
EC-CouncilCertified Ethical Hacker
Domain 3Objective 1
Vulnerability Analysis and CVSS CEH Practice Questions (Page 8)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 36–40
- 36
A vulnerability assessment report lists the following findings: (1) an outdated SSL/TLS configuration on a web server, (2) a missing security patch on a database server, (3) a SQL injection flaw in a custom application, and (4) a weak password policy on a domain controller. How should these findings be categorized?
Select an answer first - 37
A security team must prioritize vulnerabilities for a patch cycle. They have the following data: Vulnerability 1: CVSS 9.0, internal system, no known exploit. Vulnerability 2: CVSS 7.5, internet-facing, public exploit. Vulnerability 3: CVSS 5.0, internal system, but the system contains sensitive customer data. Which vulnerability should be patched first?
Select an answer first - 38
A vulnerability scanner reports a CVSS v3.1 base score of 6.1 for a web application vulnerability. The security team needs to determine the severity rating and decide if it should be fixed before the next release. What is the severity rating and what does it imply?
Select an answer first - 39
A security engineer is analyzing a CVSS vector string for a vulnerability in a desktop application. The vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. The engineer needs to explain why the attack vector is 'Local' rather than 'Network'. Which statement correctly justifies this classification?
Select an answer first - 40
Which CVSS metric indicates the level of access an attacker must have before being able to exploit a vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CEH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.