
EC-CouncilEthical Hacking Essentials
Domain 8Objective 5
Penetration Testing Guidelines and Recommendations EHE Practice Questions (Page 7)
Part of the Cloud Computing and Penetration Testing domain, which makes up ~12% of our current practice bank.
40questions here
8free pages
2concepts
Questions 31–35
- 31
A penetration tester is engaged to assess a client's hybrid infrastructure. The client has a strict requirement that no testing may be performed on the production database, but the tester believes the database is the most likely target for attackers. The client also wants a comprehensive assessment. What is the best course of action?
Select an answer first - 32
A penetration testing team is documenting their findings. They want to ensure that the client can verify the vulnerabilities independently. What should the team include in the documentation?
Select an answer first - 33
A penetration tester is engaged to test a client's application that is hosted in a public cloud. The client is concerned about the test affecting other customers who share the same infrastructure. The tester wants to perform a thorough test. What is the best approach?
Select an answer first - 34
A penetration tester is assessing a client's cloud environment. The client is concerned about data residency regulations and wants to ensure that no data leaves a specific geographic region during testing. What should the tester do?
Select an answer first - 35
A penetration tester is preparing a final report for a client. The client wants to understand the overall security posture and the most critical risks. Which section of the report should be emphasized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.