Ethical › Module 13 › Lesson 5
Quiz — Web Servers
10 APPLY questions on server hygiene.
Opening
Web servers — Module Quiz
Ten APPLY items on the sentences this module refused to collapse: a web server exposes leftovers — default pages, directory listing, outdated banners — on a stack YOU run; patch cadence, unused modules, TLS off-loopback, and a worker that is not root are the daemon ticket, not an exploit pack; access and error logs are first-responder memory on YOUR clerk, never steal or wipe someone else’s; the only listener lab is HOST hardcoded 127.0.0.1, a throwaway root, listing 403, ceh-webserver-lab.txt chmod 600, then you stop the server. Cyberlium’s artifacts are $HOME/cyberlium-lab notes (web-server-exposes, patching-modules, server-logs, ceh-webserver-lab) chmod 600. Gobuster/dirb/ffuf of strangers, default-page dorking as a target list, module exploits “to verify the patch,” 0.0.0.0 café binds, covering tracks in nginx logs, and pointing the client at any other IP are all failing answers even when they look “more CEH.” Audit a stack you run. Localhost python http.server is the clerk. Directory brute of strangers is out. “I was practicing” is not a defense. This path is original Cyberlium teaching mapped to the CEH v13 web-servers domain — not official EC-Council training, not a certification, not exam dumps. Completing it does not grant CEH. Wrong answers still teach. Empty ethics lines fail. Next after this quiz is The App Is the Attack Surface: Module 14 maps input, auth, and session as a checklist — deep SQLi/XSS live in Topic 10; here the authorized methodology, still no exploit pack.
Knowledge Check
APPLY: A teammate pastes gobuster, names a local shop, and says “CEH web-server enum.” What is exposed here, and what do you do?
Multiple choice
Knowledge Check
APPLY: True or False: Google-dorking leftover “It works!” pages and curling the hits is ethical, because Module 13 is hacking web servers.
True or False
Knowledge Check
APPLY: Which sentence correctly names the three leftovers without turning them into a hunt?
Multiple choice
Knowledge Check
APPLY: A classmate wants to paste a module exploit because a public Server header said Apache “to understand patching.” What is the daemon ticket?
Multiple choice
Knowledge Check
APPLY: Select defender actions that match “least modules + transport + privilege” on a stack you run. (Select 2)
Select all that apply
Knowledge Check
APPLY: You filled server-logs-notes.txt. Which pairing is required?
Multiple choice
Knowledge Check
APPLY: True or False: If loopback is boring, the ethical lab is to point harden_webserver_client.py at a cloud IP and gobuster campus beside it.
True or False
Knowledge Check
APPLY: You ran the Lesson 4 lab. Which completion matches ethics and hygiene?
Multiple choice
Knowledge Check
APPLY: A blog titled with a cert acronym publishes “web-server labs” as gobuster plus a module exploit plus log wiping. What does Cyberlium Module 13 tell you?
Multiple choice
Knowledge Check
APPLY: You carry Module 13 into Module 14. Which pairing is true, and what opens after this quiz?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a home router login (TP-Link / Netgear / Huawei / "Router Admin"). Is that DEMO in scope as a hacking target?
Multiple choice
Answer all 11 knowledge checks to continue. (0/11 answered)