SY0-701 exam dumps

SY0-701 practice question 119 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 119

Single answerCryptographic attacks: Downgrade , Collision , Birthday

A company is migrating legacy web applications behind a reverse proxy that terminates TLS. During testing, a security analyst notices that when a client initially attempts a modern TLS connection, a man-in-the-middle test tool can interfere and cause the session to reconnect with an older protocol and weaker cipher suite that the proxy still allows for backward compatibility. The analyst is concerned this could let attackers force less secure encryption even though both endpoints support stronger settings. Which of the following best describes this attack?

  1. A

    Downgrade attack

  2. B

    Collision attack

  3. C

    Birthday attack

  4. D

    Replay attack

Show answer and explanation

Correct answer: A

Explanation

This scenario describes a downgrade attack, in which an attacker interferes with cryptographic negotiation so systems that are capable of strong security fall back to weaker options. In practice, this risk is reduced by disabling deprecated protocols and cipher suites, enforcing modern TLS configurations, and avoiding unnecessary backward compatibility. This aligns with current best practices from standards bodies such as NIST and industry guidance to disable obsolete SSL/TLS versions and weak cipher support. By contrast, collision and birthday attacks apply to hash functions, where an attacker seeks two different inputs with the same digest; they are not attacks on protocol negotiation. Replay attacks involve retransmission of captured valid data and are a different class of attack entirely.

  • A. Correct.

    Correct. A downgrade attack occurs when an attacker forces two systems that support stronger cryptographic settings to negotiate older, weaker protocols, ciphers, or modes instead. In this scenario, the reverse proxy still permits legacy TLS settings for compatibility, and the attacker interferes with negotiation so the connection falls back to weaker encryption.

  • B. Incorrect.

    Incorrect. A collision attack targets hash functions by finding two different inputs that produce the same hash value. That is not what is happening here. The issue described involves protocol and cipher negotiation being forced to a weaker state, not duplicate hash outputs.

  • C. Incorrect.

    Incorrect. A birthday attack is a practical technique used to find hash collisions more efficiently by exploiting probability described by the birthday paradox. While related to collision attacks, it still focuses on hash functions rather than forcing a TLS session to use older protocols or weaker ciphers.

  • D. Incorrect.

    Incorrect. A replay attack involves capturing valid transmissions and retransmitting them later to gain unauthorized effects, often against authentication or transaction workflows. The scenario here is about manipulating cryptographic negotiation during session establishment, not reusing previously captured traffic.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam