- Home
- All questions
- Question 486
CompTIA Security+ study material · question 486 of 611
Why is disabling old TLS versions on the server necessary rather than merely deprioritising them?
Show the answer
Answer: C. A client will negotiate whatever the server still offers, so an attacker can force a downgrade
Preference order does not stop negotiation; only removing the option closes the downgrade path.
Source: OWASP Transport Layer Security Cheat Sheet (OWASP) — OWASP Transport Layer Security Cheat Sheet › Server Configuration