🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 27 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During a web-server assessment, you run "nmap -p 80,443 --script http-methods " against an Internet-facing Apache 2.4 host. The script reports that GET, HEAD, POST, OPTIONS, PUT, DELETE, and PATCH are allowed and that PUT requests are not restricted by a WebDAV ACL. What is the most effective next step to attempt remote compromise?

  • Send an HTTP TRACE request to harvest authentication cookies through cross-site tracing.

  • Issue repeated HTTP DELETE requests to critical resources to crash the site and trigger a system reboot.

  • Use the OPTIONS method to identify the Apache version string and search for a public exploit.

  • Upload a server-side script via an HTTP PUT request and browse to it to obtain a web shell.

Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot