
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 3
Network Scanning and Reconnaissance WAHS Practice Questions (Page 4)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 16–20
- 16
How does packet fragmentation help in evading detection during a scan?
Select an answer first - 17
Which of the following techniques is commonly used for host discovery to determine if a host is alive on a network?
Select an answer first - 18
A company wants to detect and block unauthorized network scanning without impacting legitimate traffic. The security team has a next-generation firewall (NGFW) that can perform deep packet inspection. Which configuration is most effective?
Select an answer first - 19
Which phase of the ethical hacking methodology does network scanning typically fall under?
Select an answer first - 20
A penetration tester is assessing a web application server. The tester has identified an open port 443 and needs to determine the exact version of the web server software to check for known vulnerabilities. The client has a strict requirement that the scan must not generate more than 50 packets per second to avoid impacting the server. Which Nmap command is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.