
EC-CouncilCertified Security Specialist
Domain 3Objective 4
Ethical Hacking Phases (reconnaissance to Exploitation) ECSS Practice Questions (Page 7)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
47questions here
10free pages
7concepts
Questions 31–35
- 31
Which of the following is an example of passive reconnaissance?
Select an answer first - 32
During an authorized penetration test, you need to identify which hosts on a subnet are alive and which TCP ports are open on those hosts. You have been given a list of IP addresses to test. Which tool and technique would most efficiently accomplish this?
Select an answer first - 33
A penetration tester has identified a critical vulnerability in a web application that allows remote code execution. The tester's goal is to gain initial access to the server to demonstrate the impact. Which phase of the ethical hacking process is the tester about to perform?
Select an answer first - 34
During an authorized penetration test, a tester has completed passive reconnaissance and identified the target's IP range. The next step is to determine which hosts are alive and which ports are open, but the tester must minimize the chance of triggering intrusion detection systems. Which technique should the tester use?
Select an answer first - 35
A penetration tester is conducting a scan of a target network. The tester wants to identify live hosts, open ports, and the services running on those ports. Which tool or technique is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.