Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 8Objective 5

Penetration Testing Guidelines and Recommendations EHE Practice Questions (Page 4)

Part of the Cloud Computing and Penetration Testing domain, which makes up ~12% of our current practice bank.

40questions here
8free pages
2concepts

Questions 16–20

  1. 16application · medium

    A penetration tester is asked to test a client's application that is hosted on a cloud provider. The client provides credentials for a test account but does not provide written authorization for the cloud provider's environment. What should the tester do?

    Select an answer first
  2. 17expert · hard

    A penetration tester is assessing a client's network that includes both on-premises and cloud resources. The client has a compliance requirement that data must not leave the country. The tester plans to use a cloud-based scanning service. What is the most important consideration?

    Select an answer first
  3. 18application · medium

    A penetration tester is conducting an assessment and discovers that a vulnerability is actually a misconfiguration that the client's team already knows about and has accepted the risk for. What should the tester do?

    Select an answer first
  4. 19application · medium

    A penetration tester is conducting an assessment for a client that has a strict no-downtime policy. The tester plans to test a critical database server. What should the tester do to align with the policy?

    Select an answer first
  5. 20application · medium

    A penetration tester is preparing to assess a client's web application. The client wants to ensure that the testing process is repeatable and that results can be compared over time. Which practice should the tester adopt?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.