
EC-CouncilEthical Hacking Essentials
Domain 6Objective 1
Web Server Attacks EHE Practice Questions (Page 3)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
44questions here
9free pages
4concepts
Questions 11–15
- 11
A web server is found to be missing several critical security patches. The server is running a legacy application that is not compatible with the latest version of the operating system. The company cannot afford to upgrade the application. Which approach is the most practical to reduce the risk?
Select an answer first - 12
A web server is vulnerable to HTTP request smuggling because it is behind a proxy that handles requests differently than the backend server. An attacker is exploiting this to bypass security controls. Which countermeasure is most effective?
Select an answer first - 13
A penetration test reveals that a web server is vulnerable to a known remote code execution vulnerability in the web server software. The vendor has released a patch, but the server is running a legacy application that is not compatible with the patched version. The application cannot be upgraded in the near term. Which mitigation strategy is most appropriate?
Select an answer first - 14
A web server is running an application that accepts user input for a search feature. The application is vulnerable to command injection because it passes user input directly to a system shell. Which countermeasure should be implemented to mitigate this vulnerability?
Select an answer first - 15
Which countermeasure is most effective in preventing directory traversal attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.