
EC-CouncilEthical Hacking Essentials
Domain 1Objective 2
Threats, Threat Sources, and Vulnerabilities EHE Practice Questions (Page 9)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
6concepts
Questions 41–44
- 41
A company's network administrator discovers that the firewall rule set has not been reviewed in two years, and several obsolete rules allow inbound RDP from the internet. Which vulnerability category does this represent, and what threat is most likely to exploit it?
Select an answer first - 42
An organization discovers that several employees have written their passwords on sticky notes attached to their monitors. Which vulnerability category does this represent, and what is the most likely threat that could exploit it?
Select an answer first - 43
An attacker sends a phishing email to employees, tricking them into entering their credentials on a fake login page. Which threat type is primarily being used?
Select an answer first - 44
A small business uses a legacy web application that still supports SSLv3. An attacker exploits this to decrypt session cookies. In this scenario, what is the vulnerability?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.