EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A web administrator is configuring a new web server and wants to ensure that all communications between the client and server are encrypted and authenticated. They provision a digital certificate and configure the web server to listen on port 443. Which protocol is being implemented to achieve this secure communication?

  1. AHTTPS
  2. BFTP/S
  3. CSSH
  4. DHTTP/2
Show answer & explanation

Correct answer: A. HTTPS

HTTPS (Hypertext Transfer Protocol Secure) is the protocol that combines HTTP with SSL/TLS encryption, typically running on port 443, to provide secure, authenticated, and encrypted communication over a computer network.

Why the other options are wrong

  • B. FTP/S (FTP Secure) is for secure file transfer, not general web communication.
  • C. SSH (Secure Shell) is for secure remote command-line access and tunneling, not for serving web pages.
  • D. HTTP/2 is a revision of HTTP that improves performance but does not inherently provide encryption; it's often used over TLS.

HTTPS

HTTPS (Hypertext Transfer Protocol Secure) is an extension of the Hypertext Transfer Protocol (HTTP) for secure communication over a computer network.

  • Uses SSL/TLS protocol for encryption and authentication.
  • Default port is 443.
  • Protects against eavesdropping, tampering, and message forgery.

Memory trick: Web's Secure Path: Always Encrypted.

More Web Application Hacking questions