Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 1Objective 2

Classification and Types of Attacks CEH Practice Questions (Page 6)

Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
12concepts

Questions 26–30

  1. 26application · easy

    A penetration tester submits a crafted input into a search field on a web application. The application returns an error message that includes the original SQL query. Which type of web application attack is this?

    Select an answer first
  2. 27application · medium

    An attacker sets up a rogue access point with the same SSID as the corporate network. When users connect, the attacker captures their credentials. Which type of wireless attack is this?

    Select an answer first
  3. 28expert · medium

    A web application allows users to upload profile pictures. An attacker uploads a file containing JavaScript that executes when another user views the profile. The script steals the viewer's session cookie. Which type of web application attack is this?

    Select an answer first
  4. 29foundation · easy

    Which type of malware is designed to spread from one system to another without requiring user interaction?

    Select an answer first
  5. 30foundation · easy

    Which of the following is an example of an active attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.