ALL PASS, NO FAIL!

CEH v13 Module 13: Hacking Web Servers — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 13 of 20

Attacking web servers: misconfigurations, directory traversal, upload flaws, and OS-level weaknesses behind HTTP services. Exam focus: misconfiguration drives this module. Practice spotting directory traversal, insecure permissions, default accounts, and server-specific quirks (IIS shortnames, Apache path handling) from config snippets and error messages.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: A directory traversal attack uses sequences like ../ to:

Answer: B — Insufficient input validation lets '.../' walk up the tree — fix with strict path validation, canonicalization, and chroot/jails.

Question 2: Which command quickly reveals a web server's response headers (server type/version)?

Answer: C — 'curl -I' fetches headers only; the Server and X-Powered-By headers leak versions for targeted CVE lookups (WhatWeb automates this at scale).

Question 3: Which HTTP header prevents clickjacking by controlling whether a page may be framed?

Answer: B — X-Frame-Options DENY/SAMEORIGIN (or CSP frame-ancestors) stops hidden iframes from overlaying your pages.

Question 4: The Strict-Transport-Security (HSTS) header instructs browsers to:

Answer: B — Once set, browsers force TLS and refuse plain HTTP — closing the downgrade window that SSLStrip exploits.

Question 5: A common first step in web server hardening is to:

Answer: A — Default content and listing expose versions, samples, and paths — attackers' first reconnaissance targets.

Question 6: WhatWeb, Nikto, and Gobuster are used to:

Answer: B — They fingerprint stacks, probe known misconfigurations (Nikto), and brute-force directory names (Gobuster) — the web recon toolkit.

Question 7: Restricting HTTP methods to only those an application needs (e.g., GET, POST, HEAD) reduces the attack surface from:

Answer: D — Unused methods (TRACE for XST, PUT/DELETE for file writes) should be denied at the server/WAF level.

Question 8: Enumerating virtual hosts on a web server helps an attacker:

Answer: A — Many apps share one IP behind different Host headers — missed in normal browsing but mappable via certificates (crt.sh) and host-header probing.

Question 9: Weak SSL/TLS configuration on a web server can enable:

Answer: D — Old ciphers, export-grade crypto, or permissive versions invite downgrade/MITM — harden with modern TLS and HSTS.

Question 10: The Content-Security-Policy (CSP) header is primarily used to:

Answer: C — A strict CSP (script-src, object-src, frame-ancestors…) limits the blast radius of any script that does get injected.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Hacking Web Servers practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 13 (Hacking Web Servers). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 13 (Hacking Web Servers) cover?

Attacking web servers: misconfigurations, directory traversal, upload flaws, and OS-level weaknesses behind HTTP services. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 13 flashcards at https://cehstudy.com/ceh-v13/module-13/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Hacking Web Servers quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Hacking Web Servers flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 13 (Hacking Web Servers). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 13 page at https://cehstudy.com/ceh-v13/module-13/. No account or sign-up required.