ExamGecko
Question list
Search
Search

Related questions











Question 212 - 200-201 discussion

Report
Export

A company encountered a breach on its web servers using IIS 7 5 Dunng the investigation, an engineer discovered that an attacker read and altered the data on a secure communication using TLS 1 2 and intercepted sensitive information by downgrading a connection to export-grade cryptography. The engineer must mitigate similar incidents in the future and ensure that clients and servers always negotiate with the most secure protocol versions and cryptographic parameters. Which action does the engineer recommend?

A.

Upgrade to TLS v1 3.

Answers
A.

Upgrade to TLS v1 3.

B.

Install the latest IIS version.

Answers
B.

Install the latest IIS version.

C.

Downgrade to TLS 1.1.

Answers
C.

Downgrade to TLS 1.1.

D.

Deploy an intrusion detection system

Answers
D.

Deploy an intrusion detection system

Suggested answer: A

Explanation:

Upgrading to TLS v1.3 is recommended because it eliminates outdated cryptographic functions and reduces the risk of downgrade attacks, which can occur when attackers force connections to use weaker encryption. TLS v1.3 only supports secure cipher suites and algorithms, enhancing the security of communications.

asked 07/10/2024
Han Valk
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first