
EC-CouncilCertified Ethical Hacker
Domain 1Objective 2
Classification and Types of Attacks CEH Practice Questions (Page 6)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 26–30
- 26
A penetration tester submits a crafted input into a search field on a web application. The application returns an error message that includes the original SQL query. Which type of web application attack is this?
Select an answer first - 27
An attacker sets up a rogue access point with the same SSID as the corporate network. When users connect, the attacker captures their credentials. Which type of wireless attack is this?
Select an answer first - 28
A web application allows users to upload profile pictures. An attacker uploads a file containing JavaScript that executes when another user views the profile. The script steals the viewer's session cookie. Which type of web application attack is this?
Select an answer first - 29
Which type of malware is designed to spread from one system to another without requiring user interaction?
Select an answer first - 30
Which of the following is an example of an active attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.