Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 1Objective 2

Threats, Threat Sources, and Vulnerabilities EHE Practice Questions (Page 5)

Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.

44questions here
9free pages
6concepts

Questions 21–25

  1. 21expert · hard

    A security team is prioritizing remediation for a web application. They find two issues: (1) a missing input validation that could allow SQL injection, and (2) a misconfigured CORS policy that allows any origin. Both are exploitable, but the SQL injection could lead to full database compromise, while the CORS issue could allow cross-site requests. Which vulnerability category should be addressed first, and why?

    Select an answer first
  2. 22expert · hard

    A security analyst is evaluating two risks: (1) a critical SQL injection flaw in an internal HR application that is only accessible by 10 employees, and (2) a low-severity misconfiguration in a public-facing web server that exposes server version information. Which risk should be prioritized for remediation, and why?

    Select an answer first
  3. 23foundation · easy

    Which of the following is classified as a physical threat?

    Select an answer first
  4. 24foundation · easy

    Which of the following is an example of a technical vulnerability?

    Select an answer first
  5. 25application · medium

    A company's office is hit by a tornado that destroys the server room and all on-site backups. Which threat type and source combination is this, and what vulnerability made the impact worse?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.