
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 3
Network Scanning and Reconnaissance WAHS Practice Questions (Page 1)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 1–5
- 1
A security analyst is conducting a scan of a target network and wants to avoid being traced back to the source IP. The analyst has access to a set of compromised hosts that can be used to relay traffic. Which Nmap option is designed to obscure the source of the scan?
Select an answer first - 2
A network administrator is performing a security assessment and needs to identify all live hosts on a subnet that blocks ICMP echo requests. Which Nmap host discovery technique is most effective in this situation?
Select an answer first - 3
Which of the following tools is specifically designed for network scanning and is widely used for port scanning and service detection?
Select an answer first - 4
When performing host discovery, why might an attacker use a TCP SYN probe to port 443 instead of an ICMP ping?
Select an answer first - 5
Which of the following is an example of active OS fingerprinting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.