ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 79 - CS0-003 discussion

Report
Export

A technician is analyzing output from a popular network mapping tool for a PCI audit:

Which of the following best describes the output?

A.
The host is not up or responding.
Answers
A.
The host is not up or responding.
B.
The host is running excessive cipher suites.
Answers
B.
The host is running excessive cipher suites.
C.
The host is allowing insecure cipher suites.
Answers
C.
The host is allowing insecure cipher suites.
D.
The Secure Shell port on this host is closed
Answers
D.
The Secure Shell port on this host is closed
Suggested answer: C

Explanation:

The output shows the result of running the ssl-enum-ciphers script with Nmap, which is a tool that can scan web servers for supported SSL/TLS cipher suites. Cipher suites are combinations of cryptographic algorithms that are used to establish secure communication between a client and a server. The output shows the cipher suites that are supported by the server, along with a letter grade (A through F) indicating the strength of the connection. The output also shows the least strength, which is the strength of the weakest cipher offered by the server. In this case, the least strength is F, which means that the server is allowing insecure cipher suites that are vulnerable to attacks or have been deprecated. For example, the output shows that the server supports SSLv3, which is an outdated and insecure protocol that is susceptible to the POODLE attack. The output also shows that the server supports RC4, which is a weak and broken stream cipher that should not be used. Therefore, the best description of the output is that the host is allowing insecure cipher suites. The other descriptions are not accurate, as they do not reflect what the output shows. The host is not up or responding is incorrect, as the output clearly shows that the host is up and responding to the scan. The host is running excessive cipher suites is incorrect, as the output does not indicate how many cipher suites the host is running, only which ones it supports. The Secure Shell port on this host is closed is incorrect, as the output does not show anything about port 22, which is the default port for Secure Shell (SSH). The output only shows information about port 443, which is the default port for HTTPS.

asked 02/10/2024
Ivan Ramirez
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first