200-901 Network Fundamentals Practice Question
Which TWO of the following are characteristics of TLS (Transport Layer Security) used in HTTPS? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It uses asymmetric encryption to exchange a symmetric session key.
Option B is correct because the TLS handshake uses asymmetric cryptography (e.g., RSA key transport or ECDHE for key agreement) to securely establish a shared symmetric session key, which is then used for bulk data encryption with algorithms like AES-GCM. Option E is correct because TLS authenticates the server via an X.509 certificate signed by a trusted CA, and can optionally authenticate the client through client certificates during mutual TLS. Option A is incorrect because stream multiplexing is a feature of HTTP/2 and QUIC, not TLS itself. Option C is incorrect because TLS is a session/presentation-layer security protocol that runs between TCP and application protocols like HTTP, not an application-layer protocol. Option D is incorrect because port 443 is the default port for HTTPS, not an inherent characteristic of TLS, which can run over any port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It supports multiplexing of multiple streams.
Why it's wrong here
TLS provides a single ordered byte stream per connection; multiplexing many streams over one connection is HTTP/2's framing layer, not TLS. It is tempting because HTTP/2 runs over TLS in browsers, but the stream multiplexing is performed by HTTP/2 above the encrypted tunnel.
- ✓
It uses asymmetric encryption to exchange a symmetric session key.
Why this is correct
TLS performs an asymmetric handshake (for example, ECDHE with RSA or ECDSA signatures) to authenticate the server and negotiate a shared symmetric session key, which then encrypts bulk traffic. This hybrid approach satisfies HTTPS's need for both secure key exchange and efficient confidentiality.
- ✗
It is an application layer protocol like HTTP.
Why it's wrong here
TLS sits between the transport and application layers, encrypting HTTP rather than being an application protocol itself; HTTP defines request methods and headers, which TLS does not. It is tempting because HTTPS traffic is often loosely called an application-layer service, but TLS operates as a session-layer security protocol beneath HTTP.
- ✗
It uses port 443 by default.
Why it's wrong here
Port 443 is the default for HTTPS, the HTTP-over-TLS application, not for TLS itself, which can secure SMTP, IMAP or LDAP on other ports. It is tempting because HTTPS and TLS are commonly conflated, yet the port assignment belongs to the HTTPS service definition.
- ✓
It provides server (and optionally client) certificate verification.
Why this is correct
TLS authenticates the server through X.509 certificates signed by a trusted certificate authority, and can additionally verify client certificates during mutual TLS. This satisfies the stem's requirement for a genuine TLS characteristic, since certificate-based identity verification underpins the encrypted HTTPS session before any application data is exchanged.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.