
EC-CouncilCertified Security Specialist
Domain 3Objective 4
Ethical Hacking Phases (reconnaissance to Exploitation) ECSS Practice Questions (Page 4)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
47questions here
10free pages
7concepts
Questions 16–20
- 16
A security consultant is beginning an authorized penetration test for a client. The client has asked the consultant to avoid any activity that could be detected by their network monitoring team during the initial information-gathering stage. The consultant needs to collect employee names, email formats, and technology stack details from public sources. Which approach should the consultant use?
Select an answer first - 17
A security analyst is tasked with identifying weaknesses in a network before an external attacker can exploit them. The analyst has already completed scanning and enumeration. What should the analyst do next to prioritize which vulnerabilities to address first?
Select an answer first - 18
Which type of information is typically extracted during the enumeration phase?
Select an answer first - 19
You are conducting a vulnerability assessment for a web application. After scanning, you find that the server is running Apache 2.4.49, which is vulnerable to a path traversal and remote code execution (CVE-2021-41773). You need to confirm whether the vulnerability is actually exploitable in this specific configuration. What should you do next?
Select an answer first - 20
What is the primary goal of the exploitation phase in ethical hacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.