handshake. Management claims this means all outbound email is now fully encrypted until it reaches recipients. As the consultant, what is the correct explanation?

  • The SMTP channel is encrypted only for this hop; without S/MIME or OpenPGP the message can still be stored or forwarded in clear text later.

  • The command digitally signs each message with the server's certificate, providing authenticity but not confidentiality.

  • It establishes an IPsec ESP tunnel between sender and recipient networks, protecting headers and body throughout transit.

  • STARTTLS guarantees end-to-end encryption of the message body until it is opened in the recipient's mail client.

Certified Ethical Hacker (CEH)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot