312-50 exam dumps

312-50 practice question 115 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 115

Single answer▪ Vulnerability Classification and Assessment

During an internal vulnerability assessment, a CEH analyst identifies three issues on a public-facing customer portal: (1) a reflected XSS in a search parameter that requires user interaction, (2) an outdated OpenSSL library on the web server with a published remote code execution CVE but no known exploit attempts in the environment, and (3) a default SNMP community string on an internal printer segment that is not reachable from the internet. Management asks which issue should be classified as the highest remediation priority based on standard vulnerability assessment practice that considers exploitability, impact, and exposure. Which finding should the analyst prioritize first?

  1. A

    The reflected XSS, because web application vulnerabilities should take precedence over infrastructure vulnerabilities on customer-facing systems

  2. B

    The outdated OpenSSL library with a published remote code execution CVE on the public-facing server

  3. C

    The default SNMP community string, because default credentials automatically make a vulnerability critical

  4. D

    All three findings should be assigned the same priority until active exploitation is confirmed

Show answer and explanation

Correct answer: B

Explanation

The best answer is the outdated OpenSSL library with a published remote code execution CVE on the public-facing server. In vulnerability classification and assessment, the analyst should prioritize based on risk, not just vulnerability category. Common frameworks such as CVSS v3.1 emphasize factors including attack vector, attack complexity, privileges required, user interaction, scope, and impact. A remotely exploitable RCE on an internet-facing system generally outranks a reflected XSS that requires user interaction and an internally exposed default SNMP community string on a lower-value segment. This reflects standard best practice from risk-based vulnerability management programs: prioritize findings with the combination of high impact, broad exposure, and feasible exploitation path. References include FIRST's CVSS v3.1 specification and NIST guidance on risk assessment and vulnerability management, such as NIST SP 800-40 and NIST SP 800-30.

  • A. Incorrect.

    Incorrect. Reflected XSS can be serious, especially on a public-facing portal, but in this scenario it requires user interaction and is generally more constrained than a remotely exploitable server-side RCE on an internet-facing host. A common mistake is to prioritize all web issues above infrastructure flaws without evaluating exploitability and impact in context.

  • B. Correct.

    Correct. A published remote code execution vulnerability in OpenSSL on a public-facing server typically represents the highest risk here because it combines high impact (possible server compromise), high exposure (internet-facing asset), and realistic exploitability. Standard assessment approaches, including CVSS-based reasoning and risk-based prioritization, place strong emphasis on attack vector, privileges required, user interaction, and impact to confidentiality, integrity, and availability.

  • C. Incorrect.

    Incorrect. Default SNMP community strings are a valid security weakness and can expose device information or allow configuration issues depending on version and permissions, but this finding is on an internal printer segment and is not internet-reachable. Its exposure and likely business impact are lower than a public-facing RCE. The misconception is assuming default credentials are automatically the top priority regardless of location and reachable attack surface.

  • D. Incorrect.

    Incorrect. Vulnerability assessment does not require confirmed active exploitation before assigning priority. In fact, one purpose of assessment is to rank and remediate weaknesses before compromise occurs. Treating all findings equally ignores standard risk-rating factors such as exposure, exploitability, required interaction, and potential impact.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam