Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 1Objective 5

Hacking Concepts and Hacker Classes EHE Practice Questions (Page 6)

Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.

37questions here
8free pages
4concepts

Questions 26–30

  1. 26application · medium

    A regional bank hires a security consultant to test its new online banking portal. The consultant signs a contract that explicitly limits testing to the portal's login and transaction modules during off-peak hours, and the bank provides a dedicated test account. During the engagement, the consultant discovers a critical SQL injection flaw in a legacy internal tool that is out of scope. The consultant does not exploit the flaw further and reports it to the bank's CISO. Which hacker class and ethical principle does this scenario best illustrate?

    Select an answer first
  2. 27foundation · easy

    What does 'responsible disclosure' mean in the context of ethical hacking?

    Select an answer first
  3. 28expert · hard

    A penetration tester is hired to test a company's web application. The contract specifies that the tester must not cause any disruption to the production environment. During the test, the tester finds a vulnerability that, if exploited, could crash the application server. The tester wants to prove the vulnerability is real. What is the most appropriate action?

    Select an answer first
  4. 29expert · medium

    A company's security team is profiling an attacker who defaced the company's website and left a political message. The attacker used a custom script that exploited a known vulnerability, but the script was poorly written and caused errors. The attacker did not attempt to hide their IP address. Which classification best describes the attacker?

    Select an answer first
  5. 30expert · medium

    A company's security team is analyzing a recent breach. The attacker used a custom tool that exploited a previously unknown vulnerability, and the attack specifically targeted the company's proprietary algorithms. The attacker left no traces and the attack was discovered only after a third party reported suspicious activity. Which classification best describes the attacker?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.