
EC-CouncilCertified Ethical Hacker
Domain 3Objective 3
Vulnerability Exploitation and Metasploit CEH Practice Questions (Page 1)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
14concepts
Questions 1–5
- 1
You are conducting a penetration test against a web server. Your initial port scan shows only port 80 open. You have identified a potential SQL injection in the login form. You need to gain a foothold on the system. Which approach aligns with the systematic exploitation methodology?
Select an answer first - 2
What is the purpose of a fuzzing auxiliary module in Metasploit?
Select an answer first - 3
After successfully exploiting a Windows target and obtaining a Meterpreter session, you need to gather system information, elevate privileges, and maintain access for later stages of the test. Which sequence of Meterpreter commands best accomplishes these goals?
Select an answer first - 4
Which of the following is an example of an evasion technique in Metasploit?
Select an answer first - 5
According to ethical hacking guidelines, when is it permissible to use exploitation techniques?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.