Courseiva
' and the…","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-web-application-penetration-test-a-tester-submits-ugc94"},{"@type":"ListItem","position":311,"name":"An attacker uses the following URL pattern to access files: http://example.com/../../etc/passwd. Which attack is being a…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-attacker-uses-the-following-url-pattern-to-access-files-a4r3c"},{"@type":"ListItem","position":312,"name":"Which THREE of the following are valid methods to prevent a downgrade attack on TLS? (Select 3)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-of-the-following-are-valid-methods-to-prevent-a-py91u"},{"@type":"ListItem","position":313,"name":"Refer to the exhibit. An ethical hacker runs the shown Nmap scan against a target. Which port state indicates that the p…","url":"https://courseiva.com/questions/ec-council/ec-ceh/refer-to-the-exhibit-an-ethical-hacker-runs-the-shown-nmap-etlqk"},{"@type":"ListItem","position":314,"name":"Which password cracking technique involves trying every possible combination of characters until the correct password is…","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-password-cracking-technique-involves-trying-every-poss-51cgo"},{"@type":"ListItem","position":315,"name":"Which cryptographic algorithm is vulnerable to a birthday attack on its hash output size of 128 bits, reducing the effec…","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-cryptographic-algorithm-is-vulnerable-to-a-birthday-at-bsu7u"},{"@type":"ListItem","position":316,"name":"An application allows users to upload XML files for processing. A tester uploads the following payload: ' and the script executes for all users who view the comment. Which type of cross-site sc","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-web-application-penetration-test-a-tester-submits-ugc94","acceptedAnswer":{"@type":"Answer","text":"Stored (persistent) XSS","comment":{"@type":"Comment","text":"Stored, or persistent, XSS is the most dangerous type, as the malicious script is permanently saved on the target server, typically in a database, comment section, or forum post. Once stored, the payload is delivered to every user who accesses the affected web page, without requiring any further interaction from the attacker. This allows for widespread and long-term compromise, as the script executes automatically each time the vulnerable content is rendered by a user's browser."}},"suggestedAnswer":[{"@type":"Answer","text":"Blind XSS","comment":{"@type":"Comment","text":"Blind XSS is a specific subtype of stored XSS where the malicious payload is saved on the server but executes in a context not directly visible to the attacker, such as an administrative backend or a logging system. The attacker typically doesn't receive an immediate visual confirmation of execution. While it involves storage, the key differentiator is the delayed and out-of-band execution, often requiring an external callback mechanism to confirm success. This differs from a general stored XSS where the script might execute for any user viewing the affected page."}},{"@type":"Answer","text":"Reflected XSS","comment":{"@type":"Comment","text":"Reflected XSS involves a malicious script being embedded in a request and then immediately \"reflected\" back in the server's response to the user's browser without being permanently stored on the server. The payload is typically delivered via a URL parameter or form input and only executes for the user who made the specific request. This non-persistent nature means the attacker must trick each victim into clicking a specially crafted link to trigger the vulnerability."}},{"@type":"Answer","text":"DOM-based XSS","comment":{"@type":"Comment","text":"DOM-based XSS occurs entirely on the client-side, where the vulnerability arises from client-side JavaScript manipulating the Document Object Model (DOM) in an unsafe manner. Unlike reflected or stored XSS, the payload might not even be sent to the server or stored there; instead, it's processed by the browser's JavaScript engine. The malicious script executes due to client-side code dynamically writing untrusted data into the DOM, often from URL fragments or local storage."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"An attacker uses the following URL pattern to access files: http://example.com/../../etc/passwd. Which attack is being attempted?","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-attacker-uses-the-following-url-pattern-to-access-files-a4r3c","acceptedAnswer":{"@type":"Answer","text":"Directory traversal","comment":{"@type":"Comment","text":"Directory traversal, also known as path traversal, is an attack that allows an attacker to access files and directories stored outside the intended web root directory. This is achieved by manipulating variables that reference files with \"dot-dot-slash\" (`../`) sequences, or similar absolute path representations, to navigate the file system. The URL pattern `../` precisely exemplifies this technique, enabling the attacker to move up the directory hierarchy to access unauthorized files."}},"suggestedAnswer":[{"@type":"Answer","text":"Command injection","comment":{"@type":"Comment","text":"Command injection vulnerabilities allow an attacker to execute arbitrary operating system commands on the host server by injecting malicious input into an application. This typically occurs when an application passes user-supplied data directly to a system shell without proper sanitization. The provided URL pattern `../` is a path manipulation technique used to traverse directories, not to inject and execute system commands, making this option incorrect."}},{"@type":"Answer","text":"Local file inclusion (LFI)","comment":{"@type":"Comment","text":"Local File Inclusion (LFI) is a vulnerability where an application includes a local file specified by the user, often leading to information disclosure or remote code execution. While LFI attacks frequently utilize directory traversal techniques (like `../`) to specify the target file's path, the question specifically describes the *method* of path manipulation itself. The URL pattern `../` is the direct indicator of a directory traversal attempt, which is a technique, whereas LFI is a broader vulnerability class."}},{"@type":"Answer","text":"Remote file inclusion (RFI)","comment":{"@type":"Comment","text":"Remote File Inclusion (RFI) is a vulnerability that allows an attacker to include a remote file, usually via a URL, on the vulnerable server. This typically leads to remote code execution as the server fetches and executes code from an external source. The URL pattern `../` is exclusively used for navigating *local* file system paths, not for specifying or including files from a remote server, making it distinct from RFI."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Which THREE of the following are valid methods to prevent a downgrade attack on TLS? (Select 3)","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-three-of-the-following-are-valid-methods-to-prevent-a-py91u","acceptedAnswer":{"@type":"Answer","text":"Disable TLS 1.0 and 1.1 on the server","comment":{"@type":"Comment","text":"Disabling specific older TLS versions like 1.0 and 1.1 on the server directly removes the server's capability to negotiate these protocols. If the server does not support or offer these versions, an attacker cannot force a client and server to communicate using them, thereby eliminating the target for a downgrade attack. This is a fundamental server-side configuration best practice for security."}},"suggestedAnswer":[{"@type":"Answer","text":"Use self-signed certificates to avoid CA trust issues","comment":{"@type":"Comment","text":"Using self-signed certificates does not prevent TLS version downgrade attacks; their primary function is to establish identity, not to enforce protocol versions. While they can avoid reliance on commercial Certificate Authorities, they introduce significant trust issues as clients must explicitly trust them, often leading to security warnings or manual trust additions. Improper validation of self-signed certificates can actually facilitate Man-in-the-Middle attacks rather than prevent them."}},{"@type":"Answer","text":"Disable all cipher suites except those using RC4","comment":{"@type":"Comment","text":"Disabling all cipher suites except those using RC4 is a highly insecure practice and does not prevent TLS version downgrade attacks. RC4 is a stream cipher known to be cryptographically weak and susceptible to various attacks, including biases in its keystream. Furthermore, cipher suite selection operates within a negotiated TLS version; a downgrade attack specifically targets the *protocol version* itself, forcing the use of an older, vulnerable protocol like TLS 1.0 or SSLv3, regardless of the cipher suites available within that version."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Refer to the exhibit. An ethical hacker runs the shown Nmap scan against a target. Which port state indicates that the port is reachable but no service is listening?","url":"https://courseiva.com/questions/ec-council/ec-ceh/refer-to-the-exhibit-an-ethical-hacker-runs-the-shown-nmap-etlqk","acceptedAnswer":{"@type":"Answer","text":"closed","comment":{"@type":"Comment","text":"A 'closed' port indicates that the target host is reachable and received Nmap's probe, but no application is currently listening on that specific port. For TCP scans, the target typically responds with an RST (reset) packet, confirming the port's accessibility while explicitly stating that no service is active there. This state is crucial as it differentiates between an inactive port and one that is blocked by a firewall, accurately reflecting the scenario where the host is up but the service is not running."}},"suggestedAnswer":[{"@type":"Answer","text":"open","comment":{"@type":"Comment","text":"An 'open' state signifies that a target port has an application actively listening for incoming connections. Nmap successfully completed a full TCP three-way handshake or received an expected response for UDP, confirming that the port is accessible and a service is ready to accept communication. This indicates a potential entry point for further enumeration and vulnerability assessment, but it is not the state depicted in the exhibit for the relevant port."}},{"@type":"Answer","text":"filtered","comment":{"@type":"Comment","text":"A 'filtered' state occurs when Nmap cannot definitively determine if a port is open or closed because a firewall, router, or other network security device is actively preventing the probe packets from reaching the target or blocking the response. This often results in Nmap receiving no response at all, or an ICMP unreachable error, indicating that the probe was dropped. This state suggests the presence of a protective mechanism, hindering direct port status assessment."}},{"@type":"Answer","text":"unfiltered","comment":{"@type":"Comment","text":"An 'unfiltered' state is primarily observed during an Nmap ACK scan, which is specifically designed to map firewall rulesets rather than ascertain if a service is listening. This state indicates that the port is accessible and not being blocked by a firewall, as the ACK probe successfully elicited an RST response. However, it provides no information about whether an application is actually listening on that port, making it distinct from 'open' or 'closed' states in terms of service availability."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Which password cracking technique involves trying every possible combination of characters until the correct password is found?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-password-cracking-technique-involves-trying-every-poss-51cgo","acceptedAnswer":{"@type":"Answer","text":"Brute force attack","comment":{"@type":"Comment","text":"A brute force attack is a systematic password cracking technique that attempts every possible character combination within a defined character set and length until the correct password is found. This method guarantees finding the password if given enough time and computational resources, as it exhaustively explores the entire search space. Its primary drawback is the immense computational power and time required, especially for longer and more complex passwords."}},"suggestedAnswer":[{"@type":"Answer","text":"Rainbow table attack","comment":{"@type":"Comment","text":"A rainbow table attack leverages precomputed hash chains to reverse a hash into its plaintext password. Instead of exhaustively guessing, it performs a lookup against a massive database of pre-calculated hash-to-plaintext mappings. This method exploits a time-memory tradeoff, significantly speeding up the cracking process for common passwords by avoiding real-time computation of every possible combination."}},{"@type":"Answer","text":"Dictionary attack","comment":{"@type":"Comment","text":"A dictionary attack attempts to crack passwords by systematically trying entries from a predefined list of common words, phrases, and previously leaked passwords. This technique relies on the prevalence of weak, easily guessable passwords found in dictionaries or public data breaches. It is highly efficient for common passwords but does not explore the entire character space, making it ineffective against complex, unique passwords."}},{"@type":"Answer","text":"Hybrid attack","comment":{"@type":"Comment","text":"A hybrid attack combines elements of both dictionary and brute force methods to enhance cracking efficiency. It typically starts with a dictionary wordlist and then systematically appends or prepends numbers, symbols, or common character variations to each dictionary entry. This approach targets common password patterns, such as 'password123' or 'Summer!', without resorting to a full, unconstrained exhaustive search of all possible character combinations."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Which cryptographic algorithm is vulnerable to a birthday attack on its hash output size of 128 bits, reducing the effective security to 64 bits against collision resistance?","url":"https://courseiva.com/questions/ec-council/ec-ceh/which-cryptographic-algorithm-is-vulnerable-to-a-birthday-at-bsu7u","acceptedAnswer":{"@type":"Answer","text":"MD5","comment":{"@type":"Comment","text":"MD5 produces a 128-bit hash value, which means its collision resistance against a birthday attack is approximately 2^64 operations. This level of complexity is well within the reach of modern computing resources, allowing for practical collision finding within a reasonable timeframe. Consequently, MD5 is widely considered cryptographically broken and highly vulnerable to birthday attacks, making it unsuitable for security-critical applications requiring collision resistance."}},"suggestedAnswer":[{"@type":"Answer","text":"SHA-256","comment":{"@type":"Comment","text":"SHA-256, while theoretically susceptible to a birthday attack as a hash function, produces a 256-bit output. This large output size provides a collision resistance of approximately 2^128, meaning finding a collision using current computational capabilities is practically infeasible. Therefore, SHA-256 is considered robust against birthday attacks and is not deemed vulnerable in a practical sense."}},{"@type":"Answer","text":"SHA-1","comment":{"@type":"Comment","text":"SHA-1 generates a 160-bit hash output, which implies a theoretical birthday attack collision resistance of 2^80 operations. Although significantly weaker than SHA-256, achieving a practical collision for SHA-1 using a birthday attack still demands immense computational resources and specialized hardware. While theoretical weaknesses exist and practical attacks have been demonstrated, it is not the most vulnerable option presented, especially compared to MD5."}},{"@type":"Answer","text":"RC4","comment":{"@type":"Comment","text":"RC4 is a stream cipher, a type of cryptographic algorithm designed for encrypting data streams by generating a pseudorandom keystream. The birthday attack specifically targets hash functions by exploiting the probability of finding two different inputs that produce the same fixed-size output hash. Since RC4 does not produce hash outputs and is not designed for collision resistance, the concept of a birthday attack does not apply to its functionality."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"An application allows users to upload XML files for processing. A tester uploads the following payload: ]>&xxe;

Certified Ethical Hacker CEH (CEH) — Questions 301–375

913 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQhard

A security analyst observes the following in a packet capture: a single source IP sends a large number of ICMP echo request packets to the broadcast address of a subnet, with the source IP spoofed to be the target victim. Which type of attack is being executed?

A.Smurf attack
B.SYN flood
C.Ping of Death
D.ICMP flood
AnswerA

A Smurf attack is a classic denial-of-service technique that exploits ICMP echo requests and network broadcast addresses. The attacker sends ICMP echo requests to a network's broadcast address, spoofing the source IP to be the victim's address. All hosts on that broadcast network then reply to the victim's spoofed IP, creating a massive flood of ICMP echo replies that overwhelms the victim's network bandwidth and resources.

Why this answer

The Smurf attack exploits IP broadcast addressing and ICMP. The attacker sends a large volume of ICMP echo request packets with the source IP spoofed to be the victim's IP address, directed to the subnet's broadcast address. Every host on that subnet replies to the victim, overwhelming it with ICMP echo reply traffic, effectively amplifying the attack.

Exam trap

The trap here is confusing a Smurf attack with a standard ICMP flood, but the key differentiator is the use of a broadcast address and IP spoofing to achieve amplification, which is unique to the Smurf attack.

How to eliminate wrong answers

Option B is wrong because a SYN flood targets the TCP three-way handshake by sending numerous SYN packets without completing the handshake, exhausting server resources; it does not use ICMP or broadcast addresses. Option C is wrong because a Ping of Death involves sending an oversized ICMP packet (greater than 65535 bytes) to cause a buffer overflow, not leveraging broadcast amplification or spoofed source IPs. Option D is wrong because an ICMP flood is a direct denial-of-service attack where the attacker sends a high volume of ICMP packets from their own IP (or a botnet) to saturate bandwidth, but it does not use broadcast amplification or spoof the victim's IP as the source.

302
Multi-Selecthard

Which THREE of the following are common indicators of a Server-Side Request Forgery (SSRF) vulnerability? (Select 3)

Select 3 answers
A.The server returns data from internal services like http://localhost/ or http://192.168.x.x/
B.The application supports file:// or dict:// URL schemes in user input
C.The application reflects user input in the page source without encoding
D.The application accepts a URL parameter that is fetched by the server
E.The server responds with a different delay when a URL is provided versus a non-URL input
AnswersA, B, D

A strong indicator of SSRF is when the server's response to an external request inadvertently includes data or error messages that clearly originate from internal network addresses, such as http://localhost/ or http://192.168.x.x/. This suggests the application processed a user-supplied URL that pointed to an internal resource, and then relayed the internal resource's content or status back to the attacker, confirming the server's ability to access and return data from its private network.

Why this answer

SSRF often involves requests to internal IPs or services, use of URL schemas like file://, and responses including internal data.

303
MCQhard

During a penetration test, you gain initial access to a Linux server as a low-privileged user. The target runs a vulnerable SUID binary owned by root. Which of the following is the MOST effective method to escalate privileges?

A.Perform an SMTP VRFY attack to enumerate users
B.Exploit the SUID binary to execute commands as root
C.Use enum4linux to enumerate SMB shares
D.Run 'sudo -l' to list sudo privileges
AnswerB

A SUID binary owned by root executes with root's effective UID regardless of the invoking user. Exploiting it to run commands therefore yields a root shell directly, which is more reliable than kernel exploits or misconfigured cron jobs.

Why this answer

The SUID binary owned by root runs with root privileges regardless of the user executing it. Exploiting a vulnerable SUID binary (e.g., via command injection, buffer overflow, or misconfigured capabilities) allows the low-privileged user to execute arbitrary commands as root, directly escalating privileges. This is the most effective method because it leverages a known privilege escalation vector specific to Linux SUID binaries.

Exam trap

The trap here is that candidates confuse enumeration techniques (SMTP VRFY, enum4linux) or standard sudo checks with direct privilege escalation methods, overlooking the immediate root-level access provided by exploiting a vulnerable SUID binary.

How to eliminate wrong answers

Option A is wrong because SMTP VRFY is an email user enumeration technique used against SMTP servers (RFC 2821), not a method to escalate privileges on a Linux server. Option C is wrong because enum4linux is a tool for enumerating SMB shares and user information from Windows systems (via SMB/CIFS), not applicable to a Linux target without Samba services. Option D is wrong because 'sudo -l' lists sudo privileges for the current user, but the question states the user is low-privileged and does not mention any sudo access; relying on sudo is ineffective if the user has no sudo entries.

304
MCQmedium

A penetration tester discovers a Linux server with the SUID bit set on the 'find' command. How could this be exploited for privilege escalation?

A.By using 'find' to delete log files
B.By using 'find' to search for files owned by root
C.By using 'find' to mount a remote share
D.By running 'find / -exec /bin/sh \;' to spawn a root shell
AnswerD

Because 'find' carries the SUID bit and is owned by root, executing it runs with root's effective UID. The -exec flag then launches /bin/sh inheriting that elevated privilege, spawning an interactive root shell and completing local privilege escalation from an unprivileged account.

Why this answer

When the SUID bit is set on the 'find' command, it executes with the privileges of the file owner (typically root). The '-exec' option allows arbitrary command execution. Running 'find / -exec /bin/sh \;' spawns a shell with root privileges, enabling full system compromise.

Exam trap

The trap here is that candidates may think SUID only applies to obvious binaries like 'passwd' or 'sudo', but CEH tests the lesser-known fact that any binary with SUID and command execution capability (like 'find' with '-exec') can be exploited for privilege escalation.

How to eliminate wrong answers

Option A is wrong because deleting log files does not leverage the SUID bit for privilege escalation; it only removes audit trails and does not grant elevated privileges. Option B is wrong because searching for files owned by root is a normal operation that does not exploit the SUID bit to gain a root shell. Option C is wrong because 'find' does not have built-in functionality to mount remote shares; mounting requires the 'mount' command or similar utilities, and the SUID bit on 'find' does not enable network filesystem mounting.

305
MCQhard

During a penetration test, an analyst uses enum4linux with the -a flag against a target. Which of the following is the MOST comprehensive set of information that can be obtained?

A.Only the domain admins and local admins
B.User list, share list, OS information, password policy, and group memberships
C.Only the SMB shares and open sessions
D.Only the NetBIOS name table
AnswerB

The '-a' (all) option in enum4linux is specifically designed to perform a full suite of enumeration functions against a target Windows or Samba system. This includes gathering a detailed user list, available SMB share names, operating system version information, the configured password policy, and comprehensive group memberships for identified users and groups. This comprehensive output provides critical intelligence for subsequent penetration testing phases.

Why this answer

enum4linux with the -a flag performs a comprehensive enumeration against a target, leveraging SMB, RPC, and NetBIOS over TCP/IP. It retrieves user lists, share lists, OS information, password policy details, and group memberships by querying the remote Windows system via SMB RPC calls (e.g., SAMR, LSA, SRVSVC). This makes it the most complete set of information obtainable from a single command, as the -a flag essentially runs all available enumeration modules.

Exam trap

The trap here is that candidates often assume enum4linux -a only retrieves shares or NetBIOS data, underestimating its full scope of SMB/RPC-based enumeration that includes users, groups, OS details, and password policy.

How to eliminate wrong answers

Option A is wrong because enum4linux -a retrieves far more than just domain admins and local admins; it enumerates all users, groups, shares, OS details, and password policy, not just administrative accounts. Option C is wrong because enum4linux -a does not limit itself to SMB shares and open sessions; it also retrieves user lists, OS information, password policy, and group memberships, making this option incomplete. Option D is wrong because enum4linux -a goes well beyond the NetBIOS name table; it performs deep SMB and RPC enumeration, including user and share enumeration, which is not captured by NetBIOS alone.

306
MCQhard

During an internal penetration test, you are tasked with enumerating services on a target server. You run a full TCP port scan and find that ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) are open. You then perform version detection on these ports. Which additional enumeration step would provide the most valuable information for identifying potential vulnerabilities?

A.Perform banner grabbing on port 22 to identify the SSH version.
B.Perform SNMP enumeration to gather system information.
C.Attempt a DNS zone transfer from the server.
D.Enumerate NetBIOS names using `nbtstat`.
AnswerA

Banner grabbing on port 22, typically used for SSH, is a fundamental reconnaissance technique. By connecting to the port and observing the initial response, an attacker can identify the specific SSH server software and its version number. This version information is crucial for cross-referencing against public vulnerability databases (e.g., CVEs) to discover known exploits, potentially leading to unauthorized access or privilege escalation if an outdated or misconfigured version is in use.

Why this answer

Banner grabbing on port 22 (SSH) is the most valuable next step because it directly identifies the SSH server version (e.g., OpenSSH 7.4). Knowing the exact version allows you to cross-reference known vulnerabilities (CVEs) for that specific SSH implementation, which is a common high-risk attack vector during internal penetration tests. While version detection already identified the service, banner grabbing can reveal additional details like patch levels or configuration quirks that version detection might miss.

Exam trap

EC-Council often tests the misconception that SNMP, DNS zone transfers, or NetBIOS enumeration are universally applicable, but the trap here is that these techniques only work when the corresponding services are actually running and accessible — the question explicitly limits open ports to 22, 80, and 443, so only banner grabbing on those ports is directly actionable.

How to eliminate wrong answers

Option B is wrong because SNMP enumeration requires SNMP (UDP ports 161/162) to be open, and the scan only found TCP ports 22, 80, and 443 — no SNMP service was detected, so this step would fail or provide no useful data. Option C is wrong because DNS zone transfer requires a DNS server (typically port 53) to be present and configured to allow transfers; the target server does not have DNS open, so this attempt would be irrelevant. Option D is wrong because NetBIOS enumeration (using nbtstat) relies on NetBIOS over TCP/IP (ports 137-139, 445), which are not open on the target; this technique is only applicable to Windows systems with NetBIOS enabled, not to a server with only SSH, HTTP, and HTTPS.

307
MCQeasy

Which of the following tools is specifically designed to automate the exploitation of SQL injection vulnerabilities and retrieve data from databases?

A.Metasploit
B.Nmap
C.Burp Suite
D.SQLMap
AnswerD

SQLMap is the industry-standard open-source penetration testing tool specifically designed to automate the process of detecting and exploiting SQL injection flaws and taking over database servers. It supports a wide array of SQL injection techniques, including boolean-based blind, time-based blind, error-based, UNION query, stacked queries, and out-of-band injections across various database management systems. Its robust capabilities extend beyond mere detection, enabling database fingerprinting, data fetching, file system access, and even command execution on the underlying operating system, making it highly specialized for this attack vector.

Why this answer

SQLMap is a purpose-built open-source penetration testing tool that automates the detection and exploitation of SQL injection vulnerabilities and can enumerate and dump database contents. It supports a wide range of DBMS backends (MySQL, MSSQL, Oracle, PostgreSQL) and injection techniques (boolean-based, time-based, UNION, error-based). This makes it the correct answer for automating SQLi exploitation and data retrieval.

Exam trap

CEH often tests the distinction between general-purpose exploitation frameworks (Metasploit) and specialized tools (SQLMap), so candidates who pick Metasploit miss the 'specifically designed for SQL injection' qualifier.

How to eliminate wrong answers

Option A is wrong because Metasploit is a general exploitation framework — it can exploit many vulnerability classes but is not specifically designed to automate SQL injection detection and data extraction. Option B is wrong because Nmap is a network scanner for host discovery, port scanning, and service/version detection; it does not exploit SQL injection. Option C is wrong because Burp Suite is a web application security testing proxy that can help identify SQLi manually or via extensions, but it is not a dedicated automated SQLi exploitation and data-dumping tool like SQLMap.

308
MCQmedium

A security analyst observes a web application returning database error messages containing table names and column names in the HTTP response. Which type of SQL injection is MOST likely being exploited?

A.Blind SQL injection (boolean-based)
B.Union-based SQL injection
C.Error-based SQL injection
D.Out-of-band SQL injection
AnswerC

Error-based SQL injection is a technique where an attacker intentionally causes the database to generate error messages that contain sensitive information. By crafting malicious SQL queries that violate database constraints or syntax rules, the application's response will include detailed error messages, such as those from MySQL's EXTRACTVALUE or UPDATEXML functions, which inadvertently disclose database contents. This method directly "returns data" by embedding it within the visible error output.

Why this answer

Error-based SQL injection is correct because the attacker deliberately causes the database to throw errors that are reflected in the HTTP response, revealing schema details like table and column names. This technique relies on verbose error messages from the DBMS (e.g., MySQL, MSSQL) to extract information directly. Unlike blind or out-of-band methods, error-based injection provides immediate feedback in the application's output.

Exam trap

CEH often tests the distinction between error-based and union-based SQL injection, as both can reveal database information, but error-based specifically relies on error messages while union-based uses the UNION operator to directly retrieve data.

How to eliminate wrong answers

Option A is wrong because blind SQL injection (boolean-based) does not return database error messages; instead, it infers data by observing true/false responses or timing differences. Option B is wrong because union-based SQL injection uses the UNION operator to append a second query and retrieve data directly, but it does not rely on error messages to expose schema information. Option D is wrong because out-of-band SQL injection exfiltrates data via a separate channel (e.g., DNS or HTTP requests to an attacker-controlled server) and does not depend on error messages in the HTTP response.

309
Multi-Selectmedium

Which TWO of the following are effective defenses against Cross-Site Request Forgery (CSRF) attacks? (Select 2)

Select 2 answers
A.Using anti-CSRF tokens
B.Setting the SameSite attribute on cookies
C.Enabling HTTP Strict Transport Security (HSTS)
D.Implementing input validation on all user inputs
E.Using Content Security Policy (CSP) headers
AnswersA, B

Anti-CSRF tokens are unique, unpredictable, secret values generated by the server and embedded into forms or AJAX requests. When a user submits a request, the server verifies that the token received matches the one issued for that specific session. This mechanism prevents attackers from forging requests, as they cannot predict or obtain the valid token required for a successful submission from the legitimate user's browser session. Without a valid token, the server rejects the request, effectively blocking the CSRF attack.

Why this answer

Option A (Using anti-CSRF tokens) is correct because a unique, unpredictable token tied to the user's session and validated server-side ensures that a forged request originating from a malicious third-party site cannot include the correct token, so the request is rejected. Option B (Setting the SameSite attribute on cookies) is correct because SameSite=Lax or SameSite=Strict prevents the browser from attaching session cookies to cross-site requests, which blocks the automatic credential submission that CSRF relies on. Option C (HSTS) is not correct because it only enforces HTTPS and prevents protocol downgrade/SSL-stripping attacks, not cross-site request forgery.

Option D (input validation) is not correct because validating input addresses injection flaws like XSS or SQLi but does not stop a browser from sending an authenticated forged request. Option E (CSP headers) is not correct because CSP mitigates XSS and content-injection risks, which is a different attack class than CSRF.

Exam trap

CEH often tests the confusion between CSRF defenses and XSS/injection defenses, trapping candidates who pick HSTS, CSP, or input validation as CSRF mitigations when they address different threat models.

310
MCQmedium

During a web application penetration test, a tester submits a comment containing '<script>alert("XSS")</script>' and the script executes for all users who view the comment. Which type of cross-site scripting (XSS) vulnerability is present?

A.Blind XSS
B.Reflected XSS
C.DOM-based XSS
D.Stored (persistent) XSS
AnswerD

Stored, or persistent, XSS is the most dangerous type, as the malicious script is permanently saved on the target server, typically in a database, comment section, or forum post. Once stored, the payload is delivered to every user who accesses the affected web page, without requiring any further interaction from the attacker. This allows for widespread and long-term compromise, as the script executes automatically each time the vulnerable content is rendered by a user's browser.

Why this answer

Stored (persistent) XSS occurs when malicious script is permanently saved on the target server (e.g., in a database, comment field, or message board) and served to every user who subsequently views that page. Because the payload executes for all viewers without any crafted URL or user interaction beyond visiting the page, it is the most dangerous XSS variant. The scenario describes exactly this: the comment is persisted and the script runs for all users who view it.

Exam trap

CEH often tests the distinction between stored, reflected, and DOM-based XSS by describing where the payload executes — candidates frequently misclassify persistent comment/forum payloads as reflected XSS because they focus on the <script> tag rather than on the persistence and multi-victim delivery.

How to eliminate wrong answers

Option A is wrong because blind XSS is a subset of stored XSS where the payload fires in a back-end/admin panel or logging system that the attacker cannot directly observe — the tester here sees execution in the public comment view, not a blind context. Option B is wrong because reflected XSS requires the payload to be echoed back in the immediate HTTP response to a crafted request (typically via a URL parameter), and it does not persist across users or sessions. Option C is wrong because DOM-based XSS executes entirely client-side when JavaScript sinks (e.g., innerHTML, document.write) process untrusted source data — the payload never needs to be stored server-side, which contradicts the persistence described here.

311
MCQmedium

An attacker uses the following URL pattern to access files: http://example.com/../../etc/passwd. Which attack is being attempted?

A.Command injection
B.Local file inclusion (LFI)
C.Directory traversal
D.Remote file inclusion (RFI)
AnswerC

Directory traversal, also known as path traversal, is an attack that allows an attacker to access files and directories stored outside the intended web root directory. This is achieved by manipulating variables that reference files with "dot-dot-slash" (`../`) sequences, or similar absolute path representations, to navigate the file system. The URL pattern `../` precisely exemplifies this technique, enabling the attacker to move up the directory hierarchy to access unauthorized files.

Why this answer

The URL pattern http://example.com/../../etc/passwd uses directory traversal (also known as path traversal) to navigate outside the web root and access the /etc/passwd file on a Linux system. The ../ sequences move up the directory tree, attempting to read a sensitive system file. This is a classic directory traversal attack.

Exam trap

CEH often tests the distinction between directory traversal and LFI/RFI; candidates may pick LFI because both involve file paths, but directory traversal is the direct manipulation of the URL path to access files, while LFI requires a vulnerable include function.

How to eliminate wrong answers

Option A is wrong because command injection involves executing arbitrary commands on the server, typically through unsanitized input in system calls, not simply accessing files via path manipulation. Option B is wrong because local file inclusion (LFI) involves including files on the server through a script's include functionality, often using a parameter like ?page=../../etc/passwd; while related, the direct URL path traversal shown here is more specifically directory traversal. Option D is wrong because remote file inclusion (RFI) involves including a file from a remote URL, which is not the case here.

312
Multi-Selecthard

Which THREE of the following are valid methods to prevent a downgrade attack on TLS? (Select 3)

Select 3 answers
A.Disable TLS 1.0 and 1.1 on the server
B.Use the TLS_FALLBACK_SCSV cipher suite
C.Use self-signed certificates to avoid CA trust issues
D.Enforce a minimum TLS version of 1.2 in server configuration
E.Disable all cipher suites except those using RC4
AnswersA, B, D

Disabling specific older TLS versions like 1.0 and 1.1 on the server directly removes the server's capability to negotiate these protocols. If the server does not support or offer these versions, an attacker cannot force a client and server to communicate using them, thereby eliminating the target for a downgrade attack. This is a fundamental server-side configuration best practice for security.

Why this answer

Disabling older TLS versions, enforcing TLS 1.2+, and using TLS_FALLBACK_SCSV prevent downgrade; disabling cipher suites does not prevent downgrade directly; using self-signed certificates increases risk.

313
MCQhard

Refer to the exhibit. An ethical hacker runs the shown Nmap scan against a target. Which port state indicates that the port is reachable but no service is listening?

A.open
B.closed
C.filtered
D.unfiltered
AnswerB

A 'closed' port indicates that the target host is reachable and received Nmap's probe, but no application is currently listening on that specific port. For TCP scans, the target typically responds with an RST (reset) packet, confirming the port's accessibility while explicitly stating that no service is active there. This state is crucial as it differentiates between an inactive port and one that is blocked by a firewall, accurately reflecting the scenario where the host is up but the service is not running.

Why this answer

A 'closed' port in Nmap indicates that the target host responded with a TCP RST (Reset) packet, meaning the port is reachable and the host is alive, but no application is listening on that port. This state confirms the port is accessible (not filtered by a firewall) yet no service is bound to it.

Exam trap

The trap here is that candidates often confuse 'closed' with 'filtered' or 'unfiltered', not realizing that a closed port specifically means the host responded with a TCP RST, proving reachability without a listening service.

How to eliminate wrong answers

Option A is wrong because an 'open' port means a service is actively listening and has responded with a SYN-ACK, not that no service is listening. Option C is wrong because 'filtered' means Nmap cannot determine if the port is open or closed due to packet filtering (e.g., firewall dropping probes), so the port may or may not be reachable. Option D is wrong because 'unfiltered' means the port is reachable but Nmap cannot determine its open/closed state (e.g., from an ACK scan), not that no service is listening.

314
MCQeasy

Which password cracking technique involves trying every possible combination of characters until the correct password is found?

A.Rainbow table attack
B.Dictionary attack
C.Brute force attack
D.Hybrid attack
AnswerC

A brute force attack is a systematic password cracking technique that attempts every possible character combination within a defined character set and length until the correct password is found. This method guarantees finding the password if given enough time and computational resources, as it exhaustively explores the entire search space. Its primary drawback is the immense computational power and time required, especially for longer and more complex passwords.

Why this answer

A brute force attack systematically tries every possible combination of characters from a defined character set (e.g., lowercase, uppercase, digits, special symbols) until the correct password is found. This method guarantees eventual success but is computationally expensive and time-consuming, especially for long or complex passwords. It is the most exhaustive form of password cracking, as it does not rely on any precomputed data or wordlists.

Exam trap

The trap here is that candidates often confuse 'brute force' with 'dictionary attack' because both involve guessing passwords, but the key distinction is that brute force exhaustively tries all combinations while dictionary attacks rely on a precompiled list of likely passwords.

How to eliminate wrong answers

Option A is wrong because a rainbow table attack uses precomputed hash chains to reverse cryptographic hash functions, not by trying every possible character combination. Option B is wrong because a dictionary attack uses a predefined list of likely passwords (e.g., common words, leaked passwords) rather than exhaustive character-by-character guessing. Option D is wrong because a hybrid attack combines dictionary words with common mutations (e.g., appending numbers or symbols) but does not attempt every possible combination of characters.

315
MCQhard

Which cryptographic algorithm is vulnerable to a birthday attack on its hash output size of 128 bits, reducing the effective security to 64 bits against collision resistance?

A.SHA-256
B.SHA-1
C.MD5
D.RC4
AnswerC

MD5 produces a 128-bit hash value, which means its collision resistance against a birthday attack is approximately 2^64 operations. This level of complexity is well within the reach of modern computing resources, allowing for practical collision finding within a reasonable timeframe. Consequently, MD5 is widely considered cryptographically broken and highly vulnerable to birthday attacks, making it unsuitable for security-critical applications requiring collision resistance.

Why this answer

MD5 produces 128-bit hashes. Birthday attack complexity for collision is 2^(n/2) = 2^64 for n=128. SHA-1 is 160-bit, SHA-256 is 256-bit, RC4 is a stream cipher not a hash.

316
MCQhard

An application allows users to upload XML files for processing. A tester uploads the following payload: <?xml version="1.0"?><!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><root>&xxe;</root>. The server returns the contents of /etc/passwd. Which attack is being performed?

A.XML External Entity (XXE) injection
B.SQL injection
C.Cross-Site Scripting (XSS)
D.Server-Side Request Forgery (SSRF)
AnswerA

XML External Entity (XXE) injection is the correct vulnerability because the provided payload explicitly defines an external entity within the DOCTYPE declaration. By referencing "file:///etc/passwd" via the SYSTEM identifier, the XML parser is instructed to retrieve the content of the specified local file. This content is then processed and potentially returned in the application's response, confirming the successful exploitation of the XML parser's ability to resolve external entities.

Why this answer

This is an XML External Entity (XXE) injection attack, where an external entity is defined to read a local file. The server's XML parser processes the entity and reflects the file content, confirming the vulnerability.

317
Multi-Selecthard

Which THREE of the following Nmap flags are commonly used for evasion techniques? (Select 3)

Select 3 answers
A.-f
B.-D
C.--mtu
D.-O
E.-sV
AnswersA, B, C

The -f flag instructs Nmap to fragment the probe packets into smaller pieces, typically 8 bytes or less, before sending them. This technique can bypass stateless firewalls or basic Intrusion Detection Systems (IDS) that only inspect the first fragment of a packet or fail to reassemble fragmented packets correctly. By splitting the TCP header across multiple fragments, it becomes harder for security devices to identify the true nature of the scan, making it a common evasion tactic.

Why this answer

The -f flag fragments the probe packets into smaller 8-byte fragments (or less, depending on the MTU). This helps evade simple packet-filtering firewalls and intrusion detection systems that do not reassemble fragments before applying rules, as the fragmented headers may bypass signature-based detection.

Exam trap

EC-Council often tests the distinction between scanning techniques (like -O and -sV) and evasion techniques (like -f, -D, --mtu), so candidates mistakenly select -O or -sV because they are common Nmap flags, even though they serve reconnaissance, not evasion.

318
MCQmedium

An employee receives an email that appears to be from the company's CEO, requesting an urgent wire transfer to a vendor. The email address is slightly different from the CEO's actual address. Which type of social engineering attack is this?

A.Phishing
B.Vishing
C.Whaling
D.Spear phishing
AnswerD

This is spear phishing because the email is crafted specifically for that employee, using the CEO's identity to add urgency and authority. The targeted nature and the spoofed email address are hallmarks of spear phishing.

Why this answer

Spear phishing is a targeted social engineering attack aimed at a specific individual or organization. In this scenario, the email is personalized to appear from the CEO but targets an employee, making it spear phishing. Unlike whaling, which targets high-profile executives, spear phishing can target any individual.

The slightly spoofed email address and urgent request for a wire transfer are common spear phishing tactics, exploiting trust and authority to trick the victim.

Exam trap

In the EC-CEH exam, candidates often confuse whaling with spear phishing because both are targeted. However, the key distinction is the target's level: whaling targets top executives (C-suite, board members), while spear phishing targets any individual. Here, since the recipient is an employee, it is spear phishing, not whaling.

How to eliminate wrong answers

Option A is wrong because phishing is a broad, untargeted attack that sends mass emails to many users, often with generic content, not a personalized request from a specific executive. Option B is wrong because vishing (voice phishing) uses phone calls or voice messages, not email, to deceive victims. Option D is wrong because spear phishing targets a specific individual or organization but does not necessarily focus on high-ranking executives; whaling is a subtype of spear phishing that specifically targets senior management.

319
MCQmedium

Which of the following Nmap flags would an attacker use to evade IDS by sending fragmented IP packets?

A.-D
B.-g
C.-sS
D.-f
AnswerD

The -f (or --fragment) flag instructs Nmap to fragment the IP packets it sends into several smaller pieces. This technique is specifically designed to evade simple packet filters and intrusion detection systems (IDS) that might inspect only the first fragment of a packet or have difficulty reassembling fragmented packets correctly. By splitting the TCP or UDP header across multiple fragments, it can bypass rules that look for specific header information in a single, complete packet, thus aiding in stealth.

Why this answer

The -f flag in Nmap instructs the tool to fragment the transmitted packets into smaller pieces (typically 8-byte fragments). This fragmentation is used to evade Intrusion Detection Systems (IDS) that rely on signature matching against complete, unfragmented packets, as the IDS may not reassemble the fragments before inspection or may fail to detect the malicious payload when spread across multiple fragments.

Exam trap

The trap here is that candidates often confuse the -f flag with the -D (decoy) flag, thinking both are used for evasion, but -f specifically targets packet fragmentation to bypass IDS, while -D hides the source IP.

How to eliminate wrong answers

Option A (-D) is wrong because the -D flag is used for decoy scanning, which spoofs multiple source IP addresses to hide the attacker's real IP, not to fragment packets. Option B (-g) is wrong because the -g flag sets a custom source port number for the scan, often to bypass firewall rules that allow traffic from specific ports (e.g., port 53 for DNS), and has nothing to do with fragmentation. Option C (-sS) is wrong because -sS performs a TCP SYN stealth scan, which sends SYN packets without completing the handshake to avoid connection logging, but it does not involve IP fragmentation.

320
MCQhard

An analyst detects an SMB enumeration attempt in network logs. Which of the following tools would MOST likely generate such traffic?

A.nmap -sT 192.168.1.1
B.enum4linux 192.168.1.1
C.snmpwalk -v 2c 192.168.1.1
D.ldapsearch -h 192.168.1.1
AnswerB

`enum4linux` is a wrapper script designed specifically for enumerating information from Windows and Samba hosts via NetBIOS and SMB. It leverages underlying tools like `rpcclient`, `net`, and `nmblookup` to extract a wide array of details. This includes user lists, group memberships, share names, password policies, and operating system information, making it highly effective for comprehensive SMB enumeration attempts.

Why this answer

enum4linux is a tool specifically designed to enumerate SMB (Server Message Block) shares, users, and other information from Windows systems using the SMB protocol. The analyst detected SMB enumeration traffic, which is exactly what enum4linux generates by querying NetBIOS and SMB services (ports 139 and 445).

Exam trap

The trap here is that candidates may confuse tools that scan ports (nmap) with tools that perform protocol-specific enumeration, leading them to choose nmap because it is a common scanning tool, but it does not generate SMB enumeration traffic itself.

How to eliminate wrong answers

Option A is wrong because nmap -sT performs a TCP connect scan, which can detect open ports but does not perform SMB enumeration; it only checks if ports are open, not extracting SMB-specific data. Option C is wrong because snmpwalk queries SNMP (Simple Network Management Protocol) on UDP ports 161/162, not SMB, and is used for retrieving MIB data from network devices. Option D is wrong because ldapsearch queries LDAP (Lightweight Directory Access Protocol) on TCP port 389, which is used for directory services like Active Directory, not for SMB enumeration.

321
MCQmedium

During a web application test, a penetration tester intercepts a request using Burp Suite Proxy, modifies the 'Referer' header, and resends the request. The application processes the request despite the modified header. Which attack is the tester attempting to validate?

A.Server-Side Request Forgery (SSRF)
B.Cross-Site Scripting (XSS)
C.Cross-Site Request Forgery (CSRF)
D.SQL injection
AnswerC

Modifying the "Referer" header is a direct test for Cross-Site Request Forgery (CSRF) defenses. Many web applications implement CSRF protection by validating the "Referer" header to ensure that a request originates from the application's own domain. A penetration tester's action of altering this header directly attempts to bypass or evaluate the robustness of such "Referer"-based validation mechanisms, simulating an attacker's attempt to circumvent this common CSRF mitigation.

Why this answer

CSRF (Cross-Site Request Forgery) attacks often rely on the Referer header for validation. By modifying it, the tester checks if the application validates the header. If the request is processed, the application is vulnerable to CSRF.

322
MCQhard

During a cloud penetration test, you discover an S3 bucket that allows listing objects. You find a file named 'config.json' that contains an IAM access key and secret key. Which of the following is the BEST next step?

A.Delete the bucket to prevent further data exposure
B.Use the keys to call sts:GetCallerIdentity and then enumerate permissions via IAM
C.Download all objects from the bucket and exfiltrate them
D.Immediately rotate the keys in the AWS console
AnswerB

After discovering AWS access keys, the immediate and most prudent step is to validate their authenticity and determine the associated identity using sts:GetCallerIdentity. This API call confirms the keys are active and reveals the IAM user or role they belong to. Following this, enumerating the permissions attached to that identity via IAM policies is critical to understand the full scope of access, identify potential escalation paths, and discover other high-value targets within the AWS environment.

Why this answer

The correct action is to use the discovered credentials to enumerate permissions via the AWS CLI, as they may grant further access.

323
MCQmedium

A security analyst receives an alert about a scan originating from an IP address that appears to be using a 'sIdle scan' technique. Which of the following characteristics would confirm this?

A.The scan uses fragmented packets and decoy IP addresses
B.The scan uses FTP bounce to hide the true source IP
C.The scan sends SYN packets with the zombie host's IP address as the source and monitors IPID changes on the zombie to determine open ports
D.The scan shows a SYN packet with the attacker's real IP but uses a zombie host to relay replies
AnswerC

This option accurately describes the idle scan's core methodology. The attacker first probes an idle "zombie" host to record its current IPID (IP Identification field). Subsequently, the attacker sends spoofed SYN packets to the target, using the zombie's IP address as the source. If the target port is open, it responds with a SYN-ACK to the zombie, causing the zombie to send an RST to the target and increment its IPID. If the target port is closed, it responds with an RST to the zombie, which does not increment the zombie's IPID. A final probe to the zombie reveals whether its IPID has incremented, indicating an open port on the target.

Why this answer

An idle scan (also known as a zombie scan) relies on sending SYN packets to the target with the spoofed source IP address of a zombie host, then monitoring the IPID sequence on that zombie to infer whether the target port is open, closed, or filtered. The key characteristic is the use of the zombie's IP as the source and the observation of IPID changes on the zombie, which is exactly what option C describes.

Exam trap

The trap here is that candidates often confuse the idle scan with other spoofing or relay techniques like FTP bounce or decoy scans, but the idle scan is uniquely defined by the use of a zombie host's IPID changes to infer port states, not by hiding the attacker's IP via relays or multiple decoys.

How to eliminate wrong answers

Option A is wrong because fragmented packets and decoy IP addresses are features of a fragmented scan or a decoy scan, not an idle scan; idle scan does not use fragmentation or multiple decoy IPs. Option B is wrong because FTP bounce is a separate technique that uses an FTP server to relay traffic and hide the true source, but it does not involve monitoring IPID changes on a zombie host. Option D is wrong because an idle scan does not send SYN packets with the attacker's real IP; the attacker's IP is never used in the probe packets—the zombie's IP is used as the source, and the zombie does not relay replies; instead, the attacker monitors the zombie's IPID to infer port states.

324
MCQeasy

Which of the following tools is specifically designed for high-speed port scanning across large address spaces?

A.Masscan
B.Zenmap
C.hping3
D.Nmap
AnswerA

Masscan is purpose-built for extremely high-speed network scanning, capable of transmitting millions of packets per second across the internet. It achieves this unparalleled speed by employing a custom, asynchronous TCP/IP stack and operating in a stateless manner, primarily focusing on rapid port discovery rather than detailed service enumeration. This design allows it to scan the entire IPv4 address space for specific ports in mere minutes, making it ideal for large-scale reconnaissance and vulnerability mapping.

Why this answer

Masscan is specifically designed for high-speed port scanning across large address spaces, capable of transmitting packets at rates exceeding 10 million packets per second. It achieves this by using asynchronous transmission and a custom TCP/IP stack, making it ideal for scanning the entire IPv4 internet or massive subnets in minutes, unlike general-purpose scanners that prioritize accuracy over raw speed.

Exam trap

The trap here is that candidates often assume Nmap is the fastest scanning tool because of its popularity and extensive feature set, but Masscan is explicitly engineered for raw speed at the cost of some accuracy, which is the key differentiator tested in this question.

How to eliminate wrong answers

Option B (Zenmap) is wrong because it is merely a graphical front-end for Nmap, not a standalone high-speed scanner; it inherits Nmap's slower, more thorough scanning approach. Option C (hping3) is wrong because it is a packet crafting and testing tool focused on custom packet generation and firewall testing, not optimized for high-speed port scanning across large address spaces. Option D (Nmap) is wrong because while it is a powerful and versatile scanner, it is designed for detailed, reliable scans with features like service detection and OS fingerprinting, and its default scanning methods are significantly slower than Masscan's asynchronous approach.

325
MCQeasy

In the context of system hacking methodology (CHPSET), which phase involves removing evidence of the attacker's activities from logs and system files?

A.Spying
B.Privilege escalation
C.Erasing tracks
D.Cracking passwords
AnswerC

Erasing tracks is the crucial final phase in the system hacking methodology, where an attacker meticulously removes all forensic evidence of their presence and activities from a compromised system. This involves clearing system logs, modifying file timestamps, deleting malicious tools, and altering audit trails to prevent detection by security analysts and incident responders. The objective is to maintain persistence and avoid attribution, making it appear as if no intrusion occurred.

Why this answer

In the CEH system hacking methodology (CHPSET), the 'Erasing tracks' phase is specifically defined as the step where attackers remove evidence of their activities, such as clearing logs, modifying timestamps, or deleting system files. This ensures that intrusion detection systems or system administrators cannot trace the attack back to the source.

Exam trap

The trap here is that candidates confuse 'Erasing tracks' with 'Privilege escalation' because both involve post-exploitation actions, but the key distinction is that erasing tracks is solely about covering forensic evidence, not gaining higher privileges.

How to eliminate wrong answers

Option A is wrong because 'Spying' is not a phase in the CHPSET methodology; it is a generic term for surveillance and does not involve log or file manipulation. Option B is wrong because 'Privilege escalation' is the phase focused on gaining higher-level access (e.g., root or Administrator) after initial compromise, not on removing evidence. Option D is wrong because 'Cracking passwords' is part of the initial access or privilege escalation phases, where attackers obtain credentials, not a phase dedicated to covering tracks.

326
MCQeasy

A system administrator wants to enumerate all users in an Active Directory domain. Which protocol and query technique should they use?

A.SNMP with public community string
B.SMB null session
C.SMTP VRFY
D.LDAP anonymous query
AnswerD

LDAP (Lightweight Directory Access Protocol) is the primary protocol for querying and modifying directory services, including Microsoft Active Directory. An anonymous LDAP query attempts to bind to the directory without providing any credentials. If the Active Directory server is misconfigured to allow anonymous binds and access to user objects, an attacker can enumerate a significant amount of user information, including usernames, email addresses, and other attributes, making it a highly effective method for user enumeration.

Why this answer

LDAP anonymous queries allow unauthenticated users to query an Active Directory domain for directory information, including user enumeration. While modern Active Directory configurations often restrict anonymous LDAP binds by default for security reasons, if enabled or misconfigured, it becomes a highly effective technique for enumerating users without credentials.

Exam trap

The trap here is that candidates often confuse SMB null sessions (a deprecated attack) with LDAP anonymous queries (a current, often-valid technique), or they mistakenly think SMTP VRFY is relevant to domain user enumeration instead of email address verification.

How to eliminate wrong answers

Option A is wrong because SNMP with a public community string is used for reading device configuration and statistics, not for enumerating Active Directory users; it targets network devices, not domain user objects. Option B is wrong because SMB null sessions were a legacy Windows vulnerability that allowed unauthenticated access to shares and user lists, but this has been disabled by default since Windows 2003 SP1 and is not a reliable modern enumeration technique. Option C is wrong because SMTP VRFY is used to verify email addresses on a mail server, not to enumerate Active Directory users; it operates at the application layer for email routing, not directory services.

327
MCQeasy

A security team is implementing measures to prevent cross-site request forgery (CSRF) attacks. Which of the following is the most effective mitigation technique?

A.Enabling SSL/TLS
B.Using HTTP GET for all form submissions
C.Implementing CSRF tokens
D.Using input validation
AnswerC

Implementing CSRF tokens is the standard and most effective defense against Cross-Site Request Forgery attacks. A unique, unpredictable token is generated by the server for each user session and embedded within forms or request headers. The server then validates this token upon receiving a request; if the token is missing or incorrect, the request is rejected, preventing an attacker from forging requests that originate from a different site without knowledge of the valid token. This mechanism ensures that only requests originating from the legitimate application are processed.

Why this answer

CSRF tokens are unique, unpredictable values that must be included in state-changing requests, ensuring the request originated from the legitimate site.

328
MCQhard

A security team finds that a web application accepts a user-supplied URL and fetches it server-side without validation. The application runs on AWS EC2 with a metadata endpoint at 169.254.169.254. Which attack is MOST likely to succeed?

A.SQL injection
B.Server-Side Request Forgery (SSRF)
C.Remote file inclusion (RFI)
D.Cross-site scripting (XSS)
AnswerB

The application fetches a user-supplied URL server-side without validation, enabling an attacker to craft a request to the internal AWS metadata endpoint at 169.254.169.254. This SSRF attack exploits the lack of input sanitisation to retrieve instance metadata, such as IAM credentials, because the server trusts its own network context. The stem’s constraint—unvalidated server-side URL fetching—directly enables this attack vector.

Why this answer

SSRF (Server-Side Request Forgery) occurs when an application fetches a user-controlled URL. By supplying the metadata endpoint, an attacker can retrieve IAM credentials, making this the most likely attack.

329
Multi-Selecteasy

Which TWO of the following are characteristics of symmetric encryption? (Select two)

Select 2 answers
A.Uses a single shared key for encryption and decryption
B.Faster than asymmetric encryption
C.Slower than asymmetric encryption
D.Provides non-repudiation
E.Uses a pair of public and private keys
AnswersA, B

Symmetric encryption algorithms, such as AES or DES, fundamentally rely on a singular, identical secret key for both the transformation of plaintext into ciphertext and the subsequent reversal of ciphertext back into plaintext. This shared secret must be securely exchanged between communicating parties prior to any encrypted data transmission. The efficiency of this method stems from using the same cryptographic key for both operations, simplifying key management for individual sessions.

Why this answer

Option A is correct because symmetric encryption is defined by the use of one single shared secret key that both encrypts and decrypts the data, unlike asymmetric algorithms that use a key pair. Option B is correct because symmetric ciphers such as AES and 3DES perform far fewer computationally expensive operations than asymmetric algorithms like RSA or ECC, making them significantly faster and better suited for bulk data encryption. Option C is incorrect because it reverses the actual performance relationship; symmetric encryption is faster, not slower, than asymmetric encryption.

Option D is incorrect because non-repudiation requires a private key known only to one party, which is a property of asymmetric cryptography, not shared-key symmetric encryption. Option E is incorrect because a public/private key pair describes asymmetric encryption, whereas symmetric encryption relies on a single shared key.

Exam trap

CEH often tests whether candidates can distinguish symmetric from asymmetric properties, so it swaps characteristics (speed, key structure, non-repudiation) between the two to catch those who memorize definitions without understanding the trade-offs.

330
MCQhard

A security analyst discovers that a containerized application running in a cloud environment can access the host's file system by mounting /var/run/docker.sock inside the container. Which type of attack does this configuration enable?

A.Server-Side Request Forgery (SSRF)
B.Privilege escalation within the container only
C.Container escape to the host
D.Denial-of-Service (DoS) attack against the container runtime
AnswerC

This is the correct answer because mounting the Docker socket (`/var/run/docker.sock`) inside a container grants the container full administrative control over the host's Docker daemon. An attacker can leverage this access to execute Docker commands, such as `docker run -v /:/host_root -it ubuntu bash`, which effectively mounts the host's root filesystem into a new container, thereby achieving a complete container escape and gaining arbitrary command execution capabilities on the host system.

Why this answer

Mounting the Docker socket inside a container allows the container to communicate with the Docker daemon on the host, potentially allowing the attacker to create new containers, escape the container, and execute commands on the host.

331
MCQmedium

A security analyst notices that the ARP cache on a workstation contains multiple entries for the same IP address with different MAC addresses. Which attack is likely occurring?

A.ARP poisoning
B.Session hijacking
C.DNS spoofing
D.MAC flooding
AnswerA

ARP poisoning sends forged ARP replies that bind one IP address to multiple attacker-controlled MAC addresses, so traffic destined for the legitimate host is redirected. Duplicate IP-to-MAC mappings in the cache are the direct symptom of this man-in-the-middle technique.

Why this answer

ARP poisoning (also called ARP spoofing) occurs when an attacker sends forged ARP replies to a network, associating their own MAC address with the IP address of a legitimate host (e.g., the default gateway). The workstation's ARP cache then stores multiple MAC addresses for the same IP, as the cache is updated with each fraudulent reply. This allows the attacker to intercept, modify, or block traffic intended for that IP, enabling man-in-the-middle attacks.

Exam trap

The trap here is confusing ARP poisoning with MAC flooding; candidates often pick MAC flooding because both involve MAC addresses, but MAC flooding targets switch CAM tables, not workstation ARP caches, and does not produce multiple MAC entries for the same IP on a single host. CEH exam questions often test this distinction.

How to eliminate wrong answers

Option B (Session hijacking) is wrong because session hijacking typically exploits an active TCP session by stealing session tokens or cookies, not by manipulating ARP cache entries. Option C (DNS spoofing) is wrong because DNS spoofing corrupts DNS resolver caches with false IP-to-domain mappings, not MAC-to-IP mappings in the ARP cache. Option D (MAC flooding) is wrong because MAC flooding overwhelms a switch's CAM table with fake MAC addresses to force it into hub mode, causing it to flood traffic out all ports; it does not create multiple ARP entries for the same IP on a single workstation.

332
MCQmedium

A security team discovers a file named 'svchost.exe' in a user's Temp folder. The file is signed by 'Microsoft Corporation' but the digital signature validation fails. Which analysis method should be used FIRST to determine if it's malicious?

A.Upload to VirusTotal
B.Dynamic analysis in a sandbox
C.Static analysis using strings and PEiD
D.Run the file on a production system to observe behavior
AnswerC

Static analysis, particularly utilizing tools like `strings` and PEiD, is the safest and most appropriate initial step for examining a suspicious executable without execution. The `strings` utility can extract human-readable text from the binary, revealing potential commands, URLs, or error messages that often indicate malicious intent. PEiD (PE Identifier) helps analysts identify the compiler, packer, or cryptor used, which is crucial for understanding obfuscation techniques and guiding further analysis, all while minimizing risk.

Why this answer

Static analysis using tools like strings and PEiD should be performed first to quickly inspect the file's metadata, embedded strings, and packer information without executing it. Since the digital signature validation fails despite claiming to be from Microsoft, static analysis can reveal anomalies such as unusual section names, suspicious imports, or packed code that indicate tampering. This non-execution approach is safe and efficient for initial triage, avoiding the risks of dynamic analysis or running the file.

Exam trap

The CEH exam often tests that candidates mistakenly choose dynamic analysis (sandbox) as the first step, but the correct order is always static analysis first to assess risk and avoid executing unknown code prematurely.

How to eliminate wrong answers

Option A is wrong because uploading to VirusTotal is a secondary step that relies on static analysis results to interpret detection ratios, and it may expose sensitive data or be blocked by corporate policy. Option B is wrong because dynamic analysis in a sandbox should not be the first step; it requires prior static analysis to ensure the sample is safe to execute and to configure the sandbox appropriately. Option D is wrong because running the file on a production system is extremely dangerous and violates fundamental security practices, as it could trigger malware execution and compromise the environment.

333
MCQhard

During an assessment, a tester discovers that the web application accepts XML input and returns the parsed data. The tester submits the following payload: <!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><root>&xxe;</root>. The response contains the contents of /etc/passwd. This vulnerability is known as:

A.Local File Inclusion (LFI)
B.Server-Side Request Forgery (SSRF)
C.XML External Entity (XXE) Injection
D.SQL injection
AnswerC

XML External Entity (XXE) injection occurs when an XML parser processes XML input containing a reference to an external entity without proper validation. This vulnerability allows an attacker to define custom entities that can reference local files, network resources, or even execute commands, leading to the disclosure of sensitive data, denial-of-service, or server-side request forgery. The ability to read local files directly via the XML parser is a hallmark of XXE.

Why this answer

The payload defines an external entity that reads a local file, a classic XXE (XML External Entity) injection.

334
MCQeasy

Which HTTP method is commonly used by WebDAV to upload files to a web server, and if misconfigured, could allow an attacker to upload malicious scripts?

A.DELETE
B.GET
C.POST
D.PUT
AnswerD

The PUT method is the designated HTTP verb for uploading files in WebDAV because it requests that the enclosed entity be stored under the supplied Request-URI. If the URI refers to an existing resource, PUT replaces it; if the URI does not point to an existing resource, the server creates it. This idempotent behavior, where repeated identical requests have the same effect as a single request, makes PUT ideal for creating or updating files directly at a specified location.

Why this answer

The PUT method is used by WebDAV to upload files to a web server. If WebDAV is misconfigured to allow unauthenticated PUT requests, an attacker can upload malicious scripts (e.g., web shells) to the server, leading to remote code execution. PUT is idempotent and directly places the request body at the specified URI.

Exam trap

CEH often tests the misconception that POST is used for file uploads, but WebDAV specifically uses PUT for uploading files, and misconfigured PUT permissions are a common attack vector.

How to eliminate wrong answers

Option A is wrong because DELETE is used to remove resources, not upload files. Option B is wrong because GET is used to retrieve resources, not upload. Option C is wrong because POST is used to submit data to be processed, often creating a new resource, but WebDAV specifically uses PUT for file uploads.

335
MCQmedium

A security team deployed a web application firewall (WAF) that blocks requests containing SQL keywords like 'SELECT', 'UNION', and 'DROP'. An attacker bypasses the WAF by encoding the payload in base64 and using a SQL injection tool that decodes it server-side. Which mitigation would be MOST effective against this?

A.Increase WAF sensitivity to block base64-encoded strings
B.Implement prepared statements with parameterized queries
C.Disable error messages to hide database errors
D.Use a more restrictive input validation regex
AnswerB

Implementing prepared statements with parameterized queries is the most robust solution because it fundamentally separates SQL code from user-supplied data. The database engine first compiles the SQL query structure, defining placeholders for input, before any user data is introduced. Subsequently, user input is bound to these placeholders as literal values, ensuring it is never interpreted as executable SQL code, thereby eliminating the possibility of SQL injection attacks.

Why this answer

Prepared statements (parameterized queries) prevent SQL injection by separating query structure from data, regardless of encoding. WAF bypasses are mitigated by using proper coding practices.

336
MCQhard

During a penetration test, a tester uses Nmap with the command: nmap -sS -D RND:10 192.168.1.100. After the scan, the IDS logs show multiple SYN packets from different source IPs hitting the target. However, the tester's true IP is not among them. Which of the following techniques is being used?

A.Idle scan
B.SYN flood
C.Decoy scan
D.Fragmentation attack
AnswerC

A Decoy scan, initiated with the -D flag, is a technique used to obfuscate the true source IP address of the scanner by interspersing it with multiple decoy IP addresses. When RND:10 is used, Nmap generates 10 random, non-existent IP addresses (or existing ones if specified) and sends scan packets from these decoys, along with the actual scanner's IP. This makes it challenging for intrusion detection systems (IDS) or firewall logs to pinpoint the actual origin of the scan amidst the noise generated by the decoys.

Why this answer

The command `nmap -sS -D RND:10` performs a SYN stealth scan with 10 randomly generated decoy IP addresses. The IDS logs show multiple SYN packets from different source IPs, but the tester's true IP is not among them because Nmap sends the decoy packets with spoofed source addresses while the real scan packet is interleaved among them. This is the definition of a decoy scan, which aims to obscure the attacker's true origin by blending it with fake sources.

Exam trap

The trap here is confusing decoy scans with idle scans, as both involve spoofed IPs, but idle scans require a zombie host and IPID manipulation, while decoy scans simply flood the target with fake sources to hide the real one.

How to eliminate wrong answers

Option A is wrong because an idle scan (nmap -sI) uses a zombie host to bounce scan traffic off, relying on IPID sequence analysis, not multiple random source IPs. Option B is wrong because a SYN flood is a denial-of-service attack that sends a high volume of SYN packets to overwhelm the target, not a stealth scanning technique to hide the tester's IP. Option D is wrong because a fragmentation attack (nmap -f) splits packets into smaller fragments to evade IDS/IPS signature detection, but does not spoof source IPs or use decoys.

337
MCQhard

An attacker has compromised a Linux machine and wants to hide a rootkit by replacing system binaries with trojaned versions. Which technique is being used to maintain persistent access while evading detection?

A.Log manipulation
B.Token impersonation
C.Steganography
D.Rootkit installation via binary replacement
AnswerD

Rootkit installation via binary replacement is a common and effective method for an attacker to maintain persistent access and hide their activities on a compromised Linux system. This technique involves replacing legitimate system binaries (e.g., `ls`, `ps`, `netstat`, `login`) with trojanized versions that execute their original function while simultaneously concealing malicious files, processes, or network connections. By subverting core system utilities, the rootkit can manipulate what the operating system reports, effectively making the attacker's presence invisible to standard monitoring tools.

Why this answer

Replacing system binaries (e.g., `ls`, `ps`, `netstat`) with trojaned versions is a classic rootkit technique. The rootkit intercepts system calls or filters output to hide its own processes, files, and network connections, allowing the attacker to maintain persistent access while evading detection by standard administrative tools.

Exam trap

EC-CEH often tests the distinction between hiding a rootkit (binary replacement) and covering tracks (log manipulation), causing candidates to confuse post-exploitation cleanup with the rootkit's evasion mechanism.

How to eliminate wrong answers

Option A is wrong because log manipulation (e.g., clearing `/var/log/auth.log`) covers tracks after an intrusion but does not involve replacing system binaries to hide a rootkit; it is a separate post-exploitation step. Option B is wrong because token impersonation is a Windows-specific privilege escalation technique (e.g., using `SeImpersonatePrivilege` to impersonate a user token) and does not apply to hiding rootkits on Linux via binary replacement. Option C is wrong because steganography hides data within other files (e.g., images or audio) for covert communication, not for replacing system binaries to maintain persistent access.

338
MCQmedium

During a penetration test, an analyst obtains a dump of password hashes from a Windows server. The hashes are in LM:NT format. The analyst wants to crack the NT portion using a brute-force attack on 8-character alphanumeric passwords. Which tool is BEST suited for this task?

A.Hashcat
B.John the Ripper
C.RainbowCrack
D.Ophcrack
AnswerA

Hashcat is the industry-standard password recovery tool, renowned for its unparalleled speed and efficiency in cracking various hash types, including NTLM, through highly optimized GPU-accelerated brute-force and dictionary attacks. Its ability to leverage modern graphics cards allows it to test billions of password candidates per second, making it the most effective choice for rapidly cracking password dumps obtained during a penetration test.

Why this answer

Hashcat is the best tool for this task because it is optimized for high-speed GPU-accelerated brute-force attacks, making it ideal for cracking 8-character alphanumeric NT hashes. It supports the LM:NT format natively and allows precise control over attack modes, including brute-force with custom character sets, which is essential for exhaustive enumeration of 62^8 possibilities.

Exam trap

CEH often tests the misconception that RainbowCrack or Ophcrack are suitable for brute-force attacks, when in fact they are primarily rainbow table tools, not brute-force engines, and are ineffective for exhaustive search without precomputed tables.

How to eliminate wrong answers

Option B (John the Ripper) is wrong because, while it can crack NT hashes, its brute-force performance is significantly slower than Hashcat on modern GPUs, and it lacks the same level of GPU optimization for high-speed attacks. Option C (RainbowCrack) is wrong because it relies on precomputed rainbow tables, not brute-force; it is designed for fast lookup attacks but cannot perform exhaustive brute-force on 8-character alphanumeric passwords without precomputed tables. Option D (Ophcrack) is wrong because it specializes in cracking LM hashes using rainbow tables, not NT hashes, and its brute-force capability is extremely limited and not suited for 8-character alphanumeric passwords.

339
MCQhard

A web server running IIS 8.5 is found to have WebDAV enabled with write permissions. Which attack is MOST likely to be successful against this configuration?

A.Cross-Site Request Forgery (CSRF)
B.SQL injection
C.File upload leading to remote code execution
D.Directory traversal
AnswerC

WebDAV provides HTTP methods like PUT and MKCOL, enabling clients to upload and manage files on the server. If WebDAV is enabled with write permissions and the server is misconfigured to allow execution of uploaded files (e.g., ASP, ASPX, PHP, or even compiled executables) within a web-accessible directory, an attacker can upload a malicious web shell or other executable code. Subsequently accessing this uploaded file through the web server will trigger its execution, granting the attacker remote code execution capabilities on the server.

Why this answer

WebDAV (Web Distributed Authoring and Versioning) is an extension to HTTP that allows clients to author and modify content on a web server. When enabled with write permissions on IIS 8.5, it permits HTTP methods like PUT, which can be used to upload files directly to the server. If the server also allows execution of uploaded files (e.g., .asp or .aspx), an attacker can upload a malicious script and execute arbitrary code, achieving remote code execution.

This is the most direct and likely attack given the configuration.

Exam trap

CEH often tests the misconception that WebDAV is only for file sharing and overlooks its potential for remote code execution when write permissions are enabled, leading candidates to choose directory traversal or CSRF instead of the more severe file upload RCE.

How to eliminate wrong answers

Option A is wrong because CSRF requires a victim with an active session to a vulnerable site, and while WebDAV could be used in a CSRF attack, it is not the most likely or direct outcome of WebDAV with write permissions; CSRF typically targets state-changing actions, not code execution. Option B is wrong because SQL injection requires an application with unsanitized database queries, which is unrelated to WebDAV write permissions; WebDAV itself does not interact with databases. Option D is wrong because directory traversal allows reading files outside the web root, but it does not directly lead to code execution; while it could be used to read sensitive files, it is not the primary risk of WebDAV with write permissions.

340
MCQhard

A security analyst notices that their Nmap scan results show all ports as 'filtered' despite the target host being alive and responsive to ping. Which of the following is the MOST likely cause?

A.The analyst's machine has a misconfigured routing table
B.The target has a host-based firewall that drops all incoming traffic silently
C.The target is running a honeypot that mimics multiple services
D.The target is an idle host that does not respond to any traffic
AnswerB

When Nmap reports a port as "filtered," it means that the Nmap probe packets (e.g., SYN for TCP, ICMP for UDP) reached the target, but no response was received from the target host. This behavior is characteristic of a firewall, either host-based or network-based, configured to silently drop incoming traffic without sending an RST packet (for TCP) or an ICMP Port Unreachable message (for UDP). Such silent drops prevent Nmap from determining the port's true state (open or closed), leading to the "filtered" classification.

Why this answer

When an Nmap scan shows all ports as 'filtered', it indicates that the target is reachable (since ping succeeds) but the probe packets (e.g., SYN, ACK) are being dropped without any response. A host-based firewall configured to silently drop all incoming traffic is the most likely cause, as it prevents Nmap from receiving RST or SYN/ACK replies, leading to the 'filtered' state for every port.

Exam trap

The trap here is that candidates often confuse 'filtered' with 'closed' or 'open', or assume a host that responds to ping must have open ports, but a firewall can silently drop all inbound TCP/UDP probes while still allowing ICMP echo requests.

How to eliminate wrong answers

Option A is wrong because a misconfigured routing table on the analyst's machine would likely cause no response at all (including ping failure) or asymmetric routing issues, not a consistent 'filtered' state on all ports while ping succeeds. Option C is wrong because a honeypot mimicking multiple services would typically respond to probes (e.g., with SYN/ACK or banners) to attract attackers, resulting in 'open' or 'closed' port states, not 'filtered'. Option D is wrong because an idle host that does not respond to any traffic would not respond to ping either, contradicting the scenario where the target is alive and responsive to ping.

341
MCQeasy

Which of the following is a primary purpose of the SameSite cookie attribute in mitigating CSRF attacks?

A.To limit the cookie to a specific path
B.To encrypt the cookie value
C.To prevent the cookie from being sent in cross-origin requests, mitigating CSRF
D.To restrict the cookie to HTTPS connections only (Secure flag)
AnswerC

This statement is correct. The "SameSite" attribute is designed to prevent a browser from sending a cookie with requests initiated from a different origin than the site that set the cookie. By restricting the automatic inclusion of session cookies in cross-origin requests, it significantly mitigates Cross-Site Request Forgery (CSRF) attacks, where an attacker tricks a user's browser into sending an authenticated request to a vulnerable web application without their explicit consent. This defense ensures that sensitive actions require a same-site context.

Why this answer

The SameSite cookie attribute controls whether a browser includes a cookie in requests that originate from a different site than the one that set the cookie. By setting SameSite=Strict or SameSite=Lax, the browser withholds the cookie on cross-site requests, which breaks the CSRF attack model where a malicious site causes the victim's browser to send an authenticated request to a trusted site. This directly prevents the attacker from riding the user's session cookie.

Exam trap

CEH often tests the confusion between cookie security attributes — candidates mix up SameSite (cross-site request control), Secure (HTTPS-only transmission), HttpOnly (JavaScript access blocking), and Path (URL scoping), so they pick Secure or Path when the question asks about CSRF mitigation.

How to eliminate wrong answers

Option A is wrong because limiting a cookie to a specific path is the function of the Path attribute, which scopes the cookie to a URL directory and does not prevent cross-site requests. Option B is wrong because cookie values are not encrypted by any cookie attribute; confidentiality requires HTTPS/TLS in transit and server-side encryption at rest, not a cookie flag. Option D is wrong because restricting a cookie to HTTPS connections is the purpose of the Secure flag, which protects against network sniffing but does nothing to stop a browser from sending the cookie on a cross-site HTTP request.

342
MCQeasy

Which of the following tools is used to crack Windows LAN Manager (LM) and NTLM password hashes using rainbow tables?

A.Ophcrack
B.Hashcat
C.John the Ripper
D.Hydra
AnswerA

Ophcrack is a specialized, open-source password cracker specifically designed for Windows LM and NTLM hashes, making it the correct tool for this task. It excels by employing precomputed rainbow tables, which are large datasets of hash chains, to quickly reverse the hashing process for these particular Windows authentication hashes. This method significantly reduces the time required to find the original password compared to traditional brute-force attacks, especially for weaker LM hashes.

Why this answer

Ophcrack is specifically designed to crack Windows LM and NTLM hashes using precomputed rainbow tables. It is optimized for Windows password hashes and provides an efficient time-memory trade-off by looking up hashes in sorted tables.

Exam trap

EC-Council often tests the distinction between tools specialized for Windows hashes (Ophcrack) versus general-purpose rainbow table tools (RainbowCrack), leading candidates to confuse the two.

How to eliminate wrong answers

Option B (Hashcat) is wrong because it is a GPU-accelerated password recovery tool that uses brute-force, dictionary, or rule-based attacks, not precomputed rainbow tables. Option C (John the Ripper) is wrong because it is a general-purpose password cracker that relies on CPU-based attacks and does not natively use rainbow tables for LM/NTLM hashes. Option D (Hydra) is wrong because it is a network authentication brute-forcing tool for protocols like SSH, FTP, and HTTP, not a hash-cracking tool.

343
Multi-Selectmedium

Which TWO techniques are considered active reconnaissance? (Choose TWO.)

Select 2 answers
A.Using Google dorking to find exposed files
B.Querying Shodan for exposed devices
C.Port scanning with Nmap
D.Banner grabbing with Netcat
E.Performing a WHOIS lookup
AnswersC, D

Port scanning with Nmap is a quintessential active reconnaissance technique because it involves sending specially crafted packets directly to a target host. Nmap probes specific TCP or UDP ports to determine their state (open, closed, filtered) and identify running services. This direct interaction generates network traffic that the target's firewalls or intrusion detection systems can log, making it detectable and undeniably active.

Why this answer

Port scanning with Nmap (Option C) is active reconnaissance because it sends crafted packets (e.g., TCP SYN, UDP probes) directly to target systems and analyzes the responses to determine open ports, running services, and operating system details. Banner grabbing with Netcat (Option D) is also active reconnaissance as it establishes a TCP connection to a target service (e.g., HTTP, FTP) and reads the service banner, which involves direct interaction with the target. Both techniques generate detectable network traffic and can be logged by intrusion detection systems.

Exam trap

The trap here is that candidates confuse 'using a tool that sometimes performs active scanning' (like Shodan, which actively scans on its own) with the user's action being active; the key distinction is whether the user's query directly interacts with the target system.

344
Multi-Selecteasy

Which TWO of the following are types of malware analysis? (Select two.)

Select 2 answers
A.Static analysis
B.Memory analysis
C.Signature analysis
D.Dynamic analysis
E.Heuristic analysis
AnswersA, D

Static analysis involves dissecting malware binaries without executing them, examining the code, structure, and embedded resources. This process often includes disassembling or decompiling the executable, extracting strings, analyzing PE headers, and identifying imported/exported functions to infer potential malicious capabilities. Its primary goal is to understand the malware's design, identify obfuscation techniques, and predict its behavior before it ever runs, providing crucial initial insights into its functionality.

Why this answer

Static analysis involves examining malware without executing it, such as inspecting file headers, strings, and disassembled code. Dynamic analysis executes the malware in a controlled sandbox to observe its runtime behavior, including network traffic, registry changes, and process creation. Both are fundamental malware analysis methodologies recognized in CEH.

Exam trap

CEH often tests the distinction between analysis types (static/dynamic) and detection methods (signature/heuristic), causing candidates to confuse detection techniques with analysis methodologies.

345
MCQmedium

An organization wants to mitigate the impact of a DDoS attack that uses large volumes of UDP traffic to exhaust bandwidth. Which of the following techniques would be MOST effective?

A.Rate limiting on all ports
B.Deploying a scrubbing center
C.Blocking all UDP traffic
D.Implementing SYN cookies
AnswerB

Deploying a scrubbing center is a highly effective strategy for mitigating DDoS attacks, particularly those involving high-volume UDP floods. These specialized facilities act as an intermediary, diverting all incoming traffic through advanced analysis systems that inspect packet headers and payloads for known attack patterns and anomalies. Malicious traffic is then filtered out, while legitimate requests are forwarded to the organization's infrastructure, ensuring business continuity without disrupting genuine user access.

Why this answer

A scrubbing center is the most effective technique because it filters out malicious UDP traffic from legitimate traffic by analyzing packet characteristics, such as source IP reputation and payload patterns, before forwarding clean traffic to the target network. This approach preserves legitimate UDP services (e.g., DNS, VoIP) while absorbing volumetric attacks, unlike simpler methods that may block all UDP or fail to scale.

Exam trap

The trap here is that candidates often confuse rate limiting as a universal solution, but it fails against volumetric UDP floods because it cannot differentiate attack traffic from legitimate UDP services, whereas a scrubbing center provides intelligent traffic filtering at scale.

How to eliminate wrong answers

Option A is wrong because rate limiting on all ports would also throttle legitimate UDP traffic (e.g., DNS queries, streaming media) and cannot distinguish between attack and benign packets, leading to service degradation. Option C is wrong because blocking all UDP traffic would disrupt critical services like DNS resolution, DHCP, and VoIP, effectively causing a self-inflicted denial of service. Option D is wrong because SYN cookies are a TCP-specific mechanism designed to mitigate SYN flood attacks by encoding connection state in the initial sequence number; they have no effect on UDP traffic, which is connectionless.

346
MCQhard

During a penetration test, a tester discovers that the target switch's MAC address table is full, causing it to flood traffic out all ports. The tester then captures network traffic using Wireshark on the same segment. Which attack was the tester performing?

A.DNS spoofing
B.MAC flooding
C.Session hijacking
D.ARP poisoning
AnswerB

MAC flooding overwhelms the switch's CAM table with spoofed source MAC addresses until it can no longer map ports, forcing the switch to flood frames out every port. This lets the tester capture traffic on the same segment, matching the stem's full MAC address table.

Why this answer

MAC flooding. When a switch's MAC address table is full, it can no longer learn new MAC addresses and enters a fail-open state, flooding all incoming frames out every port except the ingress port. This allows the tester to capture traffic destined for other hosts on the same VLAN by placing their NIC in promiscuous mode and using Wireshark, effectively performing a MAC flooding attack to turn the switch into a hub-like device.

Exam trap

The EC-CEH exam often tests the distinction between MAC flooding and ARP poisoning, where candidates mistakenly choose ARP poisoning because both involve traffic capture, but the key differentiator is that MAC flooding exploits a full CAM table, while ARP poisoning manipulates ARP caches without filling the switch's MAC table.

How to eliminate wrong answers

Option A is wrong because DNS spoofing involves corrupting DNS responses to redirect traffic to a malicious server, not exploiting a full MAC address table. Option C is wrong because session hijacking targets an active TCP session or application session token to take over an authenticated session, not by flooding a switch's CAM table. Option D is wrong because ARP poisoning (ARP spoofing) manipulates ARP caches to associate a malicious MAC with a legitimate IP, causing traffic to be sent to the attacker; while it also enables traffic capture, it does not rely on filling the switch's MAC address table to capacity.

347
Multi-Selectmedium

Which TWO tools are commonly used for ARP poisoning attacks?

Select 2 answers
A.Wireshark
B.Cain & Abel
C.tcpdump
D.Ettercap
E.Nmap
AnswersB, D

Cain & Abel is a well-known password recovery and network sniffing tool primarily designed for Microsoft Windows operating systems. Among its extensive features, it specifically incorporates robust ARP poisoning functionalities, allowing an attacker to perform Man-in-the-Middle (MITM) attacks by sending forged ARP replies to redirect network traffic. This enables the interception of data, including credentials, between targeted hosts on a local area network.

Why this answer

Cain & Abel and Ettercap are both dedicated ARP poisoning tools that manipulate the ARP cache of target devices to intercept traffic on a local network. Cain & Abel performs ARP poisoning to enable man-in-the-middle attacks, while Ettercap uses ARP spoofing to redirect packets between hosts. Both tools are explicitly listed in CEH exam objectives for network sniffing and MITM attacks.

Exam trap

The trap here is that candidates often confuse passive sniffing tools (like Wireshark or tcpdump) with active attack tools, assuming any network tool can perform ARP poisoning, but only tools specifically designed to send forged ARP packets (like Cain & Abel and Ettercap) can execute the attack.

348
MCQeasy

A security analyst wants to identify all live hosts on a network without generating excessive traffic. Which of the following techniques is MOST appropriate for this purpose?

A.Banner grabbing with Netcat
B.Full TCP connect scan on all ports
C.UDP scan on common ports
D.Ping sweep using ICMP echo requests
AnswerD

A ping sweep, also known as an ICMP sweep, is a highly efficient and low-traffic method for host discovery that involves sending ICMP echo request packets to a range of IP addresses. Any host that is live and configured to respond to ICMP will send an ICMP echo reply packet back to the sender. The receipt of these replies reliably indicates the presence of an active host on the network, making it a foundational and quick technique for initial network reconnaissance.

Why this answer

A ping sweep using ICMP Echo Requests (Type 8) is the most efficient method to identify live hosts on a network because it sends a single packet per target and listens for ICMP Echo Replies (Type 0). This generates minimal traffic compared to full port scans, making it ideal for initial reconnaissance without overwhelming the network or triggering intrusion detection systems.

Exam trap

The trap here is that candidates often confuse host discovery with service discovery, choosing a port-based scan (like TCP connect or UDP) because they think 'scanning' always involves ports, but the question explicitly asks for identifying live hosts with minimal traffic, which is the textbook purpose of a ping sweep.

How to eliminate wrong answers

Option A is wrong because banner grabbing with Netcat requires an active TCP connection to a specific port on a host, which is a post-discovery technique used to identify services, not to find live hosts, and it generates more traffic per host than a simple ping. Option B is wrong because a full TCP connect scan on all 65,535 ports per host would generate massive traffic (thousands of packets per host), defeating the goal of minimizing network load and being easily detected. Option C is wrong because a UDP scan on common ports sends datagrams that often receive no response (due to stateless nature or firewalls), making it unreliable for host discovery and still generating more traffic than a single ICMP packet per host.

349
Multi-Selecteasy

Which TWO of the following are commonly used to mitigate SQL injection vulnerabilities? (Select 2)

Select 2 answers
A.Stored procedures
B.Output encoding
C.Input validation
D.Parameterized queries
E.HTTPS encryption
AnswersA, D

Stored procedures, when implemented with parameterized inputs, offer a robust defense against SQL injection. By pre-compiling the SQL statements on the database server, they ensure that user-supplied data is treated strictly as data values, not executable code. This separation prevents malicious input from altering the intended query logic, effectively neutralizing injection attempts before execution.

Why this answer

Stored procedures (A) are correct because they let the database execute predefined SQL with parameters, so user input is passed as data rather than concatenated into the query string, which prevents injected SQL from altering the statement's logic. Parameterized queries (D) are correct because they use placeholders (e.g., ? or :name) bound to typed parameters, ensuring the database treats user input strictly as values and never as executable SQL, which is the most reliable defense against SQL injection. Output encoding (B) is not the right control here because it protects against XSS by escaping data rendered into HTML, not against SQL injection.

Input validation (C) is a useful defense-in-depth measure but is not a primary SQL injection mitigation, since attackers can often craft input that passes validation yet still exploits a poorly built query. HTTPS encryption (E) only protects data in transit and does nothing to stop SQL injection, which exploits how queries are constructed and executed.

Exam trap

CEH often tests the confusion between input validation and parameterized queries, where candidates might select input validation as a primary mitigation, but the exam expects the two most robust and recommended defenses: stored procedures and parameterized queries.

350
MCQeasy

You are a penetration tester hired by a financial services company to assess the security of their external web application. The application is a customer portal hosted on a Linux server with Apache 2.4.6 and PHP 7.2. During reconnaissance, you discover that the server responds to HTTP OPTIONS requests and the Allow header includes PUT and DELETE methods. The application uses a MySQL database backend. You also find a file upload feature in the profile section that accepts JPEG images. While testing, you notice that uploading a file with a .php extension returns a '403 Forbidden' error, but uploading a file with .php5 or .phtml extension succeeds. The uploaded files are stored in /uploads/ directory. What should be your next step to escalate the attack?

A.Use the PUT method to upload a malicious file directly to the web root.
B.Upload a PHP web shell with .phtml extension and access it via the /uploads/ directory to execute commands.
C.Exploit the IIS WebDAV vulnerability to execute commands.
D.Attempt SQL injection in the login form to extract database credentials.
AnswerB

This approach leverages a common file upload vulnerability bypass technique. By using a '.phtml' extension, which Apache servers often interpret as PHP, the attacker can circumvent typical blacklist filters that block '.php' files. Once uploaded to an accessible directory like '/uploads/', the web shell can be requested, allowing the attacker to execute arbitrary commands on the server, achieving remote code execution.

Why this answer

The server allows file uploads with .phtml extension, which Apache processes as PHP due to its configuration. Uploading a PHP web shell with .phtml extension to the /uploads/ directory and accessing it directly allows command execution, escalating the attack. This bypasses the 403 Forbidden restriction on .php files while leveraging the existing upload functionality.

Exam trap

The trap here is that candidates may assume PUT method (Option A) is the primary escalation path because it is listed in the Allow header, but they overlook that the file upload feature with .phtml extension is a confirmed, working vector that directly leads to code execution.

How to eliminate wrong answers

Option A is wrong because the PUT method, while listed in the Allow header, typically requires WebDAV to be enabled on Apache, and direct PUT to web root is often restricted by server configuration or requires authentication; it is not a reliable escalation path without further evidence. Option C is wrong because IIS WebDAV vulnerability is specific to Microsoft IIS servers, not Apache on Linux; the server is running Apache 2.4.6 on Linux, so this option is irrelevant. Option D is wrong because SQL injection in the login form is a separate attack vector that may be possible but is not the immediate next step given the confirmed file upload vulnerability with .phtml extension; the question asks for escalation based on the discovered upload flaw.

351
MCQmedium

A security analyst notices that users receive emails from a known vendor requesting urgent payment to a new bank account. The email domain is misspelled (e.g., vvendorfake.com). Which type of social engineering is this?

A.Spear phishing
B.Whaling
C.Phishing
D.Vishing
AnswerA

Targeted emails with personalized context and spoofed domain indicate spear phishing.

Why this answer

This is spear phishing because the attack is specifically targeted at users of a known vendor, using a misspelled domain (vvendorfake.com) to impersonate that vendor. Unlike generic phishing, spear phishing involves personalized context (e.g., referencing a known vendor and urgent payment) to increase credibility. The misspelled domain exploits users' trust in the legitimate vendor's name, making it a targeted social engineering technique.

Exam trap

The trap is that candidates confuse generic phishing (mass email) with spear phishing, which uses specific context like the known vendor name. In the EC-CEH exam, remember that spear phishing is targeted.

How to eliminate wrong answers

Option B (Whaling) is wrong because whaling targets high-level executives (e.g., CEOs) with highly personalized attacks, not general users receiving vendor payment requests. Option C (Phishing) is wrong because it is too broad; while this attack uses phishing elements, the specific targeting of a known vendor and misspelled domain qualifies it as spear phishing, not generic mass phishing. Option D (Vishing) is wrong because vishing uses voice calls (e.g., VoIP) to deceive victims, not email-based attacks with misspelled domains.

352
MCQhard

An attacker intercepts a TLS-encrypted session and attempts to force the client and server to use a weaker cipher suite. Which type of attack is being performed?

A.Man-in-the-middle (MITM) attack
B.Birthday attack
C.Replay attack
D.Downgrade attack
AnswerD

A Downgrade attack specifically involves an attacker actively manipulating the TLS handshake process between a client and server. The attacker forces the communication parties to negotiate and use an older, less secure protocol version or weaker cipher suite than they would normally prefer or support. This significantly reduces the cryptographic strength of the session, making it easier for the attacker to decrypt intercepted data.

Why this answer

A downgrade attack tricks the communicating parties into negotiating a less secure version of TLS or a weaker cipher suite, making it easier for the attacker to break the encryption.

353
MCQhard

A web application takes a URL from user input and fetches the content to display on the page. An attacker submits a URL pointing to an internal service like http://localhost:8080/admin. The server retrieves the internal resource and returns it. What is this attack?

A.Cross-Site Scripting (XSS)
B.Server-Side Request Forgery (SSRF)
C.Directory Traversal
D.Remote File Inclusion (RFI)
AnswerB

Server-Side Request Forgery (SSRF) occurs when a web application is coerced into making requests to an arbitrary domain specified by the attacker, often to internal systems or services that are not directly accessible from the internet. By manipulating a user-supplied URL parameter, an attacker can trick the vulnerable server into fetching data from internal network resources, cloud metadata APIs, or other services, thereby exposing sensitive information or enabling further attacks. This directly matches the scenario described.

Why this answer

Server-Side Request Forgery (SSRF) occurs when a server makes requests to internal resources based on user-supplied URLs.

354
MCQmedium

During a penetration test, a tester runs 'dnsrecon -d example.com -t axfr' and receives a full list of DNS records. What does this indicate about the target's DNS configuration?

A.The DNS server has DNSSEC enabled
B.The DNS server allows recursive queries
C.The DNS server allows zone transfers from any host
D.The DNS server is authoritative for the domain
AnswerC

The `dnsrecon` tool, when used with the `-d` flag, attempts to perform a zone transfer (AXFR) from the specified domain's DNS servers. A successful execution, as implied by the question context, indicates that the DNS server is configured to permit full zone transfers to any requesting host, including unauthorized external entities. This represents a significant security misconfiguration, as it exposes sensitive network topology and host information.

Why this answer

The 'dnsrecon -d example.com -t axfr' command performs a DNS zone transfer (AXFR) request. Receiving a full list of DNS records indicates that the target DNS server is misconfigured to allow zone transfers from any host, which exposes the entire DNS zone data (including internal hostnames and IP addresses) to unauthorized parties. This is a critical information disclosure vulnerability.

Exam trap

The trap here is that candidates confuse 'authoritative' with 'vulnerable' — being authoritative is normal, but allowing unrestricted zone transfers is the misconfiguration; EC-Council often tests this by making option D sound correct because the server is authoritative, but the real issue is the lack of access control on the AXFR query.

How to eliminate wrong answers

Option A is wrong because DNSSEC (DNS Security Extensions) provides data integrity and authentication via digital signatures, but it does not control or prevent zone transfers; a server can have DNSSEC enabled and still allow unauthorized AXFR. Option B is wrong because recursive queries allow the DNS server to resolve queries for external domains on behalf of clients, which is a separate setting (often controlled by 'allow-recursion') and not directly related to zone transfer permissions. Option D is wrong because being authoritative for a domain means the server holds the official zone data for that domain, which is normal and expected; the security issue is not that it is authoritative, but that it allows zone transfers from any host without restriction.

355
MCQmedium

Which type of malware is characterized by modifying its own code to evade signature-based detection, often changing its appearance each time it replicates?

A.Polymorphic virus
B.Trojan horse
C.Macro virus
D.Boot sector virus
AnswerA

A polymorphic virus is specifically designed to evade detection by antivirus software through continuous modification of its own code. Each new infection generates a unique, encrypted version of the virus body, coupled with a varying decryption routine. This constant mutation of its signature makes it extremely challenging for traditional signature-based detection systems to identify and quarantine, directly aligning with the characteristic of modifying its own code.

Why this answer

A polymorphic virus is designed to change its code signature each time it replicates, using a mutation engine to generate new decryption routines or code patterns. This behavior allows it to evade signature-based detection by antivirus software, which relies on static patterns to identify threats.

Exam trap

A common trap in CEH exams is confusing polymorphic malware (which changes its decryption routine) with metamorphic malware (which rewrites its entire code). Polymorphic malware uses a mutation engine but retains a fixed code body, while metamorphic malware changes its entire code structure.

How to eliminate wrong answers

Option B is wrong because a Trojan horse disguises itself as legitimate software to trick users into installing it, but it does not inherently modify its own code to evade detection. Option C is wrong because a macro virus infects documents by embedding malicious macros, and while it can replicate, it typically does not change its code signature polymorphically. Option D is wrong because a boot sector virus infects the master boot record of a storage device and does not employ code mutation to alter its appearance on each replication.

356
MCQmedium

An organization receives an email that appears to be from the CEO, urgently requesting that the recipient wire funds to a new vendor. The email contains the CEO's name and title but the sender address is slightly misspelled. Which type of social engineering attack is this?

A.Pretexting
B.Whaling
C.Vishing
D.Spear phishing
AnswerB

Whaling is a highly targeted form of phishing specifically aimed at senior executives, C-level management, or other high-profile individuals within an organization. These attacks are meticulously crafted and personalized, often leveraging publicly available information to create convincing emails that appear to come from a legitimate, trusted source, such as a legal firm or a high-ranking internal contact. The objective is typically to trick the executive into authorizing large wire transfers, revealing sensitive corporate data, or granting access to critical systems. The scenario describes an email likely targeting a high-level individual, making whaling the most precise classification.

Why this answer

This is a whaling attack because the attacker impersonates a high-profile executive (the CEO) to deceive the recipient into transferring funds. Whaling is a subtype of spear phishing that specifically targets individuals with authority or financial access, often by spoofing a senior executive's email address. In this scenario, the CEO's identity is used to exploit trust and urgency, making it a whaling attack.

Exam trap

The trap here is that candidates may choose 'Spear phishing' because they recognize it as a targeted email attack, but fail to distinguish that 'Whaling' is the specific subtype reserved for high-level executives, which is the key differentiator in CEH exam questions.

How to eliminate wrong answers

Option A (Pretexting) is wrong because pretexting involves creating a fabricated scenario or false identity to obtain information, not sending a spoofed email impersonating a specific executive. Option C (Vishing) is wrong because vishing is a voice-based social engineering attack conducted over the phone (VoIP), not via email. Option D (Spear phishing) is wrong because while this attack is a type of spear phishing, the term 'whaling' is the more specific and correct classification when the target is a high-ranking executive like the CEO.

357
MCQeasy

Which Google dork would a penetration tester use to find login pages of websites that have 'admin' in the URL?

A.site:admin login
B.filetype:pdf admin login
C.intitle:"login" inurl:admin
D.inurl:"admin" inurl:"login"
AnswerD

This dork effectively leverages the `inurl:` operator, which specifically restricts search results to pages where the specified keyword appears within the URL string. By combining `inurl:"admin"` and `inurl:"login"`, the search precisely targets web pages that contain both "admin" and "login" within their URL paths. This combination is highly effective for identifying administrative login interfaces, as these keywords frequently appear together in the URLs of such sensitive portals.

Why this answer

The Google dork `inurl:"admin" inurl:"login"` specifically searches for pages where both 'admin' and 'login' appear in the URL. This is a precise way to find login pages on administrative interfaces, as it targets URLs containing both terms, which is a common pattern for admin login portals.

Exam trap

The trap here is that candidates often choose `intitle:"login" inurl:admin` (Option C) thinking it's more comprehensive, but they overlook that many admin login pages do not have 'login' in the HTML title tag, making the `intitle:` operator too restrictive for this specific goal.

How to eliminate wrong answers

Option A is wrong because `site:admin login` is not a valid Google dork; `site:` requires a domain name, not a keyword, and 'admin login' as a search phrase would just match pages containing those words anywhere, not specifically in the URL. Option B is wrong because `filetype:pdf admin login` restricts results to PDF files, which is irrelevant for finding login pages (typically HTML/ASPX/PHP), and the terms 'admin' and 'login' are searched in the page content, not the URL. Option C is wrong because `intitle:"login" inurl:admin` searches for pages with 'login' in the title and 'admin' in the URL, but this misses pages where 'login' is only in the URL (not the title), which is common for many admin login pages.

358
Drag & Dropmedium

Drag and drop the steps to set up a reverse shell using Netcat into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

In a reverse shell using Netcat, the correct sequence is: first, the attacker sets up a listener on a chosen port; second, the victim executes a command that connects back to the attacker's listener; third, the attacker gains a shell on the victim machine; fourth, the attacker executes commands; and finally, cleanup is performed to close the connection. This order ensures the listener is ready before the victim connects, and that the shell is operational before executing any commands or terminating the session.

359
Multi-Selectmedium

Which TWO of the following are examples of static malware analysis techniques? (Select two.)

Select 2 answers
A.Running the malware in a sandbox
B.Capturing network traffic during execution
C.Monitoring process behavior with Process Monitor
D.Checking file hash on VirusTotal
E.Examining strings in the binary
AnswersD, E

Checking a file hash on VirusTotal is a static analysis method because it involves generating a unique digital fingerprint of the file's contents without ever executing the program. This hash is then compared against a vast database of known malware hashes and associated static signatures, which are also derived from non-execution analysis. The process relies solely on the intrinsic properties of the file itself, providing an immediate, non-behavioral assessment.

Why this answer

Option D is correct because checking a file hash on VirusTotal is a static technique: you compute a cryptographic hash (e.g., MD5/SHA-256) of the sample and look it up in a database without ever executing the code. Option E is correct because examining strings in the binary uses tools like strings or a disassembler to extract embedded ASCII/Unicode text and other artifacts from the file on disk, again without running it. Both D and E analyze the malware's static properties (hash values, embedded strings) rather than its runtime behavior.

In contrast, A (sandbox execution), B (capturing network traffic during execution), and C (monitoring process behavior with Process Monitor) all require the malware to run, making them dynamic analysis techniques, not static ones.

Exam trap

The trap here is that candidates often confuse dynamic analysis (execution-based) with static analysis (non-execution-based), mistakenly selecting sandboxing or process monitoring as static techniques because they involve 'analyzing' the malware, but the CEH exam strictly distinguishes them by whether the code is run.

360
MCQeasy

A security analyst receives an alert indicating that a workstation is sending outbound connections to a known malicious IP address. The analyst suspects a Trojan. Which tool is BEST for performing dynamic analysis of the suspicious binary?

A.VirusTotal
B.Sandbox
C.String analysis
D.PEiD
AnswerB

A sandbox provides a secure, isolated environment where suspicious binaries can be executed and observed without risking the host system. It meticulously records all dynamic behaviors, including file system modifications, registry changes, network connections, process injections, and API calls. This controlled execution allows security analysts to understand the malware's true intent and operational capabilities in real-time.

Why this answer

Dynamic analysis involves executing the suspicious binary in a controlled environment to observe its runtime behavior, such as outbound connections, registry changes, and file system modifications. A sandbox provides an isolated environment specifically designed for this purpose, allowing the analyst to safely monitor the Trojan's actions without risking the production network. This makes it the best choice for analyzing the workstation's outbound connections to a known malicious IP address.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse tools like VirusTotal or PEiD (static) with sandboxing (dynamic) when the question explicitly requires observing runtime behavior such as outbound connections.

How to eliminate wrong answers

Option A is wrong because VirusTotal is a static analysis tool that checks file hashes against known malware signatures using multiple antivirus engines; it does not execute the binary to observe runtime behavior like outbound connections. Option C is wrong because string analysis is a static analysis technique that extracts readable text from the binary (e.g., IP addresses, API calls) but does not involve execution, so it cannot reveal dynamic behavior such as actual network connections. Option D is wrong because PEiD is a static analysis tool used to detect packers, compilers, or cryptors in PE files; it does not execute the binary and cannot observe runtime activities like outbound connections.

361
MCQmedium

An ethical hacker is performing a vulnerability scan against a Windows Server 2019 host using Nessus. The scan returns a finding titled 'Microsoft Windows SMB Registry Remotely Accessible' with a CVSS base score of 5.0. The report marks the vulnerability as 'Medium' severity but does not provide a specific patch. Which of the following should the tester do NEXT to determine the actual risk and remediation?

A.Run a full credential brute-force attack against SMB to see if the registry can be accessed.
B.Correlate the finding with the Microsoft Security Response Center (MSRC) advisory and verify the registry key exposure with a manual check.
C.Immediately exploit the SMB registry exposure using Metasploit to prove impact before reporting.
D.Mark the finding as a false positive because CVSS 5.0 is not critical and ignore it.
AnswerB

This is correct because a scanner's generic finding often lacks patch-level detail. Correlating with MSRC advisories and manually verifying the exposed registry key confirms whether the issue is truly exploitable and identifies the precise patch. This reduces false positives and gives the client actionable remediation guidance, which is the core of vulnerability analysis.

Why this answer

A scanner finding without a specific patch requires validation against vendor advisories and manual confirmation. Correlating with MSRC advisories and checking the registry key manually establishes whether the exposure is real and what patch applies. This avoids false positives and provides precise remediation, which is essential in vulnerability analysis before any exploitation.

Exam trap

The trap here is assuming a medium CVSS score means the finding can be ignored or that exploitation is the only way to validate it.

362
Multi-Selectmedium

Which TWO of the following are examples of application-layer DDoS attacks? (Choose two.)

Select 2 answers
A.UDP flood
B.Slowloris
C.HTTP flood
D.SYN flood
E.Smurf attack
AnswersB, C

Slowloris exhausts a web server's connection pool by opening many partial HTTP requests and holding them open, sending periodic header fragments to prevent timeouts. Operating at the application layer, it satisfies the stem's requirement by targeting HTTP rather than network or transport resources, unlike volumetric or SYN-flood techniques.

Why this answer

Slowloris (B) is an application-layer DDoS attack because it opens many partial HTTP connections to a web server and keeps them alive by sending incomplete headers, exhausting the server's connection pool at Layer 7. HTTP flood (C) is also an application-layer attack because it overwhelms a web application with seemingly legitimate HTTP GET or POST requests, consuming server and application resources. By contrast, UDP flood (A) is a volumetric transport/network-layer attack that saturates bandwidth with UDP packets, SYN flood (D) exploits the TCP three-way handshake at the transport layer by leaving half-open connections, and Smurf attack (E) is an ICMP-based network-layer amplification attack using broadcast addresses.

Exam trap

The trap here is that candidates often confuse transport-layer attacks (like SYN floods and UDP floods) with application-layer attacks, because both can cause denial of service, but only application-layer attacks target specific protocols like HTTP, DNS, or SMTP at Layer 7.

363
MCQhard

A forensic analyst examines a system infected with malware that displays ransomware notes and encrypts files. The analyst uses a sandbox to observe behavior. During analysis, the malware contacts a C2 server and downloads additional payloads. Which type of malware analysis is being performed?

A.Dynamic analysis
B.Static analysis
C.Network analysis
D.Code analysis
AnswerA

Dynamic analysis involves executing the malware within a controlled, isolated environment, such as a sandbox or virtual machine, to observe its real-time behavior. This method allows forensic analysts to meticulously document system changes, process interactions, file modifications, and network communications initiated by the malicious code as it runs. It is crucial for understanding the full operational impact and capabilities of sophisticated threats.

Why this answer

Dynamic analysis involves executing the malware in a controlled environment (sandbox) to observe its runtime behavior, such as contacting a C2 server and downloading additional payloads. This contrasts with static analysis, which examines the code without execution. The scenario explicitly describes observing behavior during execution, confirming dynamic analysis.

Exam trap

EC-CEH often tests the distinction between dynamic and static analysis by describing runtime behavior (like C2 contact) and expecting candidates to recognize that only dynamic analysis involves executing the sample in a sandbox. A common mistake is to select 'network analysis' because the malware contacts a C2 server, but network analysis is a subset of dynamic analysis; the question specifically emphasizes sandbox execution.

How to eliminate wrong answers

Option B is wrong because static analysis examines the malware's code or structure without executing it, such as disassembling or analyzing file headers, not observing runtime behavior like C2 communication. Option C is wrong because network analysis focuses specifically on capturing and inspecting network traffic (e.g., using Wireshark) to identify communication patterns, but the question describes a broader behavioral observation in a sandbox, not just network traffic. Option D is wrong because code analysis is a subset of static analysis that involves reviewing source or binary code, not executing the malware to observe its actions.

364
MCQeasy

Which of the following tools is specifically designed to crack Windows LAN Manager (LM) and NTLM hashes using rainbow tables?

A.Hashcat
B.RainbowCrack
C.John the Ripper
D.Ophcrack
AnswerD

Ophcrack is a dedicated and highly effective password cracker specifically designed to recover Windows LM and NTLM hashes by leveraging precomputed rainbow tables. It comes with pre-generated tables optimized for these hash types, allowing for very fast lookups and password recovery, even from live systems or SAM files. Its primary strength lies in its specialized focus and efficient implementation of rainbow table technology for Windows authentication credentials.

Why this answer

Ophcrack is specifically designed to crack Windows LM and NTLM hashes using precomputed rainbow tables. It leverages the time-memory trade-off technique to rapidly reverse these hashes without brute-forcing, making it the correct choice for this targeted task.

Exam trap

The trap here is that candidates often confuse RainbowCrack (a generic rainbow table tool) with Ophcrack (which is specifically designed for Windows LM/NTLM hashes), leading them to select RainbowCrack despite Ophcrack being the correct answer due to its Windows-specific focus.

How to eliminate wrong answers

Option A is wrong because Hashcat is a general-purpose password recovery tool that uses GPU acceleration and supports many hash types, but it is not specifically designed for rainbow table attacks; it primarily uses brute-force, dictionary, and rule-based attacks. Option B is wrong because RainbowCrack is a generic rainbow table implementation that can crack various hash types, but it is not specifically tailored to Windows LM/NTLM hashes and lacks the integrated Windows-focused features of Ophcrack. Option C is wrong because John the Ripper is a versatile password cracking tool that supports many hash formats, but it does not natively use rainbow tables; its primary methods are dictionary and brute-force attacks.

365
MCQmedium

A penetration tester uses the tool 'ScoutSuite' against an AWS target. Which of the following BEST describes the purpose of this tool?

A.Enumerate IAM users and roles for privilege escalation
B.Perform automated penetration testing of web applications
C.Exploit vulnerabilities in cloud services
D.Audit cloud infrastructure for misconfigurations and compliance
AnswerD

ScoutSuite's core functionality involves programmatically fetching extensive configuration data from various cloud services, including AWS S3, EC2, IAM, and Security Groups, through API interactions. It then meticulously analyzes this collected data against a robust set of predefined security best practices and compliance benchmarks. This process culminates in a comprehensive, human-readable report highlighting critical misconfigurations such as publicly exposed storage buckets, overly permissive IAM policies, unencrypted resources, or unpatched instances, thereby providing a clear overview of the cloud environment's security posture.

Why this answer

ScoutSuite is an open-source multi-cloud security auditing tool that assesses cloud environments (AWS, Azure, GCP) by scanning for misconfigurations and compliance violations. It does not perform exploitation or penetration testing; instead, it checks for issues like overly permissive security groups, unencrypted S3 buckets, or unused IAM roles, aligning with option D's description of auditing cloud infrastructure for misconfigurations and compliance.

Exam trap

EC-Council often tests the distinction between auditing and exploitation, so the trap here is that candidates confuse 'auditing for misconfigurations' with 'exploiting vulnerabilities,' leading them to choose option C, even though ScoutSuite is purely a read-only assessment tool.

How to eliminate wrong answers

Option A is wrong because ScoutSuite does not specifically enumerate IAM users and roles for privilege escalation; it audits all cloud resources for misconfigurations, and while it may report IAM issues, its primary purpose is not targeted enumeration for privilege escalation. Option B is wrong because ScoutSuite is not a web application penetration testing tool; it focuses on cloud infrastructure configuration, not web application vulnerabilities like SQL injection or XSS. Option C is wrong because ScoutSuite does not exploit vulnerabilities; it is a read-only auditing tool that identifies misconfigurations without performing any exploitation actions.

366
Multi-Selectmedium

Which TWO techniques are commonly used for privilege escalation on Linux systems? (Select two.)

Select 2 answers
A.Kernel exploits
B.SUID/GUID abuse
C.Token impersonation
D.DLL hijacking
E.Pass-the-hash
AnswersA, B

Exploiting kernel vulnerabilities to gain root.

Why this answer

Kernel exploits (A) are a common privilege escalation technique on Linux because they target vulnerabilities in the kernel itself, allowing an attacker to execute arbitrary code with root privileges. By exploiting flaws such as buffer overflows or race conditions in kernel modules, an attacker can elevate from a low-privileged user to full root access. This is a classic method because the kernel runs with the highest system privileges, and a successful exploit bypasses all user-level security controls.

Exam trap

EC-Council often tests the distinction between Windows-specific and Linux-specific privilege escalation techniques, and the trap here is that candidates may confuse token impersonation or pass-the-hash as cross-platform methods, when they are strictly tied to Windows authentication and security models.

367
Multi-Selecteasy

Which THREE of the following are password cracking techniques? (Select 3)

Select 3 answers
A.Dictionary attack
B.Brute-force attack
C.Phishing
D.Steganography
E.Rainbow table attack
AnswersA, B, E

Uses a wordlist to guess passwords.

Why this answer

A dictionary attack is a password cracking technique where an attacker uses a precompiled list of likely passwords (a dictionary file) to attempt authentication against a target system. It relies on the fact that many users choose common words or phrases as passwords, making it effective against weak passwords but ineffective against strong, random ones.

Exam trap

The trap here is that candidates may confuse password cracking techniques with broader attack categories like social engineering (phishing) or data hiding (steganography), which are distinct concepts in the CEH exam's enumeration and system hacking domain.

368
Multi-Selecthard

Which THREE of the following are effective countermeasures against evil twin attacks in wireless networks? (Select THREE.)

Select 3 answers
A.Implementing client-side certificate validation for network authentication
B.Using WPA3-Enterprise with 802.1X authentication
C.Enabling MAC address filtering on the AP
D.Disabling SSID broadcast on the legitimate AP
E.Using a VPN over the wireless connection
AnswersA, B, E

Implementing client-side certificate validation for network authentication is a robust countermeasure because it mandates that the client verify the identity of the access point (AP) using a pre-installed, trusted digital certificate. If a rogue AP, such as an evil twin, attempts to impersonate the legitimate network, it will lack the correct certificate, causing the client to reject the connection and preventing users from inadvertently connecting to the malicious network.

Why this answer

Evil twin attacks involve a rogue AP impersonating a legitimate one. Countermeasures include using WPA3-Enterprise with 802.1X for mutual authentication, implementing client-side certificate validation, and using VPNs to encrypt traffic even over rogue APs.

369
MCQmedium

An organization experiences a DDoS attack where the attacker sends a flood of UDP packets to a server, causing it to become unresponsive. The packets appear to come from many different source IP addresses and are directed to random high-numbered ports. Which type of DDoS attack is this?

A.ICMP flood
B.UDP flood
C.SYN flood
D.Smurf attack
AnswerB

A UDP flood attack involves sending a high volume of User Datagram Protocol (UDP) datagrams to random high-numbered ports on a target server. The server then attempts to identify which application, if any, is listening on each port. When no application is found, the server typically generates an ICMP "Destination Unreachable" packet in response. This continuous process consumes significant server resources, including CPU cycles and outgoing network bandwidth, leading to service degradation or denial for legitimate users, precisely matching the described scenario.

Why this answer

A UDP flood attack works by overwhelming a target server with a high volume of UDP packets sent to random high-numbered ports. The server checks each port for a listening application, and when none is found, it responds with ICMP Destination Unreachable messages, consuming CPU and bandwidth until the server becomes unresponsive. The use of spoofed source IP addresses makes it difficult to filter the attack traffic based on source alone.

Exam trap

The trap here is that candidates confuse a UDP flood with a SYN flood because both involve flooding and spoofed IPs, but the key differentiator is the transport layer protocol (UDP vs. TCP) and the use of random high-numbered ports versus specific TCP ports.

How to eliminate wrong answers

Option A is wrong because an ICMP flood uses ICMP echo request (ping) packets, not UDP packets, and targets the network layer rather than random high-numbered UDP ports. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending incomplete SYN segments, not UDP packets, and targets specific TCP ports. Option D is wrong because a Smurf attack sends ICMP echo requests to a network's broadcast address with a spoofed victim IP, causing all hosts to reply to the victim, which is an ICMP-based amplification attack, not a direct UDP flood to random ports.

370
MCQhard

An attacker successfully escalates privileges on a Windows server using a known vulnerability in the Print Spooler service (PrintNightmare). Which type of privilege escalation does this represent?

A.Local exploit in a service
B.DLL hijacking
C.SUID abuse
D.Token impersonation
AnswerA

A local exploit in a service directly targets vulnerabilities within a running Windows service, such as the Print Spooler. These services often operate with elevated privileges, like SYSTEM, and a successful exploit can allow an attacker to execute arbitrary code with those higher permissions. This method directly leverages a flaw in the service's code or configuration to escalate privileges from a low-privileged user account. PrintNightmare is a prime example, exploiting a vulnerability in the Print Spooler service to achieve SYSTEM-level access.

Why this answer

The PrintNightmare vulnerability (CVE-2021-34527) allows an attacker to execute arbitrary code with SYSTEM privileges via the Windows Print Spooler service. Since the attacker exploits a vulnerability in a running service (spoolsv.exe) to elevate from a lower-privileged user to SYSTEM, this is a classic local exploit in a service. The attack does not involve hijacking DLLs, abusing SUID bits (a Unix concept), or impersonating tokens, making option A the correct classification.

Exam trap

The trap here is that candidates confuse 'service exploitation' with 'token impersonation' because both can achieve SYSTEM privileges, but PrintNightmare is specifically a service-level exploit, not a token manipulation attack.

How to eliminate wrong answers

Option B (DLL hijacking) is wrong because PrintNightmare exploits a vulnerability in the Print Spooler service itself, not by placing a malicious DLL in a path that the service loads. Option C (SUID abuse) is wrong because SUID is a Unix/Linux permission mechanism, not applicable to Windows privilege escalation. Option D (Token impersonation) is wrong because while token manipulation can be used in some privilege escalation techniques, PrintNightmare directly exploits a service vulnerability to gain SYSTEM access, not by stealing or impersonating an existing token.

371
MCQhard

A tester sends the following payload to a web application: %3Cscript%3Ealert('XSS')%3C/script%3E. The application echoes back the decoded payload in the response without sanitization. This behavior is typical of which type of vulnerability?

A.HTTP Response Splitting
B.DOM-based XSS
C.Stored XSS
D.Reflected XSS
AnswerD

Reflected Cross-Site Scripting, or Non-Persistent XSS, occurs when a malicious script, often embedded in a URL parameter, is immediately returned by the web server in its HTTP response without proper sanitization. The browser then interprets and executes this unsanitized script as part of the legitimate page content. The payload "><script>alert('XSS')</script>" is characteristic of a reflected attack, designed to break out of an HTML context and execute client-side code upon immediate reflection.

Why this answer

Reflected XSS occurs when an application immediately echoes user-supplied input in the response without proper sanitization. The payload is not stored on the server but reflected back to the user, executing in the victim's browser. The given payload is URL-encoded and decoded by the server, then echoed, which is typical of reflected XSS.

Exam trap

CEH often tests the difference between reflected, stored, and DOM-based XSS; candidates may confuse reflected with stored because both involve echoing, but reflected is immediate and not persistent.

How to eliminate wrong answers

Option A is wrong because HTTP Response Splitting involves injecting CRLF characters to manipulate headers, not executing scripts. Option B is wrong because DOM-based XSS occurs when client-side JavaScript processes input unsafely, not when the server echoes it. Option C is wrong because Stored XSS involves the payload being saved on the server (e.g., in a database) and later displayed to other users.

372
MCQmedium

During a reconnaissance phase, a tester uses `dnsrecon -d example.com -t axfr`. What specific DNS query is being attempted?

A.A subdomain brute-force
B.A zone transfer request
C.A reverse DNS lookup
D.A SRV record enumeration
AnswerB

When dnsrecon is executed with only the domain specified, such as dnsrecon -d example.com, its default behavior is to attempt a DNS zone transfer (AXFR). This process requests a full copy of the DNS zone file from the authoritative name server. If the server is misconfigured to allow unauthorized zone transfers, the tester can obtain a comprehensive list of all hostnames, IP addresses, and other DNS records for the domain, providing extensive reconnaissance data.

Why this answer

The `-t axfr` flag in `dnsrecon` specifies a zone transfer request (AXFR). This query attempts to retrieve the entire DNS zone file from a nameserver, which can reveal all DNS records for the domain. A successful zone transfer is a critical misconfiguration because it exposes internal network topology and hostnames.

Exam trap

The trap here is that candidates may confuse `-t axfr` with other reconnaissance techniques like brute-forcing or record enumeration, but the CEH exam specifically tests the exact command flag for zone transfers.

How to eliminate wrong answers

Option A is wrong because a subdomain brute-force uses a wordlist to guess subdomains, not the AXFR query type. Option C is wrong because a reverse DNS lookup queries an IP address for a PTR record, not a domain for a zone transfer. Option D is wrong because SRV record enumeration uses the `-t srv` flag or similar, not `-t axfr`, which is specific to zone transfers.

373
MCQmedium

A security team wants to mitigate a DNS amplification DDoS attack. Which of the following techniques would be MOST effective in preventing the attack from leveraging open DNS resolvers?

A.Deploy a web application firewall
B.Disable recursion on DNS servers for external queries
C.Use anycast routing for DNS servers
D.Implement rate limiting on DNS responses
AnswerB

Disabling recursion on DNS servers for external queries is the most effective direct mitigation against DNS amplification attacks. By configuring a DNS server to only perform recursive lookups for internal, trusted clients and to only respond authoritatively for its own zones to external requests, it prevents the server from acting as an open recursive resolver. This crucial configuration change eliminates the server's ability to be exploited by attackers to amplify small queries into large responses directed at a victim, thereby removing it as a participant in such attacks.

Why this answer

Disabling recursion on DNS servers for external queries prevents them from acting as open resolvers. In a DNS amplification attack, the attacker sends a small query with a spoofed source IP to an open resolver, which then sends a large response to the victim. By blocking recursion for external clients, the server will only answer for domains it authoritatively hosts, thus eliminating the amplification vector.

Exam trap

The trap here is that candidates confuse rate limiting or anycast as effective defenses, but the CEH exam specifically tests that the root cause of DNS amplification is open recursion, and disabling recursion is the most direct mitigation.

How to eliminate wrong answers

Option A is wrong because a web application firewall (WAF) operates at Layer 7 and is designed to filter HTTP/HTTPS traffic, not DNS queries (UDP port 53), so it cannot mitigate DNS amplification attacks. Option C is wrong because anycast routing improves availability and distributes traffic across multiple DNS servers but does not prevent them from being used as open resolvers; an anycast server with recursion enabled can still be exploited. Option D is wrong because rate limiting on DNS responses reduces the volume of traffic from a single server but does not stop the attacker from using many open resolvers to amplify traffic; the core vulnerability is recursion, not response rate.

374
MCQmedium

A security analyst notices that the web application returns different response times when a valid username is submitted versus an invalid one during login. Which type of vulnerability is likely being exploited?

A.Time-based SQL injection
B.Reflected XSS
C.Blind boolean-based SQL injection
D.CSRF
AnswerA

Time-based SQL injection is the correct answer because the scenario explicitly describes inferring information based on *timing differences* in the web application's response. This technique is employed when direct error messages or content changes are not visible to the attacker. Attackers inject SQL queries containing database-specific time-delay functions (e.g., SLEEP() in MySQL, WAITFOR DELAY in MS SQL Server) within a conditional statement. If the injected condition evaluates to true, the database pauses for a specified duration, causing a noticeable delay in the application's response, thereby confirming the truthfulness of the condition and allowing data exfiltration character by character.

Why this answer

Time-based SQL injection involves injecting SQL code that causes the database to pause if a condition is true, allowing an attacker to infer information based on response times. The observed difference in response times for valid vs. invalid usernames is characteristic of this technique.

375
MCQmedium

An ethical hacker needs to crack a set of NTLM hashes obtained from a Windows system. Which tool would be MOST efficient for performing a dictionary attack with hybrid rules?

A.John the Ripper
B.Hashcat
C.Ophcrack
D.RainbowCrack
AnswerB

Hashcat is the industry-standard password recovery tool, highly optimized for cracking NTLM hashes due to its unparalleled support for GPU acceleration. It efficiently leverages modern graphics cards to perform millions of guesses per second, significantly reducing cracking time. Furthermore, Hashcat offers a wide array of attack modes, including dictionary, brute-force, mask, and sophisticated hybrid attacks, making it exceptionally versatile and fast for obtaining NTLM hashes.

Why this answer

Hashcat is the most efficient tool for performing a dictionary attack with hybrid rules because it is GPU-accelerated, supports the NTLM hash mode (1000), and allows the application of rule-based mutations (e.g., appending digits or special characters) directly to dictionary words. Its speed and flexibility in handling large wordlists with complex rule sets make it superior for cracking NTLM hashes in a professional penetration test.

Exam trap

EC-Council often tests the misconception that John the Ripper is the best all-around password cracker, but for GPU-accelerated hybrid dictionary attacks on NTLM hashes, Hashcat is the industry standard due to its speed and rule engine.

How to eliminate wrong answers

Option A is wrong because John the Ripper, while capable of dictionary and hybrid attacks, is primarily CPU-based and significantly slower than Hashcat for large-scale NTLM cracking, making it less efficient for this specific task. Option C is wrong because Ophcrack is designed specifically for LM and NTLM hashes using rainbow tables, not for dictionary attacks with hybrid rules; it lacks rule-based mutation capabilities. Option D is wrong because RainbowCrack is a tool for precomputed rainbow table attacks, not for dictionary attacks with hybrid rules; it requires tables to be generated beforehand and cannot apply real-time rule mutations.

Page 4

Page 5 of 13

Page 6