
EC-CouncilEthical Hacking Essentials
Domain 1Objective 2
Threats, Threat Sources, and Vulnerabilities EHE Practice Questions (Page 7)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
6concepts
Questions 31–35
- 31
A company has a legacy application that is critical to operations but has a known unpatched vulnerability. Patching the application would require a full day of downtime, which would disrupt business. The application is not internet-facing but is accessible from the internal network. Which mitigation strategy best balances security and business continuity?
Select an answer first - 32
A user receives an email that appears to be from the company's IT department, asking the user to verify their password by clicking a link. The link leads to a fake login page. Which threat type and threat source combination does this represent?
Select an answer first - 33
A company is deciding how to allocate its security budget. They face two threats: a high likelihood of ransomware attacks from external cybercriminals, and a low likelihood of a disgruntled insider leaking data. The company has limited resources. Which approach best balances the risk?
Select an answer first - 34
Which of the following best describes the relationship between threats and vulnerabilities?
Select an answer first - 35
A company is assessing threats to its new cloud-based customer database. They identify three threats: (1) a competitor stealing data, (2) a cloud provider employee with access, and (3) a natural disaster affecting the data center. Which threat source is most difficult to defend against?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.