Courseiva

Certified Ethical Hacker CEH (CEH) — Questions 751–825

913 questions total · 13pages · All types, answers revealed

Page 10

Page 11 of 13

Page 12
751
MCQhard

An IoT device uses the MQTT protocol without any authentication or encryption. An attacker on the same network subscribes to all topics on the MQTT broker. Which of the following is the MOST effective immediate countermeasure?

A.Disable the MQTT broker entirely and switch to HTTP
B.Implement client authentication and enable TLS encryption
C.Change the default topic names to obfuscated strings
D.Use a VPN for all IoT device communication
AnswerB

Implementing client authentication ensures that only authorized IoT devices can connect to the MQTT broker, preventing unauthorized actors from publishing or subscribing to sensitive data streams. Concurrently, enabling TLS encryption secures the communication channel itself, protecting all data transmitted between devices and the broker from eavesdropping, tampering, and man-in-the-middle attacks. This combination establishes robust confidentiality, integrity, and access control for MQTT communications, directly addressing the core security vulnerabilities.

Why this answer

The vulnerability is that the MQTT broker accepts connections from anyone (no authentication) and transmits data in cleartext (no encryption), allowing an attacker to subscribe to all topics. Implementing client authentication (username/password or client certificates) prevents unauthorized subscriptions, while enabling TLS encrypts the payload and credentials in transit. Together these directly close the two gaps that let the attacker eavesdrop.

Exam trap

CEH often tests the misconception that changing default topic names or using a VPN is sufficient to secure MQTT, when the core issue is missing authentication and encryption at the protocol level.

How to eliminate wrong answers

Option A is wrong because replacing MQTT with HTTP does not inherently add authentication or encryption and abandons a purpose-built IoT protocol without addressing the root cause. Option C is wrong because obfuscating topic names is security through obscurity; an attacker who can subscribe to all topics will still see the obfuscated names and their contents. Option D is wrong because a VPN only encrypts traffic between endpoints and does not authenticate MQTT clients to the broker, so an attacker already on the same network segment could still subscribe.

752
MCQmedium

A penetration tester executes the following command: nmap -sS -p 1-1000 --script banner 192.168.1.10. After the scan, the tester notices several filtered ports. Which of the following BEST explains why Nmap reports a port as "filtered"?

A.The port is open, and the service is responding with a banner
B.A firewall is blocking the probe packets, and Nmap cannot determine if the port is open
C.The port is open and actively listening
D.The port is closed and the target sent an RST packet
AnswerB

Filtered means no response reached Nmap, typically because a firewall dropped the probe packets silently. With the TCP SYN scan (-sS), an open port returns SYN/ACK and a closed port returns RST; absence of either leaves the state indeterminate, so Nmap cannot confirm whether the port is open or closed.

Why this answer

Nmap's SYN scan (-sS) sends a SYN packet to the target port. When the probe receives no response or an ICMP unreachable message (e.g., type 3 code 13), Nmap classifies the port as 'filtered'. This typically indicates a firewall, ACL, or network filter is dropping the packets, preventing Nmap from determining whether the port is open or closed.

Exam trap

The trap here is that candidates often confuse 'filtered' with 'closed', but 'closed' requires an RST response, while 'filtered' indicates no response or an ICMP block, typically due to a firewall.

How to eliminate wrong answers

Option A is wrong because a port that responds with a banner would be classified as 'open', not 'filtered'. Option C is wrong because an open and actively listening port would respond with a SYN-ACK, leading Nmap to report it as 'open', not 'filtered'. Option D is wrong because a closed port sends an RST packet in response to the SYN probe, which Nmap interprets as 'closed', not 'filtered'.

753
MCQmedium

A web application is vulnerable to server-side request forgery (SSRF). An attacker sends a request that causes the server to make an internal HTTP request to http://169.254.169.254/latest/meta-data/. What is the attacker attempting to achieve?

A.Exploit a command injection vulnerability in the web server
B.Access the cloud instance metadata to obtain temporary credentials
C.Perform a denial-of-service attack on the internal network
D.Perform a port scan on the internal network
AnswerB

This is the most common and impactful exploitation path for SSRF when targeting cloud environments. Cloud providers like AWS, GCP, and Azure expose local metadata services (e.g., http://169.254.169.254 for AWS EC2) that provide critical information about the running instance, including temporary security credentials (IAM roles), network configuration, and user data. By leveraging SSRF to access these endpoints, an attacker can obtain sensitive credentials, potentially escalating privileges and gaining access to other cloud resources.

Why this answer

The IP address 169.254.169.254 is the link-local address used by AWS EC2 Instance Metadata Service (IMDS). When an SSRF vulnerability forces the server to request this URL, the attacker is attempting to retrieve instance metadata, which can include IAM role temporary credentials, instance identity documents, and user data. These credentials can then be used to pivot into the AWS account.

Exam trap

CEH often tests the specific IP 169.254.169.254 as the cloud metadata endpoint; candidates who do not recognize it may incorrectly assume the attacker is performing a port scan or DoS instead of credential theft.

How to eliminate wrong answers

Option A is wrong because SSRF does not execute OS commands; command injection requires unsanitized input passed to a shell, which is a different vulnerability class. Option C is wrong because a single metadata request does not generate enough traffic to cause a denial-of-service; SSRF is used for data exfiltration or pivoting, not volumetric attacks. Option D is wrong because port scanning requires the attacker to control the target host and port across many requests; the metadata endpoint is a single known service, not a scanning target.

754
MCQmedium

During an internal penetration test, an analyst uses `enum4linux -a 10.0.0.5` and retrieves a list of local users, including an account named 'sqlsvc'. The analyst then attempts to crack the password using a dictionary attack. Which password cracking tool would be most efficient for this task?

A.RainbowCrack
B.SNMPwalk
C.John the Ripper
D.Ophcrack
AnswerC

John the Ripper is a robust, open-source password cracking utility widely recognized for its versatility in performing dictionary attacks against a multitude of hash types. It can efficiently process password hashes, including NTLM and LM hashes commonly found in Windows environments and potentially extracted or identified through SMB enumeration tools like enum4linux. Its extensive wordlist support and customizable rules make it an ideal choice for attempting to crack enumerated user passwords via dictionary attack.

Why this answer

John the Ripper is the most efficient tool for performing a dictionary attack against password hashes retrieved from a system, such as those obtained from the SAM database or via enum4linux. It supports a wide range of hash types and can be configured to use custom wordlists, making it ideal for cracking the 'sqlsvc' account password in an internal penetration test.

Exam trap

EC-Council often tests the distinction between dictionary attacks and rainbow table attacks, leading candidates to choose RainbowCrack or Ophcrack when the question explicitly specifies a dictionary attack method.

How to eliminate wrong answers

Option A is wrong because RainbowCrack uses precomputed rainbow tables for time-memory trade-off attacks, not dictionary attacks; it is inefficient for targeted cracking of a single account without a matching table. Option B is wrong because SNMPwalk is a tool for querying SNMP-enabled devices to enumerate MIB values, not a password cracking tool. Option D is wrong because Ophcrack specializes in cracking Windows LM and NTLM hashes using rainbow tables, not general dictionary attacks, and requires specific table sets.

755
MCQmedium

During a penetration test, an ethical hacker finds that a web application transmits sensitive data in plaintext over HTTPS. Which of the following best describes this security issue?

A.Weak TLS cipher suite
B.Lack of application-layer encryption
C.SSL stripping attack
D.Man-in-the-middle attack
AnswerB

This is the correct answer because while HTTPS encrypts data in transit between the client and server, it does not inherently encrypt data at the application layer before it is sent or when it is stored. If sensitive fields are not encrypted by the application itself, they could be exposed in memory, logs, or databases on the server side, even if the network communication is secure. The application's failure to encrypt sensitive data before processing or storage creates a vulnerability independent of transport security.

Why this answer

The core issue is that the web application transmits sensitive data in plaintext over HTTPS, meaning the data is encrypted in transit by TLS but not encrypted at the application layer. This leaves the data vulnerable to exposure if the TLS termination point (e.g., a reverse proxy or load balancer) is compromised or if logs capture the plaintext payload. Application-layer encryption (e.g., encrypting the data before sending it over HTTPS) ensures end-to-end confidentiality, even if the TLS channel is broken or inspected.

Exam trap

The trap here is that candidates confuse 'encrypted in transit' (TLS) with 'encrypted at the application layer,' assuming HTTPS alone provides end-to-end data confidentiality, but the CEH exam tests the distinction between transport-layer and application-layer encryption.

How to eliminate wrong answers

Option A is wrong because a weak TLS cipher suite refers to the use of outdated or insecure cryptographic algorithms (e.g., RC4, DES) for the TLS handshake, which is not the issue here—the data is transmitted over HTTPS with presumably strong TLS, but the application itself does not encrypt the payload. Option C is wrong because an SSL stripping attack is a man-in-the-middle technique that downgrades HTTPS to HTTP, which is not described in the scenario; the question states the data is transmitted over HTTPS, not that the protocol is downgraded. Option D is wrong because a man-in-the-middle attack is an active interception technique (e.g., ARP spoofing, rogue access point) that could capture plaintext data, but the security issue described is the lack of application-layer encryption, not the presence of an active attack.

756
MCQeasy

Which of the following tools is specifically designed to perform Google dorking and automate searching for vulnerable web applications and sensitive information?

A.Maltego
B.theHarvester
C.Googledork
D.Shodan
AnswerC

Googledork is a specialized utility explicitly engineered to automate the process of Google Hacking, commonly known as Google Dorking. This tool systematically generates and executes advanced search queries (dorks) against the Google search engine, leveraging specific operators like site:, filetype:, intitle:, and inurl: to discover exposed sensitive files, misconfigured servers, login pages, and other vulnerable information indexed by Google. Its core function is to streamline the identification of security weaknesses through targeted search engine exploitation, making it the correct answer.

Why this answer

Googledork (also known as Google Dork) is a tool specifically designed to automate Google dorking queries, which use advanced search operators to find vulnerable web applications and sensitive information exposed in search results. It systematically executes predefined dork queries against Google's index to identify SQL injection points, exposed configuration files, login pages, and other security weaknesses, making it the correct choice for this task.

Exam trap

The trap here is that candidates often confuse general OSINT tools like theHarvester or Maltego with Google-dorking-specific automation, failing to recognize that Googledork is the only option explicitly built for executing and automating Google dork queries.

How to eliminate wrong answers

Option A is wrong because Maltego is a graphical link analysis tool used for open-source intelligence (OSINT) and relationship mapping between entities (e.g., domains, email addresses, people), not for automating Google dorking queries. Option B is wrong because theHarvester is a tool for gathering email addresses, subdomains, and virtual hosts from public sources like search engines and PGP key servers, but it does not focus on executing Google dork queries to find vulnerable web applications. Option D is wrong because Shodan is a search engine for internet-connected devices (e.g., IoT, servers, webcams) and their banners, not a tool for performing Google dorking against Google's search index.

757
MCQmedium

During a penetration test, the tester needs to identify the operating system of a remote host without sending any packets to it. Which technique should the tester use?

A.Banner grabbing with Telnet
B.Passive OS fingerprinting using captured packets
C.Querying Shodan for the target IP
D.Active OS fingerprinting with Nmap -O
AnswerB

Passive OS fingerprinting analyzes network traffic that has already been captured or is passively observed, without sending any new packets to the target. Tools like p0f examine characteristics within TCP/IP headers, such as initial Time-To-Live (TTL) values, window sizes, Don't Fragment (DF) bit settings, and TCP options, to infer the operating system. This method is highly stealthy as it leaves no trace on the target system, making it ideal for undetected reconnaissance.

Why this answer

Passive OS fingerprinting (Option B) is correct because it analyzes captured network traffic—such as TCP/IP packet headers, TTL values, window sizes, and DF flags—to infer the remote host's operating system without sending any packets. This technique relies on subtle differences in how various OS stacks implement RFC 793, making it ideal for stealthy reconnaissance where no direct contact with the target is permitted.

Exam trap

The trap here is that candidates often confuse 'passive OS fingerprinting' with 'banner grabbing' or 'Shodan queries,' assuming any non-intrusive method qualifies, but the key constraint is 'without sending any packets,' which eliminates all options except passive analysis of already-captured traffic.

How to eliminate wrong answers

Option A is wrong because banner grabbing with Telnet requires establishing an active TCP connection to the target, which sends packets and violates the 'no packets sent' constraint. Option C is wrong because querying Shodan is a passive information-gathering method that uses a third-party database, but it does not directly identify the OS of a remote host from the tester's own captured traffic; Shodan may provide OS guesses based on its own active scans, but the question specifies the tester must not send packets, and Shodan's data is not derived from the tester's capture. Option D is wrong because active OS fingerprinting with Nmap -O sends crafted probes (e.g., SYN, FIN, NULL scans) to the target and analyzes responses, which directly contradicts the requirement of not sending any packets.

758
Multi-Selecteasy

Which TWO of the following are types of malware analysis? (Select 2)

Select 2 answers
A.Penetration testing
B.Static analysis
C.Dynamic analysis
D.Network analysis
E.Code review
AnswersB, C

Static analysis involves examining malware without executing it, focusing on its internal structure and potential functionality. This method includes disassembling the executable, analyzing strings, inspecting header information, and reviewing embedded resources to infer the malware's capabilities, target APIs, and potential network indicators. It provides insights into the code logic and design before dynamic execution.

Why this answer

Static analysis examines malware without executing it, focusing on file structure, strings, and code signatures to identify malicious indicators. Dynamic analysis runs the malware in a controlled sandbox environment to observe runtime behavior, such as registry changes, network connections, and process injections. Both are fundamental malware analysis methodologies recognized by the CEH exam.

Exam trap

The CEH exam often tests the distinction between malware analysis types and other security activities like penetration testing or code review, tricking candidates who confuse 'analyzing malware' with 'testing for vulnerabilities' or 'reviewing source code.'

759
Multi-Selectmedium

Which TWO of the following are common indicators of a DNS spoofing attack? (Select 2)

Select 2 answers
A.High volume of DNS queries from a single source
B.ARP cache entries show unexpected MAC-IP mappings
C.The switch's CAM table is full
D.The resolved IP address for a domain does not match the legitimate server
E.Users are redirected to a malicious website despite typing the correct URL
AnswersD, E

When the IP address returned by a DNS query for a specific domain name differs from the legitimate server's actual IP, it is a primary indicator of DNS spoofing. An attacker has successfully intercepted or poisoned the DNS resolution process, substituting the correct IP with a malicious one. This manipulation ensures that subsequent client connections intended for the legitimate domain are instead directed to the attacker-controlled host.

Why this answer

DNS spoofing (cache poisoning) involves an attacker injecting forged DNS records into a resolver's cache. When a user's system queries a domain, the resolver returns the attacker-controlled IP address instead of the legitimate server's IP, causing traffic to be misdirected.

Exam trap

The trap here is confusing DNS spoofing with ARP spoofing or other network-layer attacks, as candidates may incorrectly associate unexpected MAC-IP mappings (Option B) with DNS manipulation rather than recognizing it as a distinct Layer 2 attack.

760
MCQmedium

Which of the following describes a Server-Side Request Forgery (SSRF) attack?

A.An attacker tricks a user into clicking a link that executes unwanted actions on a web application where the user is authenticated.
B.An attacker injects malicious scripts into a web page that executes in other users' browsers.
C.An attacker forces the web server to make HTTP requests to arbitrary destinations, potentially accessing internal resources.
D.An attacker manipulates input to execute system commands on the server.
AnswerC

This precisely defines Server-Side Request Forgery (SSRF), a vulnerability where a web application is tricked into making HTTP requests to an attacker-specified location. The server, acting on behalf of the attacker, can then access internal network resources, metadata services, or other systems that are typically inaccessible from the external internet. This allows for internal network reconnaissance, port scanning, and potential data exfiltration by bypassing firewall restrictions.

Why this answer

SSRF occurs when an attacker manipulates a server-side application into making HTTP requests to attacker-chosen destinations. Because the request originates from the server, it can reach internal-only resources (metadata endpoints, internal APIs, databases) that the attacker cannot access directly.

Exam trap

CEH often tests the confusion between SSRF, CSRF, and XSS — candidates see 'server makes requests' and pick CSRF because both involve the server, missing that CSRF abuses a victim's session while SSRF abuses the server's network position.

How to eliminate wrong answers

Option A is wrong because it describes Cross-Site Request Forgery (CSRF), where a victim's authenticated session is abused to perform actions. Option B is wrong because it describes Cross-Site Scripting (XSS), where malicious scripts execute in other users' browsers. Option D is wrong because it describes command injection, where user input is passed to a system shell — a different vulnerability class entirely.

761
MCQmedium

A penetration tester uses Burp Suite Repeater to manually modify and resend HTTP requests to a web server. In which phase of the testing methodology is this tool most commonly employed?

A.Reconnaissance
B.Reporting
C.Exploitation
D.Scanning and enumeration
AnswerC

Exploitation involves leveraging identified vulnerabilities to achieve a specific objective, such as gaining unauthorized access, escalating privileges, or exfiltrating sensitive data. Burp Suite Repeater is an indispensable tool for this phase, allowing testers to meticulously modify request parameters, headers, or body content with crafted payloads. This precision enables the confirmation and exploitation of vulnerabilities like SQL injection, cross-site scripting, or authentication bypasses by observing the server's direct, often vulnerable, responses.

Why this answer

Burp Suite Repeater is used to manually craft and reissue requests, typically during the exploitation phase after identifying potential vulnerabilities. It allows testing parameter manipulation, injection payloads, and observing responses.

762
MCQmedium

A web application allows users to upload profile images. An attacker uploads a file named 'image.php.png' with malicious PHP code, and the server executes it as PHP. Which type of vulnerability is this?

A.Directory traversal
B.Command injection
C.SQL injection
D.Unrestricted file upload
AnswerD

Unrestricted file upload is the correct answer because it directly describes the vulnerability where a web application allows users to upload files without adequately validating their type, size, or content. This critical flaw enables an attacker to upload malicious files, such as web shells or scripts, to the server. Once uploaded, these files can often be executed by the web server, leading to severe consequences like remote code execution, server compromise, or defacement.

Why this answer

The vulnerability is unrestricted file upload because the application allows an attacker to upload a file with a double extension ('image.php.png') that the server executes as PHP. This occurs when the server does not properly validate file types, extensions, or content, allowing executable code to be uploaded and run. The double extension tricks the server into treating the file as an image while the PHP interpreter executes it.

Exam trap

CEH often tests the distinction between file upload and other injection vulnerabilities — candidates may confuse the double extension trick with directory traversal or command injection.

How to eliminate wrong answers

Option A is wrong because directory traversal involves accessing files outside the intended directory using sequences like '../', which is not described here. Option B is wrong because command injection involves executing arbitrary OS commands through vulnerable input fields, not uploading a file. Option C is wrong because SQL injection involves manipulating SQL queries through input, which is unrelated to file upload functionality.

763
MCQmedium

An incident responder finds that the Windows Event Logs on a compromised server have been cleared, and the Security log shows gaps in coverage. Additionally, a rootkit is suspected. Which phase of the hacking methodology does the clearing of logs represent?

A.Privilege escalation
B.Cracking passwords
C.Erasing tracks
D.Executing applications
AnswerC

Erasing tracks, also known as covering tracks or anti-forensics, is a post-exploitation phase where an attacker attempts to remove or alter evidence of their presence and activities on a compromised system. Clearing Windows event logs is a quintessential example of this technique, as it directly eliminates critical forensic data that incident responders rely on to understand the attack timeline, methods, and scope. This action aims to hinder detection and attribution, making it significantly harder for security teams to reconstruct the incident.

Why this answer

Clearing Windows Event Logs and creating gaps in the Security log is a classic post-exploitation step to remove forensic evidence of the attacker's actions. In the CEH hacking methodology, this falls under 'Erasing tracks' (also known as covering tracks), which is the final phase after maintaining access. The rootkit suspicion further supports this, as rootkits often include log-wiping or log-modification capabilities to hide their presence.

Exam trap

The trap here is that candidates confuse 'Erasing tracks' with 'Privilege escalation' because clearing logs often requires administrative privileges, but the phase is defined by the intent to hide evidence, not the permission level used.

How to eliminate wrong answers

Option A is wrong because privilege escalation is the phase where an attacker gains higher-level permissions (e.g., from user to administrator), not the act of removing logs. Option B is wrong because cracking passwords is a technique used during the 'Gaining Access' phase to obtain credentials, not a phase for hiding evidence. Option D is wrong because executing applications is a generic action that can occur in multiple phases (e.g., exploitation or maintaining access), but it does not specifically describe the act of clearing logs to avoid detection.

764
MCQeasy

An attacker sends an email to the CEO of a company, pretending to be a board member and requesting a wire transfer for a confidential acquisition. Which social engineering attack is this?

A.Whaling
B.Vishing
C.Spear phishing
D.Phishing
AnswerA

Whaling is a highly sophisticated form of phishing specifically designed to target high-profile individuals within an organization, such as CEOs, CFOs, or other senior executives. Attackers meticulously craft personalized emails, often impersonating a trusted entity or a critical business contact, to trick these high-value targets into divulging sensitive information or authorizing fraudulent transactions. The objective is typically significant financial gain or access to critical corporate data, leveraging the executive's authority and access.

Why this answer

Whaling is a targeted social engineering attack that specifically goes after high-profile individuals like C-suite executives or board members. In this scenario, the attacker impersonates a board member to trick the CEO into authorizing a wire transfer, which is a classic whaling tactic because it exploits the authority and trust associated with senior leadership.

Exam trap

The trap here is that candidates confuse whaling with spear phishing, but the CEH exam distinguishes whaling as a specific subtype targeting executives, while spear phishing is broader and can target any individual or role.

How to eliminate wrong answers

Option B (Vishing) is wrong because vishing is a voice-based phishing attack conducted over phone calls or VoIP, not via email. Option C (Spear phishing) is wrong because while spear phishing is targeted, it typically targets mid-level employees or specific groups, not exclusively high-ranking executives like a CEO; whaling is a subset of spear phishing focused on senior management. Option D (Phishing) is wrong because phishing is a broad, mass-email attack sent to many recipients, lacking the personalized targeting of a specific high-value individual like a CEO.

765
MCQhard

A security analyst runs the command: nmap -sS -p 80,443,8080 --script http-headers scanme.nmap.org. The output shows that port 80 is filtered. What does 'filtered' mean in this context?

A.The port is open, but the service is not responding
B.The port is open and actively listening
C.The port is closed, but the target is responding with RST packets
D.A firewall or IDS is preventing the probe from reaching the port
AnswerD

The 'filtered' state in an Nmap SYN scan is a critical indicator that the probe packet sent by Nmap did not receive any response from the target host. This typically occurs when a network filtering device, such as a firewall, an Intrusion Detection System (IDS), or an access control list (ACL) on a router, intercepts and drops the SYN packet. Consequently, Nmap cannot determine if the port is open or closed because the communication path is obstructed.

Why this answer

In Nmap, a 'filtered' port status indicates that the port is being blocked by a firewall, IDS, or other network filtering device, preventing the probe from reaching the target service. The -sS (SYN stealth scan) sends a SYN packet; if no response is received or an ICMP unreachable (type 3, code 13) is returned, Nmap marks the port as filtered. This does not mean the port is open or closed—it means the scan could not determine the state due to filtering.

Exam trap

The trap here is that candidates confuse 'filtered' with 'closed' or 'open|filtered', forgetting that 'filtered' specifically indicates a firewall or IDS is interfering, not that the port is simply unresponsive or sending RSTs.

How to eliminate wrong answers

Option A is wrong because 'filtered' does not imply the port is open; an open port that is not responding would typically be marked as 'open|filtered' if no response is received, not simply 'filtered'. Option B is wrong because an open and actively listening port would be reported as 'open' by Nmap after receiving a SYN/ACK response, not 'filtered'. Option C is wrong because a closed port responds with RST packets, which Nmap reports as 'closed', not 'filtered'; 'filtered' specifically means the probe was dropped or blocked without a TCP-level response.

766
Multi-Selectmedium

Which TWO of the following Nmap flags can be used to bypass firewall restrictions? (Select 2)

Select 2 answers
A.-P0 (disable ping)
B.-f (fragment packets)
C.-T4 (aggressive timing)
D.-sS (SYN scan)
E.-D (decoy scan)
AnswersB, E

The -f flag enables packet fragmentation, splitting the TCP header across multiple small IP packets. This technique can bypass older or less sophisticated stateless firewalls and intrusion detection systems (IDS) that are not configured to reassemble fragmented packets before inspection. By breaking the packet into smaller, non-contiguous pieces, the firewall might only see incomplete headers or data, allowing the full packet to pass through undetected and reassemble at the target.

Why this answer

The -f flag fragments packets into smaller 8-byte chunks, which can evade simple firewall rules that inspect packet headers for known signatures or block oversized packets. Option E is correct because the -D flag performs a decoy scan by spoofing multiple source IP addresses, making it difficult for a firewall to identify the true scanning host and block it.

Exam trap

The trap here is that candidates often confuse stealth scanning (-sS) with firewall evasion, not realizing that SYN scans are still detectable by modern firewalls that track connection states, while fragmentation and decoys directly manipulate packet structure or source identity to bypass filters.

767
MCQhard

A penetration tester is assessing an AWS environment and discovers an S3 bucket with the following bucket policy: `{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":"*","Action":"s3:GetObject","Resource":"arn:aws:s3:::example-bucket/*"}]}`. Which of the following is the MOST likely security issue?

A.The bucket policy allows public read access to all objects
B.The bucket policy allows only GetObject, which is too restrictive
C.The bucket policy should use a Principal of AWS instead of *
D.The bucket policy is missing a Deny statement for write operations
AnswerA

The bucket policy explicitly grants `s3:GetObject` permission to `Principal: "*"`, which signifies anonymous public access. This configuration allows any user on the internet, without authentication, to retrieve all objects stored within the S3 bucket. Such unrestricted read access poses a significant security risk, potentially exposing sensitive data to unauthorized parties and violating data privacy regulations.

Why this answer

The policy allows anyone (Principal: *) to read any object in the bucket, making it publicly accessible and a common misconfiguration.

768
MCQhard

You are the security lead for a multinational corporation that uses a hybrid cloud architecture with AWS and on-premises data centers. The company recently deployed a fleet of IoT sensors in a remote factory to monitor equipment. These sensors communicate via MQTT to an AWS IoT Core endpoint, which forwards data to an S3 bucket and a DynamoDB table. The factory network is isolated but has a site-to-site VPN to the corporate HQ. Over the past week, the S3 bucket has experienced an unusual number of PUT requests from an IP address that resolves to a known malicious host. The DynamoDB table shows write spikes at odd hours. The MQTT broker logs indicate that some sensors are publishing data with invalid client IDs. Meanwhile, the VPN logs show no anomalies. You need to identify the likely attack vector and recommend a course of action. Which of the following is the BEST course of action?

A.Disable the site-to-site VPN and require all traffic to go through a bastion host.
B.Implement client certificate authentication on AWS IoT Core and revoke any unregistered client IDs.
C.Move the S3 bucket and DynamoDB table to the on-premises data center to reduce cloud exposure.
D.Replace all IoT sensors with new ones that have firmware-level encryption.
AnswerB

Implementing client certificate authentication on AWS IoT Core mandates that all devices present a valid, trusted X.509 certificate to establish a secure, authenticated connection before publishing data. This cryptographic identity verification prevents unauthorized entities from injecting malicious PUT requests by ensuring only provisioned and registered sensors can interact with the platform. Revoking any unregistered client IDs further tightens security by invalidating any potential rogue or compromised credentials.

Why this answer

The attack exploits weak authentication on MQTT connections to AWS IoT Core. By implementing client certificate authentication, you ensure only registered devices with valid X.509 certificates can publish data, directly blocking the malicious PUT requests and write spikes. Revoking unregistered client IDs eliminates the invalid client IDs observed in the MQTT broker logs, closing the primary attack vector without disrupting legitimate sensor traffic.

Exam trap

The trap here is that candidates focus on network-level controls (VPN, bastion hosts) or data relocation, missing that the attack exploits weak IoT device authentication at the application layer, which requires identity-based controls like client certificates.

How to eliminate wrong answers

Option A is wrong because disabling the site-to-site VPN would break legitimate corporate connectivity and does not address the MQTT-based attack; the VPN logs show no anomalies, indicating the attack is not traversing the VPN. Option C is wrong because moving S3 and DynamoDB on-premises defeats the purpose of a hybrid cloud architecture and does not fix the root cause—weak IoT device authentication—while increasing latency and operational complexity. Option D is wrong because replacing all sensors with firmware-level encryption is costly, time-consuming, and does not solve the immediate authentication gap; encryption protects data in transit but does not prevent unauthorized devices from connecting to the MQTT broker.

769
Multi-Selecthard

Which of the following Nmap scan types is MOST effective for evading a stateful firewall that only allows established connections? (Select one)

Select 1 answer
A.TCP SYN scan (-sS)
B.TCP connect scan (-sT)
C.Idle scan (-sI)
D.Ping sweep (-sn)
E.UDP scan (-sU)
AnswersC

An idle scan (-sI) is highly effective for evading stateful firewalls because the attacker never directly sends packets to the target. Instead, it leverages a "zombie" host's IP ID sequence to infer open ports on the target. The target's firewall sees packets originating from the trusted zombie, which may already have legitimate traffic flowing, or simply doesn't see unsolicited probes from an unknown source. This indirect method allows the attacker to map the target's ports without revealing their own IP address, making detection and blocking by stateful firewalls significantly more challenging.

Why this answer

An idle scan (-sI) is effective against a stateful firewall that only allows established connections because it spoofs the source IP of a zombie host that already has an established session with the target. The firewall sees the packets as belonging to that existing session and allows them. A TCP SYN scan (-sS) sends unsolicited SYN packets that are not part of any existing session, so the stateful firewall would block them because it only permits traffic for established connections.

Exam trap

Candidates often mistakenly think that a SYN scan is stealthy, but against a stateful firewall that only allows established connections, unsolicited SYN packets are blocked. The idle scan is the key technique that exploits existing sessions to evade such firewalls.

770
Multi-Selecthard

Which THREE of the following are legitimate uses of the Shodan search engine in a security assessment? (Select 3)

Select 3 answers
A.Performing SQL injection on a web application
B.Discovering internet-connected industrial control systems (ICS) with default passwords
C.Mapping all SSL/TLS certificates for a domain to find subdomains
D.Sending phishing emails to employees of a target organization
E.Identifying open ports and services on all hosts in a given IP range
AnswersB, C, E

Shodan excels at identifying internet-facing industrial control systems (ICS) by indexing their unique banners, open ports, and service metadata, such as those associated with Modbus, Siemens S7, or Tridium Niagara protocols. While Shodan itself does not test for default passwords, its detailed service information often reveals specific device models, firmware versions, or web interfaces. This context allows security researchers to infer or attempt commonly known default credentials, facilitating the discovery of vulnerable ICS devices.

Why this answer

Option B is correct because Shodan indexes internet-facing devices and exposes banners and metadata for ICS/SCADA systems (e.g., Modbus, Siemens, BACnet), allowing an assessor to identify exposed industrial control systems that may still use default credentials. Option C is correct because Shodan indexes SSL/TLS certificate data, including subject CN and SAN fields, so querying by certificate or domain reveals related subdomains and hostnames tied to a target's certificates. Option E is correct because Shodan continuously scans the internet and stores port/banner data, so an assessor can query an IP range (e.g., net:192.168.0.0/16) to enumerate open ports and running services without directly scanning the hosts.

Option A is not a Shodan use because Shodan is a passive search engine for internet-connected device banners and does not perform active SQL injection attacks against web applications. Option D is not a Shodan use because Shodan does not send phishing emails; that is a social-engineering activity unrelated to its search/indexing capabilities.

Exam trap

The trap here is that candidates confuse Shodan's passive banner-gathering capability with active exploitation or social engineering, leading them to select options that involve direct interaction with the target (SQL injection or phishing) instead of legitimate reconnaissance.

771
Multi-Selecthard

Which TWO of the following are features of a Remote Access Trojan (RAT)?

Select 2 answers
A.It encrypts files and demands ransom
B.It infects the Master Boot Record
C.It replicates itself across the network autonomously
D.It often includes a backdoor to bypass authentication
E.It provides the attacker with remote control over the infected system
AnswersD, E

A fundamental feature of many Remote Access Trojans (RATs) is the establishment of a backdoor. This backdoor provides a covert method for the attacker to regain access to the compromised system, often bypassing standard authentication mechanisms like usernames and passwords. This ensures persistent control, even if the initial exploit vector is patched or the user changes credentials, facilitating long-term surveillance or data exfiltration.

Why this answer

A Remote Access Trojan (RAT) is designed to provide an attacker with covert remote control over an infected system, often including a backdoor to bypass standard authentication mechanisms. This allows the attacker to execute commands, exfiltrate data, or use the system as a pivot point, which directly aligns with options D and E.

Exam trap

The trap here is that candidates may confuse a RAT with other malware types, such as ransomware (option A) or worms (option C), because they all involve malicious code, but the CEH exam specifically tests the unique remote-control and backdoor capabilities that define a RAT.

772
MCQmedium

A penetration tester executes the command: snmpwalk -c public -v2c 192.168.1.50. Which of the following BEST describes the purpose of this command?

A.Modify SNMP settings on the remote device
B.Perform a brute-force attack on the SNMP community string
C.Test the SNMP agent for denial of service vulnerabilities
D.Enumerate the MIB tree of the SNMP agent using the 'public' community string
AnswerD

The `snmpwalk` utility is specifically designed to query an SNMP agent and traverse its Management Information Base (MIB) tree. By sending a series of GETNEXT requests, it systematically retrieves all Object Identifiers (OIDs) and their corresponding values accessible through the agent. The `c public` argument specifies the community string "public," which is a common default or weak credential used to gain read-only access for enumeration purposes. This command effectively maps the device's configuration and status information.

Why this answer

The `snmpwalk` command is used to retrieve a subtree of management information from an SNMP agent. By specifying `-c public` (the community string) and `-v2c` (SNMP version 2c), the command performs a GETNEXT request cycle to walk the entire MIB tree, enumerating all accessible OIDs and their values. Option D correctly identifies this as enumerating the MIB tree using the 'public' community string.

Exam trap

The trap here is that candidates may confuse `snmpwalk` with a modification or attack tool, but the CEH exam expects you to recognize it as a standard enumeration command that leverages the SNMP GETNEXT operation to walk the MIB tree.

How to eliminate wrong answers

Option A is wrong because `snmpwalk` is a read-only operation that retrieves data; it cannot modify SNMP settings on the remote device. Option B is wrong because `snmpwalk` does not perform brute-force attacks; tools like `onesixtyone` or `hydra` are used for brute-forcing community strings, and the command already provides the community string 'public'. Option C is wrong because `snmpwalk` is not a denial of service test; it is a standard enumeration technique, and DoS testing would involve flooding or malformed packets, not a normal GETNEXT walk.

773
MCQeasy

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

A.Ransomware
B.Spyware
C.Keylogger
D.Adware
AnswerA

Ransomware employs asymmetric encryption to lock files with a public key while the private decryption key remains solely with the attacker, directly satisfying the stem’s constraint of demanding payment for decryption. This contrasts with other malware types that may delete, exfiltrate, or corrupt data without encrypting it for ransom.

Why this answer

Ransomware is a type of malware that encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands payment, typically in cryptocurrency, for the decryption key. This matches the description of encrypting files and demanding payment for the decryption key, which is the defining characteristic of ransomware.

Exam trap

The trap here is that candidates may confuse ransomware with spyware or adware because all three are types of malware, but only ransomware specifically uses file encryption as a mechanism for extortion, not data theft or advertising.

How to eliminate wrong answers

Option B (Spyware) is wrong because spyware is designed to covertly gather information about the user, such as keystrokes, browsing habits, or credentials, and does not encrypt files or demand payment. Option C (Keylogger) is wrong because a keylogger specifically records keystrokes to capture sensitive data like passwords, but it does not encrypt files or issue a ransom demand. Option D (Adware) is wrong because adware automatically displays or downloads advertisements, often generating revenue for its creator, and lacks the file-encryption and extortion functionality of ransomware.

774
MCQmedium

A security engineer notices repeated log entries showing a user account logging in at odd hours and then clearing event logs. The engineer suspects credential theft. Which phase of the CHPSET methodology involves erasing tracks?

A.Erasing tracks
B.Hiding files
C.Spying
D.Cracking passwords
AnswerA

When a security engineer observes repeated log entries indicating unauthorized activity, an attacker's immediate priority after gaining access is often to eliminate or alter these digital footprints. Erasing tracks involves anti-forensic techniques like clearing event logs, modifying timestamps, or injecting benign entries to obscure malicious actions. This critical step aims to delay detection, complicate incident response, and prevent security personnel from understanding the full scope of the breach.

Why this answer

The CHPSET methodology (Cracking passwords, Hiding files, Planting backdoors, Spying, Erasing tracks, and Transferring files) defines the phases of system hacking. Erasing tracks is the phase where attackers clear event logs, modify log files, or use tools like `wevtutil` or `clearlogs.exe` to remove evidence of their activities, matching the engineer's observation of cleared logs after suspicious logins.

Exam trap

The CEH exam often tests the CHPSET methodology by asking which phase corresponds to a specific action, and the trap here is that candidates confuse 'erasing tracks' with 'hiding files' because both involve concealment, but hiding files is about data storage, not log manipulation.

How to eliminate wrong answers

Option B is wrong because hiding files involves concealing stolen data or tools using techniques like NTFS alternate data streams or hidden attributes, not clearing logs. Option C is wrong because spying refers to monitoring user activity or capturing keystrokes (e.g., with keyloggers) to gather information, not erasing forensic evidence. Option D is wrong because cracking passwords is the phase of obtaining credentials via methods like brute-force or dictionary attacks, which occurs before the attacker gains access and then erases tracks.

775
MCQeasy

During a penetration test, you need to enumerate SMB shares on a Windows target. Which of the following tools is specifically designed for this purpose?

A.ldapsearch
B.nmap
C.enum4linux
D.snmpwalk
AnswerC

enum4linux is a powerful Perl script specifically designed for enumerating information from Windows and Samba hosts, making it ideal for SMB share enumeration during penetration tests. It consolidates multiple SMB-specific enumeration techniques, including querying for user lists, group memberships, operating system information, and crucially, listing available SMB shares and their permissions. This tool leverages protocols like NetBIOS and SMB to gather comprehensive details, providing a focused and efficient approach to discovering shared resources.

Why this answer

enum4linux is specifically designed to enumerate SMB shares and other information from Windows and Samba systems. It leverages the SMB/CIFS protocol to extract share listings, user lists, and other details using tools like smbclient, rpclient, and net, making it the correct choice for SMB enumeration.

Exam trap

The trap here is that candidates may choose nmap because it can scan for SMB services, but the question asks for a tool specifically designed for enumerating SMB shares, not just detecting the service.

How to eliminate wrong answers

Option A is wrong because ldapsearch is a tool for querying LDAP directories, not for enumerating SMB shares. Option B is wrong because while nmap can scan for open SMB ports (e.g., 139, 445) and run some SMB scripts, it is a general-purpose port scanner, not a tool specifically designed for SMB share enumeration. Option D is wrong because snmpwalk is used to retrieve SNMP MIB data from network devices, not for SMB share enumeration.

776
MCQhard

A security analyst runs the following command: 'python macof -i eth0 -n 1000'. Shortly after, the switch begins flooding traffic to all ports. What is the analyst trying to achieve?

A.DHCP starvation to exhaust IP addresses
B.STP manipulation to cause network loops
C.MAC flooding to force the switch into hub mode for sniffing
D.ARP cache poisoning to redirect traffic
AnswerC

The 'python macof' command correctly executes a MAC flooding attack. This attack rapidly generates and sends frames with unique, spoofed source MAC addresses, overwhelming the switch's Content Addressable Memory (CAM) table. Once the CAM table is full, the switch enters a 'fail-open' mode, behaving like a hub by broadcasting all incoming traffic to every port, thereby enabling an attacker to sniff network traffic.

Why this answer

The command 'python macof -i eth0 -n 1000' runs the macof tool, which generates a large number of frames with random source MAC addresses. This is a classic MAC flooding attack designed to overflow the switch's Content Addressable Memory (CAM) table. When the CAM table is full, the switch can no longer learn new MAC addresses and falls back to flooding all incoming frames out of every port, effectively behaving like a hub, which allows the attacker to sniff traffic that would normally be isolated.

Exam trap

The CEH exam often tests the distinction between MAC flooding (CAM table overflow) and ARP cache poisoning, so candidates may confuse the two because both involve MAC addresses, but MAC flooding targets the switch's forwarding table while ARP poisoning targets host ARP caches.

How to eliminate wrong answers

Option A is wrong because DHCP starvation exhausts IP addresses by sending many DHCP requests with fake MAC addresses, but the macof tool does not interact with DHCP servers; it floods the switch's CAM table with random MAC addresses. Option B is wrong because STP manipulation involves sending crafted Bridge Protocol Data Units (BPDUs) to cause loops or topology changes, whereas macof does not generate BPDUs or interact with Spanning Tree Protocol. Option D is wrong because ARP cache poisoning uses spoofed ARP replies to associate an attacker's MAC with a legitimate IP address, which is a different attack at Layer 2/3; macof only floods random MACs to overflow the CAM table, not to poison ARP caches.

777
MCQmedium

A security analyst is asked to perform a fast scan of a large network (e.g., /16 subnet) to identify live hosts. Which tool is MOST suitable for this task due to its high speed?

A.hping3
B.Nmap
C.Masscan
D.Wireshark
AnswerC

Masscan is purpose-built for extremely high-speed network scanning, capable of scanning the entire internet in minutes by operating asynchronously and sending raw packets. Unlike traditional scanners, it does not maintain a full TCP connection state, allowing it to saturate network links with SYN packets and quickly identify open ports across vast IP address ranges. This stateless, raw packet approach makes it the optimal choice for rapid, large-scale port discovery when speed is the paramount requirement.

Why this answer

Masscan is the most suitable tool for this task because it is designed specifically for high-speed scanning of large address spaces, such as a /16 subnet (65,536 hosts). It uses asynchronous transmission and can send packets at rates exceeding 10 million packets per second, making it significantly faster than Nmap for raw host discovery across massive ranges.

Exam trap

The trap here is that candidates often assume Nmap is always the fastest scanning tool due to its popularity, but Masscan is specifically engineered for speed on massive networks, and the CEH exam tests this distinction.

How to eliminate wrong answers

Option A is wrong because hping3 is a packet crafting and testing tool, not optimized for high-speed scanning of large networks; it operates synchronously and is better suited for targeted firewall testing or DoS simulation. Option B is wrong because while Nmap is powerful and versatile, its default scanning methods (e.g., TCP SYN scan) are slower than Masscan on very large subnets due to its sequential or semi-parallel processing overhead and lower default packet rate. Option D is wrong because Wireshark is a packet capture and analysis tool, not a scanning tool; it cannot actively send probes to discover live hosts.

778
MCQhard

During a penetration test, you execute a command that sends a large number of spoofed ICMP echo request packets to a subnet's broadcast address. This results in a flood of replies to the target system. Which attack have you performed?

A.Ping of Death
B.Smurf attack
C.UDP flood
D.ICMP flood
AnswerB

A Smurf attack exploits ICMP by sending spoofed echo requests to a subnet's broadcast address, causing every host to reply to the victim. This matches the stem's constraint exactly: the spoofed source is the target, and the amplified replies flood it, achieving traffic amplification through broadcast reflection.

Why this answer

The Smurf attack works by sending a large number of ICMP echo request packets with a spoofed source IP (the victim's address) to a subnet's broadcast address. All hosts on that subnet receive the request and reply to the spoofed source, overwhelming the victim with ICMP echo replies. This amplifies traffic because a single request triggers many responses, making it a classic amplification DDoS attack.

Exam trap

Candidates often confuse Smurf attack with a standard ICMP flood. The critical distinction is that a Smurf attack uses a subnet broadcast address and spoofs the victim's IP, causing all hosts in the subnet to reply to the victim, amplifying traffic. A simple ICMP flood sends many pings directly to the target without amplification.

In CEH, this amplification and spoofing is the key to recognizing the Smurf attack.

How to eliminate wrong answers

Option A is wrong because Ping of Death involves sending a malformed ICMP packet larger than 65,535 bytes to cause a buffer overflow, not spoofed broadcast traffic. Option C is wrong because a UDP flood uses UDP packets (often to random ports) to exhaust resources, not ICMP echo requests to a broadcast address. Option D is wrong because an ICMP flood typically sends a high volume of ICMP packets directly to a target without spoofing or broadcast amplification, whereas the Smurf attack specifically exploits the broadcast address for amplification.

779
MCQeasy

A security analyst runs 'nbtstat -A 192.168.1.10' and receives a table showing the machine name and a list of names registered. Which service is being enumerated?

A.SNMP
B.LDAP
C.SMTP
D.NetBIOS
AnswerD

The `nbtstat` command is a dedicated utility for diagnosing and troubleshooting NetBIOS over TCP/IP (NBT) name resolution issues and displaying NetBIOS name table information. When executed with the `-a` (adapter status) or `-A` (adapter status by IP address) switch followed by an IP address, `nbtstat` queries the remote machine for its NetBIOS name table. This process reveals registered names, services, and often MAC addresses, directly constituting NetBIOS enumeration and making it the correct answer.

Why this answer

The 'nbtstat -A' command performs a NetBIOS name table lookup against a remote IP address using the NetBIOS over TCP/IP (NBT) protocol. It queries the target's NetBIOS name service (UDP port 137) and returns the registered names, including the machine name, workgroup/domain, and logged-in users. This directly enumerates the NetBIOS service, making D the correct answer.

Exam trap

The trap here is that candidates confuse the nbtstat command with other enumeration tools, mistakenly thinking it queries SNMP or LDAP because those services also reveal system information, but nbtstat is exclusively a NetBIOS enumeration command.

How to eliminate wrong answers

Option A is wrong because SNMP (Simple Network Management Protocol) uses UDP ports 161/162 and is enumerated with tools like snmpwalk or snmp-check, not the nbtstat command. Option B is wrong because LDAP (Lightweight Directory Access Protocol) operates on TCP port 389 and is enumerated via ldapsearch or similar directory queries, not through NetBIOS name resolution. Option C is wrong because SMTP (Simple Mail Transfer Protocol) runs on TCP port 25 and is enumerated with commands like VRFY or EXPN, or tools like smtp-user-enum, not via nbtstat.

780
MCQmedium

In the context of system hacking methodology (CHPSET), which phase involves hiding malicious files from the operating system and security tools using techniques such as NTFS alternate data streams (ADS) or steganography?

A.Privilege escalation
B.Erasing tracks
C.Hiding files
D.Cracking passwords
AnswerC

Hiding files is a crucial post-exploitation activity within the system hacking methodology, designed to conceal malicious tools, backdoors, rootkits, or exfiltrated data on a compromised system. This action ensures the attacker's continued access and persistence by making their presence difficult for defenders to detect through standard system monitoring. It is a fundamental technique for maintaining a covert foothold and preventing the discovery of persistent mechanisms.

Why this answer

The 'Hiding files' phase of the CHPSET (Cracking, Hacking, Privilege escalation, Spying, Erasing tracks, Hiding files) methodology specifically involves concealing malicious files from the OS and security tools. Techniques like NTFS alternate data streams (ADS) allow data to be stored in a file's metadata stream (e.g., type echo payload > file.txt:stream) without affecting the visible file size, while steganography hides data within images or audio files. This phase occurs after gaining access and before covering tracks.

Exam trap

The trap here is that candidates confuse 'hiding files' with 'erasing tracks' (Option B) in the EC-CEH methodology, as both involve evasion, but erasing tracks focuses on log and evidence removal, not file concealment via ADS or steganography.

How to eliminate wrong answers

Option A is wrong because privilege escalation is the phase where an attacker gains higher-level permissions (e.g., from user to administrator) using exploits like token manipulation or service misconfigurations, not hiding files. Option B is wrong because erasing tracks (also called covering tracks) involves clearing logs, timestamps, and evidence of intrusion (e.g., using wevtutil or clearing event logs), not concealing files themselves. Option D is wrong because cracking passwords is part of the initial 'Cracking' phase, where tools like John the Ripper or Hashcat are used to recover plaintext passwords from hashes, not to hide files.

781
MCQmedium

A penetration tester uses a tool to perform a man-in-the-middle attack by sending forged DNS responses that redirect users to a malicious website. Which tool is MOST likely being used to perform DNS spoofing?

A.Nmap
B.Wireshark
C.Ettercap
D.tcpdump
AnswerC

Ettercap is a comprehensive and versatile suite specifically designed for Man-in-the-Middle attacks on switched LANs. It excels by implementing robust ARP spoofing to redirect traffic between two hosts through the attacker's machine, effectively placing itself in the middle. Beyond simple interception, Ettercap includes powerful plugins for active manipulation, such as DNS spoofing, content filtering, and packet injection, making it a primary tool for intercepting, analyzing, and altering network communications in real-time. Its integrated framework directly supports the actions needed for a successful MITM attack.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks, including ARP poisoning and DNS spoofing. It can intercept DNS requests and forge fake responses to redirect victims to a malicious IP, making it the correct tool for DNS spoofing.

Exam trap

The trap here is that candidates often confuse packet capture tools (Wireshark, tcpdump) with active attack tools, forgetting that DNS spoofing requires injecting forged packets, not just passive observation.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning and discovery tool, not designed to forge DNS responses or perform MITM attacks. Option B is wrong because Wireshark is a packet analyzer used for passive traffic capture and inspection, not for injecting forged DNS packets. Option D is wrong because tcpdump is a command-line packet capture tool that only captures and displays packets; it cannot actively spoof DNS responses.

782
MCQmedium

A user receives a text message claiming their bank account is locked and requiring them to click a link to verify. This social engineering method is called:

A.Phishing
B.Whaling
C.Vishing
D.SMiShing
AnswerD

SMiShing is the precise term for a phishing attack conducted via Short Message Service (SMS) text messages. In this method, attackers send deceptive text messages, often containing malicious links or requests for personal information, to mobile phone users. The goal is to trick recipients into clicking links that install malware, redirect to fraudulent websites, or directly provide sensitive data, perfectly matching the described scenario of a text message claiming bank account issues.

Why this answer

SMiShing (SMS phishing) is the correct term because the attack vector is a text message (SMS) that tricks the user into clicking a malicious link. Unlike email-based phishing, SMiShing exploits the higher trust users often place in SMS messages and the limited security controls on mobile devices.

Exam trap

The CEH exam often tests the distinction between phishing (email), vishing (voice), and SMiShing (SMS) by presenting a scenario that clearly involves a text message, leading candidates to mistakenly choose 'Phishing' due to its broader familiarity.

How to eliminate wrong answers

Option A is wrong because phishing generally refers to email-based social engineering attacks, not SMS. Option B is wrong because whaling targets high-profile executives or individuals, not generic bank account users. Option C is wrong because vishing uses voice calls (VoIP or phone) to deceive victims, not text messages.

783
MCQmedium

An organization is experiencing repeated DDoS attacks that consume all available bandwidth. Which mitigation technique is MOST effective for handling such volumetric attacks?

A.Blackholing all traffic to the target IP
B.Anycast network distribution
C.Rate limiting on the firewall
D.Scrubbing centers
AnswerD

Scrubbing centres divert incoming traffic to dedicated facilities that filter and clean malicious volumetric floods before forwarding legitimate packets, absorbing the bandwidth-saturating load upstream. This preserves the organisation's own internet link, which on-premises filtering cannot achieve during a bandwidth-exhaustion attack.

Why this answer

Scrubbing centers (Option D) are the most effective mitigation for volumetric DDoS attacks because they use specialized hardware and software to filter malicious traffic from legitimate traffic before it reaches the target network. Unlike simpler methods, scrubbing centers can handle massive bandwidth floods by redirecting traffic through high-capacity filtering nodes that inspect packets, drop attack traffic based on signatures or behavioral analysis, and forward only clean traffic. This approach is specifically designed for volumetric attacks that saturate bandwidth, as it offloads the filtering burden from the target's own infrastructure.

Exam trap

A common mistake is to assume that anycast distribution (Option B) mitigates volumetric attacks by spreading traffic across servers. However, anycast only distributes the load; it does not filter malicious traffic. Volumetric attacks require actual traffic scrubbing to remove malicious data, which is provided by scrubbing centers (Option D).

How to eliminate wrong answers

Option A is wrong because blackholing all traffic to the target IP (via BGP null routing) drops all traffic, including legitimate traffic, effectively causing a denial of service for valid users and not mitigating the attack but rather accepting defeat. Option B is wrong because anycast network distribution primarily helps distribute traffic across multiple geographic locations to absorb some attack volume, but it does not filter malicious traffic; it only spreads the load, and if the attack is large enough, it can still overwhelm all anycast nodes. Option C is wrong because rate limiting on the firewall is a reactive, per-connection or per-IP threshold mechanism that is ineffective against volumetric floods that originate from many distributed sources (e.g., botnets) and can be bypassed by varying source IPs; it also risks dropping legitimate traffic if thresholds are set too low.

784
MCQmedium

An attacker uses a technique where they send a SYN packet with a spoofed source IP address to the target, and the target responds with SYN/ACK to the spoofed IP. The attacker never completes the handshake. This technique is known as:

A.SYN flood
B.TCP connect scan
C.Idle scan
D.Half-open scan
AnswerC

An Idle scan is a highly stealthy port scanning technique that leverages a "zombie" host, an idle machine with a predictable IPID (IP Identification field) sequence. The attacker spoofs the zombie's IP address to send SYN packets to the target port. By observing changes in the zombie's IPID after the target responds (or doesn't respond) to the spoofed packet, the attacker can infer whether the target port is open, closed, or filtered, without directly interacting with the target.

Why this answer

The idle scan (option C) is correct because it uses a spoofed SYN packet with a zombie host's IP address to probe open ports on the target. The target sends a SYN/ACK to the zombie, but the attacker never completes the handshake; instead, the attacker monitors the zombie's IPID (IP Identification) field to infer whether the target's port is open or closed. This technique is defined in RFC 793 and leverages the zombie's predictable IPID sequence to perform a blind, stealthy scan.

Exam trap

The trap here is that candidates confuse the idle scan with a half-open scan because both involve not completing the handshake, but the idle scan uniquely requires a spoofed source IP and a zombie host to measure IPID changes, whereas a half-open scan uses the attacker's own IP and sends a RST directly.

How to eliminate wrong answers

Option A (SYN flood) is wrong because it is a denial-of-service attack that sends a high volume of SYN packets to exhaust target resources, not a reconnaissance technique using a spoofed IP to infer port states. Option B (TCP connect scan) is wrong because it completes the full three-way handshake using the attacker's real IP address, not a spoofed source IP, and is detectable in logs. Option D (Half-open scan) is wrong because it sends a SYN packet with the attacker's own IP, receives a SYN/ACK, and then sends a RST to avoid completing the handshake; it does not use a spoofed IP or a third-party zombie to mask the attacker's identity.

785
MCQmedium

A penetration tester gains access to a Linux server and attempts to escalate privileges. They run `sudo -l` and see that the user can run `/usr/bin/vim` as root without a password. Which privilege escalation technique should the tester use?

A.Perform token impersonation using SeImpersonatePrivilege
B.Use vim's shell escape via `:!bash` to get a root shell
C.Exploit a kernel vulnerability (CVE-2023-xxxx)
D.Abuse the SUID bit on vim
AnswerB

This is the correct approach because if vim is launched with sudo privileges, even if sudo is configured to require a password, the vim process itself will be running as root. Within vim, the :!bash command allows the user to execute an arbitrary shell command. Since vim is already running as root, the spawned bash shell will inherit these root privileges, effectively granting a root shell without needing to know the root password directly.

Why this answer

The `sudo -l` output shows that the user can run `/usr/bin/vim` as root without a password. Vim has a built-in shell escape feature: from within vim, typing `:!bash` (or `:!sh`) executes a shell with the privileges of the user running vim. Since vim is run via sudo as root, the spawned shell will be a root shell, directly escalating privileges without needing additional exploits.

Exam trap

CEH exams often test the distinction between sudo-based privilege escalation and SUID-based escalation; the trap here is that candidates may incorrectly focus on the SUID bit (Option D) when the actual vector is the sudo rule allowing arbitrary command execution via vim's shell escape.

How to eliminate wrong answers

Option A is wrong because token impersonation using SeImpersonatePrivilege is a Windows-specific privilege escalation technique (e.g., JuicyPotato), not applicable to Linux. Option C is wrong because exploiting a kernel vulnerability (CVE-2023-xxxx) is unnecessary when a simple sudo misconfiguration already grants root access; it is overkill and risks system instability. Option D is wrong because the SUID bit on vim is not relevant here; the user already has sudo permission to run vim as root, so the escalation vector is the sudo rule, not the SUID bit.

786
MCQhard

An organization's security team observes a surge in outgoing DNS queries to external servers from a single internal host, with each query returning unusually large responses (e.g., 4000 bytes). The host is not configured as a DNS resolver. Which attack is MOST likely occurring?

A.DNS cache poisoning
B.DNS zone transfer
C.DNS amplification DDoS attack
D.DNS tunneling
AnswerD

DNS tunneling is a technique used to encapsulate data of other protocols within DNS queries and responses, often for covert communication or data exfiltration. While it involves using DNS traffic to bypass firewalls or security controls, its primary goal is to establish a hidden communication channel, not to generate an enormous volume of large, legitimate-looking DNS responses for denial-of-service. The data volume is typically limited by the tunneling payload, not designed for massive amplification.

Why this answer

The scenario describes a single internal host initiating a surge of outgoing DNS queries to external servers and receiving unusually large responses (e.g., 4000 bytes). This behavior, particularly from a host not configured as a DNS resolver, is a strong indicator of DNS tunneling. In DNS tunneling, a compromised host establishes a covert communication channel by encapsulating data within DNS queries and responses, often for data exfiltration or command and control.

Large DNS responses, frequently utilizing record types like TXT, are commonly employed to transfer significant amounts of data back to the compromised host. DNS amplification DDoS attacks, in contrast, involve an attacker spoofing a victim's IP address to send small queries to open resolvers, causing the victim to be overwhelmed by large, unsolicited responses; the victim does not actively send the initial queries in this scenario.

Exam trap

The CEH exam often tests the distinction between DNS tunneling and DNS amplification. Candidates might mistakenly choose DNS amplification DDoS attack (C) by focusing solely on 'large responses' and misinterpreting the internal host as the *victim* of an amplification attack. However, the critical detail is that the internal host is *sending* the outgoing queries and *receiving* the large responses, which is characteristic of DNS tunneling (D) where data is exfiltrated or commanded.

In a DNS amplification attack, the victim *receives* large responses without initiating the queries themselves (their IP is spoofed).

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning involves corrupting a resolver's cache with forged DNS records to redirect traffic, not generating large response volumes from a single host. Option B is wrong because DNS zone transfer is a legitimate mechanism for replicating DNS zone data between authoritative servers, typically using TCP port 53, and does not involve sending large responses to a single host from external servers. Option D is wrong because DNS tunneling encodes non-DNS data (e.g., SSH, HTTP) within DNS queries and responses for covert communication, but it does not produce the massive response sizes (4000 bytes) characteristic of amplification; tunneling typically uses small, consistent packet sizes to avoid detection.

787
MCQhard

During a penetration test, the tester runs `enum4linux -U 192.168.1.20` and obtains a list of usernames. What service is being enumerated, and what is the primary risk associated with this information disclosure?

A.NFS; it can lead to unauthorized file access
B.SNMP; it can reveal community strings
C.SMB; it can facilitate password spraying or brute‑force attacks
D.LDAP; it can expose directory structure
AnswerC

enum4linux queries SMB (and NetBIOS) services, and the -U switch extracts account names via null or anonymous sessions. Valid usernames enable password spraying or brute-force attacks against authentication endpoints, so the disclosure directly satisfies the stem's risk requirement by narrowing the credential search space.

Why this answer

enum4linux is a tool that queries SMB (Server Message Block) services on a target, typically over TCP ports 139 or 445. The `-U` flag specifically enumerates users from the SAM database via the SMB protocol. The primary risk of obtaining a valid username list is that it enables password spraying or brute-force attacks against SMB authentication, which can lead to unauthorized access.

Exam trap

The CEH exam often tests the association between the specific enumeration tool and its corresponding service, so the trap here is confusing enum4linux with other enumeration tools like `snmpwalk` (SNMP) or `ldapsearch` (LDAP), leading candidates to pick a plausible-sounding but incorrect service.

How to eliminate wrong answers

Option A is wrong because NFS (Network File System) is enumerated with tools like `showmount` or `rpcinfo`, not enum4linux, and the risk of unauthorized file access is associated with NFS export misconfigurations, not username enumeration. Option B is wrong because SNMP (Simple Network Management Protocol) is enumerated with tools like `snmpwalk` or `onesixtyone`, and the risk of revealing community strings is unrelated to SMB username enumeration. Option D is wrong because LDAP (Lightweight Directory Access Protocol) is enumerated with tools like `ldapsearch` or `windapsearch`, and while it can expose directory structure, enum4linux does not interact with LDAP.

788
MCQeasy

Which of the following is a type of malware that replicates itself by attaching to executable files and requires human action to spread, such as opening an infected attachment?

A.Worm
B.Ransomware
C.File virus
D.Trojan
AnswerC

A file virus is a classic form of malware that replicates by attaching its malicious code to legitimate executable files or scripts on a host system. When an infected program is executed, the virus code runs first, often infecting other uninfected files on the same system or accessible network drives. This direct modification and execution-based propagation mechanism is a fundamental characteristic of file viruses, making them a clear example of replicating malware.

Why this answer

A file virus (also known as a file infector) is a type of malware that replicates by inserting its code into executable files (e.g., .exe, .com, .dll). It requires human action to spread, such as opening an infected email attachment or running an infected program, because the virus code is only activated when the host executable is executed.

Exam trap

The trap here is that candidates often confuse a file virus with a worm because both can spread via email attachments, but the key differentiator is that a worm self-replicates without human interaction, while a file virus requires the user to execute the infected file.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads automatically over networks without requiring human action, exploiting vulnerabilities like open ports or weak credentials. Option B is wrong because ransomware is a type of malware that encrypts files or locks systems to demand a ransom, and it does not primarily replicate by attaching to executables; its spread often relies on other vectors like phishing or exploits. Option D is wrong because a Trojan is malware disguised as legitimate software that does not self-replicate; it relies on social engineering to trick users into installing it, but it does not attach to executable files to propagate.

789
MCQhard

Refer to the exhibit. During a penetration test, the results show port 80 as 'filtered'. Which of the following is the most likely reason?

A.The SSH service is interfering with the scan.
B.The target host is offline.
C.The web server is not running.
D.A firewall or ACL is blocking the port.
AnswerD

An Nmap port scan result of 'filtered' specifically indicates that Nmap was unable to determine if the port is open or closed because its probes did not elicit a definitive response, or an ICMP unreachable message was received. This behavior is characteristic of a firewall, Access Control List (ACL), or other packet filtering device actively dropping or rejecting the Nmap probe packets targeting port 80. Such security mechanisms are designed to prevent unauthorized access by blocking traffic to specific ports, making the port appear 'filtered' to the scanner.

Why this answer

A 'filtered' port state in Nmap means the probe was sent but no response was received, and the most common cause is a firewall, ACL, or packet-filtering device silently dropping the packets. Unlike 'closed' (RST returned) or 'open' (SYN-ACK returned), 'filtered' indicates active blocking. This is the textbook interpretation of Nmap's filtered state.

Exam trap

CEH often tests the distinction between 'closed' (RST received, service not listening) and 'filtered' (no response, firewall blocking); candidates confuse the two and select 'web server not running'.

How to eliminate wrong answers

Option A is wrong because SSH runs on port 22 and has no mechanism to interfere with port 80 scans — services do not block scans of unrelated ports. Option B is wrong because an offline host typically produces a 'host seems down' message or all ports show as filtered due to no response, but the question specifies port 80 as filtered while implying other ports responded, indicating selective filtering rather than host downtime. Option C is wrong because a non-running web server would return a TCP RST, resulting in a 'closed' state, not 'filtered'.

790
MCQmedium

During a penetration test, an analyst runs the following command: 'reaver -i wlan0mon -b 00:11:22:33:44:55 -vv'. What is the PRIMARY purpose of this command?

A.Perform a de-authentication attack on the target AP
B.Capture the 4-way handshake for WPA cracking
C.Brute-force the WPS PIN to recover the Wi-Fi passphrase
D.Scan for nearby access points and their BSSIDs
AnswerC

Reaver is a specialized tool engineered to exploit a design flaw in the Wi-Fi Protected Setup (WPS) protocol. It systematically attempts to guess the 8-digit WPS PIN by brute-forcing the first four digits, then the next three, and finally the checksum digit. This method leverages the fact that WPS validates the PIN in two halves, significantly reducing the number of possible combinations and allowing Reaver to recover the Wi-Fi passphrase.

Why this answer

Reaver is a tool designed to exploit the WPS PIN authentication mechanism. The command targets a specific BSSID to perform a brute-force attack on the WPS PIN, which can reveal the WPA/WPA2 passphrase if successful.

791
MCQhard

A web application firewall (WAF) blocks requests containing ' UNION SELECT '. A penetration tester wants to bypass this restriction to perform a union-based SQL injection. Which of the following techniques is MOST likely to succeed?

A.Use double URL encoding: '%25%35%35%25%34%65%25%34%39...'
B.Use hex encoding: '0x554e494f4e2053454c454354'
C.Use URL encoding: '%55%4e%49%4f%4e%20%53%45%4c%45%43%54'
D.Use inline comments: 'UN/**/ION/**/SE/**/LECT'
AnswerD

Inline comments, like '/**/', are valid SQL syntax that allows arbitrary text to be inserted without affecting query execution. By strategically placing these comments within keywords (e.g., 'UN/**/ION'), an attacker can break up the signature of a known malicious string (e.g., "UNION SELECT") into smaller, non-matching fragments. This technique effectively bypasses WAFs that rely on simple, exact string matching or regular expressions that do not account for such obfuscation, as the WAF sees 'UN', then '/**/', then 'ION', rather than the full "UNION" keyword.

Why this answer

Using comments or alternative encoding can bypass WAF rules. Inline comments like '/**/' can break up keywords.

792
MCQhard

As a network defender, you notice an unusually high number of incomplete TCP three-way handshakes from a single external IP to multiple internal hosts. What is the most likely attack taking place?

A.UDP flood
B.SYN flood
C.ARP spoofing
D.ICMP flood
AnswerB

A SYN flood sends many SYN packets without completing the ACK, leaving half-open connections that exhaust the target's backlog queue. This matches the incomplete three-way handshakes from one source to multiple hosts. It is a denial-of-service technique, not session hijacking or scanning.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets to target hosts without completing the handshake (i.e., not sending the final ACK). This leaves the target with half-open connections, exhausting its connection table and denying service to legitimate traffic. The observation of incomplete handshakes from a single external IP to multiple internal hosts is a classic signature of a SYN flood.

Exam trap

EC-Council often tests the distinction between a SYN flood and a UDP flood, where candidates mistakenly choose UDP flood because they associate 'flood' with any high-volume attack, but the key clue is the incomplete TCP three-way handshake, which is specific to SYN floods.

How to eliminate wrong answers

Option A (UDP flood) is wrong because a UDP flood targets UDP ports with a high volume of datagrams, not TCP handshake packets, and would not produce incomplete TCP three-way handshakes. Option C (ARP spoofing) is wrong because ARP spoofing operates at Layer 2 by poisoning ARP caches to intercept traffic on a local network, not by sending incomplete TCP handshakes from an external IP. Option D (ICMP flood) is wrong because an ICMP flood uses ICMP echo request packets (pings) to overwhelm a target, not TCP SYN packets, and would not result in incomplete TCP handshakes.

793
Multi-Selecthard

A security analyst is investigating a malware incident. The analyst observes that the malware creates a scheduled task to run a script every time the system starts, and it also modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to execute a payload. Which two persistence techniques is the malware using? (Choose two.)

Select 2 answers
A.Bootkit
B.Registry Run key
C.Service creation
D.DLL hijacking
E.Scheduled task
AnswersB, E

The scenario explicitly mentions modification of the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, which is a classic registry Run key persistence method. This key causes the specified program to execute automatically when the user logs on. Therefore, this is one of the correct answers.

Why this answer

The malware uses two persistence techniques: creating a scheduled task to run at startup and modifying the registry Run key to execute a payload on user logon. Both are explicitly described in the scenario. The other options are different persistence methods not mentioned.

Exam trap

The trap here is assuming that any mention of 'startup' implies a service or bootkit, but the specific artifacts named—scheduled task and HKCU Run key—are the definitive indicators.

794
MCQeasy

A security analyst notices that a web application returns different page sizes when a valid user ID is submitted versus an invalid one in the URL parameter. Which type of vulnerability is most likely being exploited?

A.Stored Cross-Site Scripting (XSS)
B.Insecure Direct Object Reference (IDOR)
C.Cross-Site Request Forgery (CSRF)
D.SQL Injection
AnswerB

Insecure Direct Object Reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, directory, database record, or key, and fails to implement proper authorization checks. An attacker can manipulate these references, often found in URL parameters or API requests, to access resources belonging to other users or entities without explicit permission. This directly matches the scenario where an analyst changes an ID to view different responses, indicating a bypass of access controls.

Why this answer

The different page sizes for valid versus invalid user IDs indicate an Insecure Direct Object Reference (IDOR) vulnerability, where the application exposes internal object references (like user IDs) without proper authorization checks. An attacker can manipulate the parameter to access other users' data, and the varying response size reveals whether the ID exists, enabling enumeration. This is a classic IDOR exploitation pattern.

Exam trap

CEH often tests the confusion between IDOR and other injection or scripting flaws — candidates may pick SQL injection because it involves manipulating parameters, but the telltale sign is response variation based on object validity.

How to eliminate wrong answers

Option A is wrong because stored XSS involves malicious scripts persisted on the server and executed in victims' browsers, not differences in page size based on ID validity. Option C is wrong because CSRF tricks authenticated users into performing unintended actions, and it does not typically manifest as response size variations for different IDs. Option D is wrong because SQL injection would likely cause database errors or unexpected data retrieval, but the specific behavior of different page sizes for valid/invalid IDs is more indicative of IDOR enumeration than SQLi.

795
MCQeasy

A security analyst wants to gather information about a target domain without directly interacting with its systems. Which technique would be MOST appropriate?

A.Send ICMP echo requests to the target network
B.Run a vulnerability scan with Nessus
C.Perform a port scan using Nmap SYN scan
D.Query WHOIS databases for domain registration information
AnswerD

Querying WHOIS databases for domain registration information is a passive reconnaissance technique because it retrieves publicly available data from centralized registries and registrars. This process does not send any network traffic directly to the target organization's servers or network infrastructure. Instead, it accesses information that has been voluntarily submitted and made public, such as registrant details, name servers, and registration dates, without alerting the target.

Why this answer

Querying WHOIS databases is a passive reconnaissance technique that retrieves publicly available domain registration information (e.g., registrar, creation/expiration dates, name servers, and administrative contacts) without sending any packets to the target's systems. This aligns with the goal of gathering information without direct interaction, as defined in the CEH footprinting phase.

Exam trap

The trap here is that candidates often confuse active scanning (like Nmap or Nessus) with passive reconnaissance, failing to recognize that any packet sent to the target constitutes direct interaction, whereas WHOIS queries are entirely external to the target's infrastructure.

How to eliminate wrong answers

Option A is wrong because sending ICMP echo requests (ping sweeps) involves direct interaction with the target network, which violates the requirement of no direct interaction. Option B is wrong because running a vulnerability scan with Nessus actively probes target systems for weaknesses, generating traffic and direct interaction. Option C is wrong because performing a port scan using Nmap SYN scan sends crafted TCP SYN packets to target hosts, which is an active reconnaissance technique that directly interacts with the target's systems.

796
Multi-Selecteasy

A web application is vulnerable to XML External Entity (XXE) injection. Which THREE of the following are potential impacts of successfully exploiting an XXE vulnerability?

Select 3 answers
A.SQL injection
B.Arbitrary file read on the server
C.Denial of Service (DoS)
D.Server-Side Request Forgery (SSRF)
E.Remote code execution via command injection
AnswersB, C, D

XXE vulnerabilities allow an attacker to define external entities that reference local files on the server using the `file://` URI scheme. When the XML parser processes this entity, it attempts to retrieve the content of the specified file, such as `/etc/passwd` or application configuration files. This content is then embedded into the XML response, enabling the attacker to read sensitive system files.

Why this answer

Option B (Arbitrary file read on the server) is correct because XXE payloads can define an external entity whose SYSTEM identifier points to a local file (e.g., <!ENTITY xxe SYSTEM "file:///etc/passwd">), causing the parser to embed the file's contents in the response. Option C (Denial of Service) is correct because entities can be nested or recursively referenced (the 'billion laughs' attack) or point to large/blocking resources, exhausting parser memory or CPU and rendering the service unavailable. Option D (Server-Side Request Forgery) is correct because an external entity with an HTTP/FTP SYSTEM URL forces the vulnerable server to make outbound requests to internal or external hosts, enabling SSRF and potential access to internal services or cloud metadata endpoints.

Option A (SQL injection) is not a direct XXE impact — XXE abuses the XML parser, not a database query interface, so any SQLi would be a separate vulnerability. Option E (Remote code execution via command injection) is not a standard XXE consequence; XXE does not invoke OS commands, and RCE typically requires additional flaws such as insecure deserialization or PHP expect:// wrappers in specific misconfigurations.

Exam trap

The trap is selecting SQL injection or RCE because they are 'impactful' — candidates must remember XXE's direct impacts are file read, SSRF, and DoS, not SQLi or command injection.

797
MCQeasy

Which of the following is the BEST defense against brute-force attacks on a login form?

A.Rate limiting on the login endpoint
B.CAPTCHA
C.Complex password policy
D.Account lockout after 5 failed attempts
AnswerD

Account lockout after 5 failed attempts can be circumvented by distributed attacks from many IPs. It is reactive and may cause denial of service for legitimate users, so it is not the best.

Why this answer

Account lockout after a small number of failed attempts (D) is the most direct and effective defense against brute-force attacks on a login form: it stops the attack at the source by disabling the targeted account after repeated failures, regardless of source IP. Rate limiting (A) is a useful complementary control, but it can be bypassed by distributing attempts across many IPs and does not stop slow, low-rate brute-force attempts. CAPTCHA (B) can be bypassed by automated solvers, and complex password policies (C) do not prevent repeated attempts.

Therefore the BEST answer is D.

Exam trap

The question uses the word 'BEST' to indicate a single correct answer. Do not assume multiple answers are correct. Account lockout is the most direct defense because it halts repeated failed attempts against the targeted account, while rate limiting can be evaded via distributed or low-rate attacks.

How to eliminate wrong answers

Option B (CAPTCHA) is wrong because while it can slow down automated attacks, it is not the best defense as it can be bypassed using OCR, machine learning, or third-party solving services, and it degrades user experience. Option C (Complex password policy) is wrong because it only increases the password search space but does not prevent brute-force attempts; attackers can still try millions of combinations over time. Option D (Account lockout after 5 failed attempts) is wrong because it is a reactive measure that can be exploited for denial-of-service attacks against legitimate users, and attackers can bypass it by using many different usernames or IP addresses in a distributed brute-force attack.

798
MCQeasy

A security analyst wants to enumerate NetBIOS names on a Windows network. Which built-in Windows command-line tool should they use?

A.nslookup
B.netstat
C.nbtstat
D.net view
AnswerC

`nbtstat` queries the NetBIOS name table and datagram services directly, returning local and remote NetBIOS names, their suffixes and cached entries. Its `-a`, `-A` and `-n` switches satisfy the stem's requirement to enumerate NetBIOS names on a Windows network, unlike tools that resolve DNS or inspect SMB sessions.

Why this answer

The nbtstat command is the correct built-in Windows tool for enumerating NetBIOS names because it directly queries and displays NetBIOS over TCP/IP (NetBT) statistics, name tables, and caches. NetBIOS name enumeration relies on the NBT protocol (RFC 1001/1002), and nbtstat -a or -A retrieves the remote machine's NetBIOS name table, which includes service types like file sharing, messaging, and workstation services.

Exam trap

The trap here is that candidates confuse 'net view' (which shows network shares) with NetBIOS name enumeration, but nbtstat is the specific tool for querying the NetBIOS name table and cache directly.

How to eliminate wrong answers

Option A (nslookup) is wrong because it is used for DNS queries (A, AAAA, MX, etc.) and has no capability to enumerate NetBIOS names, which operate at a different layer (NetBIOS session service over TCP/UDP 137-139). Option B (netstat) is wrong because it displays active TCP/UDP connections, listening ports, and routing tables, but it does not query or resolve NetBIOS names or name tables. Option D (net view) is wrong because while it lists shared resources on a network, it relies on the Server Message Block (SMB) protocol and does not directly enumerate the raw NetBIOS name table or cache; it is a higher-level command that uses NetBIOS indirectly but is not the tool for name enumeration.

799
MCQeasy

Which of the following techniques is considered PASSIVE reconnaissance?

A.Ping sweeping a subnet
B.Banner grabbing with Telnet
C.Running a SYN scan with Nmap
D.Performing a WHOIS lookup
AnswerD

Performing a WHOIS lookup involves querying publicly accessible databases maintained by domain registrars and Regional Internet Registries (RIRs) to retrieve information about domain names or IP address blocks. This process retrieves data from third-party servers, such as ICANN-accredited registrars, without ever sending a single packet to the target organization's network infrastructure. Consequently, the target remains completely unaware of the inquiry, making it a quintessential passive reconnaissance technique.

Why this answer

WHOIS queries retrieve domain registration records from public databases like whois.iana.org or RDAP servers. Since the target server is never contacted directly — only public registries are queried — no packets are sent to the target's infrastructure, making it a purely passive reconnaissance technique.

Exam trap

EC-Council often tests the distinction between passive and active reconnaissance by making candidates think that any network-based query (like WHOIS) is active, when in fact WHOIS queries public third-party databases, not the target's own systems.

How to eliminate wrong answers

Option A is wrong because ping sweeping sends ICMP Echo Request packets to multiple hosts and waits for replies, actively probing the target network. Option B is wrong because banner grabbing with Telnet establishes a TCP connection (port 23 or other) to the target service and reads the initial banner, which is an active interaction. Option C is wrong because running a SYN scan with Nmap sends crafted TCP SYN packets to target ports and analyzes responses, which is an active scanning technique that can be detected by intrusion detection systems.

800
Multi-Selectmedium

Which TWO of the following are characteristics of a polymorphic virus?

Select 2 answers
A.It uses a decryption routine that varies
B.It uses a constant signature across all infections
C.It changes its code signature each time it replicates
D.It can only infect boot sectors
E.It always remains in memory
AnswersA, C

A polymorphic virus employs a sophisticated mutation engine that generates a unique decryption routine for each new infection instance. This varying decryption stub is prepended to the encrypted virus body, ensuring that the overall code signature changes every time the virus replicates. This constant alteration of the decryption mechanism is crucial for evading static signature-based antivirus detection, as the virus's executable form never presents the same byte pattern.

Why this answer

A polymorphic virus uses a decryption routine that varies with each infection, preventing signature-based detection. Option C is also correct because the changing decryption routine causes the virus's code signature to change each time it replicates, further evading signature matching.

Exam trap

The trap here is that candidates confuse 'polymorphic' with 'metamorphic' — polymorphic changes the decryption routine but keeps the payload constant, whereas metamorphic rewrites the entire code body, and the exam often tests this distinction by listing 'constant signature' as a distractor.

801
MCQeasy

An attacker sends an email that appears to come from the CEO of the company, requesting an urgent wire transfer to a specific account. This is an example of which social engineering attack?

A.Whaling
B.Spear phishing
C.Phishing
D.Pretexting
AnswerA

Whaling is a highly specialized form of spear phishing that specifically targets high-profile individuals within an organization, such as CEOs, CFOs, or other senior executives. The attacker crafts extremely convincing emails, often spoofing the identity of a trusted internal or external party, to trick these 'big fish' into divulging sensitive information or authorizing fraudulent transactions. The objective is typically significant financial gain or access to critical corporate data, leveraging the executive's authority and perceived urgency.

Why this answer

Whaling is a targeted social engineering attack that specifically goes after high-profile individuals like the CEO or CFO. In this scenario, the attacker impersonates the CEO to trick an employee into authorizing a fraudulent wire transfer, which is the classic hallmark of whaling rather than generic phishing.

Exam trap

The trap here is that candidates confuse whaling with spear phishing because both are targeted, but whaling is specifically reserved for attacks against senior executives or high-value targets, not just any individual.

How to eliminate wrong answers

Option B (Spear phishing) is wrong because spear phishing targets a specific individual or group but does not necessarily focus on senior executives; the attack here is explicitly against the CEO's identity. Option C (Phishing) is wrong because phishing is a broad, untargeted attack sent to many users, not a personalized email impersonating a specific executive. Option D (Pretexting) is wrong because pretexting involves creating a fabricated scenario or pretext to obtain information, not directly requesting an action like a wire transfer via email impersonation.

802
Multi-Selecthard

A security analyst is reviewing a web application log and sees the following request: GET /page?file=../../../etc/passwd HTTP/1.1. Which TWO vulnerabilities are most likely being attempted? (Select two)

Select 2 answers
A.Directory traversal
B.Remote file inclusion (RFI)
C.SQL injection
D.Local file inclusion (LFI)
E.Command injection
AnswersA, D

Directory traversal, also known as path traversal, is an attack that exploits insufficient security validation or sanitization of user-supplied input to access files and directories stored outside the intended web root directory. The `../` sequence, or its URL-encoded equivalent `%2e%2e%2f`, allows an attacker to navigate up the directory hierarchy. By chaining multiple `../` sequences, an attacker can potentially access sensitive system files like `/etc/passwd` or configuration files, thereby compromising the system's confidentiality.

Why this answer

Option A (Directory traversal) is correct because the payload ../../../etc/passwd uses dot-dot-slash sequences to escape the web root and reference files outside the intended directory, which is the classic signature of a path traversal attack. Option D (Local file inclusion) is correct because the same traversal sequence is being passed to the file parameter to make the application include a local server-side file such as /etc/passwd, a hallmark of LFI attempts. Option B (RFI) is not indicated because the value references a local path rather than a remote URL or protocol such as http:// or ftp://.

Option C (SQL injection) is not indicated because there are no SQL metacharacters, quotes, or query fragments in the payload. Option E (Command injection) is not indicated because no shell operators or system commands (e.g., ;, |, &&, whoami) appear in the request.

Exam trap

CEH often tests the overlap between directory traversal and LFI — candidates frequently pick RFI because they see 'file=' and assume remote inclusion, but the payload's local path (`/etc/passwd`) rules RFI out.

803
MCQmedium

A security analyst discovers a user downloaded a file that, when executed, creates a hidden process that connects to a remote server and allows full remote control of the system. Which type of malware BEST describes this behavior?

A.Worm
B.Ransomware
C.Remote Access Trojan (RAT)
D.Polymorphic virus
AnswerC

A Remote Access Trojan (RAT) is a sophisticated form of malware specifically engineered to grant an attacker comprehensive, covert administrative control over an infected system. It establishes a persistent backdoor, enabling remote execution of commands, file manipulation, keystroke logging, screen capture, and even webcam/microphone activation. This direct, interactive control makes a RAT the definitive tool for remote system manipulation and surveillance.

Why this answer

The behavior described—downloading a file that, when executed, creates a hidden process that connects to a remote server and provides full remote control—is the classic definition of a Remote Access Trojan (RAT). A RAT is a type of malware that allows an attacker to remotely control the victim's system, often using a command-and-control (C2) channel over protocols like TCP or HTTP. The hidden process and outbound connection to a remote server are key indicators of a RAT, distinguishing it from other malware types that do not provide interactive remote control.

Exam trap

The trap here is that candidates often confuse a RAT with a worm or virus because they focus on the 'remote control' aspect, but fail to recognize that a RAT specifically provides interactive remote access, whereas worms and viruses have different primary behaviors like self-replication or code mutation.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads across networks without requiring user interaction to execute a downloaded file, and it does not typically provide full remote control of a single system. Option B is wrong because ransomware encrypts files or locks the system to demand a ransom, and it does not create a hidden process for remote control or connect to a remote server for interactive access. Option D is wrong because a polymorphic virus changes its code signature to evade detection but does not inherently create a hidden process or establish a remote control channel; its primary behavior is infection and mutation, not remote access.

804
MCQhard

Refer to the exhibit. A security analyst runs ping and arp commands. What is the most likely attack occurring?

A.Distributed denial of service (DDoS) attack
B.MAC flooding attack
C.ARP spoofing attack
D.Ping flood attack
AnswerC

An ARP spoofing attack, also known as ARP poisoning, involves an attacker sending forged Address Resolution Protocol (ARP) replies to a target system, associating the attacker's MAC address with the IP address of another legitimate device on the local network. The exhibit's indication of duplicate MAC addresses for different IP addresses in the ARP cache is a definitive symptom of this attack. This allows the attacker to intercept, modify, or drop traffic intended for the legitimate device, effectively performing a man-in-the-middle attack.

Why this answer

The combination of `ping` and `arp` commands reveals an ARP spoofing attack. The `arp -a` output shows the same MAC address (00-11-22-33-44-55) mapped to multiple IP addresses (192.168.1.1 and 192.168.1.2), which is a classic indicator of ARP cache poisoning. The `ping` commands confirm that both IPs are reachable, but the duplicate MAC entry proves an attacker is intercepting traffic by associating their MAC with multiple IPs.

Exam trap

The trap here is that candidates confuse MAC flooding (which targets switch CAM tables) with ARP spoofing (which targets host ARP caches), but the exhibit's `arp -a` output showing multiple IPs for one MAC is the definitive sign of ARP cache poisoning, not a switch-level attack.

How to eliminate wrong answers

Option A is wrong because a DDoS attack would overwhelm the target with traffic from multiple sources, not cause duplicate MAC entries in the ARP cache. Option B is wrong because a MAC flooding attack fills the switch's CAM table with fake MAC addresses to force it into hub mode, but the exhibit shows ARP table entries, not switch behavior or CAM table overflow. Option D is wrong because a ping flood attack sends a high volume of ICMP echo requests to consume bandwidth, but the exhibit shows only a few ping replies and no indication of resource exhaustion or abnormal traffic volume.

805
MCQeasy

A security analyst wants to enumerate all users from an SMTP server. Which of the following SMTP commands can be used for user enumeration?

A.DATA
B.MAIL FROM
C.HELO
D.VRFY
AnswerD

The VRFY (Verify) command is specifically designed to query an SMTP server to determine if a particular mailbox or user exists on the system. When provided with a username or email address, the server typically responds with information indicating whether the user is valid, often including their full name or a success code. This direct validation capability makes VRFY a highly effective tool for enumerating valid user accounts on an SMTP server, which is precisely what the security analyst aims to achieve.

Why this answer

The VRFY command is used in SMTP to verify whether a mailbox exists on the server. By issuing VRFY followed by a username, the server typically responds with a 250 code if the user exists or a 550 code if not, enabling user enumeration. This is a recognized technique in security assessments to discover valid email accounts.

Exam trap

The trap here is that candidates often confuse VRFY with EXPN or think that HELO or MAIL FROM can be abused for enumeration, but only VRFY directly queries the server for user existence.

How to eliminate wrong answers

Option A is wrong because DATA is used to begin the transmission of the email body content, not for user enumeration. Option B is wrong because MAIL FROM specifies the sender's address in an SMTP transaction and does not query the server for user existence. Option C is wrong because HELO initiates the SMTP session by identifying the client to the server and provides no mechanism to enumerate users.

806
MCQmedium

An attacker uses a tool that sends crafted RCPT TO commands to an SMTP server to verify email addresses. Which SMTP enumeration technique is being used?

A.AUTH
B.RCPT TO
C.EXPN
D.VRFY
AnswerB

The RCPT TO:<address@domain.com> command is a fundamental SMTP instruction used to specify an intended recipient for an email. Attackers exploit this by sending numerous RCPT TO commands with guessed email addresses to a target mail server. The server's response, such as a 250 OK for a valid address or a 550 No such user here for an invalid one, allows for systematic enumeration of active email accounts. This method is highly effective for building target lists for further attacks.

Why this answer

The RCPT TO command is used in SMTP to specify the recipient of an email. By sending crafted RCPT TO commands to an SMTP server, an attacker can observe the server's response (e.g., '250 OK' for valid addresses vs. '550 No such user' for invalid ones) to enumerate valid email addresses. This technique directly exploits the SMTP protocol's recipient verification behavior.

Exam trap

The trap here is that candidates often confuse RCPT TO with VRFY, assuming VRFY is the primary enumeration command, but in practice, VRFY is frequently disabled, making RCPT TO the more reliable and commonly tested technique in CEH scenarios.

How to eliminate wrong answers

Option A is wrong because AUTH is an SMTP command used for authentication, not for verifying email addresses; it does not reveal whether a recipient exists. Option C is wrong because EXPN is used to expand mailing lists or aliases, returning all members of a list, not to verify individual email addresses. Option D is wrong because VRFY is used to verify if a user exists on the server, but it is often disabled or restricted for security reasons, whereas RCPT TO is more commonly available and effective for enumeration.

807
Multi-Selecteasy

Which TWO tools can be used to enumerate SMB shares and users on a Windows target? (Choose two.)

Select 2 answers
A.smbclient
B.enum4linux
C.nslookup
D.snmpwalk
E.ldapsearch
AnswersA, B

smbclient is a powerful command-line utility for interacting with SMB/CIFS shares on Linux/Unix systems. It can be used to list available shares on a target host using the `-L` option, and with appropriate credentials, it can also enumerate users by attempting to connect to specific shares or by leveraging null sessions if permitted. This makes it a primary tool for SMB enumeration.

Why this answer

smbclient (A) is correct because its -L and -N options let you list SMB shares and, with -U, authenticate to enumerate shares and users on a Windows host over TCP 445/139. enum4linux (B) is correct because it wraps smbclient, rpcclient, and nmblookup to pull share lists, user lists, and group/password-policy data from SMB/RPC on Windows targets. nslookup (C) is wrong because it only queries DNS records and cannot touch SMB. snmpwalk (D) is wrong because it walks SNMP OIDs (UDP 161) and does not enumerate SMB shares or users. ldapsearch (E) is wrong because it queries LDAP directories (TCP 389/636) rather than SMB/RPC services.

Exam trap

The trap here is that candidates may confuse LDAP-based enumeration (ldapsearch) with SMB-based enumeration, or assume SNMP tools like snmpwalk can enumerate SMB shares, when in fact only tools that directly communicate over SMB/RPC (like smbclient and enum4linux) are appropriate for this task.

808
MCQhard

An attacker uses SMTP commands to verify the existence of email accounts on a mail server. Which sequence of SMTP commands is used for this purpose?

A.EHLO, AUTH, STARTTLS
B.HELO, MAIL FROM, RCPT TO, DATA
C.NOOP, QUIT, RSET
D.VRFY, EXPN, RCPT TO
AnswerD

VRFY, EXPN, and RCPT TO are effective SMTP commands for enumerating valid user accounts and aliases on a mail server. VRFY (Verify) explicitly requests the server to confirm if a specified user or mailbox exists, often returning a 250 OK response for valid users or a 550 error for non-existent ones. EXPN (Expand) requests the server to expand a mailing list or alias, revealing the individual members or addresses it contains. RCPT TO, even without a subsequent DATA command, can be used to test for recipient validity by observing the server's response code (e.g., 250 OK vs. 550 User unknown).

Why this answer

The VRFY command asks the mail server to verify whether a given email address exists, EXPN expands a mailing list to reveal individual addresses, and RCPT TO (used in the SMTP transaction) can also be used to check address validity by observing the server's response. Together, these commands allow an attacker to enumerate valid email accounts on the server.

Exam trap

The trap here is that candidates often confuse the standard SMTP mail-sending sequence (HELO, MAIL FROM, RCPT TO, DATA) with the enumeration-specific commands, forgetting that VRFY and EXPN are explicitly designed for address verification.

How to eliminate wrong answers

Option A is wrong because EHLO, AUTH, and STARTTLS are used for SMTP session initiation, authentication, and encryption negotiation, not for verifying email account existence. Option B is wrong because HELO, MAIL FROM, RCPT TO, and DATA are the standard sequence for sending an email message, not specifically for enumeration, though RCPT TO can be abused for enumeration it is not the primary sequence. Option C is wrong because NOOP is a no-operation command, QUIT ends the session, and RSET resets the session; none of these commands verify email account existence.

809
Multi-Selecthard

Which THREE of the following are valid techniques for covering tracks after compromising a system? (Select 3 correct answers)

Select 3 answers
A.Clearing event logs using wevtutil
B.Exploiting SUID binaries to gain root
C.Installing a rootkit to hide malicious processes
D.Using timestomp to modify file timestamps
E.Disabling Windows Defender via Group Policy
AnswersA, C, D

Clearing event logs using `wevtutil` is a direct method of covering tracks by eliminating forensic evidence. The `wevtutil` command-line utility allows an attacker to clear specific Windows Event Logs, such as Security, System, or Application logs, which record system activities, security events, and application errors. By removing these logs, an attacker can erase records of their login attempts, command executions, file accesses, and other malicious actions, significantly hindering incident response and forensic investigations.

Why this answer

A is correct because wevtutil is a Windows command-line utility used to manage event logs. After compromising a system, an attacker can use 'wevtutil cl' followed by a log name (e.g., 'wevtutil cl System') to clear specific event logs, thereby erasing evidence of their activities. This is a direct and common technique for covering tracks by removing forensic artifacts.

Exam trap

EC-Council often tests the distinction between privilege escalation (gaining higher access) and covering tracks (hiding evidence), causing candidates to mistakenly select SUID exploitation as a track-covering technique.

810
Multi-Selecteasy

Which TWO of the following are valid port states that Nmap can report? (Select 2)

Select 2 answers
A.Unknown
B.Secured
C.Open
D.Filtered
E.Blocked
AnswersC, D

An 'Open' port indicates that an application is actively listening for connections on that port on the target host. For TCP, this means Nmap successfully completed a three-way handshake, confirming the port is ready to accept incoming connections. For UDP, it typically means a response was received from the service, confirming its presence and readiness to process requests.

Why this answer

Nmap reports a port as Open (option C) when a TCP SYN/connect scan or UDP probe receives a response indicating a service is actively listening on that port, making it one of the six standard states (open, closed, filtered, unfiltered, open|filtered, closed|filtered). Nmap reports a port as Filtered (option D) when packet filtering (e.g., a firewall dropping packets) prevents Nmap from determining whether the port is open or closed, typically resulting in no response or an ICMP unreachable error. The other options are not part of Nmap's port state vocabulary: 'Unknown' (A) is not a state Nmap outputs, 'Secured' (B) is not an Nmap state, and 'Blocked' (E) is not used by Nmap—filtering is the term Nmap uses instead.

Exam trap

The trap here is that candidates confuse 'filtered' with generic terms like 'blocked' or 'secured', or assume Nmap uses a catch-all 'unknown' state, when in fact Nmap has a precise, limited set of six states that must be memorized for the CEH exam.

811
Multi-Selecteasy

Which TWO of the following are enumeration techniques?

Select 2 answers
A.Buffer overflow
B.Cross-site scripting
C.LDAP enumeration
D.SQL injection
E.SMTP enumeration
AnswersC, E

LDAP enumeration is a technique used to query Lightweight Directory Access Protocol (LDAP) services to extract detailed information about an organization's directory structure. This process can reveal valid usernames, group memberships, organizational units, and even password policies by sending specific queries to the LDAP server. Attackers leverage this information to map out the internal network, identify potential targets for credential stuffing, or understand the hierarchy for privilege escalation attempts. It is a critical step in gathering intelligence about user and system resources.

Why this answer

LDAP enumeration (C) is a valid enumeration technique because it queries directory services on port 389 (or 636 for LDAPS) to extract information such as user accounts, group memberships, and organizational structure via anonymous or authenticated binds. SMTP enumeration (E) is also a valid enumeration technique, using commands like VRFY, EXPN, and RCPT TO to discover valid email addresses and usernames on a mail server. Both techniques focus on gathering information about a target rather than exploiting it.

In contrast, buffer overflow (A), cross-site scripting (B), and SQL injection (D) are exploitation or attack techniques that compromise or manipulate a system, not enumeration methods.

Exam trap

EC-Council often tests the distinction between enumeration (passive or active information gathering) and exploitation (active attacks that compromise systems), so candidates mistakenly classify buffer overflow, XSS, or SQL injection as enumeration techniques when they are actually attack vectors.

812
MCQeasy

A company wants to test the security of its web application by simulating attacks from an external perspective. They have no prior knowledge of the internal network or application architecture. Which type of test should they perform?

A.Black-box test
B.White-box test
C.Red team engagement
D.Gray-box test
AnswerA

A black-box test simulates an external attacker with no prior knowledge of the target system's internal architecture, source code, or credentials. Testers interact with the web application solely through its public interfaces, mimicking real-world threat actors attempting to exploit vulnerabilities from the outside. This approach is ideal for assessing the effectiveness of perimeter defenses and identifying externally exploitable flaws, directly aligning with a company's goal to test its web application's security from an external perspective.

Why this answer

A black-box test is the correct choice because the company has no prior knowledge of the internal network or application architecture. This simulates an external attacker with zero insider information, testing the application from an outsider's perspective without access to source code, network diagrams, or credentials. The test relies solely on publicly available information and direct interaction with the application's interfaces.

Exam trap

The trap here is that candidates often confuse 'black-box test' with 'red team engagement', but red team engagements are broader and may include internal knowledge or physical attacks, whereas a black-box test strictly limits information to what is publicly available.

How to eliminate wrong answers

Option B (White-box test) is wrong because it requires full knowledge of the internal architecture, source code, and network design, which contradicts the 'no prior knowledge' condition. Option C (Red team engagement) is wrong because it is a broader, goal-oriented simulation that often includes social engineering and physical breaches, not solely an external web application test without internal knowledge. Option D (Gray-box test) is wrong because it involves partial knowledge (e.g., credentials or API documentation), which the company explicitly lacks.

813
MCQmedium

A network administrator notices an unusually high number of half-open TCP connections to the company's web server. The source IPs are spoofed. Which type of attack is MOST likely occurring?

A.Smurf attack
B.UDP flood
C.SYN flood
D.ICMP flood
AnswerC

A SYN flood is a classic denial-of-service attack that exploits the TCP three-way handshake. The attacker sends a large volume of TCP SYN (synchronize) requests to a target server but never completes the handshake by sending the final ACK (acknowledgment). This leaves numerous "half-open" connections in the server's memory, exhausting its connection table and preventing legitimate clients from establishing new connections, thus denying service.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IPs to the target server. The server responds with SYN-ACK packets and allocates resources for each half-open connection, exhausting its connection queue and preventing legitimate connections. The description of half-open TCP connections with spoofed source IPs is the classic signature of a SYN flood.

Exam trap

The trap here is that candidates confuse a SYN flood with a Smurf attack because both use spoofed IPs, but Smurf attacks rely on ICMP broadcast amplification, not TCP half-open connections.

How to eliminate wrong answers

Option A is wrong because a Smurf attack uses ICMP echo requests sent to a network's broadcast address with a spoofed victim IP, causing all hosts to reply to the victim, not half-open TCP connections. Option B is wrong because a UDP flood sends large numbers of UDP packets to random ports, overwhelming the target's bandwidth or processing, but does not involve TCP handshake states or half-open connections. Option D is wrong because an ICMP flood overwhelms the target with ICMP packets (e.g., ping floods), consuming bandwidth or CPU, but does not create half-open TCP connections.

814
MCQhard

A security team detects unusual outbound traffic from a host that appears to be a reverse shell. Which of the following Nmap features would be MOST effective for identifying the service running on the listening port of the command-and-control server?

A.UDP scan using the -sU flag
B.Nmap Scripting Engine (NSE) with the http-enum script
C.OS fingerprinting using the -O flag
D.Service version detection using the -sV flag
AnswerD

Service version detection using the -sV flag is the most appropriate technique as it actively probes open ports, collects service banners, and compares the responses against Nmap's extensive nmap-service-probes database. This method allows for the precise identification of the service name, version, and sometimes even the underlying protocol, even if it's an unusual or custom service like a reverse shell listening on a non-standard port. This direct service identification is critical for understanding the nature of the unusual outbound traffic.

Why this answer

The -sV flag instructs Nmap to perform service version detection by probing open ports and analyzing the responses to determine the exact application and version running on the listening port. In a reverse shell scenario, identifying the service (e.g., a specific SSH, HTTP, or custom listener) on the C2 server is critical for understanding the attack vector and planning remediation.

Exam trap

The trap here is that candidates confuse OS fingerprinting (-O) with service version detection (-sV), thinking that identifying the OS will reveal the service, but the CEH exam emphasizes that -sV is the dedicated flag for service and version identification on listening ports.

How to eliminate wrong answers

Option A is wrong because a UDP scan (-sU) is used to discover UDP services, but reverse shells typically use TCP for reliable communication, and UDP scanning would not effectively identify a TCP-based listening service. Option B is wrong because the http-enum script is designed to enumerate directories and files on HTTP/HTTPS services, but the C2 server may not be running a web service, and this script does not perform general service identification. Option C is wrong because OS fingerprinting (-O) determines the operating system of the target host, not the specific service or application version running on a listening port, which is irrelevant for identifying the C2 service.

815
MCQeasy

Which tool is specifically designed to create fake login pages for phishing campaigns and can be integrated with Metasploit?

A.Social Engineering Toolkit (SET)
B.Nmap
C.Wireshark
D.Ettercap
AnswerA

The Social Engineering Toolkit (SET) is explicitly designed for various social engineering attacks, including the creation of convincing fake login pages. Its "Web Attack Vectors" module, specifically the "Credential Harvester Attack," allows an attacker to clone legitimate websites, including their login forms. This cloned page then captures any credentials entered by unsuspecting victims, forwarding them to the attacker while often redirecting the user to the actual legitimate site to avoid suspicion.

Why this answer

The Social Engineering Toolkit (SET) is specifically designed to automate social engineering attacks, including the creation of fake login pages (credential harvesting) for phishing campaigns. It includes a built-in 'Website Attack Vectors' module that can clone legitimate sites and capture submitted credentials, and it offers direct integration with Metasploit to deliver payloads or establish reverse shells upon credential submission.

Exam trap

The CEH exam often tests the distinction between general-purpose tools (like Nmap or Wireshark) and specialized social engineering frameworks, leading candidates to confuse a network attack tool (Ettercap) with a phishing-specific tool like SET.

How to eliminate wrong answers

Option B is wrong because Nmap is a network scanning and reconnaissance tool used for port discovery and service enumeration, not for creating phishing pages or social engineering attacks. Option C is wrong because Wireshark is a network protocol analyzer used for packet capture and traffic inspection, not for generating fake login pages or integrating with Metasploit for phishing. Option D is wrong because Ettercap is a man-in-the-middle attack tool focused on ARP poisoning and packet sniffing on local networks, not for crafting phishing pages or credential harvesting via fake login forms.

816
MCQmedium

A security analyst observes the following log entry on a web server: 'GET /?url=http://169.254.169.254/latest/meta-data/ HTTP/1.1'. This request appears to originate from a compromised web application. Which cloud attack technique is being attempted?

A.Server-Side Request Forgery (SSRF)
B.SQL Injection
C.Container escape
D.Cross-Site Scripting (XSS)
AnswerA

Server-Side Request Forgery (SSRF) occurs when a web server is tricked into making requests to an arbitrary domain specified by an attacker. The log entry showing a request to `http://169.254.169.254/latest/meta-data/iam/security-credentials/` is a classic example targeting a cloud instance metadata service. This allows the attacker to obtain sensitive information, such as temporary IAM credentials, which can then be used to escalate privileges within the cloud environment.

Why this answer

The log shows a GET request with a 'url' parameter pointing to 'http://169.254.169.254/latest/meta-data/', which is the AWS Instance Metadata Service (IMDS) endpoint. An attacker is attempting to trick the server into making an HTTP request to this internal address on their behalf, a classic Server-Side Request Forgery (SSRF) attack. By accessing the metadata service, the attacker could retrieve sensitive information such as IAM credentials, instance identity documents, or user data.

The presence of the 'url' parameter strongly indicates the application is designed to fetch remote resources, and the attacker is abusing that functionality to reach internal-only services.

Exam trap

CEH often tests the confusion between SSRF and other injection attacks by presenting a URL that includes a parameter, leading candidates to mistakenly choose SQL Injection or XSS based on the presence of a query string.

How to eliminate wrong answers

Option B is wrong because SQL Injection involves injecting malicious SQL statements into input fields to manipulate a database, not crafting a URL to access an internal metadata endpoint. Option C is wrong because container escape refers to breaking out of a containerized environment to access the host system, which is unrelated to an HTTP request targeting a cloud metadata service. Option D is wrong because Cross-Site Scripting (XSS) attacks execute malicious scripts in a victim's browser, whereas this attack is executed server-side by the web application itself, not in a client browser.

817
MCQhard

An attacker sends a TCP SYN packet to a port and receives a TCP RST packet in response. According to Nmap's port state classification, what is the state of this port?

A.Filtered
B.Unfiltered
C.Closed
D.Open
AnswerC

When a TCP SYN packet is sent to a port that is not actively listening for connections, the target host's TCP/IP stack responds with a TCP RST (Reset) packet. This RST packet serves to immediately terminate the connection attempt, signaling to the sender that there is no application bound to that specific port. This is the standard and expected behavior for a closed port, making 'Closed' the correct answer when an RST is received after a SYN.

Why this answer

When Nmap sends a TCP SYN packet to a port and receives a TCP RST packet in response, it indicates that the port is reachable but no service is listening on it. Per RFC 793, a RST is sent when a SYN arrives on a closed port, so Nmap classifies this port as 'closed'.

Exam trap

EC-Council often tests the misconception that a RST response means the port is 'filtered' or 'open', but the correct interpretation per Nmap's classification is that a RST directly indicates a 'closed' port.

How to eliminate wrong answers

Option A is wrong because 'filtered' means the probe was dropped or blocked by a firewall or packet filter (no response or ICMP unreachable), not a TCP RST. Option B is wrong because 'unfiltered' is a special state used only in ACK scans (e.g., -sA) where the port is reachable but its open/closed status cannot be determined; it does not apply to a SYN scan receiving a RST. Option D is wrong because an 'open' port would respond with a SYN-ACK, not a RST.

818
MCQmedium

Refer to the exhibit. An analyst runs an Nmap scan and finds these services. Which known vulnerability is most likely to be successfully exploited?

A.CVE-2021-41773 (Apache Path Traversal)
B.CVE-2017-5638 (Struts2 RCE)
C.CVE-2014-0160 (Heartbleed)
D.CVE-2020-1472 (Zerologon)
AnswerA

This is the correct vulnerability because Apache HTTP Server version 2.4.49, as implied by the Nmap scan, is specifically susceptible to CVE-2021-41773. This critical path traversal vulnerability allows an attacker to map URLs to files outside the expected document root, potentially leading to information disclosure or, under certain configurations (e.g., if mod_cgi is enabled), remote code execution. The Nmap scan likely identified the precise Apache version, directly correlating it to this known flaw.

Why this answer

The exhibit shows Apache HTTP Server on port 80, which is vulnerable to CVE-2021-41773, a path traversal and file disclosure flaw in Apache HTTP Server 2.4.49. This vulnerability allows an attacker to use a specially crafted URL to traverse directories outside the document root, potentially reading sensitive files like /etc/passwd or executing arbitrary code if CGI scripts are enabled. The presence of Apache on port 80 directly aligns with this vulnerability, making it the most likely to be successfully exploited.

Exam trap

EC-CEH often tests the ability to match a specific service (e.g., Apache HTTP on port 80) with its corresponding CVE, rather than assuming a generic web vulnerability, so candidates may incorrectly choose Heartbleed (port 443) or Struts2 (Java framework) without verifying the service type.

How to eliminate wrong answers

Option B is wrong because CVE-2017-5638 (Struts2 RCE) targets Apache Struts2, a Java-based web application framework, not the Apache HTTP Server shown on port 80; the exhibit shows no evidence of Struts2 services. Option C is wrong because CVE-2014-0160 (Heartbleed) is a vulnerability in OpenSSL versions 1.0.1 through 1.0.1f, affecting HTTPS services on port 443, but the exhibit only lists port 80 (HTTP) with no SSL/TLS service. Option D is wrong because CVE-2020-1472 (Zerologon) is a privilege escalation vulnerability in Microsoft Netlogon Remote Protocol (MS-NRPC) used in Active Directory domain controllers, which is unrelated to the Apache HTTP service on port 80.

819
MCQmedium

After compromising a system, an attacker wants to erase their tracks. They clear the Windows Event Logs using `wevtutil cl` commands. However, the logs are forwarded to a remote SIEM. Which covering tracks technique would be MOST effective to avoid detection?

A.Modify specific event log entries to remove evidence of their actions
B.Disable Windows Event Log service (EventLog)
C.Use a rootkit to hide files and processes
D.Encrypt the log files
AnswerA

Modifying specific event log entries is the most sophisticated method for post-compromise evidence removal, as it allows for targeted deletion. Attackers employ specialized tools to parse event logs, identify incriminating entries related to their activities—such as failed logins, privilege escalation, or command execution—and then selectively delete or alter these records. This technique maintains the appearance of normal system operation by leaving benign log data intact, making detection by SIEMs or forensic analysts significantly more challenging than simply clearing all logs.

Why this answer

Modifying specific event log entries directly removes the incriminating evidence without disrupting the logging pipeline. Since logs are forwarded to a remote SIEM, simply clearing or disabling local logs would trigger an alert due to a gap in log forwarding. By surgically editing only the relevant entries (e.g., using PowerShell or API calls to alter Event Log records), the attacker avoids detection while the SIEM continues to receive logs, maintaining the appearance of normal operation.

Exam trap

The trap here is that candidates often assume clearing logs (wevtutil cl) is sufficient, but the question explicitly states logs are forwarded to a remote SIEM, making any disruption to the log stream (disabling, encrypting, or clearing) a red flag, whereas targeted modification of entries is stealthier and avoids breaking the forwarding pipeline.

How to eliminate wrong answers

Option B is wrong because disabling the Windows Event Log service (EventLog) would stop all log generation and forwarding, causing the SIEM to immediately detect a missing heartbeat or log gap, which is a strong indicator of compromise. Option C is wrong because a rootkit hides files and processes but does not alter or remove existing event log entries; the incriminating log data would still be present and forwarded to the SIEM. Option D is wrong because encrypting the log files would render them unreadable locally and likely break the forwarding pipeline, again creating a detectable anomaly in the SIEM's log stream.

820
MCQhard

During a forensic investigation, an analyst retrieves a suspicious executable. Running 'strings' reveals no readable text, and VirusTotal shows zero detections. However, when executed in a sandbox, the binary connects to a remote IP and injects code into 'explorer.exe'. Which conclusion is MOST accurate?

A.The file is a worm because it connects to a remote IP
B.The file is likely a packed trojan that evades signature-based detection
C.The file is benign because static analysis found no indicators
D.The file is a false positive and the sandbox environment is compromised
AnswerB

The absence of discernible strings during static analysis and zero detections by antivirus engines strongly suggest the file is packed or heavily obfuscated to evade signature-based detection. Subsequent dynamic analysis in a sandbox environment, revealing malicious behaviors such as network connections to suspicious IPs or process injection, confirms its true malicious intent. These combined indicators are highly characteristic of a packed trojan designed to bypass initial security checks and execute its payload.

Why this answer

The absence of readable strings and zero VirusTotal detections strongly suggest the executable is packed or obfuscated, a common evasion technique used by trojans. The sandbox behavior—connecting to a remote IP and injecting code into explorer.exe—confirms malicious intent, specifically trojan-like remote access and process injection. This combination of static stealth and dynamic malicious activity indicates a packed trojan designed to bypass signature-based antivirus.

Exam trap

The trap here is that candidates assume 'no static indicators' means the file is benign, ignoring that packing is a deliberate evasion technique, and that dynamic analysis (sandbox execution) is essential to uncover hidden malicious behavior.

How to eliminate wrong answers

Option A is wrong because connecting to a remote IP alone does not define a worm; worms self-replicate and spread autonomously, whereas this file exhibits trojan behavior (remote access and code injection). Option C is wrong because static analysis (e.g., 'strings') is insufficient to declare a file benign; packed malware intentionally hides indicators, and dynamic analysis revealed malicious activity. Option D is wrong because the sandbox environment is not compromised; the binary's outbound connection and injection are consistent with malware behavior, not a false positive from a compromised sandbox.

821
Multi-Selecthard

Which THREE of the following are methods for covering tracks after compromising a system? (Select 3)

Select 3 answers
A.Installing a rootkit to hide files and processes
B.Escalating privileges to SYSTEM
C.Disabling antivirus software
D.Using steganography to hide stolen data in images
E.Clearing event logs
AnswersA, D, E

Installing a rootkit is a sophisticated method for covering tracks, as a rootkit is a collection of tools designed to obtain and maintain privileged access to a computer while actively hiding its presence. By modifying core operating system components, rootkits can conceal malicious files, running processes, network connections, and even user accounts from standard system utilities and security software. This makes it extremely difficult for forensic investigators to detect the attacker's activities and persistence mechanisms, effectively covering their tracks post-compromise.

Why this answer

Installing a rootkit is a classic method for covering tracks because it operates at the kernel or user level to intercept system calls (e.g., NtQuerySystemInformation on Windows) and hide malicious files, processes, registry keys, and network connections from standard enumeration tools like Task Manager or netstat. This prevents the victim from detecting the compromise during routine monitoring.

Exam trap

EC-CEH often tests the distinction between actions taken during the attack (privilege escalation, disabling AV) and actions taken after the attack to erase evidence (clearing logs, hiding files with rootkits, steganography), so candidates mistakenly select privilege escalation or AV disabling as track-covering methods.

822
Multi-Selecteasy

A penetration tester successfully gains access to a Linux server as a low-privilege user. The goal is to escalate to root. Which THREE methods could the tester use to achieve privilege escalation?

Select 3 answers
A.Enumerate SUID binaries with 'find / -perm -4000'
B.Exploit a vulnerable SUID binary to spawn a root shell
C.Use 'sudo -l' to list allowed commands and exploit misconfigurations
D.Check /etc/shadow for weak password hashes
E.Run a local kernel exploit that matches the kernel version
AnswersB, C, E

Exploiting a vulnerable SUID binary is a direct and highly effective privilege escalation technique. If a program designed to run with root privileges (due to its SUID bit) contains a flaw, such as a buffer overflow, path injection, or insecure file handling, an attacker can manipulate it to execute arbitrary code. This allows the attacker to spawn a shell with root permissions, effectively gaining full control over the system.

Why this answer

Option B is correct because a SUID binary executes with the file owner's privileges (typically root), so exploiting a vulnerable SUID program (e.g., via GTFOBins techniques or buffer overflow) can yield a root shell. Option C is correct because 'sudo -l' reveals the sudoers permissions for the current user, and misconfigurations such as NOPASSWD entries or allowed binaries like vim, find, or less can be abused to spawn a root shell. Option E is correct because a local kernel exploit matching the exact kernel version (verified with 'uname -r') can leverage a known vulnerability such as Dirty COW (CVE-2016-5195) or PwnKit to escalate to root.

Option A is not a privilege escalation method by itself; 'find / -perm -4000' is only an enumeration step that identifies SUID binaries, which must then be exploited as in option B. Option D does not belong because /etc/shadow is normally readable only by root, so a low-privilege user cannot read the hashes; even if obtained, cracking them yields credentials rather than a direct escalation path.

Exam trap

The trap here is that candidates mistake enumeration commands (like 'find / -perm -4000') for actual exploitation methods, or they assume /etc/shadow is accessible to low-privilege users without realizing it is root-protected.

823
MCQmedium

A penetration tester is assessing a web application and notices that the application reflects the User-Agent header in the response body without sanitization. What attack could be performed using this behavior?

A.Cross-Site Scripting (XSS)
B.Directory traversal
C.Server-Side Request Forgery (SSRF)
D.SQL injection
AnswerA

If a web application reflects unsanitized user-controlled input, such as the User-Agent HTTP header, directly into the HTML response, it creates a reflected Cross-Site Scripting (XSS) vulnerability. An attacker can inject malicious client-side scripts (e.g., JavaScript) into the User-Agent string. When another user's browser renders this page, the injected script executes within their browser's security context, potentially leading to session hijacking, defacement, or redirection.

Why this answer

Reflecting unsanitized input in HTTP headers can lead to reflected XSS.

824
MCQmedium

Which cloud security assessment tool is specifically designed to audit AWS environments against best practices and CIS benchmarks?

A.Pacu
B.ScoutSuite
C.Nessus
D.Metasploit
AnswerB

ScoutSuite is an open-source multi-cloud security auditing tool specifically engineered to assess the security posture of cloud environments across major providers like AWS, Azure, GCP, Alibaba Cloud, and OCI. It achieves this by leveraging cloud provider APIs to collect configuration data and then identifies security 'findings' or misconfigurations against a comprehensive set of predefined best practices and compliance rules. The tool generates an interactive HTML report, highlighting potential attack surfaces and compliance deviations within the cloud infrastructure.

Why this answer

ScoutSuite is an open-source multi-cloud security auditing tool that natively supports AWS and evaluates configurations against CIS benchmarks and security best practices. It uses read-only API calls to enumerate resources and produces an HTML report highlighting misconfigurations such as public S3 buckets, overly permissive IAM policies, and unencrypted volumes. This makes it the correct answer for auditing AWS against CIS benchmarks.

Exam trap

CEH often tests the distinction between offensive cloud tools (Pacu) and defensive auditing tools (ScoutSuite, Prowler), so candidates who see 'AWS' and 'penetration testing' context may incorrectly choose Pacu.

How to eliminate wrong answers

Option A is wrong because Pacu is an AWS exploitation framework used for post-exploitation and privilege escalation during penetration tests, not for CIS benchmark auditing. Option C is wrong because Nessus is a general-purpose vulnerability scanner that checks hosts and services for CVEs, not cloud configuration posture against CIS benchmarks. Option D is wrong because Metasploit is an exploitation framework for delivering payloads and exploiting vulnerabilities, not a cloud configuration auditing tool.

825
MCQeasy

A security analyst runs the command `nbtstat -A 192.168.1.105` on a Windows machine. What information is the analyst most likely trying to gather?

A.The NetBIOS name table and MAC address of the remote host
B.The LDAP directory structure of the domain
C.The SNMP community strings of the target
D.The SMB shares available on the remote host
AnswerA

The `nbtstat -a` (or `-A`) command is specifically designed to display the NetBIOS name table of a remote computer, identified by its IP address. This table includes registered NetBIOS names, their types, and crucially, the MAC address associated with the network interface. It provides valuable information for identifying systems and services relying on NetBIOS over TCP/IP, making it a direct and effective reconnaissance tool for this protocol.

Why this answer

The `nbtstat -A` command performs a NetBIOS name table lookup against the specified IP address using the NetBIOS over TCP/IP (NBT) protocol. It returns the remote host's NetBIOS name table, which includes registered names and services, along with the MAC address of the network adapter. This is a standard enumeration technique to identify the hostname, logged-in user, and other NetBIOS-related information.

Exam trap

The trap here is that candidates confuse `nbtstat -A` with `net view` or `nbtstat -a`, mistakenly thinking it lists SMB shares or uses a hostname instead of an IP address, when in fact `-A` specifically targets a remote IP and returns the NetBIOS name table and MAC.

How to eliminate wrong answers

Option B is wrong because LDAP directory structure is queried using LDAP-specific tools like `ldapsearch` or `nslookup` with SRV records, not `nbtstat`. Option C is wrong because SNMP community strings are obtained via SNMP enumeration tools like `snmpwalk` or `snmpenum`, not through NetBIOS commands. Option D is wrong because SMB shares are enumerated using commands like `net view` or tools like `smbclient`, while `nbtstat` only reveals NetBIOS names and MAC addresses, not share listings.

Page 10

Page 11 of 13

Page 12