
EC-CouncilCertified Ethical Hacker
Domain 3Objective 1
Vulnerability Analysis and CVSS CEH Practice Questions (Page 7)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 31–35
- 31
A security analyst is researching a newly disclosed vulnerability and wants to find its CVE identifier, a CVSS v3.1 base score, and a description of the affected software. Which resource should the analyst consult first?
Select an answer first - 32
Given the CVSS vector string "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", which metric indicates that the vulnerability can be exploited without any user interaction?
Select an answer first - 33
A security analyst is researching a newly disclosed vulnerability in a widely used network device. The analyst wants to find the official CVE identifier, the CVSS score, and references to patches or mitigations. Which resource should the analyst consult first?
Select an answer first - 34
A security analyst is prioritizing vulnerabilities from a recent scan. The organization's compliance team requires that any vulnerability affecting internet-facing systems be remediated before internal ones. Which approach best aligns the remediation order with this policy?
Select an answer first - 35
A security manager is reviewing a vulnerability assessment report for a financial application. The report includes the following vulnerabilities: (1) a SQL injection in the login form with a CVSS score of 9.8, (2) a cross-site scripting (XSS) vulnerability in a comment field with a CVSS score of 6.1, and (3) a misconfigured security header with a CVSS score of 5.3. The application is internet-facing and processes sensitive customer data. The manager has limited resources and must prioritize remediation. Which vulnerability should be addressed first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.