Courseiva
Web Communication Security →mediumMultiple Choice

GSEC Web Communication Security Practice Question

A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?

⚠ Common exam trap

The trap here is assuming that any cipher suite with AES and SHA-1 is automatically weak due to the hash algorithm, when the critical flaw is actually the static RSA key exchange lacking forward secrecy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It lacks forward secrecy because the RSA key exchange does not generate ephemeral session keys.

The cipher suite TLS_RSA_WITH_AES_128_CBC_SHA relies on static RSA key exchange, where the client encrypts a premaster secret with the server's public key. This means the session key is tied to the server's long-term private key. If that private key is compromised later, an attacker who recorded the encrypted session can decrypt it retroactively. Forward secrecy requires ephemeral key exchanges like ECDHE or DHE, which generate unique session keys that are not recoverable from the long-term key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It lacks forward secrecy because the RSA key exchange does not generate ephemeral session keys.

    Why this is correct

    TLS_RSA_WITH_AES_128_CBC_SHA uses static RSA key exchange, meaning the premaster secret is encrypted with the server's long-term RSA key. If an attacker records the encrypted session and later obtains the server's private key, they can decrypt all past sessions. This violates forward secrecy, a critical property for protecting historical traffic. Modern best practice mandates ECDHE or DHE cipher suites to ensure each session has unique ephemeral keys.

  • ✗

    It uses AES in CBC mode, which is vulnerable to padding oracle attacks such as POODLE.

    Why it's wrong here

    While AES-CBC can be susceptible to padding oracle attacks like Lucky Thirteen, POODLE specifically targets SSLv3's CBC padding and is not applicable to TLS 1.0+ implementations that correctly handle padding. The cipher suite name indicates TLS, not SSLv3, and the primary weakness here is the key exchange, not the block cipher mode. CBC mode itself is not inherently broken when implemented properly.

  • ✗

    It uses SHA-1 for integrity, which is considered cryptographically broken for MACs.

    Why it's wrong here

    SHA-1 is used in the HMAC construction for message authentication, and while SHA-1 has known collision weaknesses, HMAC-SHA1 remains secure for integrity protection in TLS because collisions do not directly translate to MAC forgeries. The real issue with this cipher suite is the lack of forward secrecy due to RSA key exchange. SHA-1 in HMAC is not the primary concern for this configuration.

  • ✗

    It allows downgrade to export-grade cryptography because of the RSA key exchange.

    Why it's wrong here

    Export-grade cryptography (e.g., EXPORT ciphers) is a separate class of weak cipher suites that were historically used for export compliance. TLS_RSA_WITH_AES_128_CBC_SHA is not an export cipher; it uses 128-bit AES, which is strong. The RSA key exchange itself does not enable downgrade to export ciphers unless the server explicitly supports them. The main flaw is the lack of forward secrecy, not export-grade weakness.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.