Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 3

Network Scanning and Reconnaissance WAHS Practice Questions (Page 1)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts

Questions 1–5

  1. 1application · medium

    A security analyst is conducting a scan of a target network and wants to avoid being traced back to the source IP. The analyst has access to a set of compromised hosts that can be used to relay traffic. Which Nmap option is designed to obscure the source of the scan?

    Select an answer first
  2. 2application · medium

    A network administrator is performing a security assessment and needs to identify all live hosts on a subnet that blocks ICMP echo requests. Which Nmap host discovery technique is most effective in this situation?

    Select an answer first
  3. 3foundation · easy

    Which of the following tools is specifically designed for network scanning and is widely used for port scanning and service detection?

    Select an answer first
  4. 4foundation · easy

    When performing host discovery, why might an attacker use a TCP SYN probe to port 443 instead of an ICMP ping?

    Select an answer first
  5. 5foundation · easy

    Which of the following is an example of active OS fingerprinting?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.