ALL PASS, NO FAIL!

CEH v13 Module 5: Vulnerability Analysis — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 5 of 20

Vulnerability management: CVSS scoring, CVEs, authenticated vs. unauthenticated scanning, and tools like Nessus and OpenVAS. Exam focus: CVSS is a calculation question waiting to happen. Be ready to score base metrics from impact and exploitability, read a Nessus or OpenVAS report, and rank remediation by risk rather than by what is loudest in the output.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: In CVSS v3 scoring, which numeric range is classified as 'Critical'?

Answer: B — CVSS bands: 0–3.9 Low, 4.0–6.9 Medium, 7.0–8.9 High, 9.0–10.0 Critical.

Question 2: The CVE dictionary of publicly disclosed cybersecurity vulnerabilities is maintained by:

Answer: A — MITRE assigns the unique CVE identifiers (e.g., CVE-2024-1234) that all scanners and advisories reference.

Question 3: A 'false positive' in vulnerability scanning is:

Answer: C — False positives arise from misconfigured scanners or wrong version detection — every finding should be manually verified before remediation or reporting.

Question 4: Logging into the target with valid credentials before a vulnerability scan enables:

Answer: D — Authenticated scanning inspects installed patches, local accounts, and configs — unauthenticated scans can only observe from outside.

Question 5: Which open-source vulnerability scanner is commonly used as an alternative to Nessus?

Answer: C — OpenVAS (Greenbone) is the leading open-source option; Burp/Acunetix are web-focused, Qualys is a commercial cloud platform.

Question 6: A vulnerability is best defined as:

Answer: D — Vulnerabilities span software flaws, unpatched versions, misconfigurations, and procedural weaknesses — anything a threat can exploit.

Question 7: Which of the following is NOT a base metric in CVSS?

Answer: D — CVSS base metrics include Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, and C/I/A impact — not remediation cost.

Question 8: Vulnerability scanners primarily identify issues by comparing target configurations and software versions against:

Answer: B — Scanners fingerprint versions/configs, then match them against CVE databases of known exploits and weaknesses.

Question 9: Which tool is focused on web application security testing?

Answer: A — Burp Suite proxies and tests web apps (XSS, SQLi, auth flaws); Metasploit is exploitation, Masscan is fast port scanning, Wireshark is packet analysis.

Question 10: Qualys is best described as:

Answer: B — Qualys delivers continuous cloud-delivered scanning and vulnerability/posture management for enterprise environments.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Vulnerability Analysis practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 5 (Vulnerability Analysis). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 5 (Vulnerability Analysis) cover?

Vulnerability management: CVSS scoring, CVEs, authenticated vs. unauthenticated scanning, and tools like Nessus and OpenVAS. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 5 flashcards at https://cehstudy.com/ceh-v13/module-05/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Vulnerability Analysis quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Vulnerability Analysis flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 5 (Vulnerability Analysis). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 5 page at https://cehstudy.com/ceh-v13/module-05/. No account or sign-up required.