Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 3Objective 3

Vulnerability Scanning and Assessment EHE Practice Questions (Page 8)

Part of the Ethical Hacking Methodology domain, which makes up ~12% of our current practice bank.

45questions here
9free pages
6concepts

Questions 36–40

  1. 36application · medium

    A vulnerability assessment team is planning a scan of a large enterprise network. They need to ensure the scan does not disrupt business operations and that the results are actionable. Which step should they perform FIRST?

    Select an answer first
  2. 37expert · hard

    A vulnerability scan of a web application reports a SQL injection vulnerability in a login form. The security analyst manually tests the form and finds that the input is properly sanitized and the vulnerability does not exist. However, the scanner also reports a cross-site scripting (XSS) vulnerability in a search field, which the analyst confirms is real. What should the analyst do with the scan results?

    Select an answer first
  3. 38foundation · easy

    What is the primary purpose of the reporting step in a vulnerability assessment?

    Select an answer first
  4. 39application · medium

    A vulnerability scan reports a critical vulnerability on a server. The security analyst manually verifies the finding and determines that the vulnerability is not actually present because the server's configuration mitigates it. What should the analyst do?

    Select an answer first
  5. 40application · medium

    A security consultant is conducting a vulnerability assessment for a client. The consultant has completed the planning phase and is about to begin the discovery phase. Which activity is part of the discovery phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.