
EC-CouncilCertified Ethical Hacker
Domain 5Objective 1
Hacking Web Servers CEH Practice Questions (Page 4)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
6concepts
Questions 16–20
- 16
A web server administrator is tasked with hardening a server that runs both a public website and a sensitive internal application. The administrator wants to reduce the attack surface while maintaining functionality. Which action is most effective?
Select an answer first - 17
A security team must assess a web server that hosts a critical application. The assessment must not disrupt production traffic. The team has access to a staging environment that mirrors the production configuration. Which approach is most appropriate?
Select an answer first - 18
During a vulnerability assessment of a web server, which technique is used to identify the server's operating system and software versions?
Select an answer first - 19
An attacker is attempting to enumerate valid usernames on a web server by sending login requests and comparing error messages. The server returns 'Invalid username' for unknown users and 'Invalid password' for known users. Which attack is being performed, and what is the best countermeasure?
Select an answer first - 20
A penetration tester is performing a web server assessment. The tester has already gathered information about the server's IP address, open ports, and web server software. According to a systematic hacking methodology, what should the tester do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.