
EC-CouncilEthical Hacking Essentials
Domain 3Objective 4
Gaining Access, Maintaining Access, and Covering Tracks EHE Practice Questions (Page 2)
Part of the Ethical Hacking Methodology domain, which makes up ~12% of our current practice bank.
26questions here
6free pages
3concepts
Questions 6–10
- 6
An attacker has compromised a Linux server and wants to maintain access. The server has a security tool that monitors for new listening ports and outbound connections. The attacker wants to avoid detection by this tool. Which method is most appropriate?
Select an answer first - 7
An attacker has compromised a Windows server and wants to hide a malicious executable from the user and from standard file listings. The attacker has administrator privileges. Which technique is most effective for hiding the file?
Select an answer first - 8
A security analyst is testing the physical security of a client's office. The analyst wants to demonstrate how an attacker could gain access to the internal network without using technical exploits. Which technique is most appropriate?
Select an answer first - 9
A security analyst is simulating an external attacker targeting a company's public-facing web server. The analyst has identified a SQL injection vulnerability in the login form and wants to gain access to the backend database. Which technique is most appropriate for this phase?
Select an answer first - 10
A penetration tester successfully exploited a SQL injection flaw on a public-facing web server and obtained a low-privilege shell. The tester needs to escalate privileges to administrator and then ensure continued access even if the web application is patched. Which sequence of actions best achieves the tester's goals while minimizing the chance of immediate detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.