
EC-CouncilEthical Hacking Essentials
Domain 6Objective 1
Web Server Attacks EHE Practice Questions (Page 9)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
44questions here
9free pages
4concepts
Questions 41–44
- 41
A security assessment of a legacy web application reveals that the server responds to both GET and PUT requests on the same resource. An attacker could upload a malicious file by sending a PUT request to a known writable path. Which countermeasure should be implemented to directly address this issue?
Select an answer first - 42
A web server is experiencing a distributed denial-of-service (DDoS) attack that is saturating the network link. The server is also vulnerable to a known application-layer attack that can crash the worker process. The administrator needs to keep the server available for legitimate users. Which combination of countermeasures is most effective?
Select an answer first - 43
What is the primary security risk associated with leaving default credentials on a web server's administrative interface?
Select an answer first - 44
A web server has been infected with malware that is using the server to launch attacks against other systems. The administrator has identified the malware but cannot remove it immediately because the server hosts a critical application. Which action should the administrator take first to limit the impact?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.