ISC2 CISSP Practice Question
TLS 1.3 removes support for RSA key exchange to mitigate against passive decryption attacks.
False
True
TLS 1.3 removes support for RSA key exchange to mitigate against passive decryption attacks.
False
True
TLS 1.3 indeed removes support for RSA key exchange to improve security. In previous TLS versions (1.2 and earlier), RSA key exchange allowed encrypted session keys to be transmitted directly to the server encrypted with the server's public key. This created vulnerability to passive decryption attacks, as anyone who later obtained the server's private key could retrospectively decrypt captured traffic. TLS 1.3 addresses this by mandating ephemeral key exchanges (like Diffie-Hellman) that provide perfect forward secrecy, ensuring that even if the private key is compromised in the future, previously recorded sessions cannot be decrypted. This removal of static RSA key exchange is a significant security improvement in TLS 1.3.
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
All IT & Cybersecurity Package plans include the following perks and exams .
Our pricing is simple. Full access to all certifications and exams in each package, for one price.
As many practice tests for as many topics as you want.
Use study mode non-stop, no limits.
Access to our AI assistant, Bash, trained to help you pass your exam.
Track your scores over time in study mode and report cards.
See how you improve over time, and where you need to focus.
Access our store with even bigger discounts than before.
Unlimited access to all performance questions and be prepared for the real thing.
All IT & Cybersecurity Package plans include unlimited access to the following study materials.
Create an account or sign in to access our study materials.