
EC-CouncilCertified Ethical Hacker
Domain 5Objective 1
Hacking Web Servers CEH Practice Questions (Page 7)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
6concepts
Questions 31–35
- 31
Which tool is a penetration testing framework that provides a wide range of exploits, payloads, and auxiliary modules for attacking web servers?
Select an answer first - 32
A company runs a public-facing web server that has been the target of repeated brute force attacks against the admin login page. The server is behind a load balancer, and the application logs show failed login attempts from many different IP addresses. The administrator wants to reduce the risk without blocking legitimate users who may share a corporate NAT IP. Which countermeasure is most effective?
Select an answer first - 33
An attacker has been sending HTTP requests with varying Host headers to a web server that hosts multiple virtual hosts. The server's default virtual host is returning sensitive error messages that reveal internal paths. Which attack is being performed, and what is the best countermeasure?
Select an answer first - 34
A company's web server is experiencing a DDoS attack that is overwhelming the network link. The attack traffic is a mix of UDP floods and HTTP requests. The company has a limited budget and needs to keep the server available for legitimate users. Which mitigation strategy is most appropriate?
Select an answer first - 35
A small e-commerce company hosts its website on a single Windows IIS server. After a recent security review, the administrator notices that the server's HTTP logs show a large number of requests for URLs containing encoded path segments like /%2e%2e/%2e%2e/winnt/system32/cmd.exe. The requests originate from many different IP addresses over a short period. What is the most likely attack being attempted, and what immediate countermeasure should the administrator implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.