200-201 exam dumps

200-201 practice question 164 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 164

Select 3

During a security review, your team discovers that a web server is using an outdated cipher suite to secure HTTPS connections. To enhance security, the team decides to update the server to support modern, secure cipher suites. Which of the following cipher suites would be considered secure and appropriate for modern HTTPS communication?

  1. A

    TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

  2. B

    TLS_RSA_WITH_AES_128_CBC_SHA

  3. C

    TLS_CHACHA20_POLY1305_SHA256

  4. D

    TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

  5. E

    TLS_RSA_WITH_3DES_EDE_CBC_SHA

Show answer and explanation

Correct answers: A, C, D

Explanation

A secure cipher suite should provide strong encryption, authentication, and integrity while avoiding outdated or vulnerable components such as RSA key exchange, CBC mode, or 3DES encryption. The correct answers (1, 3, 4) represent modern, secure cipher suites that meet the requirements for a secure HTTPS connection.

  • A. Correct.

    This is a secure cipher suite that uses Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for key exchange, RSA for authentication, AES-256 in GCM mode for encryption, and SHA-384 for integrity. It is widely recommended for modern HTTPS communication.

  • B. Incorrect.

    This cipher suite uses RSA for key exchange and AES-128 in CBC mode for encryption, which is considered insecure due to vulnerabilities in CBC mode. It is outdated and not recommended.

  • C. Correct.

    This is a secure and modern cipher suite that uses ChaCha20 for encryption and Poly1305 for authentication, making it suitable for resource-constrained environments or modern security needs.

  • D. Correct.

    This is a secure cipher suite using ECDHE for key exchange, ECDSA for authentication, AES-256 in GCM mode for encryption, and SHA-384 for integrity. It is recommended for modern security.

  • E. Incorrect.

    This cipher suite uses RSA for key exchange and 3DES for encryption, which is considered insecure due to the limited key size and vulnerabilities in 3DES. It is outdated and not recommended.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam