
EC-CouncilCertified Security Specialist
Domain 3Objective 4
Ethical Hacking Phases (reconnaissance to Exploitation) ECSS Practice Questions (Page 3)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
47questions here
10free pages
7concepts
Questions 11–15
- 11
A penetration tester is hired to assess the security of a company. Before any active scanning, the tester wants to build a profile of the organization's network, including IP address ranges, domain names, and employee email formats. Which activity is most appropriate for this stage?
Select an answer first - 12
An ethical hacker is performing reconnaissance for a client. The hacker wants to gather information about the client's network without alerting the intrusion detection system (IDS). Which approach is most appropriate?
Select an answer first - 13
After identifying a critical vulnerability in a web application, you need to gain access to the underlying database to demonstrate the impact. You have a valid exploit that gives you a reverse shell. What is the immediate next step in the ethical hacking process?
Select an answer first - 14
After scanning a network, you find that a Windows server has NetBIOS (ports 137-139) and SMB (port 445) open. You need to extract user accounts, group memberships, and shared resources to plan a password attack. Which tool is most appropriate for this task?
Select an answer first - 15
What is the main purpose of the scanning phase in ethical hacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.