
EC-CouncilEthical Hacking Essentials
Domain 6Objective 1
Web Server Attacks EHE Practice Questions (Page 6)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
44questions here
9free pages
4concepts
Questions 26–30
- 26
A small e-commerce company recently migrated its web storefront to a new Linux server. The administrator left the default installation of Apache with the default 'it works' page, enabled directory listing, and did not change the default 'admin' account on the content management system. Which two countermeasures should the administrator implement first to reduce the most immediate risk?
Select an answer first - 27
An attacker is attempting to access files outside the web root by sending requests like /../../etc/passwd. The web server is running on a Linux system. Which countermeasure would be most effective in blocking this type of attack?
Select an answer first - 28
A web server is experiencing a DoS attack that is overwhelming the network bandwidth. The attack traffic is coming from many distributed sources. The server is behind a firewall and a load balancer. Which mitigation strategy is most effective in this scenario?
Select an answer first - 29
A security analyst is reviewing web server logs and notices requests like 'GET /../../etc/passwd' and 'GET /%2e%2e/%2e%2e/etc/passwd'. The server is returning HTTP 200 responses with file content. Which web server attack technique is being attempted, and what is the most effective countermeasure?
Select an answer first - 30
A web server is running a content management system (CMS) that is frequently targeted by attackers. The server also hosts other applications. The company wants to isolate the CMS to reduce the impact of a compromise. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.