
EC-CouncilEthical Hacking Essentials
Domain 1Objective 2
Threats, Threat Sources, and Vulnerabilities EHE Practice Questions (Page 1)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
6concepts
Questions 1–5
- 1
In information security, what is a vulnerability?
Select an answer first - 2
A company is assessing the risk of a data breach. They identify that their employees use weak passwords, and that the company stores sensitive customer data on a server with a known vulnerability. Which combination of threat source and vulnerability category is most relevant to this risk?
Select an answer first - 3
A security audit reveals that a database server has default credentials enabled and is missing critical security patches. Which vulnerability categories are present?
Select an answer first - 4
An attacker uses a USB drop attack, leaving infected USB drives in the parking lot. An employee plugs one in, and malware installs. Which threat type and vulnerability category are involved?
Select an answer first - 5
A company is deciding between two security investments: (1) advanced endpoint protection to stop malware, and (2) a security awareness training program to reduce phishing. The company has seen both malware infections and successful phishing attacks. Which approach is most balanced?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.