Courseiva

Certified Ethical Hacker CEH (CEH) — Questions 676–750

913 questions total · 13pages · All types, answers revealed

Page 9

Page 10 of 13

Page 11
676
Multi-Selectmedium

Which TWO of the following are common weaknesses in IoT devices that are often exploited by attackers?

Select 2 answers
A.Use of hardware security modules (HSM)
B.Implementation of secure boot
C.Use of default or hard-coded credentials
D.Use of insecure protocols such as MQTT without TLS
E.Firmware update mechanism with signed updates
AnswersC, D

The prevalence of default or hard-coded credentials represents a severe and common weakness in IoT devices. Many manufacturers ship devices with easily guessable default usernames and passwords (e.g., 'admin/admin', 'root/password') or embed unchangeable credentials directly into the firmware. Attackers frequently exploit these known credentials through automated scanning and brute-force attacks, gaining unauthorized access to devices, which can then be used for botnets, data exfiltration, or further network penetration.

Why this answer

Option C is correct because many IoT devices ship with factory-default or hard-coded credentials (e.g., admin/admin, root/root) that users never change, giving attackers trivial access via services like Telnet or SSH on ports 23/22. Option D is correct because IoT devices frequently run lightweight protocols such as MQTT, CoAP, or HTTP without TLS encryption, allowing attackers to eavesdrop on, tamper with, or inject messages on the network. Options A and B are incorrect because hardware security modules and secure boot are security hardening measures that protect keys and verify firmware integrity, not weaknesses.

Option E is incorrect because firmware updates signed with cryptographic signatures are a security best practice that prevents malicious or tampered firmware from being installed, rather than a common exploitable weakness.

Exam trap

EC-Council often tests the distinction between security controls (HSM, secure boot, signed updates) and actual vulnerabilities (default credentials, cleartext protocols), so candidates mistakenly select secure features as weaknesses.

677
MCQeasy

Which of the following is a type of malware that spreads by replicating itself across a network without requiring a host file?

A.Worm
B.Trojan
C.Ransomware
D.Virus
AnswerA

A worm is a standalone malware computer program that replicates itself to spread to other computers. Unlike a virus, it does not need to attach to an existing program or host file to propagate. Worms often exploit network vulnerabilities to spread autonomously across networks, consuming bandwidth and system resources, and can carry payloads like backdoors or ransomware. This self-contained, network-aware replication is its defining characteristic.

Why this answer

A worm is a standalone malware that replicates itself across a network by exploiting vulnerabilities or using network protocols (e.g., SMB, RDP, or email) without needing a host file. Unlike viruses, worms do not attach to existing programs; they self-propagate via network connections, often consuming bandwidth and creating backdoors.

Exam trap

The trap here is confusing a worm with a virus, as both self-replicate, but the key differentiator is that a worm does not require a host file and spreads via network protocols, while a virus must attach to a host file to propagate.

How to eliminate wrong answers

Option B (Trojan) is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution to install and typically requires a host file or system to operate. Option C (Ransomware) is wrong because ransomware encrypts files or locks systems for extortion and does not self-propagate across a network without user interaction or a host file. Option D (Virus) is wrong because a virus requires a host file (e.g., executable, script, or document) to attach to and replicate, whereas the question specifies propagation without a host file.

678
MCQhard

During a security assessment, a tester runs hping3 with the command: hping3 -S -p 80 -c 5 10.0.0.1. The response shows that packets with the SYN flag set receive SYN-ACK replies. Which of the following conclusions is MOST accurate?

A.Port 80 is open on 10.0.0.1
B.A firewall is blocking the scan
C.Port 80 is closed on 10.0.0.1
D.The target is using a stateful firewall that allows the connection
AnswerA

When hping3 sends a TCP SYN packet to a target port, the receipt of a SYN-ACK packet in response is the definitive indication that the port is open and an application is actively listening. This response signifies the second step of the TCP three-way handshake, where the target acknowledges the SYN and sends its own synchronization request. Therefore, a SYN-ACK from 10.0.0.1 on port 80 confirms that the port is open and ready to establish a connection.

Why this answer

The hping3 command with the -S flag sends TCP SYN packets to port 80 on 10.0.0.1. Receiving SYN-ACK replies indicates that the target responded with the second step of the TCP three-way handshake, which only occurs when the port is open and listening. This confirms that port 80 is open on the target host.

Exam trap

The trap here is that candidates may confuse the SYN-ACK response with firewall behavior or closed port responses, but the correct interpretation is that a SYN-ACK directly indicates an open port per TCP specification.

How to eliminate wrong answers

Option B is wrong because a firewall blocking the scan would typically drop the packets or send ICMP unreachable messages, not respond with SYN-ACKs. Option C is wrong because a closed port would respond with RST packets, not SYN-ACKs, per RFC 793. Option D is wrong because while a stateful firewall might allow the connection, the SYN-ACK response itself is direct evidence that the port is open on the target host, not just a firewall behavior.

679
MCQmedium

A security analyst reviews logs and notices that an attacker crafted a packet with a source IP address matching the target's IP address, and sent it to a network's broadcast address. Which type of attack does this describe?

A.UDP flood
B.Ping of Death
C.Smurf attack
D.SYN flood
AnswerC

A Smurf attack is a classic distributed denial-of-service (DDoS) technique that leverages an intermediary network to amplify traffic against a victim. The attacker sends an ICMP echo request packet to a network's IP broadcast address, but with the source IP address spoofed to that of the intended victim. All hosts on the intermediary network that receive the broadcast then reply to the spoofed source IP, flooding the victim with numerous ICMP echo replies. This amplification effect can quickly overwhelm the victim's network resources.

Why this answer

The Smurf attack is a distributed denial-of-service (DDoS) attack that exploits ICMP echo request packets. The attacker spoofs the source IP address to be the target's IP and sends these packets to a network's broadcast address. All hosts on that network then reply to the target, overwhelming it with ICMP echo replies.

Exam trap

The trap here is that candidates confuse the Smurf attack with a simple ICMP flood or Ping of Death, but the key differentiator is the use of a broadcast address to amplify traffic, not just sending malformed or high-volume ICMP packets.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends a high volume of UDP packets to random ports on the target, exhausting its resources, and does not involve spoofing the target's IP as the source or using a broadcast address. Option B is wrong because a Ping of Death sends an oversized ICMP packet (greater than 65,535 bytes) to crash the target, not a broadcast-based amplification attack. Option D is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source IPs to exhaust the target's connection table, and it does not use broadcast addresses or ICMP.

680
Multi-Selectmedium

During a web application penetration test, a tester discovers a file inclusion vulnerability. Which THREE of the following are potential impacts or exploitation scenarios? (Choose THREE.)

Select 3 answers
A.Disclosure of sensitive files like /etc/passwd
B.Remote code execution via log poisoning
C.Port scanning of internal network hosts
D.Denial of service by including large files
E.Session hijacking by including session files
AnswersA, B, E

Local File Inclusion (LFI) vulnerabilities allow an attacker to read arbitrary files from the server's file system. By manipulating the vulnerable parameter with paths like /etc/passwd or /etc/shadow, an attacker can directly access and disclose critical system configuration files, user credentials, or application source code. This exposure of sensitive data is a primary and direct impact of LFI, providing valuable information for further exploitation.

Why this answer

Option A is correct because a Local File Inclusion (LFI) vulnerability allows an attacker to traverse the filesystem using sequences like ../../ and read arbitrary files the web server can access, with /etc/passwd being the classic proof-of-concept target for confirming file disclosure on Linux. Option B is correct because LFI can be escalated to Remote Code Execution through log poisoning: the attacker injects PHP code into a log file (e.g., Apache access.log via a crafted User-Agent header) and then includes that log file, causing the server to execute the injected code. Option E is correct because if PHP session files are stored in a predictable, web-accessible location (e.g., /var/lib/php/sessions/sess_<id>), an attacker who can control or know a session ID can include that file to read or manipulate session data, enabling session hijacking.

Option C is not a typical LFI impact: port scanning is associated with SSRF, where the server makes outbound requests to internal hosts, not with file inclusion, which reads local files. Option D is not a standard LFI impact either: while including very large files could theoretically consume resources, denial of service is not a recognized primary exploitation scenario for file inclusion vulnerabilities in this context.

Exam trap

CEH often tests whether candidates confuse file inclusion impacts with SSRF-style impacts (like port scanning) or generic DoS, when the exam expects the three canonical outcomes: file disclosure, RCE via log poisoning, and session hijacking.

681
MCQmedium

A web developer wants to mitigate CSRF attacks. Which of the following configurations for cookies is most effective when combined with CSRF tokens?

A.HttpOnly flag
B.SameSite=Strict
C.Domain attribute
D.Secure flag
AnswerB

The SameSite=Strict attribute is a powerful defense against CSRF attacks by instructing the browser to only send the cookie with requests originating from the same site as the cookie's domain. This means if a user is logged into `example.com` and then visits `malicious.com`, any requests `malicious.com` attempts to make back to `example.com` will not include the session cookie. Consequently, the malicious request will not be authenticated, effectively preventing the forgery.

Why this answer

SameSite=Strict prevents the browser from sending cookies for cross-site requests, which blocks CSRF attacks.

682
Matchingmedium

Match each CEH phase to its key activity.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Gathering information about the target

Identifying live hosts, open ports, and services

Exploiting vulnerabilities to enter the system

Installing backdoors for persistent access

Clearing logs and hiding evidence

Why these pairings

The five phases of ethical hacking (as per EC-Council) are Reconnaissance, Scanning & Enumeration, Gaining Access, Maintaining Access, and Clearing Tracks. In this set, options A-D correctly match phases to their key activities, while options E and F are distractors with swapped definitions.

683
Multi-Selecteasy

Which TWO of the following correctly describe aspects of the shared responsibility model in cloud computing?

Select 2 answers
A.The cloud provider is responsible for managing customer application encryption keys
B.The customer is responsible for network firewall configuration in PaaS
C.The customer is responsible for securing data stored in the cloud
D.The cloud provider is responsible for patching the guest operating system in IaaS
E.The cloud provider is responsible for physical security of data centers
AnswersC, E

Regardless of the cloud service model (IaaS, PaaS, SaaS), the customer always retains primary responsibility for the security of their data itself. This encompasses implementing appropriate encryption for data at rest and in transit, configuring robust access controls and identity management, and ensuring data integrity and compliance. The cloud provider secures the underlying infrastructure that stores the data, but the data's content security is the customer's domain.

Why this answer

In the shared responsibility model, the customer is responsible for security IN the cloud (e.g., data, application configurations, identity management) while the provider is responsible for security OF the cloud (e.g., physical security, network infrastructure). Option C is correct because customers must secure their stored data. Option E is correct because providers secure data center physical access.

Option A is incorrect: the cloud provider does not manage customer encryption keys; that is the customer's responsibility. Option B is incorrect: in PaaS, the provider manages the network firewall; the customer manages application-level security only. Option D is incorrect: in IaaS, the customer patches the guest OS; the provider patches the hypervisor and physical infrastructure.

684
MCQmedium

Which of the following is the most effective defense against Cross-Site Request Forgery (CSRF) attacks?

A.Content Security Policy (CSP)
B.CSRF tokens
C.Rate limiting
D.Input validation
AnswerB

CSRF tokens are the most effective defense against Cross-Site Request Forgery (CSRF) attacks. These unique, unpredictable, and secret values are generated server-side for each user session and embedded within critical state-changing requests, such as form submissions. The server then validates the presence and correctness of this token upon receiving the request, ensuring that the request originated from the legitimate application and not from an attacker's malicious site.

Why this answer

CSRF tokens are the most effective defense because they are unique, unpredictable values embedded in each form or request that the server validates. Without a valid token, the server rejects the request, preventing an attacker from forging a legitimate user's action even if the victim is authenticated.

Exam trap

EC-Council often tests the misconception that input validation or CSP can prevent CSRF, when in fact CSRF exploits the browser's automatic inclusion of credentials (cookies) and requires a server-side token or SameSite cookie attribute to verify request intent.

How to eliminate wrong answers

Option A is wrong because Content Security Policy (CSP) is primarily designed to mitigate XSS and data injection attacks by controlling resource loading, not to validate the origin or authenticity of state-changing requests. Option C is wrong because rate limiting only reduces the speed of repeated attacks but does not prevent a single forged request from being executed. Option D is wrong because input validation (e.g., sanitizing or escaping user input) addresses injection attacks like SQLi or XSS, not the lack of origin verification that CSRF exploits.

685
MCQmedium

An employee receives an email that appears to be from the CEO, asking the employee to urgently wire funds to a vendor. The email address is slightly misspelled. What type of social engineering attack is this?

A.Pharming
B.Spear phishing
C.Whaling
D.Vishing
AnswerC

Whaling is a specialized form of spear phishing that specifically targets high-profile individuals, such as senior executives, CEOs, or government officials, or impersonates them to deceive employees. In this scenario, an email appearing to be from the CEO directly aligns with the definition of whaling, as it leverages the authority of a top executive to induce a specific action. The objective is often to trick recipients into making large financial transfers or divulging sensitive corporate data, exploiting the perceived urgency and command from a C-level executive.

Why this answer

This is a whaling attack because it specifically targets a high-profile individual (the CEO) to deceive another employee into performing a financial action. The slight misspelling of the email address is a classic whaling technique, as the attacker impersonates a senior executive to exploit authority and urgency. Unlike generic phishing, whaling focuses on C-level executives or decision-makers.

Exam trap

EC-Council often tests the distinction between spear phishing and whaling by emphasizing that whaling specifically targets senior executives, while spear phishing can target any individual or role within an organization.

How to eliminate wrong answers

Option A is wrong because pharming redirects users from legitimate websites to fraudulent ones by manipulating DNS or host files, not by sending deceptive emails. Option B is wrong because spear phishing targets a specific individual or organization but does not necessarily involve impersonating a senior executive; the key differentiator here is the impersonation of the CEO, which is the hallmark of whaling. Option D is wrong because vishing (voice phishing) uses phone calls or voice messages, not email, to trick victims.

686
MCQmedium

During a penetration test, you run `smtp-user-enum -M VRFY -U users.txt -t 10.0.0.10` and receive responses '252 2.5.2 User <username>' for some users and '550 5.1.1 User unknown' for others. What does this indicate?

A.The SMTP server is using EXPN instead of VRFY
B.The SMTP server is revealing valid usernames via the VRFY command
C.The SMTP server is vulnerable to command injection
D.The SMTP server is properly configured to prevent enumeration
AnswerB

The differing server responses to the VRFY command—typically a '250 OK' for valid users and a '550 No such user' or similar for invalid ones—unambiguously confirm the server is revealing valid usernames. This behavior allows an attacker to systematically enumerate existing user accounts on the system. Such information is a critical vulnerability, enabling subsequent attacks like brute-force password attempts or targeted phishing campaigns.

Why this answer

The VRFY command in SMTP (RFC 821) asks the server to verify whether a mailbox exists. A response starting with '252' indicates the user is valid, while '550 5.1.1' means the user does not exist. By comparing these responses, the attacker can enumerate valid usernames on the mail server, which is exactly what the output shows.

Exam trap

EC-Council often tests the distinction between VRFY and EXPN, where candidates mistakenly think EXPN is being used when the output clearly shows VRFY responses, or they assume any non-250 response means the server is secure.

How to eliminate wrong answers

Option A is wrong because EXPN (expand) returns mailing list members, not individual user verification, and the tool explicitly used the VRFY command, not EXPN. Option C is wrong because command injection would require the server to execute arbitrary commands from the input, which is not indicated by standard VRFY responses. Option D is wrong because a properly configured server to prevent enumeration would either disable VRFY entirely or return a generic response (e.g., '252' for all users) to avoid revealing which users exist.

687
MCQmedium

An ethical hacker is testing a web application that uses cookies for session management. The tester notices that the session cookie does not have the HttpOnly or Secure flags set. Which attack is most likely to succeed due to this misconfiguration?

A.SQL injection
B.Cross-site request forgery (CSRF)
C.Session hijacking via cross-site scripting (XSS)
D.Clickjacking
AnswerC

Session hijacking via Cross-Site Scripting (XSS) occurs when an attacker injects malicious client-side scripts into a web page viewed by other users. If the session cookie lacks the HttpOnly flag, the injected script can access document.cookie to read and exfiltrate the victim's session identifier. With the stolen session cookie, the attacker can then impersonate the victim, gaining unauthorized access to their authenticated session without needing their credentials. This directly targets the client-side session token.

Why this answer

The absence of the HttpOnly flag allows JavaScript to access the session cookie via `document.cookie`. An attacker can exploit a cross-site scripting (XSS) vulnerability to steal the cookie and perform session hijacking. The missing Secure flag further exposes the cookie to interception over unencrypted HTTP connections, making the attack easier to execute.

Exam trap

The trap here is that candidates often confuse CSRF with session hijacking, but CSRF does not require reading the cookie—it only requires the browser to automatically include it in requests, whereas XSS-based session hijacking directly steals the cookie value.

How to eliminate wrong answers

Option A is wrong because SQL injection exploits database query vulnerabilities, not cookie flag misconfigurations; it does not rely on cookie attributes. Option B is wrong because CSRF exploits the trust a site has in a user's browser, typically using forged requests, and does not require reading cookies; missing HttpOnly/Secure flags do not directly enable CSRF. Option D is wrong because clickjacking uses transparent overlays to trick users into clicking UI elements, and it does not involve stealing or accessing session cookies.

688
MCQmedium

During a penetration test, you run the following command: hping3 -S -p 80 --flood 192.168.1.100. What is the PRIMARY purpose of this command?

A.Banner grab the HTTP service on port 80
B.Fingerprint the operating system of the target
C.Perform a TCP connect scan to identify open ports
D.Execute a denial-of-service (DoS) attack against the target's web server
AnswerD

The command `hping3 -S --flood -p 80 <target_ip>` is specifically engineered to launch a SYN flood denial-of-service attack. By rapidly sending a massive volume of TCP SYN packets to port 80, the target's web server is forced to allocate resources for numerous half-open connections. This quickly exhausts the server's connection queue, preventing legitimate users from establishing new connections and effectively denying service.

Why this answer

The command `hping3 -S -p 80 --flood 192.168.1.100` sends a high volume of TCP SYN packets to port 80 of the target without completing the three-way handshake. The `--flood` flag disables packet rate limiting, causing a rapid stream of SYN packets that exhausts the target's connection queue, effectively performing a SYN flood denial-of-service (DoS) attack against the web server.

Exam trap

The trap here is that candidates confuse a SYN flood DoS attack with a SYN scan (port scanning), but the `--flood` flag explicitly indicates a denial-of-service intent, not reconnaissance.

How to eliminate wrong answers

Option A is wrong because banner grabbing requires receiving and analyzing a service response, but `--flood` sends packets as fast as possible without waiting for replies, making banner capture impossible. Option B is wrong because OS fingerprinting relies on analyzing subtle differences in TCP/IP stack responses (e.g., TTL, window size), but the `--flood` mode overwhelms the target and does not collect or analyze response packets for fingerprinting. Option C is wrong because a TCP connect scan completes the three-way handshake (SYN, SYN-ACK, ACK), whereas this command only sends SYN packets and never completes the handshake, so it cannot identify open ports reliably.

689
Multi-Selectmedium

Which THREE of the following are valid methods for DDoS mitigation?

Select 3 answers
A.Rate limiting
B.Increasing server timeout values
C.Scrubbing centers
D.Disabling SYN cookies
E.Anycast routing
AnswersA, C, E

Rate limiting is a crucial DDoS mitigation technique that restricts the number of requests a server or application will accept from a specific source within a defined time window. By setting thresholds for connections, requests per second, or bandwidth usage, it prevents a single attacker or a small group of bots from overwhelming server resources. This method helps to differentiate between legitimate traffic spikes and malicious floods, allowing the system to maintain availability for valid users while shedding excessive, potentially harmful traffic.

Why this answer

Rate limiting is a valid DDoS mitigation method because it restricts the number of requests a server accepts from a single source within a given time window, preventing resource exhaustion. By enforcing thresholds (e.g., via iptables or application-layer rate limiters), it reduces the impact of volumetric attacks like HTTP floods without blocking legitimate traffic entirely.

Exam trap

The trap here is that candidates confuse mitigation techniques with configuration errors, such as thinking that increasing timeouts or disabling SYN cookies would help, when in fact these actions weaken defenses against specific attack vectors like SYN floods or slow HTTP attacks.

690
MCQeasy

A penetration tester obtains a hash dump from a compromised Windows system and wants to crack LM and NTLM hashes quickly using precomputed tables. Which tool would be most efficient for this task?

A.Hashcat
B.John the Ripper
C.Ophcrack
D.RainbowCrack
AnswerC

Ophcrack is a dedicated password cracker specifically designed to recover Windows LM and NTLM hashes by employing precomputed rainbow tables. This tool efficiently performs lookups within its extensive tables to reverse hashes back into their original plaintext passwords, making it exceptionally fast for common password sets. Its specialized focus on these hash types, combined with its user-friendly graphical interface, positions it as the optimal choice for this particular hash cracking method in a penetration testing scenario.

Why this answer

Ophcrack is the most efficient tool for quickly cracking LM and NTLM hashes using precomputed tables because it is specifically designed to leverage rainbow tables (precomputed hash chains) for these hash types. It can crack LM hashes almost instantly and NTLM hashes with high success rates when paired with the correct rainbow tables, making it ideal for fast offline password recovery from a hash dump.

Exam trap

CEH often tests the distinction between tools that use precomputed tables (rainbow tables) versus those that use brute-force or dictionary attacks; candidates mistakenly choose Hashcat or John the Ripper because they are more well-known, but Ophcrack is the only option specifically optimized for LM/NTLM rainbow table cracking.

How to eliminate wrong answers

Option A is wrong because Hashcat is a GPU-accelerated password cracker that uses brute-force, dictionary, or rule-based attacks, not precomputed tables; it is slower for LM/NTLM when rainbow tables are available. Option B is wrong because John the Ripper is a versatile cracker that supports many hash types but does not natively use precomputed rainbow tables; it relies on wordlists and brute-force, which are less efficient for this specific task. Option D is wrong because RainbowCrack is a tool that generates and uses rainbow tables, but it is a command-line utility that requires separate table generation or download and is less user-friendly than Ophcrack, which has a GUI and bundled tables for LM/NTLM.

691
MCQmedium

A user reports that their system has become sluggish and they see pop-up advertisements even when no browser is open. Additionally, unknown processes are running in Task Manager. Which type of malware is most likely responsible?

A.Worm
B.Adware
C.Ransomware
D.Spyware
AnswerB

Adware is specifically designed to display unwanted advertisements, often in the form of pop-ups, banners, or injected ads within web pages. This constant display and the underlying processes required to generate these ads consume significant CPU and RAM, leading directly to noticeable system sluggishness. It frequently alters browser settings, making it a direct cause for both the reported performance degradation and persistent pop-ups.

Why this answer

Adware is designed to display unwanted advertisements, often in the form of pop-ups, and can degrade system performance by consuming CPU and memory resources. The presence of unknown processes in Task Manager indicates that the adware has installed additional components or bundled software that runs persistently, even when no browser is open, which is a hallmark of adware behavior.

Exam trap

The trap here is that candidates confuse 'adware' with 'spyware' because both can be bundled with free software, but adware's primary symptom is unwanted ads, not data theft, which is the key differentiator in this scenario.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads across networks without user interaction, and while it can cause sluggishness, it does not typically display pop-up advertisements. Option C is wrong because ransomware encrypts files or locks the system to demand a ransom, and it does not show pop-up ads or run unknown processes as its primary symptom. Option D is wrong because spyware is designed to covertly collect sensitive information (e.g., keystrokes, browsing habits) and does not usually generate pop-up advertisements; its presence is often hidden, not announced via ads.

692
Multi-Selectmedium

A penetration tester is enumerating services on a target Windows server. Which TWO tools are specifically designed for SMB enumeration? (Select two.)

Select 2 answers
A.John the Ripper
B.SNMPwalk
C.Nmap
D.enum4linux
E.smbclient
AnswersD, E

enum4linux is a comprehensive tool specifically designed for enumerating information from Windows and Samba hosts. It automates the process of extracting user lists, group memberships, shared resources, password policies, and other critical details by querying NetBIOS and SMB services. This makes it highly effective for gathering intelligence on a Windows target, going beyond simple port identification to deep service enumeration.

Why this answer

enum4linux (D) is a Perl script that wraps Samba tools like smbclient, rpcclient, and net to enumerate SMB shares, users, and OS information from Windows systems. smbclient (E) is a native Samba client that allows direct interaction with SMB shares, including listing, connecting, and transferring files. Both are purpose-built for SMB enumeration.

Exam trap

The trap here is that candidates may select Nmap because it has SMB scripts, but the question asks for tools 'specifically designed' for SMB enumeration, which excludes general-purpose scanners like Nmap.

693
MCQmedium

An attacker gains physical access to a restricted area by following an authorized employee through a secured door without swiping a badge. This technique is known as:

A.Tailgating
B.Pretexting
C.Quid pro quo
D.Baiting
AnswerA

Tailgating exploits the human element of physical security: the attacker gains entry by closely following an authorised employee through a secured door, bypassing badge authentication entirely. The stem's constraint is unauthorised physical access without credentials, which tailgating satisfies precisely.

Why this answer

Tailgating is a social engineering attack where an unauthorized person physically follows an authorized employee through a secured entry point (e.g., a badge-protected door) without presenting their own credentials. This exploits the human tendency to hold the door for others, bypassing electronic access control systems (e.g., RFID badge readers) that would otherwise deny entry. The CEH exam defines this as a physical breach of perimeter security, distinct from digital or verbal manipulation.

Exam trap

The trap here is confusing 'tailgating' with 'pretexting' because both involve deception, but tailgating is purely physical (following through a door) while pretexting is purely verbal (creating a false story).

How to eliminate wrong answers

Option B (Pretexting) is wrong because it involves fabricating a scenario (e.g., impersonating IT support) to trick a victim into divulging information, not physically following someone through a door. Option C (Quid pro quo) is wrong because it relies on offering a service or benefit (e.g., 'free antivirus scan') in exchange for credentials, not physical proximity. Option D (Baiting) is wrong because it uses a physical lure (e.g., an infected USB drive left in a parking lot) to compromise a system, not direct physical access by trailing an employee.

694
Multi-Selecthard

Which THREE of the following are indicators of a slowloris DDoS attack?

Select 3 answers
A.ICMP echo replies from random IPs
B.Normal traffic volume but connections remain open for a long time
C.Many half-open HTTP connections
D.Server logs showing incomplete HTTP requests
E.High volume of UDP packets
AnswersB, C, D

Slowloris is a low-bandwidth attack that does not generate a high volume of data packets. Instead, it exploits the server's connection handling by opening numerous legitimate-looking HTTP connections and then keeping them alive for extended durations. This is achieved by sending partial HTTP requests and periodically sending additional, non-terminating HTTP headers, preventing the server from timing out the connection and freeing up resources. The prolonged open state of these connections, despite minimal data transfer, exhausts the server's available connection pool.

Why this answer

B is correct because a Slowloris DDoS attack works by opening many connections to a target web server and keeping them open for as long as possible, sending partial HTTP requests to tie up server resources. This results in normal traffic volume but with connections that remain open for extended periods, preventing legitimate users from connecting.

Exam trap

The trap here is that candidates often associate DDoS attacks with high traffic volume, but Slowloris is a low-and-slow attack that uses normal traffic volume with persistent, incomplete connections, so they may incorrectly select high-volume options like A or E.

695
MCQmedium

A penetration tester is attempting to enumerate user accounts on a mail server. They connect to port 25 and issue the commands `VRFY root` and `EXPN support`. Which protocol is being targeted?

A.LDAP
B.SMTP
C.SMB
D.SNMP
AnswerB

The Simple Mail Transfer Protocol (SMTP) is the correct answer because it includes specific commands like `VRFY` (verify) and `EXPN` (expand) that can be leveraged for user enumeration. The `VRFY` command attempts to validate a specific email address or username on the target mail server, often returning a 250 OK response if the account exists. Similarly, `EXPN` can reveal members of a mailing list or alias, indirectly confirming valid user accounts. When not disabled or restricted, these commands provide a direct method for attackers to identify valid user accounts on a system.

Why this answer

The commands VRFY and EXPN are SMTP (Simple Mail Transfer Protocol) commands defined in RFC 821 and RFC 5321. VRFY is used to verify whether a mailbox exists on the server, while EXPN expands a mailing list alias to reveal its members. Since the tester connected to port 25 (the default SMTP port) and issued these commands, SMTP is the protocol being targeted.

Exam trap

The trap here is that candidates may confuse SMTP commands with other protocol operations, such as associating VRFY with LDAP directory lookups or EXPN with SNMP expansion, because they focus on the word 'enumerate' rather than the specific port and command syntax.

How to eliminate wrong answers

Option A is wrong because LDAP (Lightweight Directory Access Protocol) uses port 389 or 636 for directory queries, not port 25, and its commands are based on LDAP operations like bind, search, and compare, not SMTP commands like VRFY or EXPN. Option C is wrong because SMB (Server Message Block) uses ports 139 and 445 for file and printer sharing, and its enumeration involves commands like net use or smbclient, not SMTP mail commands. Option D is wrong because SNMP (Simple Network Management Protocol) uses ports 161 and 162 for network device management via GET, SET, and TRAP operations, not SMTP commands on port 25.

696
MCQeasy

Which tool is specifically designed to crack Windows LAN Manager (LM) and NTLM hashes using rainbow tables?

A.John the Ripper
B.RainbowCrack
C.Hashcat
D.Ophcrack
AnswerD

Ophcrack is a free, open-source password cracker specifically designed for Windows passwords, making it the correct answer. It leverages precomputed rainbow tables, often distributed as a live CD or USB, which are highly optimized for cracking LM (LAN Manager) and NTLM hashes. Its primary function and user-friendly interface are tailored to exploit the known weaknesses of these Windows authentication protocols, providing an efficient and straightforward solution for recovering Windows user passwords.

Why this answer

Ophcrack is specifically designed to crack Windows LM and NTLM hashes using precomputed rainbow tables. It relies on the time-memory trade-off technique, where rainbow tables allow rapid reversal of hashes without brute-forcing each password individually. This makes it the correct choice for the scenario described.

Exam trap

The trap here is that candidates confuse 'rainbow table' tools with general hash crackers like Hashcat or John the Ripper, but the question specifically asks for a tool designed for Windows LM/NTLM hashes using rainbow tables, which is Ophcrack's unique niche.

How to eliminate wrong answers

Option A is wrong because John the Ripper is a general-purpose password cracker that supports many hash types and modes (dictionary, brute-force, incremental), but it does not natively use rainbow tables as its primary attack vector. Option B is wrong because RainbowCrack is a tool that generates and uses rainbow tables for hash cracking, but it is not specifically designed for Windows LM/NTLM hashes; it supports multiple hash algorithms (e.g., MD5, SHA1) and requires separate table generation. Option C is wrong because Hashcat is a high-speed GPU-accelerated password recovery tool that supports many hash modes (including NTLM), but it relies on dictionary, brute-force, or rule-based attacks, not precomputed rainbow tables.

697
Drag & Dropmedium

Drag and drop the steps to configure a firewall rule in iptables to block incoming SSH traffic into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for configuring an iptables rule to block incoming SSH is to first check the current rules (e.g., with `iptables -L`) to avoid conflicts, then add the drop rule for SSH (e.g., `iptables -A INPUT -p tcp --dport 22 -j DROP`), next verify that the rule is in place (`iptables -L`), then save the rules permanently (e.g., `iptables-save`), and finally test the block by attempting an SSH connection from an external host.

698
Multi-Selecthard

A penetration tester is performing a check for HTTP response splitting. Which THREE of the following conditions must be present for this attack to succeed?

Select 3 answers
A.The application reflects user input in the HTTP response headers
B.The application reflects user input in the HTTP response body
C.The application uses HTTPS exclusively
D.The attacker can inject multiple header lines to create a second HTTP response
E.The application does not sanitize or encode CRLF sequences (%0d%0a)
AnswersA, D, E

For HTTP Response Splitting to occur, user-supplied input containing CRLF sequences must be directly incorporated into an HTTP response header. This allows an attacker to terminate the current header line and inject new, arbitrary header fields or even an entirely new response body. Without this direct reflection in the headers, the injected CRLF sequences would not be interpreted as control characters for the HTTP protocol, making the attack impossible.

Why this answer

HTTP response splitting succeeds when three conditions align. Option A is correct because the application must reflect attacker-controlled input into HTTP response headers (e.g., a Location or Set-Cookie header), which is the injection point for the attack. Option E is correct because the reflected input must contain unsanitized CRLF sequences (%0d%0a), since these carriage-return/line-feed characters terminate the current header and let the attacker start new ones.

Option D is correct because the injected CRLF must be sufficient to forge additional header lines and a second HTTP response body, which is the actual splitting effect. Option B is not required: reflection in the response body alone does not let the attacker manipulate header boundaries. Option C is irrelevant: HTTPS encrypts transport but does not prevent header injection, and the attack works over HTTP or HTTPS alike.

Exam trap

CEH often tests whether candidates confuse response splitting with reflected XSS — both involve unsanitized input reflection, but response splitting specifically requires header reflection and CRLF injection, not body reflection.

699
MCQeasy

An employee receives an SMS message that claims to be from the IT department, asking the employee to click a link to verify their email account. Which social engineering attack is this?

A.Vishing
B.Phishing
C.SMiShing
D.Whaling
AnswerC

SMiShing, a portmanteau of 'SMS' and 'phishing,' is a specific type of social engineering attack that utilizes text messages to deceive recipients. Attackers send fraudulent SMS messages, often containing malicious links that lead to credential harvesting sites or malware downloads, or instructing victims to call a fraudulent number. This method exploits the trust users place in their mobile devices and the immediacy of text messages to prompt quick, unthinking responses, making it the direct answer for an SMS-based attack.

Why this answer

C is correct because SMiShing (SMS phishing) specifically uses SMS text messages as the attack vector to deliver a malicious link or request, exactly as described in the scenario. Unlike email-based phishing, SMiShing exploits the trust users place in text messages and often bypasses email security filters.

Exam trap

The trap here is that candidates confuse 'phishing' as a generic term for all social engineering attacks, but the CEH exam distinguishes SMiShing as the specific term for SMS-based phishing.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls or voice messages, not SMS text messages. Option B is wrong because phishing typically refers to email-based attacks, not SMS-based attacks. Option D is wrong because whaling targets high-profile individuals (e.g., executives) with personalized attacks, not general employees via mass SMS.

700
Multi-Selectmedium

Which THREE of the following are common techniques used in the 'Cracking passwords' phase of system hacking? (Select 3)

Select 3 answers
A.Brute force attack
B.Rainbow table attack
C.Keylogging
D.Social engineering
E.Dictionary attack
AnswersA, B, E

A brute force attack is an exhaustive password cracking method that systematically attempts every possible character combination (letters, numbers, symbols) of a specified length until the correct password or key is discovered. While computationally intensive, especially for long and complex passwords, it guarantees success given sufficient time and processing resources. This makes it a fundamental and powerful technique in a cracker's arsenal.

Why this answer

A brute force attack systematically tries every possible combination of characters until the correct password is found. This is a fundamental technique in the password cracking phase, often used when no prior knowledge of the password exists. It is computationally expensive but guaranteed to succeed given enough time.

Exam trap

The trap here is confusing password capturing techniques (like keylogging or social engineering) with password cracking techniques that operate on captured hashes or encrypted passwords.

701
MCQmedium

During a penetration test, you gain access to a Linux server as a low-privileged user. Which of the following is an effective technique to escalate privileges by exploiting misconfigured file permissions?

A.Pass-the-hash
B.Token impersonation
C.SUID/GUID abuse
D.Kerberoasting
AnswerC

SUID (Set User ID) and SGID (Set Group ID) are special permissions in Linux that allow an executable to run with the privileges of the file's owner or group, respectively, rather than the user executing it. If a program with SUID permissions is owned by root and can be manipulated (e.g., by executing arbitrary commands or writing to sensitive files), it can be abused for privilege escalation. This is a common and effective technique on Linux systems.

Why this answer

SUID (Set User ID) and GUID (Group ID) bits allow a binary to execute with the privileges of the file owner (often root) rather than the calling user. If a low-privileged user can run a binary with the SUID bit set that performs unsafe operations (e.g., spawning a shell, reading arbitrary files, or executing commands), they can leverage it to gain root-level access. This is a classic privilege escalation vector on Linux systems when file permissions are misconfigured.

Exam trap

The trap here is that candidates may confuse SUID/GUID abuse with Windows-specific techniques like token impersonation or pass-the-hash, because the CEH exam often intermixes cross-platform attack vectors to test your ability to match the technique to the correct operating system.

How to eliminate wrong answers

Option A is wrong because pass-the-hash is a Windows-based attack that reuses NTLM hashes to authenticate to remote systems; it does not apply to Linux file permission misconfigurations. Option B is wrong because token impersonation is a Windows privilege escalation technique that manipulates access tokens (e.g., SeImpersonatePrivilege) to assume another user's identity; it is not relevant to Linux SUID/GUID abuse. Option D is wrong because Kerberoasting is an Active Directory attack that requests Kerberos service tickets to crack service account passwords; it targets Windows domain environments, not local Linux file permissions.

702
MCQhard

A penetration tester runs the following command: `macof -i eth0 -s 192.168.1.100 -d 10.0.0.1`. Which attack is being performed?

A.DNS spoofing
B.ARP poisoning
C.MAC flooding
D.DHCP starvation
AnswerC

MAC flooding is an attack designed to overwhelm a network switch's MAC address table (CAM table) by sending a large number of frames with unique, spoofed source MAC addresses. When the CAM table becomes full, the switch often enters a "fail-open" mode, behaving like a hub by broadcasting all incoming traffic to all ports. The `macof` utility, part of the `dsniff` suite, automates this process by rapidly generating and sending thousands of frames with random source MAC and IP addresses, effectively causing the switch to flood traffic.

Why this answer

The `macof` tool is designed to flood a switch with packets containing random source MAC addresses, overwhelming the Content Addressable Memory (CAM) table. Once the CAM table is full, the switch enters a fail-open state and broadcasts all frames, allowing the attacker to sniff traffic that would normally be isolated to specific ports. This is a classic MAC flooding attack, not ARP poisoning or DHCP starvation.

Exam trap

In the CEH exam, candidates often confuse MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets host ARP caches). Both involve MAC addresses and can enable man-in-the-middle attacks, but the tool 'macof' specifically performs MAC flooding.

How to eliminate wrong answers

Option A is wrong because DNS spoofing involves corrupting DNS responses to redirect traffic, typically using tools like `dnsspoof` or `ettercap` with DNS filters, not `macof`. Option B is wrong because ARP poisoning manipulates ARP caches to associate a malicious MAC with a legitimate IP, using tools like `arpspoof` or `ettercap`; `macof` does not send ARP replies or requests. Option D is wrong because DHCP starvation floods a DHCP server with fake DHCPDISCOVER messages to exhaust its IP address pool, using tools like `yersinia` or `dhcpstarv`, not `macof`.

703
MCQmedium

A penetration tester uses the tool 'Pacu' during an AWS security assessment. Which phase of testing is Pacu most commonly associated with?

A.Reporting and documentation
B.Vulnerability scanning
C.Exploitation and post-exploitation
D.Reconnaissance
AnswerC

Pacu is specifically engineered as an open-source exploitation framework for AWS, providing a comprehensive suite of modules tailored for active penetration testing. It excels in the exploitation phase by leveraging identified misconfigurations or weak credentials to gain unauthorized access or elevate privileges within an AWS account. Furthermore, Pacu facilitates post-exploitation activities such as establishing persistence, enumerating sensitive data, performing lateral movement across AWS services, and backdooring resources, making it a powerful tool for simulating real-world attacks.

Why this answer

Pacu is an exploitation framework for AWS, used after initial access to escalate privileges, pivot, and maintain access. It is not typically used for initial reconnaissance (Nmap, ScoutSuite) or reporting.

704
MCQeasy

Which of the following is the PRIMARY purpose of banner grabbing during the reconnaissance phase?

A.To determine the version of a running service
B.To discover open ports
C.To identify the operating system
D.To map the network topology
AnswerA

Banner grabbing involves connecting to a network service (e.g., HTTP, FTP, SSH) and observing the initial data or "banner" it sends back. This banner frequently contains crucial information such as the service name, its specific version number, and sometimes even the underlying operating system or patch level. Identifying these versions is critical for penetration testers to pinpoint known vulnerabilities associated with particular software releases, enabling targeted exploit attempts.

Why this answer

Banner grabbing is a technique used to extract service banners that often include software name and version details. The primary purpose is to determine the version of a running service, as this information allows an attacker to identify known vulnerabilities specific to that version for further exploitation.

Exam trap

The trap here is that candidates confuse banner grabbing with OS fingerprinting or port scanning, but the CEH exam specifically tests that banner grabbing's primary goal is service version identification, not OS detection or port discovery.

How to eliminate wrong answers

Option B is wrong because discovering open ports is accomplished through port scanning (e.g., SYN scan, TCP connect scan), not banner grabbing, which occurs after a port is already known to be open. Option C is wrong because while banner information can sometimes hint at the OS, the primary and direct purpose of banner grabbing is to identify the service version, not the OS; OS detection is typically done via TCP/IP stack fingerprinting (e.g., nmap -O). Option D is wrong because mapping network topology involves techniques like traceroute, SNMP sweeps, or analyzing routing tables, not banner grabbing, which only interacts with a single service on a single host.

705
Multi-Selectmedium

Which TWO of the following are effective defenses against SQL injection attacks?

Select 2 answers
A.Implementing stored procedures with dynamic SQL
B.Disabling error messages
C.Using an ORM that generates parameterized queries
D.Using prepared statements with parameterized queries
E.Escaping user input with addslashes()
AnswersC, D

Object-Relational Mappers (ORMs) provide an effective defense against SQL injection by abstracting database interactions and typically generating parameterized queries. Instead of concatenating user input directly into SQL strings, ORMs bind input values as parameters, ensuring they are treated as data and not executable code. This fundamental separation prevents malicious input from altering the query's structure, thereby neutralizing injection attempts.

Why this answer

Option C is correct because ORMs that generate parameterized queries separate SQL code from user-supplied data, so input is bound as data rather than concatenated into the statement, which prevents injection payloads from altering query structure. Option D is correct because prepared statements with parameterized queries send the SQL template to the database first and bind parameters afterward, ensuring untrusted input cannot change the query's logic. Option A is not effective because stored procedures that build dynamic SQL internally still concatenate user input, reintroducing the injection risk.

Option B is not a defense because hiding error messages only reduces information disclosure; it does not stop malicious SQL from executing. Option E is not reliable because addslashes() is a weak, context-unaware escaping function that fails against many encodings and database-specific syntax, so it should not be used as a primary SQL injection defense.

Exam trap

CEH often tests the misconception that input escaping (addslashes, magic quotes) or hiding errors is a sufficient SQLi defense — the exam expects you to recognize that only parameterization separates code from data.

706
MCQmedium

An attacker uses the Social Engineering Toolkit (SET) to send a malicious email to employees of a company, claiming to be from IT support and urging them to click a link to reset their password. Which social engineering attack is being performed?

A.Vishing
B.Phishing
C.Baiting
D.SMiShing
AnswerB

Phishing is a prevalent cyberattack where adversaries employ deceptive emails to trick recipients into divulging confidential information or executing malicious actions. The Social Engineering Toolkit (SET) is frequently used to craft convincing fake login pages or deliver malware via email attachments, making it a classic vector for credential harvesting or system compromise. This method leverages trust and urgency to bypass security awareness and technical controls.

Why this answer

The Social Engineering Toolkit (SET) is used to craft and send fraudulent emails that appear to come from a trusted source (IT support), urging the recipient to click a link and enter credentials. This is a classic phishing attack because it uses email as the vector and relies on deception to steal sensitive information. Unlike vishing (voice) or SMiShing (SMS), the attack is executed via email, which is the defining characteristic of phishing.

Exam trap

The CEH exam often tests the distinction between phishing, vishing, and SMiShing by focusing on the delivery medium (email vs. voice vs. SMS), so candidates must remember that 'phishing' specifically refers to email-based social engineering.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses telephone calls or VoIP systems to trick victims, not email. Option C is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim, not sending a deceptive email. Option D is wrong because SMiShing (SMS phishing) uses text messages (Short Message Service) as the attack vector, not email.

707
MCQhard

You are a security consultant hired by a mid-sized company with 500 employees. The company has a central office with a lobby, reception, and two secure areas: the server room (requires keycard and PIN) and the executive floor (requires keycard only). Recently, employees have reported seeing unfamiliar people in restricted areas. Security logs show keycard access for the server room only during business hours, but no anomalies. However, the executive floor logs show multiple entries by a single employee, John from Sales, at odd hours. John claims he was working late. The company has a policy that all employees must wear ID badges visibly. You observe that employees often hold doors open for colleagues, and the receptionist does not verify visitor badges. Which of the following actions should you recommend FIRST to address the most likely attack vector?

A.Investigate John's activities and consider disciplinary action
B.Upgrade keycard readers to biometric scanners
C.Implement mantraps and enforce a policy of one person per keycard entry
D.Install additional CCTV cameras in hallways
AnswerC

Mantraps are highly effective physical security controls consisting of two interlocking doors, designed to permit only one person to pass through at a time after successful authentication. This physical barrier directly prevents tailgating by making it impossible for a second individual to enter behind an authorized person. Coupling this technical control with a strictly enforced policy reinforces security protocols, ensuring both physical and administrative measures actively mitigate the tailgating threat.

Why this answer

The most likely attack vector is tailgating (piggybacking), where unauthorized individuals gain physical access by following an authorized employee through a secured door without using their own credentials. Option C directly addresses this by implementing mantraps (a small room with two interlocking doors that only allows one person to pass at a time) and enforcing a strict one-person-per-keycard-entry policy, which physically prevents tailgating. This is the first and most effective control because it mitigates the root cause—social engineering exploiting human courtesy—rather than focusing on symptoms like John's after-hours access or adding surveillance that doesn't prevent the act.

Exam trap

EC-Council often tests the distinction between authentication (e.g., biometrics) and access control (e.g., mantraps), and the trap here is that candidates confuse improving credential verification with preventing the social engineering technique of tailgating, leading them to choose a more expensive but ineffective solution like biometric readers.

How to eliminate wrong answers

Option A is wrong because investigating John's activities focuses on a single employee's behavior (which may be legitimate) rather than addressing the systemic vulnerability of tailgating that allows unfamiliar people into restricted areas. Option B is wrong because upgrading to biometric scanners improves authentication but does not prevent tailgating; an unauthorized person can still follow an authenticated employee through the door after the biometric scan. Option D is wrong because installing additional CCTV cameras only provides passive monitoring and evidence collection after an incident, not active prevention of the tailgating attack vector.

708
MCQmedium

A penetration tester attempts a SQL injection on a login form and receives no error messages, but notices a delay in the server response when injecting ' OR SLEEP(5)--. Which type of SQL injection is this?

A.Union-based SQL injection
B.Boolean-based blind SQL injection
C.Time-based blind SQL injection
D.Error-based SQL injection
AnswerC

Time-based blind SQL injection is the appropriate technique when the application provides no direct output and no discernible boolean difference in its responses. This method relies on making the database server pause for a specific duration (e.g., using `SLEEP()`, `WAITFOR DELAY`, or `PG_SLEEP()`) if a particular injected condition is met. By measuring the time taken for the server to respond, the penetration tester can infer the truthfulness of conditions and extract data character by character.

Why this answer

Time-based blind SQL injection relies on inducing a time delay to infer the truth of a condition, as no error or data is returned.

709
MCQmedium

An employee receives an email that appears to be from the CEO, requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ceo@cornpany.com instead of ceo@company.com). This is an example of which type of attack?

A.Whaling
B.Phishing
C.Pretexting
D.Spear phishing
AnswerD

Spear phishing is a highly targeted form of phishing that uses personalized information to increase the credibility and effectiveness of the attack. Attackers conduct reconnaissance to gather details about the target, such as their name, job title, company, and even internal relationships, to craft a convincing email. An email appearing to be from the CEO to a specific employee leverages this personalized context and perceived authority, making it a classic example of a spear phishing attempt designed to elicit a specific response.

Why this answer

Spear phishing is a targeted phishing attack aimed at a specific individual or organization, using personalized information to increase credibility. In this scenario, the attacker spoofs the CEO's identity and uses a misspelled domain (typosquatting) to trick the employee into performing a wire transfer, which is a classic spear phishing technique. Unlike generic phishing, spear phishing tailors the message to the victim's role and context, making it more effective.

Exam trap

The trap here is that candidates confuse 'whaling' with 'spear phishing' because both target specific individuals, but whaling specifically targets high-level executives, while spear phishing can target any individual within an organization, as in this case where the email impersonates the CEO rather than targeting them.

How to eliminate wrong answers

Option A is wrong because whaling is a specific type of spear phishing that targets high-profile executives (e.g., CEO, CFO) directly, but the question describes an email impersonating the CEO, not targeting the CEO. Option B is wrong because phishing is a broad, untargeted attack sent to many recipients, lacking the personalization and specific context (e.g., using the CEO's name and a misspelled domain) seen here. Option C is wrong because pretexting involves creating a fabricated scenario (pretext) to obtain information, often via phone or in person, and does not inherently rely on email spoofing or typosquatting like this example.

710
MCQmedium

Which of the following best describes a Server-Side Request Forgery (SSRF) attack?

A.An attacker tricks the server into making requests to internal or external resources
B.An attacker sends a malicious script that executes in a user's browser
C.An attacker forges HTTP requests to perform actions on behalf of an authenticated user
D.An attacker injects SQL commands into a database query
AnswerA

Server-Side Request Forgery (SSRF) occurs when an attacker exploits a vulnerability in a web application to compel the server itself to make arbitrary requests. These requests can target internal network resources, such as other services, databases, or cloud metadata APIs, which are typically inaccessible directly from the internet. The server acts as a proxy, fetching data or performing actions on behalf of the attacker, often bypassing firewall rules and network segmentation. This allows for reconnaissance, port scanning, and even direct interaction with sensitive internal systems.

Why this answer

A Server-Side Request Forgery (SSRF) attack occurs when an attacker manipulates a vulnerable server into making HTTP requests to arbitrary destinations, often bypassing network segmentation to access internal resources (e.g., 127.0.0.1, RFC 1918 addresses) or external services. The server acts as a proxy, allowing the attacker to interact with systems that are not directly reachable, such as cloud metadata endpoints (e.g., AWS http://169.254.169.254/latest/meta-data/) or internal databases.

Exam trap

The trap here is that candidates often confuse SSRF with CSRF (Option C) because both involve forged requests, but SSRF targets the server's ability to make requests to internal resources, while CSRF targets the user's browser to perform actions on their behalf.

How to eliminate wrong answers

Option B is wrong because it describes Cross-Site Scripting (XSS), where malicious scripts execute in a user's browser, not server-side requests. Option C is wrong because it describes Cross-Site Request Forgery (CSRF), where an attacker forges requests to perform actions on behalf of an authenticated user, but the server is tricked into sending requests to internal resources, not the user's browser. Option D is wrong because it describes SQL injection, where malicious SQL commands are injected into a database query, not HTTP requests made by the server.

711
MCQmedium

During a penetration test, a tester captures network traffic and notices a large number of ARP replies claiming that 192.168.1.1 is at MAC address 00:11:22:33:44:55, which is different from the legitimate gateway MAC. Which attack is likely in progress?

A.Session hijacking
B.ARP poisoning
C.MAC flooding
D.DNS spoofing
AnswerB

ARP poisoning floods the segment with forged ARP replies binding the gateway IP to an attacker MAC, so victims send traffic to the attacker instead of the real router. The mismatched MAC in the captured replies is the defining signature.

Why this answer

ARP poisoning (also known as ARP spoofing) is the correct answer because the attacker is sending forged ARP replies that associate the legitimate gateway IP (192.168.1.1) with an attacker-controlled MAC address (00:11:22:33:44:55). This causes victim hosts to update their ARP cache with the false mapping, redirecting traffic intended for the gateway to the attacker's machine, enabling man-in-the-middle (MITM) attacks.

Exam trap

The trap in this question is confusing ARP poisoning (which manipulates Layer 2 MAC-to-IP mappings via forged ARP replies) with MAC flooding (which overwhelms switch CAM tables with fake MAC addresses). The key clue is that the attacker is sending multiple ARP replies for a single target IP (the gateway) with a spoofed MAC, not a flood of different MACs.

How to eliminate wrong answers

Option A is wrong because session hijacking typically involves stealing or predicting session tokens (e.g., cookies or session IDs) after initial authentication, not manipulating ARP cache entries at Layer 2. Option C is wrong because MAC flooding is an attack that overwhelms a switch's CAM table with fake MAC addresses to force it into hub mode (flooding all traffic), not sending specific forged ARP replies to poison a single IP-to-MAC mapping. Option D is wrong because DNS spoofing corrupts DNS resolver caches with false IP-to-domain mappings (e.g., returning a malicious IP for www.example.com), not ARP cache entries for a gateway IP.

712
Multi-Selectmedium

A security analyst is planning a reconnaissance activity that must remain undetected. Which TWO of the following techniques should they choose?

Select 2 answers
A.Engage in social engineering to extract network diagrams from employees
B.Gather information from public OSINT sources like Shodan and social media
C.Conduct a passive reconnaissance by analyzing DNS records without querying the target's DNS servers directly
D.Use Nmap with default scripts to enumerate services
E.Perform a full TCP connect scan on all ports
AnswersB, C

Collecting data from Open Source Intelligence (OSINT) sources, such as Shodan for internet-facing device information or social media for organizational details, is a purely passive reconnaissance technique. This method involves querying publicly available databases and websites, generating no direct network traffic to the target's infrastructure, thus ensuring complete undetectability.

Why this answer

OSINT sources like Shodan and social media provide publicly available information without interacting with the target's systems, keeping the reconnaissance passive and undetected. Option C is correct because passive reconnaissance via DNS records (e.g., using cached or third-party DNS databases) avoids querying the target's authoritative DNS servers, thus not generating logs or alerts on the target's infrastructure.

Exam trap

The trap here is that candidates often confuse 'passive reconnaissance' with 'stealth scanning,' assuming that techniques like SYN scan or Nmap's default scripts are undetected, when in fact any direct packet transmission to the target is active and detectable.

713
MCQmedium

A penetration tester is assessing an organization's physical security. The tester wants to gain unauthorized access to a secured server room that uses a biometric fingerprint scanner. Which of the following techniques would be MOST effective for bypassing the biometric scanner?

A.Shoulder surfing the authorized user's fingerprint pattern
B.Picking the lock on the server room door
C.Using a gelatin mold of an authorized user's fingerprint
D.Tailgating behind an authorized employee
AnswerC

Using a gelatin mold is a classic and often effective method for creating a spoofed fingerprint, as gelatin can accurately capture and replicate the unique ridge patterns and valleys of an authorized user's print. When pressed against a scanner, particularly older optical or capacitive types lacking advanced liveness detection, the gelatin replica can mimic the electrical or optical properties of a real finger. This allows the penetration tester to deceive the biometric system into granting access.

Why this answer

Gelatin molds can replicate the exact ridge and valley patterns of a fingerprint, which many capacitive and optical fingerprint scanners read. This bypasses the biometric authentication without requiring the user's cooperation, making it the most direct method to defeat the scanner itself.

Exam trap

The trap here is that candidates often choose tailgating (Option D) as the easiest social engineering method, but the question specifically asks for bypassing the biometric scanner, not the door lock or human controls.

How to eliminate wrong answers

Option A is wrong because shoulder surfing captures only a visual pattern, not the three-dimensional ridge details or capacitance differences needed to spoof a fingerprint scanner. Option B is wrong because picking the lock bypasses the door lock but does not address the biometric scanner, which would still need to be defeated to gain access. Option D is wrong because tailgating relies on following an authorized person through the door, but it does not bypass the biometric scanner itself and may be prevented by mantraps or security awareness.

714
MCQmedium

During a wireless penetration test, the tester runs `airodump-ng wlan0mon` and sees numerous beacon frames from a network. The tester then sends deauthentication packets using `aireplay-ng -0 5 -a <BSSID> wlan0mon`. What is the PRIMARY purpose of this deauthentication attack?

A.To crash the access point and cause a denial of service
B.To force a client to reconnect and capture the WPA/WPA2 handshake
C.To obtain the WPS PIN of the access point
D.To perform a rogue AP attack by spoofing the BSSID
AnswerB

Correct: `airodump-ng` is utilized to monitor wireless traffic and capture the WPA/WPA2 4-way handshake, which is essential for offline password cracking. To expedite this process, a deauthentication attack (typically executed with `aireplay-ng` alongside `airodump-ng`) is employed. This attack forces an authenticated client to disconnect and then immediately reconnect to the access point, thereby generating the necessary handshake frames for `airodump-ng` to record.

Why this answer

Deauthentication attacks force clients to reconnect, allowing capture of the WPA/WPA2 4-way handshake during reconnection, which is needed for offline cracking.

715
MCQmedium

A network administrator notices that the switch's CAM table is full, causing the switch to flood all incoming traffic out of all ports. Which attack is MOST likely occurring?

A.ARP poisoning
B.DHCP starvation
C.DNS spoofing
D.MAC flooding
AnswerD

MAC flooding overwhelms the switch's CAM table with forged source MAC addresses, exhausting its capacity. Once full, the switch cannot map addresses to ports and floods all incoming frames out of every port, satisfying the described symptom of indiscriminate flooding.

Why this answer

MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table by sending thousands of frames with unique, random source MAC addresses. Once the CAM table is full, the switch enters a fail-open state and begins flooding all incoming frames out every port, effectively turning it into a hub and allowing the attacker to sniff traffic. This directly matches the scenario where a full CAM table causes flooding.

Exam trap

In EC-CEH exams, MAC flooding (which fills the CAM table) is often confused with ARP poisoning (which poisons the ARP cache). Both can lead to traffic interception, but the cause differs: MAC flooding exploits the switch's learning mechanism, while ARP poisoning manipulates the host's ARP table.

How to eliminate wrong answers

Option A is wrong because ARP poisoning manipulates the IP-to-MAC mappings in a host's ARP cache to redirect traffic, not by filling the switch's CAM table. Option B is wrong because DHCP starvation exhausts the pool of available IP addresses from a DHCP server, causing denial of service for new clients, but it does not fill the switch's CAM table or cause port flooding. Option C is wrong because DNS spoofing corrupts DNS resolution to redirect users to malicious sites, and it has no effect on the switch's MAC address table or flooding behavior.

716
MCQhard

A security auditor is assessing the physical security of a corporate office building that houses a data center. The building has a single main entrance with a reception desk staffed during business hours (8 AM to 6 PM). After hours, employees use a keycard reader to access the building. The data center itself requires a separate keycard and a 6-digit PIN. The auditor notices that during lunch hours (12-1 PM), the reception desk is often unattended, and employees frequently hold the door for others to avoid using their keycard. Additionally, a recent social engineering test revealed that an attacker was able to call the help desk, claim to be a new employee, and request a password reset, which was granted without proper verification. Based on this scenario, which of the following is the MOST effective combination of controls to mitigate both the physical and social engineering weaknesses?

A.Install a mantrap at the main entrance and require two-factor authentication for the data center door.
B.Install a mantrap at the main entrance and require multi-factor authentication (MFA) for all password reset requests.
C.Deploy security guards at the entrance 24/7 and implement a policy that all visitors must be escorted.
D.Implement a callback verification process for all password reset requests and require a manager approval.
AnswerB

A mantrap at the main entrance is a robust physical security control that effectively prevents tailgating and unauthorized physical access to the premises. Simultaneously, requiring multi-factor authentication (MFA) for all password reset requests significantly strengthens logical security by making it much harder for social engineers to gain unauthorized account access, even if they successfully trick an employee into initiating a reset. This combination addresses both physical and social engineering vulnerabilities comprehensively.

Why this answer

It addresses both weaknesses: a mantrap prevents tailgating at the main entrance (physical security), and requiring MFA for password reset requests mitigates the social engineering attack by adding an authentication factor beyond just a phone call. This combination directly counters the observed vulnerabilities—unattended reception and weak identity verification—without over-engineering or leaving gaps.

Exam trap

The trap here is that candidates focus on the most obvious single weakness (e.g., tailgating or password reset) and choose a control that only fixes that one, missing the requirement for a combination that addresses both physical and social engineering flaws simultaneously.

How to eliminate wrong answers

Option A is wrong because while a mantrap stops tailgating, requiring two-factor authentication only for the data center door does nothing to prevent the social engineering attack on the help desk (password reset). Option C is wrong because deploying 24/7 guards and an escort policy is costly and does not address the social engineering weakness; the attacker called the help desk, not the physical entrance. Option D is wrong because a callback verification process and manager approval only address the social engineering vector, leaving the physical tailgating problem during lunch hours completely unmitigated.

717
MCQmedium

A penetration tester uses SQLMap with the following command: sqlmap -u 'http://target.com/page?id=1' --batch --dbs. Which of the following best describes what this command will do?

A.Enumerate all database names in non-interactive mode
B.Dump the entire contents of the current database
C.Perform a time-based blind SQL injection to extract data
D.Enumerate all tables in all databases
AnswerA

The `--dbs` option explicitly instructs sqlmap to enumerate and display the names of all accessible databases on the target system by querying the database's information schema or system tables. Concurrently, the `--batch` option ensures that sqlmap operates in a non-interactive mode, automatically accepting default choices and proceeding without requiring user input for any prompts or questions that might arise during the enumeration process. This combination efficiently retrieves database names without interruption, which is ideal for automated scripting.

Why this answer

--dbs enumerates database names; --batch uses default options without interactive input.

718
Multi-Selecthard

Which THREE of the following are effective DDoS mitigation techniques? (Select 3)

Select 3 answers
A.Rate limiting
B.Scrubbing centers
C.Blackholing all traffic to the target
D.IP spoofing
E.Anycast network distribution
AnswersA, B, E

Correct. Rate limiting can throttle attack traffic.

Why this answer

Rate limiting is effective because it restricts the number of requests a server will accept from a single IP address or session within a given time window, typically enforced via token bucket or leaky bucket algorithms. This prevents a single attacker or botnet node from overwhelming server resources, though it must be carefully tuned to avoid blocking legitimate users.

Exam trap

EC-CEH often tests the misconception that blackholing (null routing) is a viable mitigation technique, but candidates must remember it is a sacrificial measure that drops all traffic, not a selective defense, and is only used when the attack overwhelms all other defenses.

719
MCQmedium

A security engineer is concerned about DNS zone transfer attacks. Which of the following countermeasures would be MOST effective in preventing unauthorized zone transfers?

A.Restrict zone transfers to authorized IP addresses only
B.Use DNSSEC to sign the zone
C.Change the default port of 53 to a non-standard port
D.Disable DNS recursion on the server
AnswerA

DNS zone transfers, specifically AXFR (full zone transfer) and IXFR (incremental zone transfer), are designed to replicate DNS zone data between primary and secondary name servers. By configuring the authoritative DNS server to only permit these transfers from a predefined list of trusted IP addresses (typically the secondary DNS servers), an administrator directly prevents unauthorized entities from enumerating an entire domain's host records. This access control mechanism is the primary and most effective defense against malicious reconnaissance via zone transfers.

Why this answer

Restricting zone transfers to authorized IP addresses only is the most effective countermeasure because it directly controls which DNS servers are allowed to request a full copy of the zone data. By configuring an allow-transfer list (e.g., using the 'allow-transfer { trusted_servers; };' directive in BIND), the primary DNS server will reject zone transfer requests from any unauthorized IP, preventing attackers from enumerating all DNS records.

Exam trap

The trap here is that candidates often confuse DNSSEC (which protects data integrity) with access control mechanisms, or they mistakenly think disabling recursion or changing ports will prevent zone transfers, when in fact zone transfers are controlled by explicit authorization settings on the authoritative server.

How to eliminate wrong answers

Option B is wrong because DNSSEC (DNS Security Extensions) provides data integrity and authentication through digital signatures, but it does not control or restrict the ability to perform a zone transfer; it only ensures that the zone data has not been tampered with. Option C is wrong because changing the default port of 53 to a non-standard port is not a viable countermeasure; DNS clients and servers expect port 53, and changing it would break normal DNS resolution, while an attacker can easily scan for the new port. Option D is wrong because disabling DNS recursion prevents the server from resolving queries for external domains on behalf of clients, but it does not affect the server's ability to perform or allow zone transfers, which are a separate function of authoritative DNS servers.

720
MCQeasy

Which Burp Suite tool is specifically designed to intercept and modify HTTP(S) traffic between the browser and the target web application?

A.Intruder
B.Scanner
C.Repeater
D.Proxy
AnswerD

Burp Proxy is the core interception component of Burp Suite, acting as a man-in-the-middle between the browser and the target web server. It is specifically designed to capture all HTTP and HTTPS traffic flowing through it, allowing security professionals to view, analyze, and modify requests and responses in real-time before they reach their destination. This real-time interception capability is fundamental for understanding application logic, identifying vulnerabilities, and manipulating data during penetration testing.

Why this answer

The Burp Suite Proxy is the core component that sits between the browser and the target web application, acting as a man-in-the-middle to intercept, inspect, and modify HTTP(S) requests and responses in real time. It is specifically designed for this interception and modification task, allowing testers to manually tamper with traffic before it reaches the server or client. Other tools like Intruder, Scanner, and Repeater rely on the Proxy to capture and forward traffic but do not themselves perform the initial interception and modification of live traffic.

Exam trap

CEH often tests the confusion between tools that rely on captured traffic (Repeater, Intruder) and the tool that actually performs the interception (Proxy), so candidates must remember that Proxy is the only component designed for live interception and modification.

How to eliminate wrong answers

Option A is wrong because Intruder is an automated attack tool used for fuzzing and brute-forcing parameters, not for intercepting and modifying live traffic. Option B is wrong because Scanner is an automated vulnerability scanner that crawls and audits applications, but it does not provide interactive interception and modification of HTTP(S) traffic. Option C is wrong because Repeater is a manual tool for editing and resending individual requests, but it does not intercept traffic between the browser and server in real time; it operates on requests already captured.

721
Multi-Selectmedium

During a penetration test, an analyst detects that an SNMP agent on a network device is using the default community string 'public'. Which TWO actions can the analyst perform using this information? (Choose TWO.)

Select 2 answers
A.Enumerate user accounts and system details
B.Extract encrypted passwords from the device
C.Write new configuration to the device
D.Perform SNMPwalk to enumerate the MIB tree
E.Disable the SNMP agent remotely
AnswersA, D

SNMP Management Information Bases (MIBs) are structured databases that store a wealth of information about network devices. Many standard MIB objects, such as those under the `host` or `users` branches, are designed to expose system details like operating system versions, running services, and even lists of local user accounts. This information, often accessible with a default read-only community string, is invaluable for attackers performing reconnaissance to identify potential vulnerabilities or valid login names.

Why this answer

The default SNMP community string 'public' typically grants read-only access to the SNMP agent. With read-only access, the analyst can perform an SNMPwalk (using tools like snmpwalk or MIB browsers) to enumerate the entire Management Information Base (MIB) tree, which often includes system details, user accounts, running processes, and network configurations. This enumeration is a key step in the Enumeration phase of a penetration test, as it can reveal sensitive information without authentication.

Exam trap

The trap here is that candidates often assume that a default read‑only community string like 'public' provides full administrative control over the device, but it only grants read‑only access. Therefore, actions such as writing configurations or disabling the agent are not possible without a read‑write community string.

722
Multi-Selectmedium

A penetration tester is assessing the security of a cloud application and discovers that it is vulnerable to Server-Side Request Forgery (SSRF). Which TWO of the following are potential impacts of this vulnerability?

Select 2 answers
A.Ability to perform a man-in-the-middle attack on the user's browser
B.Access to cloud instance metadata (e.g., AWS IMDS)
C.Direct modification of DNS records
D.Remote code execution on internal servers
E.Direct access to the database without authentication
AnswersB, D

SSRF enables a malicious actor to force the vulnerable server to make requests to internal endpoints. Cloud instance metadata services, such as AWS IMDS (Instance Metadata Service), are often accessible from the instance itself via a well-known internal IP address (e.g., 169.254.169.254). An SSRF vulnerability can be leveraged to query these services, potentially retrieving sensitive information like temporary IAM role credentials, user data, or network configuration details, which can then be used for privilege escalation or further attacks within the cloud environment.

Why this answer

Option B is correct because SSRF lets the attacker make the vulnerable server issue HTTP requests to the cloud metadata endpoint (e.g., http://169.254.169.254/latest/meta-data/ for AWS IMDS), potentially exposing IAM credentials, instance identity, and other sensitive data. Option D is correct because SSRF can be chained to reach internal-only services (such as Redis, Elasticsearch, or admin panels) that are not exposed externally, and those services may allow command execution or be exploited via deserialization/RCE vulnerabilities. Option A is not a direct SSRF impact because man-in-the-middle attacks on a user's browser require network interception or TLS compromise, not server-side request forgery.

Option C is incorrect because modifying DNS records requires access to the DNS provider or zone management interface, which SSRF does not directly grant. Option E is incorrect because SSRF does not bypass database authentication; it only enables the server to make requests, and direct unauthenticated database access would require separate misconfiguration or credentials.

Exam trap

CEH often tests the confusion between SSRF and other vulnerabilities like CSRF or direct database access, leading candidates to overestimate or underestimate the impact of SSRF.

723
MCQeasy

A security analyst wants to gather information about a target domain using public records without directly interacting with the target's systems. Which technique is the analyst employing?

A.Vulnerability scanning
B.OSINT using WHOIS queries
C.Active reconnaissance
D.Social engineering
AnswerB

OSINT (Open Source Intelligence) using WHOIS queries is a highly effective passive information gathering technique. It involves querying public databases to retrieve domain registration details such as registrant names, contact information, registration and expiration dates, and nameservers. This method is considered passive because it does not directly interact with the target's live systems or network, relying solely on publicly available records.

Why this answer

OSINT (Open Source Intelligence) using WHOIS queries is a passive reconnaissance technique that gathers domain registration details from public WHOIS databases without interacting with the target's systems. This aligns with the requirement to use public records and avoid direct contact, making it the correct choice for footprinting.

Exam trap

EC-Council often tests the distinction between active and passive reconnaissance, and the trap here is that candidates confuse WHOIS queries with active techniques because they involve sending a query, but since the query goes to a public third-party database (not the target's systems), it remains passive.

How to eliminate wrong answers

Option A is wrong because vulnerability scanning actively sends probes and packets to the target's systems to identify weaknesses, which directly interacts with the target and is not passive. Option C is wrong because active reconnaissance involves direct interaction with the target's systems (e.g., port scanning, ping sweeps), which violates the 'without directly interacting' condition. Option D is wrong because social engineering involves manipulating human targets through direct or indirect communication (e.g., phishing calls), which is an active technique and not based on public records.

724
MCQhard

A security analyst is tasked with performing passive reconnaissance on a target organization. Which of the following is the BEST approach to gather information about the target's technology stack without directly interacting with the target's systems?

A.Engage in social engineering via phone calls
B.Use Shodan to search for target infrastructure
C.Initiate a DNS zone transfer request
D.Perform a port scan with Nmap
AnswerB

Utilizing Shodan for target infrastructure searches is a quintessential passive reconnaissance technique because it relies entirely on pre-collected, publicly available data. Shodan continuously scans the internet and indexes information about internet-connected devices, services, and their configurations, storing this data in its own databases. An analyst querying Shodan does not send any direct network traffic to the target's systems, thereby avoiding detection and remaining completely non-intrusive.

Why this answer

Shodan is a search engine that indexes banners from internet-connected devices, allowing an analyst to discover a target's exposed services, open ports, and technology stack (e.g., web servers, SSH versions, IoT devices) without sending any packets to the target's systems. This makes it a purely passive reconnaissance technique, as it relies on Shodan's pre-collected data rather than direct interaction.

Exam trap

EC-Council often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse Shodan (a passive, third-party data source) with active tools like Nmap or DNS zone transfers, which require direct interaction with the target's systems.

How to eliminate wrong answers

Option A is wrong because social engineering via phone calls involves direct interaction with the target's employees, which is an active technique and risks alerting the target. Option C is wrong because initiating a DNS zone transfer request sends a query to the target's DNS server, which is an active interaction that can be logged and often fails due to RFC 1035 restrictions (zone transfers are typically disabled). Option D is wrong because performing a port scan with Nmap sends packets directly to the target's IP addresses, making it an active reconnaissance method that can be detected by intrusion detection systems.

725
MCQhard

During a penetration test, the tester runs `ldapsearch -x -H ldap://192.168.1.20 -b 'dc=domain,dc=com' '(objectclass=*)'`. The output reveals user objects with 'userPassword' attributes in clear text. Which type of enumeration is being performed, and what is the security implication?

A.NFS enumeration; it indicates that NFS shares are world-readable
B.LDAP enumeration; it indicates that the LDAP server stores passwords in plaintext, posing a credential theft risk
C.SNMP enumeration; it indicates that the community string is weak
D.SMTP enumeration; it indicates that the mail server is misconfigured
AnswerB

The `ldapsearch -x -h <host>` command initiates an anonymous or simple authenticated query against an LDAP server. If successful, it enumerates directory attributes. The discovery of plaintext passwords within the returned LDAP attributes signifies a critical security misconfiguration, as sensitive user credentials are directly exposed. This poses a severe risk of credential theft, allowing attackers to reuse these passwords for lateral movement or access to other systems.

Why this answer

The `ldapsearch` command is used to query an LDAP directory service. The option `-x` specifies simple authentication, and the filter `(objectclass=*)` retrieves all entries. The output revealing `userPassword` attributes in clear text indicates that the LDAP server is storing passwords in plaintext, which is a severe security risk because an attacker can directly harvest credentials for lateral movement or privilege escalation.

Exam trap

The trap here is that candidates may confuse the `ldapsearch` command with other enumeration tools (like `snmpwalk` or `smtp-user-enum`) and fail to recognize that the specific command and output directly indicate LDAP enumeration with plaintext password exposure.

How to eliminate wrong answers

Option A is wrong because NFS enumeration uses commands like `showmount -e` or `rpcinfo`, not `ldapsearch`, and the output would show exported shares, not user objects with passwords. Option C is wrong because SNMP enumeration uses tools like `snmpwalk` with community strings, and the output would contain OIDs and MIB values, not LDAP directory entries. Option D is wrong because SMTP enumeration uses commands like `VRFY` or `EXPN` to verify email addresses, and the output would be SMTP response codes, not LDAP attributes.

726
MCQeasy

A security analyst captures a large number of unique initialization vectors (IVs) from a wireless network using airodump-ng. Which attack are they MOST likely preparing to execute?

A.WPS PIN brute-force attack
B.Evil twin AP deployment
C.WEP key recovery using aircrack-ng
D.WPA handshake capture
AnswerC

WEP key recovery using tools like aircrack-ng is the correct answer because WEP's fundamental cryptographic weakness stems from its inefficient use of Initialization Vectors (IVs) with the RC4 stream cipher. Attackers exploit the small 24-bit IV space and the plaintext transmission of IVs, leading to frequent IV reuse with the same WEP key. By collecting a large number of unique IVs, often hundreds of thousands to millions, statistical analysis can be performed to deduce the WEP key by observing patterns in the keystream generated from the IV and the key.

Why this answer

WEP encryption is vulnerable to statistical attacks that require capturing many unique IVs to recover the WEP key. The large number of unique IVs indicates preparation for a WEP cracking attack using a tool like aircrack-ng.

727
MCQmedium

A penetration tester is authorized to test a company's wireless network. After capturing the WPA2 4-way handshake, the tester attempts to crack it offline but fails because the passphrase is long and complex. The tester then decides to create a rogue access point that mimics the corporate SSID and captures the handshake from a connecting client. Which attack is the tester performing?

A.WPS PIN brute force
B.Evil twin
C.Deauthentication attack
D.KRACK attack
AnswerB

An evil twin is a rogue access point that impersonates a legitimate Wi-Fi network to trick clients into connecting. Once the victim connects, the attacker can capture the WPA2 handshake or credentials. This matches the scenario where the tester creates a fake AP with the corporate SSID to capture the handshake from a connecting client.

Why this answer

The tester sets up a rogue access point with the same SSID as the corporate network to trick a client into connecting, thereby capturing the WPA2 handshake. This is the definition of an evil twin attack. The other options describe different wireless attacks that do not match the scenario's details.

Exam trap

The trap here is confusing an evil twin with a deauthentication attack, since both can be used to capture a handshake, but only the evil twin involves a rogue access point mimicking a legitimate SSID.

728
MCQhard

During a penetration test, you discover a Windows service running with SYSTEM privileges that has a weak file permission allowing the 'Everyone' group to modify its executable. Which privilege escalation technique is MOST directly applicable here?

A.Token impersonation
B.Weak service binary permissions
C.DLL hijacking
D.Unquoted service path
AnswerB

Weak service binary permissions represent a critical privilege escalation vulnerability where an attacker possesses write access to the executable file of a Windows service. By replacing the legitimate service binary with a malicious payload, such as a reverse shell or a user-creation script, the attacker can achieve elevated privileges. When the compromised service is subsequently started or restarted by the operating system, it will execute the attacker's code, typically under the SYSTEM account, granting full control over the machine.

Why this answer

The scenario describes a Windows service executable with weak file permissions that allow the 'Everyone' group to modify it. This directly enables an attacker to replace the legitimate executable with a malicious one, which will then be executed with SYSTEM privileges when the service starts. This is the classic 'weak service binary permissions' privilege escalation vector, often exploited using tools like `icacls` or `accesschk` to identify the vulnerability.

Exam trap

EC-Council often tests the distinction between modifying the service binary itself (weak binary permissions) versus exploiting path parsing (unquoted service path) or dependency loading (DLL hijacking), so candidates must focus on the specific permission weakness described.

How to eliminate wrong answers

Option A is wrong because token impersonation typically requires an existing token (e.g., from a named pipe or RPC) to steal or duplicate, not a writable service binary. Option C is wrong because DLL hijacking involves placing a malicious DLL in a path where the service searches for missing DLLs, not modifying the service's primary executable. Option D is wrong because an unquoted service path exploits spaces in the service binary path to execute an unintended executable, not the modification of the existing binary itself.

729
MCQhard

A penetration tester uses the following Nmap command: nmap -sS -O -p 1-1000 10.0.0.1. The output shows port 22 as open, and OS detection suggests 'Linux 2.6.x'. The tester then runs: nmap -sV -p 22 10.0.0.1. What additional information does the second scan provide?

A.It confirms the OS is Linux 2.6.x
B.It checks if the port is filtered by a firewall
C.It identifies the version of the SSH service running
D.It performs a UDP scan on port 22
AnswerC

The -sV flag instructs Nmap to perform service version detection on the specified port, which in this context is port 22, commonly used for SSH. Nmap achieves this by sending various probes to the port and analyzing the responses, often comparing banner grabs or protocol handshakes against its extensive service signature database. This process accurately identifies the specific SSH daemon and its version, such as OpenSSH 8.2p1, providing crucial intelligence for vulnerability assessment.

Why this answer

The second scan uses the `-sV` flag, which enables version detection. Nmap probes the open port 22 (SSH) to determine the exact service version (e.g., OpenSSH 5.3p1). This is distinct from OS detection (`-O`), which guesses the operating system based on TCP/IP stack fingerprinting.

The `-sV` scan provides granular service version information, not OS confirmation or firewall status.

Exam trap

The trap here is confusing OS detection (`-O`) with service version detection (`-sV`), leading candidates to think `-sV` confirms the OS when it actually identifies the application version running on the port.

How to eliminate wrong answers

Option A is wrong because `-sV` does not confirm the OS; OS detection is performed by the `-O` flag in the first scan, and version detection only identifies the application version, not the underlying OS. Option B is wrong because checking if a port is filtered by a firewall requires a different scan type, such as a SYN scan (`-sS`) with firewall evasion techniques or a scan that analyzes RST responses; `-sV` assumes the port is open and attempts a full connection to grab the service banner. Option D is wrong because `-sV` performs TCP version detection on the specified port (22), not a UDP scan; a UDP scan requires the `-sU` flag.

730
MCQhard

A penetration tester uses the following command to scan a target: nmap -sU -sV -p 53,161,162 10.0.0.1. Which of the following BEST describes what this scan will accomplish?

A.Full port scan of all 65535 UDP ports
B.Ping sweep and OS detection on the target
C.UDP scan on three ports with service version detection
D.TCP SYN scan on ports 53, 161, 162 with version detection
AnswerC

This option accurately describes the Nmap command's functionality. The -sU flag specifically instructs Nmap to perform a UDP port scan, targeting services that communicate via the User Datagram Protocol. Concurrently, the -sV flag enables service version detection, attempting to identify the application and its version running on any discovered open UDP ports. The -p 53,161,162 argument precisely limits this comprehensive scan to three specific UDP ports.

Why this answer

The `-sU` flag initiates a UDP scan, `-p 53,161,162` limits the scan to those three specific ports, and `-sV` enables service version detection. This combination performs a UDP scan on only the specified ports and attempts to identify the versions of services running on them.

Exam trap

The trap here is that candidates may confuse `-sU` (UDP scan) with `-sS` (TCP SYN scan) or assume that `-sV` implies OS detection, when in fact `-sV` is strictly for service version detection and OS detection requires the `-O` flag.

How to eliminate wrong answers

Option A is wrong because the command specifies `-p 53,161,162`, which limits the scan to only those three UDP ports, not all 65535 UDP ports. Option B is wrong because the command uses `-sU` (UDP scan) and `-sV` (version detection), not `-sn` (ping sweep) or `-O` (OS detection). Option D is wrong because `-sU` specifies a UDP scan, not a TCP SYN scan (which would use `-sS`), and the ports 53, 161, 162 are commonly associated with UDP services (DNS, SNMP).

731
MCQhard

A security analyst observes an SSL/TLS handshake where the client and server negotiate TLS 1.0 instead of TLS 1.2, despite the server supporting TLS 1.2. Which attack BEST describes the manipulation of the handshake to force weaker encryption?

A.Man-in-the-middle attack
B.Replay attack
C.Downgrade attack
D.Birthday attack
AnswerC

A downgrade attack specifically targets the SSL/TLS handshake process by forcing the communicating parties to negotiate and use an older, weaker, and often vulnerable version of the protocol. During the ClientHello message, an attacker intercepts and modifies the list of supported protocol versions, removing stronger options like TLS 1.2 or 1.3. This manipulation tricks the server into agreeing upon an outdated protocol, such as SSL 3.0 or TLS 1.0, which may contain known cryptographic weaknesses that can then be exploited for decryption or further compromise.

Why this answer

A downgrade attack occurs when an attacker forces the client and server to negotiate a lower, less secure version of a protocol (e.g., from TLS 1.2 to TLS 1.0) to exploit vulnerabilities in the older version.

732
Multi-Selecthard

An organization is investigating a potential malware infection. The security analyst observes unusual outbound connections to a known malicious IP address and finds a suspicious process running under a user's session. The analyst decides to perform memory analysis using Volatility. Which TWO commands would be most useful to identify the malicious process and its network connections?

Select 2 answers
A.volatility -f memory.dmp netscan
B.volatility -f memory.dmp pslist
C.volatility -f memory.dmp procdump
D.volatility -f memory.dmp svcscan
E.volatility -f memory.dmp malfind
AnswersA, B

The `volatility -f memory.dmp netscan` command is crucial for initial malware investigation because it enumerates all active network connections present in the memory dump. This allows incident responders to quickly identify suspicious outbound connections to unknown or malicious IP addresses, which are strong indicators of command and control (C2) communication, data exfiltration, or botnet activity. Confirming such network activity is a primary step in validating a potential infection.

Why this answer

The `netscan` plugin in Volatility scans the memory dump for network connections and sockets, including TCP and UDP endpoints, which directly reveals outbound connections to the malicious IP. The `pslist` plugin lists all running processes by walking the process list in the kernel, allowing the analyst to identify the suspicious process by name or PID. Together, these two commands provide the process identity and its network activity, which is exactly what the scenario requires.

Exam trap

The trap here is that candidates may choose `malfind` (option E) because it sounds malware-specific, but it does not list all processes or network connections, whereas `pslist` and `netscan` directly answer the question of identifying the process and its outbound connections.

733
MCQhard

Refer to the exhibit. A security analyst reviews the firewall log and notices that user jdoe accessed a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not the usual file server subnet. Which type of social engineering attack is most likely being attempted?

A.Phishing
B.Vishing
C.Tailgating
D.Baiting
AnswerC

Tailgating is a physical security breach where an unauthorized individual gains access to a restricted area by following an authorized person through a controlled entry point without proper authentication. Once physically inside the secured perimeter, the attacker can connect their device to the internal network, potentially assigning themselves an unauthorized internal IP address, which would then be logged by the firewall attempting connections like SMB, indicating an internal compromise.

Why this answer

The firewall log shows user jdoe accessing a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not on the usual file server subnet. This indicates the attacker has physically entered the building or restricted area by following an authorized person (tailgating) and then connected a rogue device to the internal network to perform lateral movement. Tailgating is the social engineering attack that relies on gaining physical access by exploiting trust or courtesy, which aligns with the unauthorized internal IP and SMB activity.

Exam trap

The trap here is that candidates see SMB and internal IP and immediately think of a technical attack like phishing or baiting, but the key clue is the physical access implied by the unusual subnet, which points to tailgating as the social engineering vector.

How to eliminate wrong answers

Option A is wrong because phishing involves sending deceptive emails or messages to trick users into revealing credentials or installing malware, not physically accessing a network and using SMB from an unusual internal IP. Option B is wrong because vishing (voice phishing) uses phone calls to extract sensitive information, not physical intrusion or network-level SMB connections. Option D is wrong because baiting involves offering something enticing (e.g., infected USB drives) to lure victims, not directly following someone into a restricted area to gain network access.

734
MCQmedium

An attacker modifies system logs to remove entries related to their activities. Which technique is being used to cover tracks?

A.Token impersonation
B.Steganography
C.Log manipulation
D.Rootkit installation
AnswerC

Log manipulation precisely describes the act of an attacker altering, deleting, or fabricating entries within system logs to obscure their malicious activities. This technique is crucial for covering tracks, evading detection by security monitoring systems, and hindering forensic investigations by removing evidence of unauthorized access or actions. Modifying log files directly addresses the scenario of removing specific entries.

Why this answer

Log manipulation is the correct answer because it directly involves altering or deleting log entries to hide evidence of unauthorized activities. Attackers often use this technique to remove traces of their actions from system logs, such as event logs in Windows or syslog files in Linux, thereby covering their tracks and avoiding detection.

Exam trap

The trap here is that candidates may confuse rootkit installation with log manipulation, as rootkits can hide logs, but the question specifically asks about modifying logs to remove entries, which is a direct action on the log files themselves, not a hiding mechanism.

How to eliminate wrong answers

Option A is wrong because token impersonation is a technique used to steal or forge authentication tokens (e.g., Kerberos tickets) to gain unauthorized access, not to modify logs. Option B is wrong because steganography hides data within other files (e.g., images or audio) to conceal communication, not to alter system logs. Option D is wrong because rootkit installation involves installing malicious software that hides processes, files, or system modifications from the OS, but it does not specifically target log files for modification; log manipulation is a separate post-exploitation step.

735
Multi-Selecthard

Which TWO of the following attacks are specifically associated with wireless networks?

Select 2 answers
A.Man-in-the-middle attack
B.De-authentication attack
C.Evil twin attack
D.Replay attack
E.Birthday attack
AnswersB, C

A De-authentication attack specifically targets the IEEE 802.11 (Wi-Fi) standard by exploiting its management frames. An attacker spoofs the MAC address of either the legitimate access point or a client and sends de-authentication frames, which are unauthenticated, to force clients to disconnect from the wireless network. This denial-of-service technique directly leverages the stateless nature of 802.11 management frames, making it an attack inherently specific to wireless local area networks (WLANs).

Why this answer

Option B, the de-authentication attack, is specifically associated with wireless networks because it exploits unencrypted 802.11 management frames: an attacker spoofs the source MAC of an access point and sends deauthentication (or disassociation) frames to a client, forcibly disconnecting it from the WLAN. Option C, the evil twin attack, is also wireless-specific: the attacker sets up a rogue access point that broadcasts the same SSID (and often the same BSSID/channel) as a legitimate AP, tricking clients into associating with it to harvest credentials or launch a man-in-the-middle. The unmarked options do not belong because A (man-in-the-middle) and D (replay) are generic attacks that apply to wired, wireless, and application-layer contexts, and E (birthday attack) is a cryptographic hash-collision attack unrelated to wireless networking.

Exam trap

EC-Council often tests the distinction between attacks that are 'specific to wireless' versus those that are 'general network attacks' — the trap is that candidates confuse a common attack vector (like man-in-the-middle) with a protocol-specific vulnerability unique to 802.11.

736
MCQmedium

A penetration tester uses the Social Engineering Toolkit (SET) to create a malicious USB drive that autoruns when inserted. Which social engineering technique is being employed?

A.Tailgating
B.Baiting
C.Pretexting
D.Phishing
AnswerB

Baiting is a social engineering attack that leverages human curiosity or greed by leaving physical media, such as USB drives or CDs, infected with malware in public or semi-public locations. The attacker relies on the victim finding the device and inserting it into their computer, thereby executing the malicious payload. The Social Engineering Toolkit (SET) is specifically designed to create such malicious payloads and facilitate the setup for baiting attacks, making it a direct match for this technique.

Why this answer

Baiting is the correct answer because the penetration tester is using a physical device (USB drive) to exploit human curiosity or greed, enticing the target to insert it into a system. The Social Engineering Toolkit (SET) can create an autorun.inf file that triggers a payload upon insertion, which is a classic baiting attack that relies on the victim's action to compromise the system.

Exam trap

The trap here is that candidates confuse baiting with phishing because both involve tricking the user, but baiting specifically relies on a physical lure (like a USB drive) rather than a digital message or link.

How to eliminate wrong answers

Option A is wrong because tailgating involves an unauthorized person following an authorized individual into a restricted area without consent, not using a malicious USB drive. Option C is wrong because pretexting involves fabricating a scenario or identity to deceive a target into divulging information, such as impersonating IT support, not deploying a physical device. Option D is wrong because phishing is a digital social engineering technique that uses deceptive emails, messages, or websites to steal credentials or deliver malware, not a physical USB-based attack.

737
MCQmedium

A security engineer runs SNMPwalk on a network device and receives community strings as 'public' and 'private'. What is the PRIMARY concern?

A.The device is vulnerable to buffer overflow attacks
B.The device is infected with malware
C.The device may be exposing sensitive configuration information
D.The device is using outdated encryption protocols
AnswerC

When an snmpwalk command successfully retrieves data using common or default community strings, it signifies that the device's SNMP agent is configured insecurely. This allows an attacker to access extensive Management Information Base (MIB) data, which frequently includes critical system details, network interface configurations, routing tables, and even potentially sensitive user account information. Such information leakage provides valuable reconnaissance for further targeted attacks.

Why this answer

The SNMP community strings 'public' and 'private' are default read-only and read-write credentials defined in SNMPv1 and SNMPv2c. An attacker who can SNMPwalk the device with these strings can enumerate the entire MIB tree, including system configuration, routing tables, interface details, and user accounts. This directly exposes sensitive configuration information, making C the primary concern.

Exam trap

EC-Council often tests the distinction between 'default credentials' and 'exploitation vectors'—candidates mistakenly associate 'public/private' with encryption or malware, when the real risk is unauthorized information disclosure via SNMP enumeration.

How to eliminate wrong answers

Option A is wrong because SNMP community strings are authentication credentials, not a vector for buffer overflow attacks; buffer overflows exploit memory corruption in protocol parsing or application code, not weak default strings. Option B is wrong because the presence of default community strings indicates poor security configuration, not malware infection; malware would require evidence of malicious processes or network behavior. Option D is wrong because SNMPv1 and SNMPv2c do not use encryption at all—they transmit community strings in cleartext; the issue is lack of encryption, not outdated encryption protocols.

738
MCQmedium

During a penetration test, you notice that a web application accepts user input and displays it directly in the browser without sanitization. Which attack is most likely to succeed?

A.SQL Injection
B.Cross-Site Request Forgery (CSRF)
C.Cross-Site Scripting (XSS)
D.Command Injection
AnswerC

Cross-Site Scripting (XSS) occurs when a web application incorporates untrusted data into a web page without proper validation or encoding, allowing attackers to inject client-side scripts. In the case of reflected XSS, the malicious script is immediately returned by the web server in its response and executed by the user's browser, directly impacting the content displayed to the user. This vulnerability directly manifests as unsanitized input being rendered in the browser.

Why this answer

The scenario describes a classic reflected Cross-Site Scripting (XSS) vulnerability. The application accepts user input and displays it directly in the browser without sanitization, allowing an attacker to inject malicious JavaScript that executes in the victim's browser. This is the defining characteristic of XSS, not SQL injection or command injection, which target server-side interpreters.

Exam trap

EC-Council often tests the distinction between reflected XSS and stored XSS; the trap here is that candidates may assume any unsanitized input is SQL injection, but the key clue is direct display in the browser without server-side processing like database queries or command execution.

How to eliminate wrong answers

Option A is wrong because SQL Injection requires the user input to be included in a database query, not simply displayed in the browser; the scenario does not mention any database interaction. Option B is wrong because Cross-Site Request Forgery (CSRF) exploits the trust a site has in a user's browser to perform unauthorized actions, but it does not involve displaying unsanitized user input directly; it requires a forged request, not reflected output. Option D is wrong because Command Injection requires the input to be passed to a system shell or command interpreter, not merely rendered in HTML; the scenario lacks any indication of server-side command execution.

739
Multi-Selecthard

Which THREE of the following are components of the CHPSET system hacking methodology? (Select three.)

Select 3 answers
A.Sniffing network traffic
B.Hiding files
C.Cracking passwords
D.Scanning ports
E.Executing applications
AnswersA, C, E

Sniffing network traffic is a fundamental component of the CHPSET (Cracking, Hiding, Planting, Sniffing, Executing, Erasing) methodology, specifically corresponding to the 'Sniffing' phase. This involves passively capturing and analyzing data packets traversing a network segment to intercept sensitive information such as credentials, session tokens, or proprietary data. Attackers utilize tools like Wireshark or tcpdump to monitor network communications, gaining insights into network topology and identifying potential vulnerabilities for further exploitation.

Why this answer

The CHPSET system hacking methodology includes six phases: Cracking (C), Hiding (H), Privilege Escalation (P), Sniffing (S), Executing (E), and Targeting (T). Among the given options, Sniffing network traffic (A) corresponds to Sniffing, Cracking passwords (C) to Cracking, and Executing applications (E) to Executing. Hiding files (B) is a specific activity under the Hiding phase but is not a distinct phase itself.

Scanning ports (D) is a reconnaissance step performed during the pre-hacking phase, not part of CHPSET. Therefore, the three correct components are A, C, and E.

Exam trap

Candidates may incorrectly select Hiding files (B) as a separate phase, but the CHPSET methodology lists 'Hiding' as a broad phase that can include various hiding techniques. The specific term 'Hiding files' is not a phase. Others may include Scanning ports (D) due to its prevalence in earlier stages, but it is not part of the system hacking phases.

740
MCQeasy

Which malware type is characterized by self-replication across networks without needing a host file?

A.Worm
B.Trojan
C.Rootkit
D.Ransomware
AnswerA

Worms are a distinct category of malware known for their ability to self-replicate and propagate independently across computer networks without requiring user interaction. They exploit vulnerabilities in network protocols or services to spread from one system to another, consuming bandwidth and system resources. This autonomous replication is their defining characteristic, enabling rapid and widespread infection.

Why this answer

A worm is a standalone malware program that replicates itself across network connections without requiring a host file or user intervention. It exploits vulnerabilities in network protocols or services (e.g., SMB, RDP) to propagate autonomously, as seen with WannaCry's use of EternalBlue.

Exam trap

EC-CEH often tests the distinction between a worm and a virus, where the trap is that candidates confuse self-replication across networks (worm) with self-replication within a single system via host files (virus).

How to eliminate wrong answers

Option B is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution to install and typically requires a host file or program. Option C is wrong because a rootkit is designed to hide its presence and maintain privileged access, not to self-replicate across networks; it often modifies OS kernel structures. Option D is wrong because ransomware encrypts files or locks systems for extortion, and while some variants (e.g., WannaCry) use worm-like propagation, the defining characteristic of ransomware is the ransom demand, not self-replication without a host file.

741
MCQhard

In a cloud environment, an attacker exploits a vulnerability in a web application to make the server send requests to internal metadata endpoints (e.g., http://169.254.169.254/latest/meta-data/). This yields IAM temporary credentials. Which attack is this?

A.Server-Side Request Forgery (SSRF) targeting cloud metadata
B.XML External Entity (XXE) injection
C.Insecure Direct Object Reference (IDOR) on metadata
D.Cross-Site Request Forgery (CSRF) targeting cloud APIs
AnswerA

An SSRF vulnerability allows an attacker to manipulate a vulnerable server-side application into making arbitrary requests to internal network resources on behalf of the attacker. In cloud environments, this is critically dangerous as it can be leveraged to query the cloud provider's instance metadata service, typically found at a well-known, non-routable IP address like 169.254.169.254. Accessing this service often reveals temporary IAM credentials, instance profiles, and other sensitive configuration data, leading to privilege escalation or data exfiltration within the cloud infrastructure.

Why this answer

The attack described is Server-Side Request Forgery (SSRF) because the attacker manipulates the web application into making HTTP requests to an internal resource—specifically the cloud instance metadata service at 169.254.169.254. This allows the attacker to retrieve IAM temporary credentials that are normally only accessible from within the instance. The key is that the server itself is tricked into performing the request, bypassing network restrictions.

Exam trap

CEH often tests the confusion between SSRF and XXE, where XXE can also lead to SSRF but requires an XML parser; the key differentiator is that SSRF directly abuses server-side request functionality without XML involvement.

How to eliminate wrong answers

Option B is wrong because XXE injection exploits XML parsers to read local files or perform SSRF, but the question explicitly states the vulnerability is in a web application that makes the server send requests to a metadata endpoint—this is classic SSRF, not necessarily involving XML. Option C is wrong because IDOR involves accessing objects by manipulating identifiers (e.g., user IDs) without authorization, not forcing the server to make requests to internal endpoints. Option D is wrong because CSRF tricks a victim's browser into making requests, not the server itself, and the target here is internal metadata, not cloud APIs.

742
Multi-Selecteasy

Which TWO of the following are common techniques used to cover tracks after compromising a system? (Choose TWO.)

Select 2 answers
A.Running a vulnerability scanner
B.Enabling firewall rules
C.Installing a rootkit
D.Creating new user accounts
E.Clearing event logs
AnswersC, E

Installing a rootkit is a highly effective technique for covering an attacker's tracks by providing stealthy, persistent access. Rootkits are designed to modify the operating system's core functions, either at the kernel or userland level, to conceal files, processes, network connections, and other malicious artifacts from legitimate system utilities and security software. This sophisticated level of hiding allows an attacker to maintain a covert presence, making detection extremely challenging for administrators and forensic analysts.

Why this answer

Installing a rootkit (Option C) is a common technique used to cover tracks because rootkits are designed to hide the attacker's presence by subverting the operating system's normal behavior, such as hiding processes, files, and registry keys from system utilities. Clearing event logs (Option E) directly removes forensic evidence of the attacker's activities, such as login attempts, privilege escalations, or file access, making it harder for incident responders to reconstruct the attack timeline.

Exam trap

In the CEH exam, candidates often mistakenly select creating new user accounts (Option D) as a track-covering technique when it is actually a persistence method that leaves obvious traces. Covering tracks focuses on hiding evidence of the attack, such as clearing logs or using rootkits to conceal malicious activity.

743
MCQhard

A security analyst observes that a server running an IoT device management platform is sending MQTT traffic to an unexpected IP address. The analyst also notes that the device's firmware contains hardcoded credentials. Which attack vector is MOST likely being exploited?

A.CoAP protocol attack
B.Insecure MQTT protocol exploitation via default credentials
C.Firmware reversing attack
D.Container escape attack
AnswerB

Insecure MQTT (Message Queuing Telemetry Transport) protocol exploitation via default credentials is a common and critical vulnerability in IoT deployments. Many MQTT brokers are configured with weak or absent authentication, or rely on easily guessable default usernames and passwords. An attacker exploiting these weaknesses can subscribe to all topics, publish malicious commands, exfiltrate sensitive data, and gain unauthorized control over connected IoT devices, directly aligning with active exploitation behavior.

Why this answer

The combination of hardcoded credentials and unexpected MQTT traffic suggests an attacker has used default credentials to compromise the device and is exfiltrating data via MQTT.

744
MCQeasy

A user receives an email claiming to be from their bank, asking them to click a link and verify their account credentials. The email contains spelling errors and the link points to a suspicious domain. What type of social engineering attack is this?

A.Vishing
B.Whaling
C.Spear phishing
D.Phishing
AnswerD

Phishing is a broad social engineering technique characterized by mass-distributed, generic fraudulent communications, typically via email, designed to trick recipients into revealing sensitive information like login credentials, credit card numbers, or installing malware. These attacks often impersonate well-known entities such as banks, social media platforms, or online services, using urgent or alarming language to prompt immediate action. The email described, claiming to be from a bank and likely seeking credentials from a general user, perfectly aligns with the characteristics of a classic phishing campaign.

Why this answer

This scenario describes a mass, unsolicited email with generic content and a suspicious link, which is the classic definition of phishing. Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information, such as credentials, by impersonating a trusted entity. The presence of spelling errors and a suspicious domain are common indicators of a phishing attempt, not a targeted attack.

Exam trap

The trap here is that candidates often confuse 'phishing' with 'spear phishing' because both involve email, but the key differentiator is the level of targeting—phishing is mass and generic, while spear phishing is personalized and researched.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) is conducted over voice calls or VoIP, not via email with a clickable link. Option B is wrong because whaling targets high-profile executives or senior management with highly personalized content, not a generic email to a random user. Option C is wrong because spear phishing is a targeted attack against a specific individual or organization using personalized details, whereas this email is generic and lacks personalization.

745
MCQhard

A security analyst observes the following Nmap output for a target host: PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https. The analyst then runs a version detection scan and notices that port 80 reports 'Apache httpd 2.4.41' but port 443 reports 'Apache httpd 2.4.41' as well. What is the MOST likely conclusion?

A.The target is running two separate web servers on different ports
B.The target is likely running a single web server that handles both HTTP and HTTPS traffic
C.The target is running a reverse proxy that forwards traffic to different backends
D.The version detection is incorrect due to false positives
AnswerB

This option represents the most common and standard configuration for a modern web server. A single instance of web server software, such as Apache or Nginx, is typically configured to listen on both port 80 for unencrypted HTTP traffic and port 443 for secure HTTPS communication. The Nmap output identifying the same server version on both ports directly supports this interpretation, as the server handles both protocols from a unified configuration.

Why this answer

When both port 80 (HTTP) and port 443 (HTTPS) report the same Apache httpd version (2.4.41), it strongly indicates that the same web server process is listening on both ports. Apache httpd can be configured to handle both plain HTTP and TLS-encrypted HTTPS traffic simultaneously, typically using separate VirtualHost directives or a single configuration that binds to both ports. The identical version string makes it unlikely that two separate web server instances are running, as they would often differ in patch level or configuration.

Exam trap

The trap here is that candidates assume different ports must mean different servers or a reverse proxy, but the CEH exam expects you to recognize that identical version strings from Nmap -sV indicate a single web server instance handling both protocols.

How to eliminate wrong answers

Option A is wrong because running two separate web servers on different ports would typically result in different version strings, build dates, or banner details; identical version output strongly suggests a single server instance. Option C is wrong because a reverse proxy (e.g., Nginx, HAProxy) would present its own banner on the listening ports, not the backend Apache version; the Nmap version detection directly queried the Apache service, not a proxy layer. Option D is wrong because Nmap version detection (-sV) uses probe-response matching against a signature database and is highly reliable for common services like Apache httpd; false positives are rare and would not produce identical version strings on two ports.

746
MCQhard

During a wireless penetration test, you discover that the target network uses WPA2-Enterprise with PEAP-MSCHAPv2. You capture the authentication traffic of a legitimate user. Which attack can you perform to recover the user's domain credentials?

A.Decrypt the traffic using the captured handshake to get the credentials.
B.WPS PIN brute-force to recover the PSK.
C.PMKID attack to crack the pre-shared key.
D.Set up a rogue RADIUS server to capture the challenge-response and perform an offline brute-force attack.
AnswerD

Setting up a rogue RADIUS server is a highly effective attack against WPA2-Enterprise networks. By impersonating the legitimate authentication server, the rogue RADIUS server can trick clients into authenticating against it. During this process, it captures the challenge-response hashes, such as NTLMv2 hashes from PEAP/MSCHAPv2, which are exchanged during the EAP authentication phase. These captured hashes can then be subjected to efficient offline dictionary or brute-force attacks to recover the actual user credentials, providing unauthorized access.

Why this answer

In WPA2-Enterprise with PEAP-MSCHAPv2, the authentication is based on a challenge-response mechanism between the client and a RADIUS server. By setting up a rogue RADIUS server, you can capture the challenge and the client's encrypted response, then perform an offline brute-force attack against the MSCHAPv2 hash to recover the user's domain credentials. This works because the MSCHAPv2 response is derived from the user's password and can be cracked offline.

Exam trap

The trap here is that candidates confuse WPA2-Enterprise with WPA2-Personal and incorrectly apply attacks like PMKID or handshake decryption, not realizing that enterprise mode relies on RADIUS-based authentication and is vulnerable to rogue server attacks rather than PSK cracking.

How to eliminate wrong answers

Option A is wrong because WPA2-Enterprise traffic is encrypted with per-session keys derived from the EAP exchange, and the captured handshake does not contain the user's credentials in a decryptable form; the handshake is used for key derivation, not for revealing plaintext credentials. Option B is wrong because WPS PIN brute-force targets WPA/WPA2-Personal networks using a PIN to recover the PSK, but WPA2-Enterprise does not use a pre-shared key or WPS, so this attack is irrelevant. Option C is wrong because the PMKID attack is used against WPA/WPA2-Personal networks to crack the PSK from the PMKID field in the beacon frame, but WPA2-Enterprise uses 802.1X authentication and does not have a PMKID derived from a PSK.

747
MCQhard

During a social engineering engagement, a tester calls the help desk posing as an employee from the IT department. The tester claims to be working on a critical system update and needs the employee's password to proceed. Which type of social engineering attack is being executed?

A.Quid pro quo
B.Baiting
C.Pretexting
D.Phishing
AnswerC

Pretexting is a highly targeted social engineering technique where an attacker creates a fabricated scenario or 'pretext' to manipulate a victim into divulging sensitive information or performing an action. This often involves extensive research to develop a believable false identity and backstory, making the attacker appear legitimate and authoritative during direct interactions like phone calls. The tester's action of calling with a false identity to extract information perfectly aligns with this method's characteristics.

Why this answer

Pretexting involves creating a fabricated scenario (pretext) to manipulate a target into divulging information. In this case, the tester falsely claims to be from the IT department working on a critical system update, which is a classic pretext to gain trust and obtain the employee's password. This differs from other social engineering types because it relies on a constructed identity and false narrative rather than a technical lure or direct exchange.

Exam trap

The trap here is that candidates confuse pretexting with phishing because both involve deception, but phishing specifically refers to electronic communication (email, SMS) while pretexting can occur over the phone or in person, and the CEH exam tests this distinction by presenting a phone call scenario without any digital lure.

How to eliminate wrong answers

Option A is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), not simply claiming a false identity. Option B is wrong because baiting uses a physical or digital lure (e.g., infected USB drive or free download) to entice the victim, not a fabricated story. Option D is wrong because phishing is a mass-deceptive technique using electronic communication (e.g., email, SMS) to trick victims into clicking malicious links or providing credentials, not a direct phone call with a crafted pretext.

748
MCQmedium

A web application tester notices that the application reflects user input in the URL without proper encoding. The tester submits a payload <script>alert('xss')</script> in a search field and the script executes in the browser. Which type of XSS vulnerability is this MOST likely?

A.Blind XSS
B.Reflected XSS
C.Stored (persistent) XSS
D.DOM-based XSS
AnswerB

Reflected XSS occurs when a malicious script injected into an HTTP request is immediately returned in the server's HTTP response without being permanently stored. The payload is non-persistent, executing only once in the victim's browser as part of that specific request and response cycle. The observation that the application 'reflects' the input directly aligns with this immediate, one-time execution characteristic, making it the correct answer.

Why this answer

Option B is correct because reflected XSS occurs when user input is immediately returned by the web server in the response without proper encoding, causing the script to execute in the victim's browser. The scenario describes a search field where the payload is reflected in the URL and executes, which is classic reflected XSS.

Exam trap

CEH often tests the confusion between reflected and DOM-based XSS; candidates may pick DOM-based because the payload is in the URL, but the key differentiator is whether the server reflects the input (reflected) or the client-side script processes it (DOM-based).

How to eliminate wrong answers

Option A is wrong because blind XSS occurs when the payload is stored and executed later in a different context, often in an admin panel, and the attacker does not see immediate results. Option C is wrong because stored XSS involves the payload being persisted on the server (e.g., in a database) and served to other users, not immediately reflected. Option D is wrong because DOM-based XSS occurs entirely on the client side when JavaScript modifies the DOM using untrusted input, without server involvement; here the input is reflected by the server.

749
Drag & Dropmedium

Drag and drop the steps to perform a buffer overflow exploit in a controlled lab environment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Identify vulnerability, find offset, generate shellcode, craft exploit, execute.

750
Multi-Selecthard

A penetration tester is assessing the security of a smart building's IoT infrastructure. The building uses Zigbee sensors for temperature and motion detection, and some devices communicate using MQTT over Wi-Fi. During the assessment, the tester captures traffic and notices that some Zigbee devices are sending unencrypted frames containing sensor IDs and values. Which TWO actions should the tester recommend to mitigate the identified vulnerabilities? (Choose two.)

Select 2 answers
A.Enable Zigbee security suite (AES-128 encryption) on all sensor devices.
B.Configure MQTT to use TLS 1.2 with mutual authentication between brokers and clients.
C.Disable encryption on MQTT to reduce latency and improve performance.
D.Implement device authentication using pre-shared keys only for Zigbee devices.
E.Segment the IoT devices into a separate VLAN and restrict access with ACLs.
AnswersA, B

This option directly addresses data confidentiality for Zigbee communications within the smart building. The Zigbee security suite, specifically utilizing AES-128 symmetric encryption, encrypts data packets exchanged between sensor devices and the coordinator. This prevents unauthorized eavesdropping and ensures the privacy of sensitive sensor readings, which is crucial for maintaining the security and integrity of the smart building's operational data.

Why this answer

Zigbee's security suite uses AES-128 encryption to protect over-the-air frames, preventing eavesdropping on sensor IDs and values. Enabling this suite ensures that captured unencrypted frames are no longer readable, directly mitigating the observed vulnerability. Option B is correct because MQTT over Wi-Fi without TLS exposes all communication in plaintext; configuring TLS 1.2 with mutual authentication encrypts the payload and verifies both broker and client identities, preventing man-in-the-middle attacks.

Exam trap

The trap here is that candidates often confuse network segmentation (VLANs) with data encryption, thinking that isolating IoT devices on a separate VLAN alone protects the confidentiality of unencrypted wireless frames.

Page 9

Page 10 of 13

Page 11