Courseiva
Network Fundamentals →mediumMultiple Select

200-901 Network Fundamentals Practice Question

Which TWO of the following are characteristics of TLS (Transport Layer Security) used in HTTPS? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It uses asymmetric encryption to exchange a symmetric session key.

Option B is correct because the TLS handshake uses asymmetric cryptography (e.g., RSA key transport or ECDHE for key agreement) to securely establish a shared symmetric session key, which is then used for bulk data encryption with algorithms like AES-GCM. Option E is correct because TLS authenticates the server via an X.509 certificate signed by a trusted CA, and can optionally authenticate the client through client certificates during mutual TLS. Option A is incorrect because stream multiplexing is a feature of HTTP/2 and QUIC, not TLS itself. Option C is incorrect because TLS is a session/presentation-layer security protocol that runs between TCP and application protocols like HTTP, not an application-layer protocol. Option D is incorrect because port 443 is the default port for HTTPS, not an inherent characteristic of TLS, which can run over any port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It supports multiplexing of multiple streams.

    Why it's wrong here

    TLS provides a single ordered byte stream per connection; multiplexing many streams over one connection is HTTP/2's framing layer, not TLS. It is tempting because HTTP/2 runs over TLS in browsers, but the stream multiplexing is performed by HTTP/2 above the encrypted tunnel.

  • ✓

    It uses asymmetric encryption to exchange a symmetric session key.

    Why this is correct

    TLS performs an asymmetric handshake (for example, ECDHE with RSA or ECDSA signatures) to authenticate the server and negotiate a shared symmetric session key, which then encrypts bulk traffic. This hybrid approach satisfies HTTPS's need for both secure key exchange and efficient confidentiality.

  • ✗

    It is an application layer protocol like HTTP.

    Why it's wrong here

    TLS sits between the transport and application layers, encrypting HTTP rather than being an application protocol itself; HTTP defines request methods and headers, which TLS does not. It is tempting because HTTPS traffic is often loosely called an application-layer service, but TLS operates as a session-layer security protocol beneath HTTP.

  • ✗

    It uses port 443 by default.

    Why it's wrong here

    Port 443 is the default for HTTPS, the HTTP-over-TLS application, not for TLS itself, which can secure SMTP, IMAP or LDAP on other ports. It is tempting because HTTPS and TLS are commonly conflated, yet the port assignment belongs to the HTTPS service definition.

  • ✓

    It provides server (and optionally client) certificate verification.

    Why this is correct

    TLS authenticates the server through X.509 certificates signed by a trusted certificate authority, and can additionally verify client certificates during mutual TLS. This satisfies the stem's requirement for a genuine TLS characteristic, since certificate-based identity verification underpins the encrypted HTTPS session before any application data is exchanged.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.