
EC-CouncilCertified Ethical Hacker
Domain 3Objective 3
Vulnerability Exploitation and Metasploit CEH Practice Questions (Page 5)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
14concepts
Questions 21–25
- 21
After a successful exploit in Metasploit, what command is used to interact with the resulting session?
Select an answer first - 22
What is the primary responsibility of an ethical hacker when performing exploitation?
Select an answer first - 23
In the exploitation methodology, what is the primary purpose of the enumeration phase?
Select an answer first - 24
You are conducting a penetration test and have completed the enumeration phase. You have identified a web server running Apache Tomcat with the manager interface exposed. You suspect a weak password on the manager account. What is the most logical next step in the exploitation methodology?
Select an answer first - 25
Which of the following is NOT a core component of the Metasploit Framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.