Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 6Objective 1

Web Server Attacks EHE Practice Questions (Page 2)

Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.

44questions here
9free pages
4concepts

Questions 6–10

  1. 6expert · hard

    A security engineer is hardening a web server that must remain available 24/7. The server is currently vulnerable to directory traversal and has a known DoS vulnerability that can be triggered by a specific HTTP request. The engineer has limited maintenance windows and cannot take the server offline for long. Which approach best balances security and availability?

    Select an answer first
  2. 7foundation · easy

    What is the primary goal of an HTTP verb tampering attack?

    Select an answer first
  3. 8expert · hard

    A company is deploying a new web application on a server that also hosts legacy applications. The new application requires PHP, but the legacy applications only use static HTML. The administrator is concerned about reducing the attack surface. Which configuration is the most secure while maintaining functionality?

    Select an answer first
  4. 9application · medium

    A web server has been compromised due to a known vulnerability in a third-party plugin. The administrator wants to prevent similar incidents in the future. Which countermeasure is most effective?

    Select an answer first
  5. 10application · medium

    A penetration tester is testing a web server and sends a request with the HTTP method 'PROPFIND'. The server responds with a 200 OK and lists directory contents. This behavior indicates that the server is vulnerable to which type of attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.