Courseiva
Cryptography Application →mediumMultiple Choice

GSEC Cryptography Application Practice Question

A security analyst is hardening a web server to ensure that only modern, secure protocols are used for HTTPS traffic. Which configuration best aligns with GSEC security standards for data in transit?

⚠ Common exam trap

Candidates often include TLS 1.1 in their selection, believing it to be 'secure enough.' GSEC standards strictly mandate disabling anything below TLS 1.2 to prevent known protocol downgrade attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable SSL and TLS 1.0/1.1, allowing only TLS 1.2 and 1.3.

Disabling legacy protocols like SSLv3 and TLS 1.0 is essential to prevent downgrade attacks like POODLE. By mandating TLS 1.2 or higher, the organization ensures that cryptographic primitives remain robust against known vulnerabilities. This practice is foundational for GSEC-compliant environments, as it mitigates the risk of man-in-the-middle interception where outdated handshake mechanisms allow attackers to force the use of weaker, exploitable encryption algorithms during the initial connection setup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Support TLS 1.0, 1.1, and 1.2 to maintain maximum backward compatibility.

    Why it's wrong here

    Supporting older protocols like TLS 1.0 and 1.1 exposes the server to known cryptographic flaws such as BEAST and Lucky13. Modern standards explicitly mandate the removal of these protocols to ensure that only secure, updated handshake procedures are utilized during client-server negotiation, thereby maintaining high security baselines.

  • ✗

    Enable SSLv3 for clients who cannot support newer TLS versions.

    Why it's wrong here

    SSLv3 is fundamentally broken and susceptible to the POODLE attack, which allows attackers to decrypt sensitive cookies. Enabling this protocol on any production server is a significant security violation, as it provides no meaningful protection against modern interception techniques or sophisticated cryptographic analysis tools.

  • ✓

    Disable SSL and TLS 1.0/1.1, allowing only TLS 1.2 and 1.3.

    Why this is correct

    Restricting traffic to TLS 1.2 and 1.3 eliminates the usage of deprecated, insecure ciphers and handshake methods. This configuration adheres to current industry best practices and compliance frameworks, effectively closing the window on several classes of protocol downgrade attacks that plague older implementations of the HTTPS stack.

  • ✗

    Use RC4 for all connections to ensure high performance over low-bandwidth links.

    Why it's wrong here

    The RC4 stream cipher is considered cryptographically broken due to significant biases in its output stream. Modern security standards strictly prohibit the use of RC4, as attackers can recover sensitive plaintext through statistical analysis, making it entirely unsuitable for protecting confidential data in any production environment.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.