An authenticated web-server scan flags several weak TLS cipher suites, including export-grade and CBC modes without AEAD. The analyst must classify the finding for remediation. How should the finding be interpreted?
Select an answer to reveal the explanation.
Short Explanation
Think of TLS settings like the locks on your front door, not the paperwork inside the house. Weak cipher suites are a protocol-hardening problem you fix by tightening the TLS configuration, so don't get baited into blaming the application code. If the scanner is naming ciphers, your remediation belongs in the transport layer, not in a source-code review.
Full Explanation
Weak TLS cipher suites are detected by vulnerability assessment tools as configuration findings in the transport layer. The scanner evaluates the server’s advertised handshake parameters, such as key exchange, authentication, bulk encryption, and integrity algorithms, then compares them against accepted cryptographic baselines. Remediation therefore changes the TLS protocol configuration—disabling deprecated suites, enforcing AEAD ciphers, and applying approved minimum TLS versions—because the exposure is the negotiated channel, not the behavior of the hosted application. A finding that names cipher suites does not indicate a logic flaw such as injection, authorization bypass, or insecure direct object reference, so source-code review is not the primary response. It is also not a certificate management issue, because certificates bind identity and validity while cipher suites define how the encrypted session is constructed. It is not a segmentation gap either, since firewall rules control reachability, whereas weak ciphers remain a risk even when the service is reachable by design. Exam caveat: CS0-004 expects analysts to map scanner output to the correct control layer before assigning tickets. Operational check: Validate the server’s negotiated cipher list after remediation and confirm only approved TLS suites remain enabled.