
EC-CouncilCertified Ethical Hacker
Domain 1Objective 4
Ethical Hacking Concepts and Scope CEH Practice Questions (Page 1)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
5concepts
Questions 1–5
- 1
A company wants to understand its overall security posture by identifying a wide range of vulnerabilities across its network, including misconfigurations, missing patches, and weak passwords. They also want to validate whether a specific known exploit can actually be used to gain access to a critical server. Which approach best satisfies both objectives?
Select an answer first - 2
A security professional is asked to test the security of a web application. The professional has no written contract or authorization from the application owner, but the request comes from a senior manager who verbally approves the test. What is the most appropriate action?
Select an answer first - 3
An organization wants to assess its security by simulating an attack to see if a known vulnerability can be exploited to gain access to sensitive data. Which activity best fits this objective?
Select an answer first - 4
A security researcher discovers a critical vulnerability in a widely used software product. The researcher is not affiliated with the vendor and has no authorization to test the product. The researcher wants to disclose the vulnerability to the vendor to help fix it. What is the most appropriate action?
Select an answer first - 5
A retailer hires a security firm to test its public e-commerce site. The contract explicitly limits testing to the web application and its APIs, and prohibits any testing of the underlying database server or the corporate network. During the engagement, the tester discovers that the web app has a SQL injection flaw that could expose customer data from the database. What is the most appropriate action for the tester?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.