Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 3Objective 1

Vulnerability Analysis and CVSS CEH Practice Questions (Page 3)

Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
8concepts

Questions 11–15

  1. 11application · easy

    During a vulnerability assessment, a tester identifies an open SMB port on a Windows server, a SQL injection flaw in a custom web application, and a missing security patch on a Linux host. How should these findings be classified?

    Select an answer first
  2. 12foundation · easy

    A vulnerability has a CVSS v3.1 base score of 9.8. What is its qualitative severity rating?

    Select an answer first
  3. 13application · easy

    A company wants to identify security weaknesses in its network before an external penetration test. The goal is to catalog vulnerabilities and rank them by severity without actively exploiting them. Which activity best fits this requirement?

    Select an answer first
  4. 14application · medium

    A security analyst is reviewing a CVSS v3.1 vector string: AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H. Which statement accurately describes this vulnerability?

    Select an answer first
  5. 15expert · hard

    A vulnerability has a CVSS base score of 7.5. The organization's security team adjusts the score to 6.2 because the affected system is not internet-facing and the exploit code is not public. Which CVSS metric groups did the team use to make this adjustment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.