Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 1Objective 2

Threats, Threat Sources, and Vulnerabilities EHE Practice Questions (Page 9)

Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.

44questions here
9free pages
6concepts

Questions 41–44

  1. 41application · medium

    A company's network administrator discovers that the firewall rule set has not been reviewed in two years, and several obsolete rules allow inbound RDP from the internet. Which vulnerability category does this represent, and what threat is most likely to exploit it?

    Select an answer first
  2. 42application · medium

    An organization discovers that several employees have written their passwords on sticky notes attached to their monitors. Which vulnerability category does this represent, and what is the most likely threat that could exploit it?

    Select an answer first
  3. 43application · medium

    An attacker sends a phishing email to employees, tricking them into entering their credentials on a fake login page. Which threat type is primarily being used?

    Select an answer first
  4. 44application · medium

    A small business uses a legacy web application that still supports SSLv3. An attacker exploits this to decrypt session cookies. In this scenario, what is the vulnerability?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to EHE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.