312-50 exam dumps

312-50 practice question 116 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 116

Single answer▪ Vulnerability Classification and Assessment

A security consultant is performing a vulnerability assessment for a company that recently deployed a public-facing customer portal. The scanner reports the following findings on the web server: (1) an outdated Apache version with a published remote code execution CVE rated CVSS v3.1 9.8, (2) support for TLS 1.0 and weak cipher suites, (3) directory listing enabled on a non-sensitive static content folder, and (4) missing HTTP security headers such as X-Frame-Options and Content-Security-Policy. The portal processes customer profile updates and is reachable from the Internet. The operations team can only remediate one issue immediately during a short maintenance window. Which finding should be classified as the highest remediation priority?

  1. A

    Directory listing enabled on a non-sensitive static content folder because it exposes server structure information

  2. B

    Missing HTTP security headers because they increase exposure to client-side attacks such as clickjacking

  3. C

    Support for TLS 1.0 and weak cipher suites because deprecated cryptography weakens transport security

  4. D

    Outdated Apache version with a published remote code execution vulnerability rated CVSS v3.1 9.8 because it presents a likely direct server compromise path

Show answer and explanation

Correct answer: D

Explanation

In CEH-style vulnerability assessment, findings should be classified and prioritized based on risk, not just the number of findings or the presence of any security weakness. A practical triage approach considers severity, exploitability, exposure, asset criticality, and business impact. Here, the key factors are: the server is Internet-facing, the vulnerability is a published remote code execution issue, and the CVSS v3.1 base score of 9.8 indicates critical severity. According to the FIRST CVSS specification, scores in the 9.0-10.0 range are Critical and generally require urgent attention. While TLS weaknesses, missing security headers, and directory listing matter, they are usually secondary to a likely direct compromise path on a production public-facing host. This prioritization approach aligns with common best practices from vulnerability management programs and guidance such as NIST's Risk Management and Vulnerability Management concepts, where remediation priority reflects both technical severity and contextual risk.

  • A. Incorrect.

    This is not the highest priority in this scenario. Directory listing can aid reconnaissance by revealing file names or structure, but the finding is explicitly limited to a non-sensitive static content folder. That makes it a lower-severity exposure compared with vulnerabilities that could directly lead to server compromise. Candidates may choose this because information disclosure is a real issue, but risk-based vulnerability assessment prioritizes exploitability and impact first.

  • B. Incorrect.

    This is a valid security weakness, but it is not the top remediation priority here. Missing headers such as X-Frame-Options and Content-Security-Policy can increase risk from attacks like clickjacking or certain script injection scenarios. However, their absence typically does not create an immediate unauthenticated server-side compromise path. It is important hardening, but lower priority than a known critical RCE on an Internet-facing system.

  • C. Incorrect.

    This is an important finding and should be remediated, especially for an Internet-facing application handling customer data. Deprecated protocols and weak ciphers can expose traffic to downgrade or cryptographic attacks and may violate compliance requirements. However, in this scenario, a published remote code execution vulnerability with a CVSS score of 9.8 on the web server itself represents a more urgent and potentially complete compromise of confidentiality, integrity, and availability.

  • D. Correct.

    This is the correct answer. A published remote code execution vulnerability on an outdated Apache version, especially one scored CVSS v3.1 9.8, indicates critical severity with high impact and typically low attack complexity. Because the system is public-facing and processes customer data, the exposure is both externally reachable and business-relevant. In vulnerability classification and assessment, such issues are prioritized above weaker hardening gaps because they can allow direct takeover of the server and follow-on attacks.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam