Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 3

Network Scanning and Reconnaissance WAHS Practice Questions (Page 7)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts

Questions 31–35

  1. 31application · medium

    A security analyst is performing reconnaissance on a target web server. The analyst needs to identify which ports are open without completing the TCP handshake, to avoid being logged by the application's connection logging. Which Nmap scan type should be used?

    Select an answer first
  2. 32application · hard

    A penetration tester is scanning a target and has identified an open port running an HTTP service. The tester needs to determine the exact web server software and version to look for known exploits, but the service is behind a load balancer that may obscure the backend version. Which approach is most likely to reveal the true version?

    Select an answer first
  3. 33foundation · easy

    In Nmap, which command-line option is used to perform service version detection?

    Select an answer first
  4. 34expert · hard

    A penetration tester is performing a scan of a target network that has a firewall configured to drop all incoming UDP packets. The tester needs to identify open UDP ports on a critical server, but the client has requested that the scan be as quick as possible. Which approach is most effective?

    Select an answer first
  5. 35application · hard

    An analyst is scanning a target that is known to have a stateful firewall that drops unsolicited SYN packets. The analyst wants to discover open TCP ports but is concerned that a standard SYN scan will be blocked. Which alternative scan type is most likely to bypass the firewall's SYN filtering?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.