
EC-CouncilCertified Ethical Hacker
Domain 3Objective 1
Vulnerability Analysis and CVSS CEH Practice Questions (Page 1)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 1–5
- 1
A penetration tester is preparing a remediation plan for a client. The client has a public-facing web server with a critical vulnerability (CVSS 9.8) that is actively being exploited in the wild. The client also has an internal database server with a high vulnerability (CVSS 8.1) that is not exposed to the internet. The client has limited staff and can only patch one system this week. Which vulnerability should be patched first?
Select an answer first - 2
A penetration tester has identified two vulnerabilities in a client's environment. Vulnerability A has a CVSS base score of 9.0 but is only exploitable by an attacker with physical access to the server room. Vulnerability B has a CVSS base score of 6.5 but is remotely exploitable without authentication and affects an internet-facing application. The client has limited resources and can only remediate one vulnerability this week. Which vulnerability should be prioritized?
Select an answer first - 3
A security analyst is investigating a vulnerability that was disclosed in a third-party library used by the company's application. The analyst needs to find out if the vulnerability has a CVE ID, what the CVSS score is, and whether there are any known exploits. Which combination of resources should the analyst use?
Select an answer first - 4
A security team has a limited maintenance window and must choose between patching a critical vulnerability (CVSS 9.8) on a non-critical internal server and patching a high vulnerability (CVSS 7.5) on an internet-facing web server. The exploit for the critical vulnerability is not public, while the high vulnerability has an active exploit in the wild. Which should the team patch first?
Select an answer first - 5
In a remediation context, why is CVSS score alone not sufficient for prioritizing vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.