
EC-CouncilCertified Ethical Hacker
Domain 3Objective 1
Vulnerability Analysis and CVSS CEH Practice Questions (Page 4)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 16–20
- 16
A vulnerability that allows an attacker to inject malicious SQL commands into a web application's database query is best classified under which vulnerability category?
Select an answer first - 17
In CVSS v3.1, which metric describes the conditions that must be met for an attack to be successful, such as whether the attacker needs to win a race condition or bypass certain mitigations?
Select an answer first - 18
During a vulnerability assessment, a tester finds that a web application uses a database with default credentials, a server is missing a critical security patch, and the firewall allows inbound Telnet. How should these be categorized?
Select an answer first - 19
In CVSS, which metric group allows an organization to adjust a vulnerability score based on the specific impact to their own systems and the availability of mitigations?
Select an answer first - 20
A security team is conducting a vulnerability assessment for a small business. The team has identified several vulnerabilities, including an outdated operating system, a weak wireless encryption protocol, and a misconfigured firewall. The business owner asks the team to explain the purpose of the vulnerability assessment. Which response best describes the purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.