When you scan the collector with a vulnerability scanner it will list all ciphers that are currently supported by the Windows OS. However the only cipher that will be used by the collector is the cipher used in the collector certificate. You can check what cipher the collector cert is using with openssl. openssl sclient connect COLLECTOR...