Be able to read connection and log exhibits, name the attack class, and select the control that actually stops it. The single most important thing is matching the observed evidence to the correct attack type before choosing a mitigation.
Start practicing
Network and Web Application Attacks — choose a session length
Free · No account required
Domain overview
This domain covers how attackers exploit network protocols and web application flaws, and how defenders detect and stop them. Questions use exhibits, logs, and scenario prompts to test whether you can identify an attack in progress, pick the right mitigation, and predict an exploit's outcome using standard tools and protocols.
Exam objectives
Recognizing attack signatures in netstat, Wireshark, and IDS/IPS alerts such as port 443 connection floods
Choosing encryption protocols (TLS/HTTPS, SSH, IPsec) to defeat sniffing and man-in-the-middle capture
Identifying SQL injection, XSS, and command injection payloads and their database or server outcomes
Mapping web server and application attacks to Apache, Ubuntu, and OWASP-style countermeasures
Assuming port 443 traffic is always safe, so encrypted command-and-control or beaconing over HTTPS is missed as benign web traffic.
Confusing SQL injection outcomes with XSS or command injection, then selecting the wrong impact such as credential theft versus database dump.
Recommending a firewall or IDS rule when the question asks for encryption to stop sniffing, which only TLS or SSH provides.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a penetration test, you notice that a web application accepts user input and displays it directly in the browser without sanitization. Which attack is most likely to succeed?
2As a network defender, you notice an unusually high number of incomplete TCP three-way handshakes from a single external IP to multiple internal hosts. What is the most likely attack taking place?
3You are performing a web application security assessment and discover that the application uses a hidden form field named 'price' to store the product price. The price is submitted with the form and used to process payments. Which attack would allow you to purchase an item for a lower price?
4A network administrator wants to prevent an attacker from using a network sniffer to capture traffic between a client and a web server. Which protocol should be enforced to encrypt all communication?
5Refer to the exhibit. A security analyst captured the HTTP request and response shown. What type of vulnerability is present?
6You are the lead security engineer for a financial technology company that hosts a critical web application on three load-balanced servers behind a reverse proxy. The application uses a REST API to process transactions. Recently, the company has experienced intermittent service outages during peak hours. Upon reviewing logs, you find that the reverse proxy is returning HTTP 503 errors for legitimate API requests, and the application servers show high CPU usage but normal memory. The network team reports no bandwidth issues. The application team claims no code changes were made. You suspect a specific type of attack is causing the outages. Which action should you take first to confirm the attack type?
7Refer to the exhibit. A penetration tester executed the SQL injection payload and received the response shown. What is the most likely outcome of this attack?
8You are a security analyst for a medium-sized e-commerce company. The company hosts its web application on a single server running Apache on Ubuntu. Recently, the operations team noticed that the server's CPU usage spikes to 100% every few minutes, causing the website to become unresponsive. They have ruled out hardware issues. The web server logs show repeated requests to the same URL with varying parameters, such as /product?id=1, /product?id=2, etc., all originating from a single IP address. Each request returns a 200 OK response, but the server takes several seconds to generate the page. The application uses a relational database backend with an ORM. You suspect an attack is occurring. What is the most likely attack and the best immediate course of action?
9Match each encryption algorithm to its type.
10Refer to the exhibit. A security analyst notices multiple ESTABLISHED connections on port 443 from different external IPs to the same process ID. What type of attack is most likely occurring?
11Refer to the exhibit. An analyst runs an Nmap scan and finds these services. Which known vulnerability is most likely to be successfully exploited?
12Refer to the exhibit. A penetration tester sends a SOAP request and receives multiple user records. Which vulnerability is present?
13Refer to the exhibit. A penetration tester observes that the DNS server returns both internal (10.0.0.0/8) and external (203.0.113.5) IP addresses for the same domain. What is this technique called?
14A penetration tester is assigned to test a web application that uses a JSON Web Token (JWT) for session management. The tester captures the token and notices it is signed with the HS256 algorithm. After several attempts to crack the signing key offline, the tester modifies the token's payload to elevate privileges and changes the 'alg' header value to 'none'. When the modified token is sent to the server, the application accepts it and grants administrative access. Which vulnerability has the tester exploited?
15A security analyst is reviewing a web server log and notices a large number of requests with the User-Agent string 'sqlmap/1.5.2#stable'. The requests contain various payloads in the 'id' parameter, such as '1' AND 1=1--' and '1' UNION SELECT null, version()--'. The analyst concludes that an automated SQL injection tool is being used against the application. Which type of attack is being performed?
Be able to read connection and log exhibits, name the attack class, and select the control that actually stops it. The single most important thing is matching the observed evidence to the correct attack type before choosing a mitigation.
The Courseiva CEH question bank contains 15 questions in the Network and Web Application Attacks domain, covering the 7% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network and Web Application Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included