EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy
A web administrator is configuring a new web server and wants to ensure that all communications between the client and server are encrypted and authenticated. They provision a digital certificate and configure the web server to listen on port 443. Which protocol is being implemented to achieve this secure communication?
- AHTTPS
- BFTP/S
- CSSH
- DHTTP/2
Show answer & explanationAnswer & explanation
Correct answer: A. HTTPS
HTTPS (Hypertext Transfer Protocol Secure) is the protocol that combines HTTP with SSL/TLS encryption, typically running on port 443, to provide secure, authenticated, and encrypted communication over a computer network.
Why the other options are wrong
- B. FTP/S (FTP Secure) is for secure file transfer, not general web communication.
- C. SSH (Secure Shell) is for secure remote command-line access and tunneling, not for serving web pages.
- D. HTTP/2 is a revision of HTTP that improves performance but does not inherently provide encryption; it's often used over TLS.
HTTPS
HTTPS (Hypertext Transfer Protocol Secure) is an extension of the Hypertext Transfer Protocol (HTTP) for secure communication over a computer network.
- Uses SSL/TLS protocol for encryption and authentication.
- Default port is 443.
- Protects against eavesdropping, tampering, and message forgery.
Memory trick: Web's Secure Path: Always Encrypted.