Certified Ethical Hacker (CEH) Practice Question

During a web application assessment you capture a TLS handshake where the server's strongest negotiated option is TLS_RSA_WITH_AES_256_CBC_SHA and no cipher suites using DHE or ECDHE are offered. You explain that captured traffic could be decrypted later if the private key is compromised. Which server-side change most directly mitigates this risk?

  • Configure the server to prefer cipher suites that use ECDHE key exchange so every session establishes an ephemeral key

  • Disable TLS compression on the server to remove CRIME-style vulnerabilities

  • Renew the RSA certificate with a 4096-bit key signed using SHA-256 instead of SHA-1

  • Replace AES-CBC with AES-GCM to achieve authenticated encryption of the data channel

Certified Ethical Hacker (CEH)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot