
EC-CouncilEthical Hacking Essentials
Domain 6Objective 1
Web Server Attacks EHE Practice Questions (Page 1)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
44questions here
9free pages
4concepts
Questions 1–5
- 1
A security auditor is reviewing a web server's configuration and notices that the server is running both a web application and a database management system on the same host. The database is listening on a public IP address. Which attack surface does this configuration primarily increase?
Select an answer first - 2
A web server is found to have several unnecessary services running, including an FTP server and a telnet daemon. The server is only supposed to serve web content. Which hardening step should be performed first?
Select an answer first - 3
A web server is hosted in a DMZ and also has a management interface that is accessible from the internal network. The management interface uses a self-signed certificate. An administrator notices that the server's web application is vulnerable to SQL injection. Which combination of measures should be implemented to reduce the risk?
Select an answer first - 4
A company runs a public-facing web server that also hosts an internal admin panel. The admin panel is accessible from the internet. The server is running an outdated version of the web server software with known vulnerabilities. The company wants to reduce the attack surface while keeping the admin panel accessible to remote administrators. Which combination of measures best achieves this?
Select an answer first - 5
A web server is vulnerable to directory traversal because the application does not validate user-supplied file paths. The developer wants to fix the issue without breaking existing functionality. Which coding practice is the most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.