
EC-CouncilEthical Hacking Essentials
Domain 6Objective 1
Web Server Attacks EHE Practice Questions (Page 4)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
44questions here
9free pages
4concepts
Questions 16–20
- 16
Which web server attack technique involves manipulating file path parameters to access files outside the intended directory?
Select an answer first - 17
A company's web server is running an outdated version of Apache that has a known remote code execution vulnerability. The server also has the WebDAV module enabled, which is not needed for the application. An administrator is planning to mitigate the risk. Which action should the administrator take first?
Select an answer first - 18
A security team is investigating a web server breach. The logs show that an attacker used a valid session cookie to access the admin panel, but the attacker's IP address is different from the legitimate admin's IP. The server is configured to allow session cookies to be sent over HTTP, and the admin panel does not have additional authentication factors. What is the most likely attack vector, and what is the best countermeasure?
Select an answer first - 19
A web server is being hardened. The server is running a public-facing application and also hosts a database that is only accessed by the application. The database is currently listening on all interfaces. Which change should be made to reduce the attack surface?
Select an answer first - 20
Which of the following best describes the attack surface of a typical web server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.