exam questions

Exam 312-50v10 All Questions

View all questions & answers for the 312-50v10 exam

Exam 312-50v10 topic 1 question 33 discussion

Actual exam question from ECCouncil's 312-50v10
Question #: 33
Topic #: 1
[All 312-50v10 Questions]

Which of the following is a serious vulnerability in the popular OpenSSL cryptographic software library? This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet.

  • A. SSL/TLS Renegotiation Vulnerability
  • B. Shellshock
  • C. Heartbleed Bug
  • D. POODLE
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
devag
7 months, 3 weeks ago
its heartbleed https://heartbleed.com/#:~:text=The%20Heartbleed%20Bug,used%20to%20secure%20the%20Internet.
upvoted 2 times
...
jersey5
8 months, 3 weeks ago
SSL and TLS Renegotiation Vulnerability - The vulnerability involves a flaw in renegotiation and allows man-in-the-middle attackers to surreptitiously introduce text at the beginning of an SSL session
upvoted 1 times
...
jersey5
8 months, 3 weeks ago
SSL and TLS Renegotiation Vulnerability - The vulnerability involves a flaw in renegotiation and allows man-in-the-middle attackers to surreptitiously introduce text at the beginning of an ASK session.
upvoted 1 times
...
jagadeesh666
9 months, 2 weeks ago
Heartbleed is a security bug in the OpenSSL cryptography library, which is a widely used implementation of the Transport Layer Security protocol.
upvoted 2 times
...
TrendMicroDLPSSucks
11 months, 3 weeks ago
where poodle is POODLE stands for ( “Padding Oracle On Downgraded Legacy Encryption”). In this vulnerability, an attacker which is Man-in-the-Middle(MiTM) first Downgrade the TLS connection to SSLv3. Then if the cipher suite uses RC4 or Block cipher in CBC mode, attacker can retrieve partial bytes of encrypted text and later on can get full plain text.
upvoted 2 times
...
TrendMicroDLPSSucks
11 months, 3 weeks ago
VCVE-2014-01601 bug is in the OPENSSL's Implmentation of the TLS/DTSL hearbeat extension, It is expolited to the lea of memory content from the server to client and from the client to the server
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...