
EC-CouncilCertified Ethical Hacker
Domain 1Objective 2
Classification and Types of Attacks CEH Practice Questions (Page 2)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 6–10
- 6
A company has a high-security data center with biometric access controls. An attacker, who is not an employee, manages to enter the data center by following an authorized employee through the biometric door without being noticed. Which type of attack is this?
Select an answer first - 7
An attacker calls an employee, pretends to be from the IT help desk, and asks for the employee's password to 'verify account settings'. The employee provides the password. Which type of social engineering attack is this?
Select an answer first - 8
A web application allows users to upload profile pictures. An attacker uploads a file containing malicious script that is stored on the server and later served to other users when they view the attacker's profile. Which type of attack is this?
Select an answer first - 9
Which web application attack involves injecting malicious SQL code into a query to manipulate the database?
Select an answer first - 10
Which classification of an attack is based on whether the attacker is a party to the communication or an external observer?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.