200-901 Network Fundamentals Practice Question
An organization is planning to implement HTTPS for their web services. Which three statements accurately describe the HTTPS protocol? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTPS uses TLS to encrypt HTTP traffic.
HTTPS uses TLS for encryption, involves certificate verification, and negotiates a symmetric session key. It does not use UDP typically (TCP is used) and it is not stateless after the handshake.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTPS uses UDP as the transport protocol.
Why it's wrong here
HTTPS runs over TCP, using TLS to encrypt HTTP traffic; UDP transport belongs to QUIC-based HTTP/3, not HTTPS as classically defined. It is tempting because HTTP/3 does use UDP with QUIC, which would be accurate when describing that newer protocol rather than the HTTPS protocol generally.
- ✓
HTTPS uses TLS to encrypt HTTP traffic.
Why this is correct
HTTPS secures HTTP by layering Transport Layer Security beneath it, so all request and response data is encrypted in transit. This satisfies the stem's requirement to describe the protocol accurately: TLS provides confidentiality and integrity, preventing eavesdropping or tampering between client and server.
- ✗
HTTPS is stateless after the initial handshake.
Why it's wrong here
HTTPS is not stateless after the handshake; the TLS session persists and HTTP itself can carry state via cookies, so the claim misstates the protocol. It is tempting because HTTP is often called stateless per request, which would be correct when describing HTTP semantics independently of the TLS session layer.
- ✓
HTTPS uses a certificate to verify the server's identity.
Why this is correct
The server presents an X.509 certificate signed by a trusted certificate authority; the client validates that chain against its trust store. This authenticates the server's identity, preventing man-in-the-middle impersonation, which the HTTPS implementation scenario requires.
- ✓
HTTPS negotiates a symmetric session key for encryption.
Why this is correct
After the TLS handshake authenticates the server, both parties derive a shared symmetric session key using asymmetric cryptography. Bulk traffic is then encrypted symmetrically because it is far faster, satisfying HTTPS's performance and confidentiality requirements.
Visual reference
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.