Courseiva
Network Fundamentals →hardMultiple Select

200-901 Network Fundamentals Practice Question

An organization is planning to implement HTTPS for their web services. Which three statements accurately describe the HTTPS protocol? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HTTPS uses TLS to encrypt HTTP traffic.

HTTPS uses TLS for encryption, involves certificate verification, and negotiates a symmetric session key. It does not use UDP typically (TCP is used) and it is not stateless after the handshake.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTPS uses UDP as the transport protocol.

    Why it's wrong here

    HTTPS runs over TCP, using TLS to encrypt HTTP traffic; UDP transport belongs to QUIC-based HTTP/3, not HTTPS as classically defined. It is tempting because HTTP/3 does use UDP with QUIC, which would be accurate when describing that newer protocol rather than the HTTPS protocol generally.

  • ✓

    HTTPS uses TLS to encrypt HTTP traffic.

    Why this is correct

    HTTPS secures HTTP by layering Transport Layer Security beneath it, so all request and response data is encrypted in transit. This satisfies the stem's requirement to describe the protocol accurately: TLS provides confidentiality and integrity, preventing eavesdropping or tampering between client and server.

  • ✗

    HTTPS is stateless after the initial handshake.

    Why it's wrong here

    HTTPS is not stateless after the handshake; the TLS session persists and HTTP itself can carry state via cookies, so the claim misstates the protocol. It is tempting because HTTP is often called stateless per request, which would be correct when describing HTTP semantics independently of the TLS session layer.

  • ✓

    HTTPS uses a certificate to verify the server's identity.

    Why this is correct

    The server presents an X.509 certificate signed by a trusted certificate authority; the client validates that chain against its trust store. This authenticates the server's identity, preventing man-in-the-middle impersonation, which the HTTPS implementation scenario requires.

  • ✓

    HTTPS negotiates a symmetric session key for encryption.

    Why this is correct

    After the TLS handshake authenticates the server, both parties derive a shared symmetric session key using asymmetric cryptography. Bulk traffic is then encrypted symmetrically because it is far faster, satisfying HTTPS's performance and confidentiality requirements.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.