Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 3

Network Scanning and Reconnaissance WAHS Practice Questions (Page 2)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts

Questions 6–10

  1. 6application · medium

    A company's security team wants to reduce the risk of internal network scanning by limiting the information available to potential attackers. They have a web server that only needs to respond to HTTP and HTTPS traffic from the internet. Which configuration is most effective for this goal?

    Select an answer first
  2. 7foundation · easy

    Why is it important to determine the version of a service running on an open port during a security assessment?

    Select an answer first
  3. 8expert · hard

    A penetration tester is scanning a target that is protected by an intrusion prevention system (IPS) which drops packets that match known scan signatures. The tester needs to identify open TCP ports and the services running on them, but must avoid detection. The tester has a limited time window. Which approach is most likely to succeed?

    Select an answer first
  4. 9application · medium

    A penetration tester is scanning a target network that has an IDS that triggers on port scans from a single IP address. The tester wants to perform a SYN scan while making it harder for the IDS to attribute the scan to the tester's IP. Which Nmap technique is most appropriate?

    Select an answer first
  5. 10expert · hard

    A penetration tester is conducting a red-team exercise against a target network that uses an IDS to detect port scans. The tester needs to scan all TCP ports on a target host, but the IDS is configured to alert on any scan that hits more than 100 ports in a 10-minute window from a single source IP. Which technique is most effective to avoid detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.