Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 1Objective 5

Hacking Concepts and Hacker Classes EHE Practice Questions (Page 7)

Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.

37questions here
8free pages
4concepts

Questions 31–35

  1. 31application · medium

    A security consultant is hired by a bank to test its online banking portal. The consultant signs a contract that defines the exact IP ranges and application URLs that may be tested, and the testing is scheduled for off-peak hours. During the test, the consultant discovers a critical vulnerability in a customer-facing API that is outside the defined scope. What is the most appropriate action for the consultant?

    Select an answer first
  2. 32expert · hard

    A security consultant is hired to perform a penetration test. The contract includes a clause that allows the consultant to use 'any means necessary' to test the security of the client's network. During the test, the consultant discovers that the client's network is also used by a third-party partner via a VPN. The consultant could easily pivot into the partner's network. The consultant has no authorization from the partner. What is the most appropriate action?

    Select an answer first
  3. 33foundation · easy

    What distinguishes a gray hat hacker from a white hat hacker?

    Select an answer first
  4. 34expert · medium

    A company discovers that a former employee, who was a skilled security engineer, has been accessing the company's network without authorization. The former employee is using a custom backdoor that they created while employed. The employee's motive appears to be revenge for being fired. Which classification best describes the former employee?

    Select an answer first
  5. 35expert · hard

    A company hires a penetration tester to evaluate its new web application. The tester is given a test account with limited privileges. During the test, the tester discovers that the application has a privilege escalation vulnerability that could allow full admin access. The tester's contract states that the goal is to 'identify vulnerabilities that could lead to unauthorized access.' The tester successfully escalates privileges and gains admin access. What should the tester do next?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.