
EC-CouncilCertified Security Specialist
Domain 3Objective 4
Ethical Hacking Phases (reconnaissance to Exploitation) ECSS Practice Questions (Page 9)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
47questions here
10free pages
7concepts
Questions 41–45
- 41
Which type of information is typically gathered during the footprinting phase?
Select an answer first - 42
During a penetration test, you have identified that a Linux server is running an outdated version of vsftpd that is vulnerable to a known backdoor exploit. Your goal is to gain initial access to the server. Which phase of ethical hacking are you about to perform?
Select an answer first - 43
After enumerating a web server, a penetration tester has a list of open ports and services. The tester now needs to identify which specific vulnerabilities exist in the software versions running on those services before attempting to exploit them. Which activity should the tester perform?
Select an answer first - 44
A security analyst is performing a scan of a target network and has identified that a host is running an FTP service on port 21. The analyst wants to determine if the FTP service is vulnerable to a known exploit. What should the analyst do next?
Select an answer first - 45
A penetration tester has completed scanning and identified that a target server is running an SMB service on port 445. The tester now needs to extract user accounts, share names, and group policies from the service to plan an attack. Which phase of the ethical hacking methodology does this activity belong to?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.