
EC-CouncilCertified Ethical Hacker
Domain 3Objective 1
Vulnerability Analysis and CVSS CEH Practice Questions (Page 6)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 26–30
- 26
Which statement best describes the role of vulnerability assessment in the ethical hacking methodology?
Select an answer first - 27
An organization has two vulnerabilities to remediate: Vulnerability A has a CVSS base score of 9.0 but is only exploitable from the internal network with no known exploit. Vulnerability B has a CVSS base score of 6.5 but is internet-facing and has a public exploit. The team has limited resources. Which should be prioritized?
Select an answer first - 28
A vulnerability assessment report for a corporate network includes the following findings: (1) a buffer overflow in a legacy application, (2) an open SMB port on a file server, (3) a default password on a network printer, and (4) a lack of encryption on a wireless network. Which classification best describes these findings?
Select an answer first - 29
During a penetration test, you discover two vulnerabilities: one with a CVSS score of 9.0 that affects an internet-facing web server, and another with a score of 6.5 that affects an internal legacy application. Based on CVSS prioritization, which vulnerability should be addressed first?
Select an answer first - 30
According to the CVSS v3.1 severity rating scale, which qualitative rating corresponds to a base score of 7.5?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.