
EC-CouncilEthical Hacking Essentials
Domain 3Objective 3
Vulnerability Scanning and Assessment EHE Practice Questions (Page 5)
Part of the Ethical Hacking Methodology domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
6concepts
Questions 21–25
- 21
In vulnerability scan results, what is a false positive?
Select an answer first - 22
A security team is planning to scan a new internal application that requires users to log in. The team wants to identify vulnerabilities that are only visible after authentication. Which type of scan should they perform?
Select an answer first - 23
A vulnerability assessment team is preparing to scan a network that includes a mix of Windows and Linux servers. They need to ensure the scan is thorough and does not miss vulnerabilities that require authentication. What should they do?
Select an answer first - 24
A vulnerability scan of a web application reports a high-risk finding for a cross-site scripting (XSS) vulnerability. The analyst reviews the scan output and sees that the scanner only tested the login page. The application has many other pages that accept user input. What is the most likely issue with the scan?
Select an answer first - 25
After a vulnerability scan, the analyst sees a critical finding for a missing security patch on a web server. The analyst manually verifies the patch is installed and the server is not vulnerable. What is the most appropriate next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.