Courseiva

Certified Ethical Hacker CEH (CEH) — Questions 526–600

913 questions total · 13pages · All types, answers revealed

Page 7

Page 8 of 13

Page 9
526
MCQhard

You are a security analyst at a financial institution. The SOC has detected anomalous outbound traffic from a server in the DMZ to an unknown IP address on TCP port 8443. The server runs a custom application that normally communicates with internal databases on port 1433. The server's OS is Windows Server 2019. Preliminary analysis shows that a new service named 'UpdateSvc' was installed three days ago, set to start automatically, and runs under the LocalSystem account. The service binary is located at C:\Windows\System32\svchost.exe (the legitimate one). However, the service's 'ImagePath' registry key points to 'C:\Windows\System32\svchost.exe -k UpdateSvc'. Additionally, a scheduled task named 'HealthCheck' runs every hour and executes 'powershell.exe -EncodedCommand <base64>'. The encoded command decodes to a script that downloads a payload from the same unknown IP on port 8443 and executes it in memory. The server has antivirus installed that detected nothing. As the analyst, which of the following is the BEST immediate course of action?

A.Reimage the server immediately to ensure the malware is completely removed.
B.Uninstall the current antivirus and install a different endpoint protection solution, then perform a full scan.
C.Delete the 'UpdateSvc' service and the 'HealthCheck' scheduled task, then run a full antivirus scan.
D.Isolate the server from the network by disconnecting the network cable and blocking the IP at the firewall, then initiate incident response procedures.
AnswerD

Isolating the compromised server is the critical first step in containing an active security incident. Disconnecting the network cable physically severs all external and internal network communication, immediately halting data exfiltration, command-and-control (C2) communications, and preventing lateral movement to other systems. Blocking the IP at the firewall provides an additional layer of network-level containment. This action preserves the system's state for forensic analysis while stopping the immediate threat, allowing for a structured incident response process to follow.

Why this answer

The immediate priority is to contain the threat by isolating the compromised server from the network (disconnecting the cable) and blocking the command-and-control IP at the firewall. This stops the ongoing outbound communication on TCP port 8443 and prevents further payload downloads or data exfiltration. Initiating incident response procedures ensures proper forensic collection and analysis, which is critical before any remediation steps like reimaging or deleting artifacts.

Exam trap

The trap here is that candidates focus on removing the malware artifacts (service and task) rather than containing the threat first, which is a fundamental incident response principle: isolate before eradicate.

How to eliminate wrong answers

Option A is wrong because reimaging the server immediately destroys volatile evidence (e.g., memory, running processes, network connections) that is essential for understanding the attack vector and scope. Option B is wrong because changing antivirus software mid-incident wastes time and does not address the active compromise; the malware is already evading detection via fileless execution (PowerShell in memory), so a scan is unlikely to find it. Option C is wrong because deleting the service and scheduled task without first isolating the server allows the attacker to reinstall them or escalate privileges, and the malware may have persistence mechanisms beyond these two artifacts.

527
Multi-Selecthard

A security analyst is investigating a potential container escape in a Kubernetes cluster. Which THREE of the following are common indicators of a container escape?

Select 3 answers
A.A process running inside the container with CAP_SYS_ADMIN capability
B.The container is running in privileged mode
C.The container is using a hostPath volume that mounts the host's /var/run/docker.sock
D.The container has a read-only root filesystem
E.The container is running as a non-root user
AnswersA, B, C

A process running inside a container with the CAP_SYS_ADMIN capability is a critical security vulnerability. This capability grants extensive privileges, often likened to root access on the host system, allowing operations such as mounting filesystems, creating device nodes, and loading kernel modules. An attacker can leverage CAP_SYS_ADMIN to break out of the container's isolation by manipulating the host's kernel or filesystem, effectively gaining control over the underlying host machine.

Why this answer

Container escape often involves breaking out of the container's isolation by exploiting misconfigurations or vulnerabilities. These indicators are common.

528
MCQmedium

A security analyst reviews a sandbox report for a suspicious executable. The report shows that the executable modified the Windows registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to add a new entry pointing to itself. This action is characteristic of which type of malware?

A.Logic bomb
B.Backdoor Trojan
C.Ransomware
D.Adware
AnswerB

Backdoor Trojans commonly use registry run keys for persistence.

Why this answer

The registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run is a standard autostart location used by Windows to launch programs at system boot. A backdoor Trojan commonly adds itself to this key to achieve persistence, ensuring it runs every time the system starts, which allows an attacker to maintain remote access. This behavior is a hallmark of backdoor Trojans, not other malware types.

Exam trap

The trap here is that candidates might associate any registry modification with ransomware or adware, but the specific action of adding itself to the Run key for persistence is most characteristic of a backdoor Trojan, not the other options.

How to eliminate wrong answers

Option A is wrong because a logic bomb is a piece of code that executes a malicious action when a specific condition is met (e.g., a date or file deletion), not a persistent autostart mechanism via registry modification. Option C is wrong because ransomware typically modifies registry keys to disable security features or alter system behavior (e.g., changing file associations or disabling recovery options), but its primary goal is encryption and ransom, not adding itself to Run for persistence—though some ransomware may do so, it is not the characteristic action described. Option D is wrong because adware usually modifies browser settings or injects advertisements, and while it may use registry Run keys for persistence, its core behavior is displaying ads, not establishing a backdoor for remote access.

529
MCQeasy

During a penetration test, a tester wants to gather email addresses, subdomains, and employee names associated with a target domain. Which of the following tools is specifically designed for such passive reconnaissance?

A.Wireshark
B.theHarvester
C.Metasploit
D.Nmap
AnswerB

theHarvester is a specialized open-source intelligence (OSINT) tool explicitly designed for passive reconnaissance. It systematically queries multiple public data sources, including search engines (Google, Bing), PGP key servers, LinkedIn, and other platforms, to gather publicly available information such as email addresses, subdomains, hostnames, and employee names. Its passive approach means it does not directly interact with the target organization's systems, making it ideal for initial information gathering without alerting the target.

Why this answer

theHarvester is a passive reconnaissance tool specifically designed to gather email addresses, subdomains, employee names, and other open-source intelligence (OSINT) from public sources such as search engines (Google, Bing), PGP key servers, and the Shodan database. It operates without sending direct packets to the target, making it ideal for passive footprinting as defined in the CEH methodology.

Exam trap

EC-Council often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse theHarvester with active tools like Nmap or Wireshark because they all involve network data, but only theHarvester gathers OSINT from third-party public sources without sending packets to the target.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects live traffic in real time, which is an active sniffing technique requiring interaction with the network, not a passive reconnaissance tool for gathering OSINT from public sources. Option C is wrong because Metasploit is an exploitation framework used for developing and executing active exploits against vulnerabilities, not for passive information gathering like email or subdomain enumeration. Option D is wrong because Nmap is an active scanning tool that sends crafted packets (e.g., SYN, ICMP) to discover hosts and services, which generates network traffic and is not passive reconnaissance.

530
Multi-Selecthard

Which THREE of the following are valid methods for exploiting cloud misconfigurations? (Select 3)

Select 3 answers
A.Using a container escape to access the host OS
B.Exploiting an S3 bucket with public read access to download sensitive files
C.Performing a SQL injection on a web application
D.Launching a DDoS attack from a botnet
E.Abusing overly permissive IAM roles to escalate privileges
AnswersA, B, E

Using a container escape to access the host OS is a critical cloud misconfiguration vulnerability. This occurs when a flaw in the container runtime, kernel, or container configuration allows an attacker to break out of the isolated container environment and gain unauthorized access to the underlying host operating system. Such an escape often leverages misconfigured capabilities, insecure mounts, or unpatched kernel vulnerabilities, directly exposing the host infrastructure to compromise.

Why this answer

Option A is correct because a container escape exploits a misconfigured or vulnerable container runtime (e.g., privileged containers, exposed Docker socket, or kernel flaws) to break isolation and reach the underlying host OS, a classic cloud misconfiguration risk. Option B is correct because an S3 bucket configured with public read access is a well-known cloud storage misconfiguration that lets anyone list and download objects, exposing sensitive files. Option E is correct because overly permissive IAM roles (e.g., wildcard actions like iam:* or sts:AssumeRole on broad resources) are a cloud identity misconfiguration that attackers abuse to escalate privileges.

Option C is not specific to cloud misconfigurations—SQL injection is an application-layer vulnerability independent of cloud configuration. Option D is also not a cloud misconfiguration exploit; a DDoS attack from a botnet abuses network/volumetric resources rather than a misconfigured cloud setting.

Exam trap

CEH often tests the distinction between cloud-specific misconfigurations and generic application or network attacks, so candidates must recognize that SQL injection and DDoS are not cloud misconfiguration exploits.

531
MCQeasy

An ethical hacker is building a profile of a target organization's employees and wants to identify names, job titles, and email address formats using only information the organization has published. Which technique is BEST suited to this goal?

A.Cracking the organization's public Wi-Fi pre-shared key from a captured handshake
B.Performing a brute-force SMTP VRFY sweep against the target's mail gateway
C.Reviewing the organization's LinkedIn company page and employee profiles
D.Enumerating SMB shares on the target's internal file servers
AnswerC

LinkedIn profiles and company pages are published by the organization and its employees, so reviewing them is passive and directly yields names, titles, departments, and often the email naming convention. This aligns perfectly with the goal of building an employee profile from publicly available information without contacting target systems.

Why this answer

Employee profiling from published data centers on sources the organization and its staff voluntarily expose, such as LinkedIn, corporate press releases, and conference speaker bios. Reviewing a LinkedIn company page and employee profiles passively reveals names, titles, and the email naming convention, which can then be validated against other public records without ever contacting the target's systems.

Exam trap

The trap here is reaching for an intrusive enumeration technique like SMTP VRFY when the scenario explicitly restricts the tester to information the organization has already published.

532
MCQmedium

A security analyst runs the command 'tcpdump -i eth0 -n host 10.0.0.5 and port 80' and sees many packets with the SYN flag set but no corresponding ACK. Which attack is likely occurring?

A.SYN flood
B.ICMP flood
C.UDP flood
D.Ping of Death
AnswerA

A SYN flood is characterized by an attacker sending a large volume of TCP SYN packets to a target server without completing the three-way handshake. The tcpdump -i eth0 -n host command would reveal a high rate of incoming TCP packets with the SYN flag set, directed at the specified host, but without corresponding SYN-ACK or ACK packets originating from the target. This pattern indicates numerous half-open connections accumulating on the target, exhausting its connection table resources.

Why this answer

The command captures TCP packets on port 80 with the SYN flag set but no corresponding ACK, which indicates that the target is receiving SYN requests but never completing the three-way handshake. This is the hallmark of a SYN flood attack, where the attacker sends a high volume of SYN packets to exhaust the server's connection queue, preventing legitimate connections.

Exam trap

The trap here is that candidates confuse a SYN flood with a generic 'flood' attack (like ICMP or UDP flood) because they focus on the word 'flood' rather than the specific TCP handshake behavior indicated by the SYN flag without ACK.

How to eliminate wrong answers

Option B is wrong because an ICMP flood involves sending a high volume of ICMP echo request (ping) packets, not TCP SYN packets, and would not be captured by a filter for port 80. Option C is wrong because a UDP flood targets UDP ports with a high volume of UDP datagrams, not TCP SYN packets, and would not match the 'port 80' filter (which is TCP-specific). Option D is wrong because a Ping of Death attack sends a malformed oversized ICMP packet to cause a buffer overflow, not TCP SYN packets, and is not related to incomplete handshakes.

533
MCQeasy

Which of the following tools is specifically designed for assessing the security of AWS environments by checking for misconfigurations in services like S3, IAM, and EC2?

A.ScoutSuite
B.Aircrack-ng
C.Nmap
D.Wireshark
AnswerA

ScoutSuite is a comprehensive open-source tool specifically engineered for auditing the security posture of multi-cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). It meticulously identifies security misconfigurations, adherence to best practices, and potential vulnerabilities across various services like IAM, storage, and compute. By generating an interactive HTML report, it provides a clear overview of an organization's cloud security risks, enabling targeted remediation efforts.

Why this answer

ScoutSuite is an open-source security auditing tool for cloud environments, including AWS. It checks for misconfigurations across multiple services and provides a detailed report.

534
MCQmedium

After gaining access to a system, an attacker modifies log files to remove evidence of their activities. This action is part of which phase of the system hacking methodology?

A.Spying
B.Executing applications
C.Hiding files
D.Erasing tracks
AnswerD

Erasing tracks is a critical post-exploitation phase where an attacker systematically removes or alters forensic evidence of their presence and activities on a compromised system. This encompasses various anti-forensic techniques, including clearing system logs (e.g., Windows Event Logs, `auth.log`), modifying timestamps, deleting temporary files, and removing command history. Modifying log files directly falls under this comprehensive objective, aimed at hindering incident response and forensic investigations.

Why this answer

'Erasing tracks,' because after gaining access, the attacker's goal is to cover their footprints by modifying or deleting log files, clearing event logs, or using tools like `wevtutil` or `clearev` to remove evidence of their activities. This phase ensures the system administrator cannot detect the intrusion or trace the attacker's actions.

Exam trap

The trap here is that candidates confuse 'Hiding files' (option C) with 'Erasing tracks,' but hiding files focuses on concealing payloads, while erasing tracks specifically targets log files and audit trails to cover the attacker's digital footprint.

How to eliminate wrong answers

Option A is wrong because 'Spying' is not a recognized phase in the CEH system hacking methodology; it is a vague term that does not correspond to any specific phase like reconnaissance or maintaining access. Option B is wrong because 'Executing applications' refers to running tools or payloads during the 'Gaining Access' or 'Maintaining Access' phases, not the post-exploitation cleanup of logs. Option C is wrong because 'Hiding files' involves concealing malicious files using techniques like NTFS alternate data streams or rootkits, which is part of the 'Maintaining Access' phase, not the specific act of erasing log evidence.

535
MCQeasy

A security analyst suspects an attacker has used a rainbow table to crack password hashes from a compromised system. Which password cracking technique involves precomputed hash chains?

A.Rainbow table attack
B.Dictionary attack
C.Brute force attack
D.Hybrid attack
AnswerA

A rainbow table attack leverages large, precomputed tables containing chains of hash values and their corresponding plaintext passwords. This method significantly speeds up the process of reversing cryptographic hashes to recover the original password, bypassing the need for real-time computation for each guess. Attackers use these tables to quickly find passwords from stolen hash databases by looking up the hash and tracing back the chain. This precomputation makes it highly effective against unsalted hashes.

Why this answer

A rainbow table attack is the correct answer because it specifically uses precomputed hash chains to reverse cryptographic hash functions. Rainbow tables are a form of time-memory trade-off where chains of hashes are computed and stored, allowing an attacker to look up a hash and quickly find the original plaintext without recomputing all possible hashes. This technique is distinct from other methods because it relies on precomputation rather than real-time guessing or dictionary lookups.

Exam trap

The trap here is that candidates often confuse 'precomputed hash chains' with a dictionary attack, thinking that a dictionary file is a form of precomputation, but a dictionary attack still requires real-time hashing of each word, whereas rainbow tables store the chain endpoints for instant lookup.

How to eliminate wrong answers

Option B (Dictionary attack) is wrong because it uses a list of likely passwords (words from a dictionary) and hashes each in real time, not precomputed hash chains. Option C (Brute force attack) is wrong because it tries every possible combination of characters sequentially, without any precomputation or stored chains. Option D (Hybrid attack) is wrong because it combines dictionary words with variations (e.g., appending numbers or symbols) but still performs real-time hashing, not precomputed chains.

536
MCQeasy

Which of the following is a symmetric encryption algorithm that uses a block cipher with a fixed block size of 128 bits and key sizes of 128, 192, or 256 bits?

A.3DES
B.RC4
C.AES
D.RSA
AnswerC

AES (Advanced Encryption Standard) is the correct answer because it is a symmetric block cipher that processes data in fixed-size blocks of 128 bits. It supports robust key lengths of 128, 192, or 256 bits, providing strong cryptographic security. Its design, based on the Rijndael cipher, makes it highly efficient and widely adopted for various secure communication and storage applications.

Why this answer

AES (Advanced Encryption Standard) is a symmetric encryption algorithm that operates as a block cipher with a fixed block size of 128 bits and supports key sizes of 128, 192, or 256 bits. It was established by NIST in 2001 (FIPS 197) and is widely used in modern cryptographic systems, including wireless security (WPA2/WPA3) and TLS.

Exam trap

The trap here is that candidates often confuse AES with 3DES due to both being symmetric block ciphers, but they fail to recall that 3DES uses a 64-bit block size (not 128 bits) and lacks the specific key size options of AES, leading them to select 3DES incorrectly.

How to eliminate wrong answers

Option A is wrong because 3DES (Triple DES) uses a block size of 64 bits, not 128 bits, and its key size is effectively 112 or 168 bits (using three 56-bit DES keys), not the specified 128/192/256-bit options. Option B is wrong because RC4 is a stream cipher, not a block cipher, and it does not have a fixed block size or support key sizes of 128/192/256 bits in the manner described; it uses variable-length keys (typically 40–2048 bits) and is deprecated due to known vulnerabilities. Option D is wrong because RSA is an asymmetric (public-key) encryption algorithm, not a symmetric one, and it does not use a fixed block size or the specified key sizes; it relies on key pairs (public/private) based on large prime numbers.

537
MCQeasy

Which of the following is a primary defense against SQL injection attacks?

A.Prepared statements
B.HTTPS encryption
C.Input blacklisting
D.Output encoding
AnswerA

Prepared statements, also known as parameterized queries, are a primary defense against SQL injection because they fundamentally separate the SQL code logic from user-supplied data. The database engine pre-compiles the query structure, treating all subsequent input as literal data values rather than executable SQL commands. This mechanism ensures that malicious characters within user input cannot alter the intended query structure, effectively preventing injection attacks by ensuring input is never interpreted as code.

Why this answer

Prepared statements with parameterized queries ensure user input is treated as data, not executable SQL code.

538
Multi-Selecthard

Which THREE of the following are common indicators of an SQL injection attack? (Choose 3.)

Select 3 answers
A.Frequent 302 redirects to login pages
B.Multiple failed connection attempts in server logs
C.Unexpected rows or columns in query results
D.Unusually slow database responses
E.Database error messages in the application response
AnswersC, D, E

The presence of unexpected rows or columns in an application's query results is a strong indicator of a successful UNION-based SQL injection. Attackers leverage the `UNION` operator to combine the results of their malicious query with the legitimate query, thereby extracting data from other tables or databases that were not intended for display. This manipulation directly alters the structure and content of the returned dataset, making it a clear sign of data exfiltration or unauthorized data retrieval.

Why this answer

SQL injection attacks commonly cause unexpected rows or columns in query results due to manipulated queries, unusually slow database responses from resource-intensive operations like UNION or subqueries, and database error messages that reveal syntax or structure to the attacker. Frequent 302 redirects and many failed connection attempts are not typical or specific indicators of SQL injection.

539
MCQmedium

A penetration tester needs to perform a brute-force attack on a web application login form. Which Burp Suite tool is specifically designed for automating parameterized attacks like password guessing?

A.Repeater
B.Scanner
C.Intruder
D.Proxy
AnswerC

Intruder is purpose-built for automating parameterized attacks by systematically injecting various payloads into specified insertion points within an HTTP request. It enables sophisticated brute-force, dictionary, and credential stuffing attacks by iterating through user-defined lists or generated sequences of values. This module offers multiple attack types, such as Sniper or Battering Ram, to efficiently test a wide range of input fields for vulnerabilities or weak credentials.

Why this answer

Burp Suite Intruder is specifically designed for automating parameterized attacks, such as brute-forcing login credentials, by allowing the tester to define payload positions and iterate through a list of values (e.g., passwords) against a target endpoint. Unlike other tools in Burp Suite, Intruder supports multiple attack types (Sniper, Battering Ram, Pitchfork, Cluster Bomb) and can handle rate limiting and session handling, making it ideal for password guessing.

Exam trap

EC-Council often tests the misconception that Repeater can be used for brute-forcing because it can resend requests, but Repeater lacks the automated payload iteration and response analysis features that Intruder provides.

How to eliminate wrong answers

Option A is wrong because Repeater is used for manually resending and modifying individual HTTP requests to observe responses, not for automating multiple iterations of parameterized attacks. Option B is wrong because Scanner is designed for automated vulnerability detection (e.g., SQL injection, XSS) and does not support custom payload lists or brute-force sequencing. Option D is wrong because Proxy is an intercepting proxy that captures and forwards traffic between the browser and target, but it lacks the automation and payload iteration capabilities required for brute-force attacks.

540
MCQhard

A security engineer observes that an internal web application uses XML to transmit data between systems. The engineer discovers that by sending a crafted XML payload, they can read sensitive files from the server's filesystem. Which attack is being performed?

A.SSRF
B.Command injection
C.XXE injection
D.XPath injection
AnswerC

XXE injection occurs when an XML parser processes XML input containing references to external entities, which are then resolved by the server without proper validation. Attackers can define malicious external entities within the Document Type Definition (DTD) to exploit this, often using the "file://" protocol to read local files from the server's filesystem, such as configuration files or sensitive credentials. This direct file disclosure via XML entity processing perfectly matches the described observation.

Why this answer

XXE (XML External Entity) injection allows reading files via external entities in XML.

541
Multi-Selectmedium

Which TWO of the following are examples of active reconnaissance techniques? (Select two)

Select 2 answers
A.Querying Shodan for open ports on a target
B.Running an Nmap SYN scan against a target
C.Searching for sensitive files using Google dorks
D.Performing a WHOIS lookup
E.Using Netcat to grab banners from a web server
AnswersB, E

Running an Nmap SYN scan against a target is a definitive example of active reconnaissance because it directly interacts with the target system by sending TCP SYN packets. The target's response, whether a SYN-ACK for open ports or an RST for closed ones, provides real-time information about its network services and host status. This direct packet exchange generates network traffic that originates from the attacker and terminates at the target, making it detectable by intrusion detection systems (IDS) or firewalls.

Why this answer

An Nmap SYN scan (also known as a half-open scan) sends a TCP SYN packet to a target port and analyzes the response. If a SYN/ACK is received, the port is open; if an RST is received, the port is closed. This scan actively interacts with the target system by sending network traffic, making it an active reconnaissance technique.

Exam trap

The trap here is that candidates often confuse passive information-gathering tools (like Shodan, Google dorks, or WHOIS) with active techniques, because they involve querying external databases rather than directly engaging the target's systems.

542
MCQeasy

A junior penetration tester runs the command: whois example.com. What type of information are they MOST likely trying to obtain?

A.DNS zone transfer information
B.The IP address of the web server
C.Open ports on the target server
D.Domain registration details such as registrar, creation date, and contact information
AnswerD

The `whois` command is specifically designed to query WHOIS databases, which contain publicly available registration information for domain names and IP address blocks. This data includes critical details such as the domain registrar, the domain's creation and expiration dates, the associated name servers, and administrative, technical, and registrant contact information. This information is invaluable for initial footprinting and reconnaissance phases of a penetration test.

Why this answer

The `whois` command queries a WHOIS server (typically operated by a Regional Internet Registry or domain registrar) to retrieve domain registration details. This includes the registrar name, creation and expiration dates, name servers, and often administrative/technical contact information. It is a core footprinting technique used to gather publicly available metadata about a domain owner and infrastructure.

Exam trap

EC-Council often tests the distinction between WHOIS (domain registration metadata) and DNS lookups (IP resolution), leading candidates to mistakenly associate WHOIS with IP addresses or server configuration details.

How to eliminate wrong answers

Option A is wrong because DNS zone transfer information is obtained using the `dig axfr` or `nslookup -type=axfr` command against an authoritative DNS server, not via WHOIS. Option B is wrong because while WHOIS may list name servers, it does not directly return the IP address of the web server; that requires a DNS A-record lookup using `nslookup` or `dig`. Option C is wrong because open ports are discovered through port scanning tools like Nmap, not through the WHOIS protocol, which only returns registration metadata.

543
Multi-Selecteasy

Which TWO of the following are symmetric encryption algorithms? (Select TWO.)

Select 2 answers
A.ECC
B.AES
C.RSA
D.3DES
E.SHA-256
AnswersB, D

AES is a symmetric block cipher: sender and receiver share one secret key for both encryption and decryption. It satisfies the question's requirement for a symmetric algorithm, unlike asymmetric options such as RSA or Diffie-Hellman, which use separate public and private key pairs.

Why this answer

AES (B) is correct because it is a symmetric block cipher that uses the same secret key for both encryption and decryption, operating on 128-bit blocks with key sizes of 128, 192, or 256 bits. 3DES (D) is also correct because it is a symmetric block cipher that applies the DES algorithm three times with a shared secret key (effectively 112 or 168 bits of key strength), using the same key for encryption and decryption. ECC (A) is not correct here because it is an asymmetric (public-key) cryptosystem based on elliptic curve mathematics, not a symmetric algorithm. RSA (C) is likewise asymmetric, relying on a public/private key pair for encryption and digital signatures.

SHA-256 (E) is a cryptographic hash function, not an encryption algorithm at all, so it cannot be symmetric encryption.

Exam trap

CEH often tests the confusion between symmetric and asymmetric algorithms, and the trap is that ECC and RSA are asymmetric, while SHA-256 is a hash, not encryption.

544
MCQmedium

A tester runs 'snmpwalk -v2c -c public 192.168.1.1' and receives a large amount of system information. What does this command do?

A.It walks the SNMP MIB tree using version 2c and the public community string.
B.It performs a brute-force attack on SNMP community strings.
C.It enumerates users on a Windows domain.
D.It sets SNMP values using the private community string.
AnswerA

The `snmpwalk` command is specifically designed to query a network device and retrieve all information available within its Management Information Base (MIB) tree, starting from a specified OID (or the root if none is given). The `v2c` flag explicitly dictates the use of SNMP version 2c, which offers improved security and data types over v1. The `c public` argument specifies "public" as the community string, acting as a password for read-only access to the device's SNMP agent at IP address 192.168.1.1. This effectively performs a comprehensive enumeration of the device's configuration and status.

Why this answer

The `snmpwalk` command is used to retrieve a subtree of management values from an SNMP agent. The `-v2c` flag specifies SNMP version 2c, which uses community-based security, and `-c public` provides the community string 'public' (often the default read-only community). The command walks the entire MIB tree starting from the root, returning all available OID values, which explains the large amount of system information received.

Exam trap

The trap here is that candidates may confuse `snmpwalk` with a brute-force tool or think it can modify SNMP values, but the command strictly performs read-only enumeration using the specified community string.

How to eliminate wrong answers

Option B is wrong because `snmpwalk` does not perform brute-force attacks; tools like `onesixtyone` or `hydra` are used for brute-forcing SNMP community strings. Option C is wrong because `snmpwalk` enumerates SNMP MIB objects, not Windows domain users; tools like `enum4linux` or `ldapsearch` are used for domain user enumeration. Option D is wrong because `snmpwalk` only reads values (GET/GETNEXT requests) and does not set or write SNMP values; setting values requires `snmpset` with a read-write community string like 'private'.

545
MCQmedium

A penetration tester wants to perform a ping sweep on a /24 subnet to identify live hosts. Which command would accomplish this efficiently?

A.nmap -sn 192.168.1.0/24
B.nmap -O 192.168.1.0/24
C.nmap -p- 192.168.1.0/24
D.nmap -sV 192.168.1.0/24
AnswerA

The `nmap -sn 192.168.1.0/24` command is the correct choice for performing a ping sweep, also known as host discovery. The `-sn` (or `--ping-scan`) flag instructs Nmap to skip port scanning and only attempt to determine if hosts are online. It achieves this by sending a combination of ICMP echo requests, TCP SYN packets to port 443, and TCP ACK packets to port 80, along with an ICMP timestamp request, to identify live hosts efficiently across the specified /24 subnet. This method quickly identifies active devices without generating extensive network traffic from full port scans.

Why this answer

`nmap -sn` performs a ping sweep (host discovery) without port scanning, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default. This efficiently identifies live hosts on a /24 subnet without the overhead of port scanning or OS detection.

Exam trap

The trap here is that candidates often confuse `-sn` (ping sweep) with `-sP` (deprecated alias) or assume that `-O` or `-sV` are faster because they provide more information, but they actually add significant overhead and are not designed for simple host discovery.

How to eliminate wrong answers

Option B is wrong because `-O` enables OS detection, which requires open ports and sends additional probes, making it slower and not focused on simple host discovery. Option C is wrong because `-p-` scans all 65535 TCP ports, which is a full port scan and extremely time-consuming for a /24 subnet, not a ping sweep. Option D is wrong because `-sV` performs service version detection on open ports, which requires a prior port scan and is not designed for host discovery.

546
MCQmedium

A security analyst performs a passive reconnaissance of a target domain using public resources. Which of the following techniques would be considered passive reconnaissance?

A.Using Netcat to grab banners from the target's email server
B.Running Nmap SYN scan on the target's web server
C.Performing a WHOIS lookup for the target domain
D.Sending a ping sweep to the target's public IP range
AnswerC

Performing a WHOIS lookup for a target domain is a classic example of passive reconnaissance. This process involves querying public databases maintained by domain registrars and registries to retrieve registration information, such as registrant contact details, domain creation/expiration dates, and nameservers. Crucially, these queries are directed at third-party WHOIS servers, not the target domain's actual servers, meaning no direct network traffic is sent to or received from the target, leaving no trace.

Why this answer

Passive reconnaissance involves gathering information without directly interacting with the target's systems, thus avoiding any network traffic that could be detected. A WHOIS lookup queries a public registry database (e.g., whois.arin.net) over port 43 or via a web interface, retrieving domain registration details without sending any packets to the target's own infrastructure. This makes it a purely passive technique.

Exam trap

The trap here is that candidates confuse 'using public resources' (like WHOIS databases) with 'sending network probes' (like banner grabbing or pings), assuming any information-gathering tool is passive if it doesn't exploit vulnerabilities.

How to eliminate wrong answers

Option A is wrong because using Netcat to grab banners requires establishing a TCP connection to the target's email server (e.g., port 25), which sends packets and is an active interaction. Option B is wrong because running an Nmap SYN scan sends crafted TCP SYN packets to the target's web server and analyzes responses, which is active reconnaissance and can be logged by intrusion detection systems. Option D is wrong because sending a ping sweep involves transmitting ICMP Echo Request packets to the target's IP range, directly probing live hosts and generating detectable traffic.

547
MCQeasy

A web application allows users to view documents by specifying a filename in the URL, e.g., /getDocument?file=report.pdf. A tester changes the file parameter to '../../etc/passwd' and retrieves the system password file. Which vulnerability is being exploited?

A.Local File Inclusion (LFI)
B.Directory traversal
C.Remote File Inclusion (RFI)
D.Command injection
AnswerB

Directory traversal, also known as path traversal, is a vulnerability that permits an attacker to read arbitrary files on the server's file system by manipulating file paths in user-supplied input. This exploit uses sequences like "../" (dot-dot-slash) to navigate outside the intended directory, bypassing security controls that fail to properly validate or sanitize file names or paths. The ability to "view documents by specifying" a path directly aligns with this vulnerability, as it focuses on accessing files located anywhere on the server.

Why this answer

The tester manipulated the 'file' parameter with '../' sequences to escape the intended directory and read /etc/passwd, which is classic directory traversal (path traversal). The vulnerability arises because the application fails to sanitize user-supplied file paths, allowing access to files outside the web root.

Exam trap

CEH often tests the confusion between directory traversal (reading arbitrary files via path manipulation) and LFI (including local files for execution), causing candidates to pick LFI when the scenario only shows file disclosure.

How to eliminate wrong answers

Option A is wrong because LFI refers to including a local file for execution within the application (e.g., via include() in PHP), which can lead to code execution; here the file is simply read and returned, which is traversal. Option C is wrong because RFI involves including a remote file from an attacker-controlled server (e.g., http://evil.com/shell.txt), which is not what happened. Option D is wrong because command injection involves injecting OS commands into a shell call (e.g., '; cat /etc/passwd'), not manipulating a file path parameter.

548
MCQmedium

An analyst wants to perform a SYN flood attack test against a server to evaluate its resilience. Which of the following tools would be the MOST appropriate for this task?

A.Nmap
B.Shodan
C.Wireshark
D.hping3
AnswerD

hping3 is a command-line oriented TCP/IP packet assembler/analyzer, specifically engineered for crafting and sending custom packets, including a high volume of SYN packets. Its robust capabilities allow for precise control over packet headers, source IP spoofing, and the ability to flood a target with a continuous stream of SYN requests, making it an ideal and highly effective tool for simulating SYN flood attacks and testing network resilience.

Why this answer

hping3 is the most appropriate tool because it is a command-line packet crafting tool that allows the user to generate custom TCP SYN packets with spoofed source IP addresses, making it ideal for simulating a SYN flood attack. Unlike other tools, hping3 can send a high volume of SYN packets without completing the three-way handshake, which is the core mechanism of a SYN flood that exhausts the server's connection queue.

Exam trap

EC-Council often tests the misconception that Nmap's SYN scan (-sS) is equivalent to a SYN flood attack, but Nmap is designed for stealthy reconnaissance with low packet rates, not for overwhelming a target with high-volume traffic.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning tool used for port discovery and service enumeration, not for generating high-volume attack traffic; it can send SYN packets for scanning but lacks the rate control and spoofing capabilities needed for a sustained SYN flood. Option B is wrong because Shodan is a search engine for internet-connected devices and does not generate any network traffic or perform attacks; it is used for reconnaissance, not exploitation. Option C is wrong because Wireshark is a packet analyzer used for capturing and inspecting network traffic, not for generating or injecting packets; it cannot initiate a SYN flood.

549
Multi-Selecteasy

A web application tester encounters a parameter that is reflected in the response without sanitization. The tester suspects XSS. Which TWO types of XSS could be present in this scenario? (Choose TWO.)

Select 2 answers
A.DOM-based XSS
B.Reflected XSS
C.Self-XSS
D.Stored (persistent) XSS
E.Blind XSS
AnswersA, B

This vulnerability occurs entirely on the client-side when a web application's JavaScript code processes user-controllable data, often from the URL fragment (#) or query string (?), and writes it unsafely into the Document Object Model (DOM). If the client-side script dynamically generates HTML or JavaScript using this unvalidated input, an attacker can inject malicious code that executes within the victim's browser. The "reflection" happens within the browser's DOM, not necessarily on the server's response.

Why this answer

Reflected XSS occurs when the input is immediately reflected in the response. DOM-based XSS occurs when client-side JavaScript processes the input unsafely. Stored XSS requires data to be saved on the server, which is not indicated here.

550
Multi-Selecteasy

Which TWO of the following are common OSINT tools for passive reconnaissance? (Select 2)

Select 2 answers
A.Metasploit
B.theHarvester
C.hping3
D.Maltego
E.Nmap
AnswersB, D

theHarvester is a highly effective OSINT tool specifically designed for passive information gathering during the reconnaissance phase. It systematically collects publicly available data such as email addresses, subdomains, hostnames, employee names, and open ports from various public sources like search engines (Google, Bing), PGP key servers, LinkedIn, and Shodan. This makes it an excellent choice for building an initial profile of a target without direct interaction.

Why this answer

theHarvester (B) is a passive OSINT tool that gathers emails, subdomains, hosts, employee names, and open ports from public sources such as search engines, PGP key servers, and Shodan without directly touching the target. Maltego (D) is a graphical OSINT and link-analysis tool that queries public data sources and transforms to map relationships among people, domains, IPs, and organizations, making it a staple of passive reconnaissance. Metasploit (A) is an exploitation framework used for active attacks, not passive information gathering. hping3 (C) is a packet-crafting tool for active network probing and firewall testing.

Nmap (E) performs active scanning by sending probes to targets, so it is not a passive OSINT tool.

Exam trap

EC-Council often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse tools like Nmap or hping3 (which are active) with passive OSINT tools because they are commonly used in the early stages of an engagement.

551
MCQeasy

A security analyst captures a large number of weak initialization vectors (IVs) using airodump-ng. Which attack does this preparation indicate?

A.WPS PIN brute force
B.WPA2 dictionary attack
C.WEP key cracking
D.Evil twin attack
AnswerC

WEP (Wired Equivalent Privacy) encryption is notoriously vulnerable due to its use of a 24-bit Initialization Vector (IV) concatenated with the static WEP key to form the RC4 cipher key. The small IV space leads to frequent IV reuse, especially with weak IVs that reveal information about the key stream. By capturing a sufficient number of these weak IVs and their corresponding encrypted packets, tools like aircrack-ng can statistically analyze the patterns to deduce the WEP key, often within minutes.

Why this answer

WEP (Wired Equivalent Privacy) uses the RC4 stream cipher with a 24-bit initialization vector (IV) that is transmitted in plaintext. Weak IVs, such as those identified by tools like airodump-ng, are predictable or repeatable, allowing an attacker to capture enough packets to recover the WEP key using statistical attacks like the FMS (Fluhrer, Mantin, Shamir) or KoreK attacks. This preparation directly indicates an attempt to crack the WEP key.

Exam trap

EC-Council often tests the distinction between WEP and WPA/WPA2 by having candidates confuse weak IVs (a WEP-specific vulnerability) with the 4-way handshake (required for WPA/WPA2 cracking), leading them to incorrectly select the WPA2 dictionary attack option.

How to eliminate wrong answers

Option A is wrong because WPS PIN brute force targets the Wi-Fi Protected Setup (WPS) PIN, not weak IVs; it involves brute-forcing the 8-digit PIN via the registrar protocol, not capturing IVs with airodump-ng. Option B is wrong because a WPA2 dictionary attack uses captured 4-way handshake packets (not weak IVs) and attempts to derive the Pairwise Master Key (PMK) from a passphrase, relying on PBKDF2-SHA1 hashing, not RC4 IV weaknesses. Option D is wrong because an evil twin attack involves setting up a rogue access point to trick clients into connecting, often for credential harvesting or man-in-the-middle, and does not require capturing weak IVs from a target network.

552
MCQeasy

A security analyst is investigating a potential compromise of a Zigbee-based smart home network. The analyst notices that an unauthorized device has joined the network and is communicating with other devices. The network uses the default Trust Center Link Key. Which of the following is the most likely cause of the unauthorized device joining the network?

A.The network is using a weak network key that was cracked by the attacker, allowing the device to join after deriving the key.
B.The network is not using Zigbee security features, such as frame counters or encryption, allowing any device to join without authentication.
C.The network is using Zigbee 3.0 with install codes, but the install code was not properly configured, allowing the device to join with the default key.
D.The network is using the default Trust Center Link Key, which is publicly known and allows any device with that key to join if the network is not using additional authentication.
AnswerD

The default Trust Center Link Key in Zigbee is a well-known value (e.g., 'ZigBeeAlliance09') that is used for initial communication with the Trust Center. If the network does not enforce unique link keys or install codes, an attacker can use this default key to join the network and communicate with devices. This is the most likely cause of the unauthorized device joining.

Why this answer

The default Trust Center Link Key in Zigbee is a global key that is publicly known. If the network does not change this key or use install codes, any device with the default key can join the network. This is a common misconfiguration in Zigbee deployments.

The unauthorized device likely used the default key to authenticate with the Trust Center and join the network, allowing it to communicate with other devices.

Exam trap

The trap here is focusing on the network key or encryption features, when the immediate enabler is the default Trust Center Link Key that is widely known and used for initial joining.

553
MCQhard

A penetration tester is attempting to escalate privileges on a Linux target. The tester runs `find / -perm -4000 -type f 2>/dev/null` and discovers that `/usr/bin/pkexec` has the SUID bit set. The target runs Ubuntu 20.04 with default configurations. Which of the following is the MOST likely next step?

A.Exploit the pkexec vulnerability (CVE-2021-4034) to gain root access
B.Change the ownership of the pkexec binary to root:root
C.Use pkexec to execute a command as root directly
D.Remove the SUID bit from pkexec to prevent misuse
AnswerA

This option is correct because CVE-2021-4034, known as "PwnKit," is a critical local privilege escalation vulnerability in the `pkexec` utility. It allows an unprivileged local attacker to gain full root privileges on a vulnerable Linux system by exploiting a memory corruption bug (out-of-bounds write) in how `pkexec` handles command-line arguments. This specific exploit path directly provides the means to achieve root access, fulfilling the objective of privilege escalation.

Why this answer

CVE-2021-4034 (PwnKit) is a memory corruption vulnerability in pkexec that allows unprivileged users to escalate privileges to root by exploiting an out-of-bounds write in the argument parsing logic. On Ubuntu 20.04 with default configurations, the pkexec binary is SUID root and vulnerable to this exploit, making it the most direct and effective next step for privilege escalation.

Exam trap

The trap here is that candidates may assume pkexec requires a password for all commands (Option C) or think that removing the SUID bit is a valid escalation step (Option D), when in fact the vulnerability bypasses authentication entirely and the goal is exploitation, not hardening.

How to eliminate wrong answers

Option B is wrong because changing ownership of the pkexec binary to root:root is already the default state and does not aid in privilege escalation; it would actually require root privileges to perform. Option C is wrong because pkexec does not allow arbitrary command execution as root without proper authorization; it enforces PolicyKit authentication and will prompt for a password unless the user has specific polkit rules. Option D is wrong because removing the SUID bit from pkexec would prevent any exploitation of the binary, but this is a remediation step, not an escalation step, and the tester's goal is to gain root access, not to harden the system.

554
MCQhard

During a penetration test, you execute the following command: dnsrecon -d example.com -t axfr. The output shows 'AXFR record received' followed by a list of all DNS records. What does this indicate about the target's DNS configuration?

A.The DNS server is using DNSSEC to secure zone transfers
B.The DNS server is vulnerable to zone transfer attacks, allowing unauthorized users to retrieve the entire zone file
C.The DNS server is properly configured and only allows zone transfers to authorized secondary servers
D.The target uses a split-DNS configuration with internal and external views
AnswerB

A successful AXFR response means the DNS server permitted an unauthenticated zone transfer, exposing every record in the zone. This misconfiguration lets anyone enumerate hosts, subdomains and mail servers, confirming the server is vulnerable to zone transfer attacks.

Why this answer

The successful execution of `dnsrecon -d example.com -t axfr` and the receipt of an AXFR (full zone transfer) response indicates that the target DNS server is misconfigured to allow zone transfers from any host. A properly secured DNS server should restrict AXFR queries to only authorized secondary (slave) servers, typically by IP address or TSIG (Transaction Signature) keys. Since the command was run from an unauthorized client, this confirms a zone transfer vulnerability, allowing an attacker to retrieve the entire DNS zone file, which reveals all hostnames, IP addresses, and service records.

Exam trap

The trap here is that candidates may confuse DNSSEC with access control mechanisms, or assume that a successful zone transfer implies proper authorization, when in fact the CEH exam emphasizes that any successful AXFR from an unauthorized client is a critical misconfiguration and vulnerability.

How to eliminate wrong answers

Option A is wrong because DNSSEC (DNS Security Extensions) does not control or restrict zone transfers; it provides data origin authentication and integrity via digital signatures, but does not prevent AXFR queries. Option C is wrong because a properly configured DNS server would not respond to an AXFR request from an unauthorized source; the fact that the zone transfer succeeded proves the configuration is insecure, not properly configured. Option D is wrong because split-DNS (split-horizon) is a design where internal and external DNS views serve different records; it does not inherently prevent zone transfers, and the successful AXFR indicates a lack of access control, not a split configuration.

555
MCQeasy

Which of the following is the PRIMARY purpose of steganography in the context of covering tracks after a system compromise?

A.To hide data within other files to avoid detection
B.To create a backdoor for future access
C.To delete system logs permanently
D.To encrypt log files so they cannot be read
AnswerA

Steganography's core purpose is to embed secret information within seemingly innocuous digital media, such as images, audio, or video files. This technique aims to conceal the very existence of the hidden data, making it difficult for an observer to even suspect that secret communication is taking place. Unlike encryption, which scrambles data, steganography focuses on covert communication by making the data appear as part of a benign carrier file, thereby avoiding detection.

Why this answer

The primary purpose of steganography in covering tracks is to hide stolen data or malicious payloads within innocuous files (e.g., images, audio, video) so that forensic tools and analysts do not detect the exfiltration or persistence. Unlike encryption, which makes data unreadable but still visible, steganography conceals the very existence of the hidden data, allowing an attacker to bypass network monitoring and file inspection. This aligns with the CEH objective of covering tracks by avoiding detection of unauthorized data transfers.

Exam trap

The trap here is that candidates confuse steganography with encryption or log manipulation, mistakenly thinking its primary purpose is to secure data (like encryption) or to remove evidence (like log deletion), rather than to conceal the existence of the data itself.

How to eliminate wrong answers

Option B is wrong because creating a backdoor is a separate post-exploitation activity (e.g., using netcat or Meterpreter) and not a function of steganography, which focuses on hiding data rather than providing access. Option C is wrong because permanently deleting system logs is typically achieved with log-wiping tools (e.g., `wevtutil` on Windows or `shred` on Linux), not steganography, which does not delete files. Option D is wrong because encrypting log files (e.g., with AES) makes them unreadable but still visible as encrypted blobs, whereas steganography hides data within other files to avoid suspicion entirely.

556
Multi-Selectmedium

Which TWO of the following are techniques used in session hijacking? (Choose 2)

Select 2 answers
A.Cookie theft
B.MAC flooding
C.ARP poisoning
D.TCP sequence prediction
E.DNS spoofing
AnswersA, D

Cookie theft directly enables session hijacking by capturing the session identifier stored in a browser cookie, allowing an attacker to impersonate the authenticated user without credentials. This satisfies the stem's requirement for a session hijacking technique, as possession of a valid session token grants immediate access to the victim's active session.

Why this answer

Cookie theft (A) is a session hijacking technique because an attacker who captures a valid session cookie — for example via XSS, sniffing an unencrypted HTTP session, or malware — can replay it to impersonate the authenticated user without knowing credentials. TCP sequence prediction (D) is also a session hijacking technique: the attacker guesses the next ISN/sequence and acknowledgment numbers to inject packets into an established TCP session, spoofing the victim's address and taking over the connection. MAC flooding (B) is a Layer 2 switch attack that overflows the CAM table to force hub-like flooding; it enables sniffing but is not itself session hijacking.

ARP poisoning (C) is a man-in-the-middle technique that redirects traffic by falsifying IP-to-MAC mappings; it can facilitate hijacking but is not the hijacking technique itself. DNS spoofing (E) forges DNS responses to redirect name resolution to a malicious host, which is a redirection/phishing technique rather than session hijacking.

Exam trap

EC-CEH often tests the distinction between session hijacking (directly taking over an active session) and network-level attacks (like ARP poisoning or MAC flooding) that merely enable interception or sniffing, causing candidates to confuse enabling techniques with the hijacking technique itself.

557
MCQhard

An analyst runs the following command: `tcpdump -i eth0 src host 192.168.1.10 and dst port 80 -w http_traffic.pcap`. What is the primary purpose of this command?

A.To perform a man-in-the-middle attack on HTTP traffic
B.To capture all traffic on eth0 and display it in real-time
C.To capture only HTTP traffic from a specific source IP and save it to a file
D.To analyze the payload of HTTP packets in real-time
AnswerC

This option accurately describes the command's functionality. The `-i eth0` flag specifies the network interface for capture. The `src host 192.168.1.10` filter ensures only packets originating from that specific IP address are captured, while `dst port 80` further narrows the scope to only include HTTP traffic (standard port 80). Finally, the `-w capture.pcap` flag instructs tcpdump to save all filtered packets to a file named `capture.pcap` for subsequent offline analysis.

Why this answer

The command `tcpdump -i eth0 src host 192.168.1.10 and dst port 80 -w http_traffic.pcap` uses a BPF (Berkeley Packet Filter) expression to capture only packets originating from source IP 192.168.1.10 and destined for TCP port 80 (HTTP). The `-w` flag writes the filtered packets directly to a pcap file, not to standard output, making the primary purpose to capture and save specific HTTP traffic for later analysis.

Exam trap

The trap here is that candidates confuse the `-w` (write to file) option with `-r` (read from file) or assume tcpdump displays output in real-time by default, leading them to choose Option B, even though the filter and `-w` flag clearly indicate a targeted capture to a file.

How to eliminate wrong answers

Option A is wrong because tcpdump is a passive packet capture tool; it does not intercept, modify, or relay packets between two parties, which are required for a man-in-the-middle attack. Option B is wrong because the `-w` flag suppresses real-time display and writes to a file, and the filter `src host 192.168.1.10 and dst port 80` limits capture to specific traffic, not all traffic on eth0. Option D is wrong because tcpdump captures raw packet headers and payloads but does not perform application-layer payload analysis or reassembly; it simply records the bytes as seen on the wire.

558
MCQmedium

Refer to the exhibit. A penetration tester observes that the DNS server returns both internal (10.0.0.0/8) and external (203.0.113.5) IP addresses for the same domain. What is this technique called?

A.DNS cache poisoning
B.Split DNS misconfiguration
C.DNS rebinding
D.DNS zone transfer
AnswerB

Split DNS, or Split-Horizon DNS, is designed to provide different DNS responses based on the client's network location, typically serving internal IP addresses to internal users and external IP addresses to external users for the same hostname. A misconfiguration occurs when the DNS server fails to properly differentiate client origins, or is configured to return both internal and external records simultaneously in a single response, thereby exposing internal network topology or causing connectivity issues.

559
MCQhard

A penetration tester runs 'nmap -sS -p 80 --script http-title 192.168.1.100' and receives output indicating port 80 is 'filtered'. What does the 'filtered' state imply?

A.The port is open and a service is listening
B.A firewall is likely blocking the probe packets
C.The service is running but the script failed
D.The port is closed and no service is listening
AnswerB

The 'filtered' state in Nmap signifies that the port is inaccessible because probe packets are being dropped, or responses are not reaching the scanner. This typically occurs when a firewall, intrusion prevention system (IPS), or other network security device is actively inspecting and blocking traffic destined for that specific port, preventing Nmap from determining if a service is listening. The lack of any definitive response (SYN/ACK for open, RST for closed) points directly to an intermediate device interfering, making this the correct explanation.

Why this answer

The 'filtered' state in Nmap indicates that the probe packets (SYN packets for a SYN scan) were dropped or did not elicit any response, typically due to a firewall or packet filter. Since no SYN/ACK or RST was received, Nmap cannot determine if the port is open or closed, so it marks it as 'filtered'. This is distinct from an 'open' state (SYN/ACK received) or 'closed' state (RST received).

Exam trap

The trap here is that candidates confuse 'filtered' with 'closed' or assume it means the service is running but unreachable, when in fact 'filtered' specifically indicates the probe was blocked by a filtering device.

How to eliminate wrong answers

Option A is wrong because an open port would return a SYN/ACK, causing Nmap to report it as 'open', not 'filtered'. Option C is wrong because the 'filtered' state is determined by the scan probe response, not by the success or failure of the http-title script; the script would only run if the port were open. Option D is wrong because a closed port would send back an RST packet, leading Nmap to report it as 'closed', not 'filtered'.

560
MCQmedium

Refer to the exhibit. A security analyst captured the HTTP request and response shown. What type of vulnerability is present?

A.Cross-Site Request Forgery (CSRF)
B.SQL Injection
C.Reflected Cross-Site Scripting (XSS)
D.Directory Traversal
AnswerC

Reflected Cross-Site Scripting (XSS) occurs when a malicious script, often embedded within a URL parameter or form input, is immediately and unsafely echoed back in the web server's HTTP response. The victim's browser then interprets and executes this injected script as part of the legitimate webpage content. The exhibit clearly shows user input containing script tags being directly reflected into the HTML response without proper sanitization, leading to client-side script execution, which is the hallmark of a reflected XSS vulnerability.

Why this answer

The HTTP response contains the search query parameter directly reflected in the HTML body without proper sanitization or encoding. Specifically, the request includes `?search=<script>alert('XSS')</script>` and the response echoes this payload verbatim in the page content, allowing the browser to execute the injected JavaScript. This is the classic signature of a reflected cross-site scripting (XSS) vulnerability, where the malicious script is immediately reflected off the web server and executed in the user's browser.

Exam trap

EC-Council often tests the distinction between reflected XSS and stored XSS, but the trap here is confusing reflected XSS with CSRF because both involve crafted URLs, but CSRF does not execute JavaScript in the response—it forges a state-changing request using the victim's session.

How to eliminate wrong answers

Option A is wrong because Cross-Site Request Forgery (CSRF) requires a forged request that changes state (e.g., a POST to transfer funds) and relies on the victim's authenticated session, not on reflected script execution in the response body. Option B is wrong because SQL Injection involves manipulating SQL queries via input fields (e.g., `' OR 1=1--`), but the exhibited payload is a JavaScript alert, not a SQL syntax-breaking string, and the response shows no database error or data leakage. Option D is wrong because Directory Traversal exploits path traversal sequences (e.g., `../etc/passwd`) to access files outside the web root, but the request parameter is `search` and the response contains HTML with the injected script, not file contents or directory listings.

561
MCQmedium

An organization wants to test its employees' susceptibility to social engineering by sending fake emails that appear to come from the IT department, requesting password resets. Which tool would be MOST effective for conducting this test?

A.Social Engineering Toolkit (SET)
B.Wireshark
C.Metasploit
D.Nmap
AnswerA

The Social Engineering Toolkit (SET) is purpose-built for simulating various social engineering attacks, making it the ideal choice for testing employee susceptibility. It provides modules for spear phishing, credential harvesting, web jacking, and infectious media generator attacks, directly targeting the human element. By deploying these simulated threats, organizations can assess how employees react to realistic social engineering tactics and identify areas for security awareness training improvement.

Why this answer

The Social Engineering Toolkit (SET) is specifically designed for social engineering attacks, including crafting convincing phishing emails that mimic internal departments like IT. It automates the creation of fake login pages and email templates, making it the most effective tool for testing employee susceptibility to password reset requests.

Exam trap

The trap here is that candidates often confuse Metasploit's exploit capabilities with social engineering, overlooking that SET is the dedicated tool for crafting and executing phishing campaigns, not just delivering payloads.

How to eliminate wrong answers

Option B (Wireshark) is wrong because it is a network protocol analyzer used for capturing and inspecting packets, not for generating social engineering attacks. Option C (Metasploit) is wrong because, while it can deliver payloads via exploits, its primary focus is on exploiting system vulnerabilities rather than crafting social engineering lures like fake IT emails. Option D (Nmap) is wrong because it is a network scanning tool used for port discovery and service enumeration, with no capability to create or send phishing emails.

562
Matchingmedium

Match each vulnerability assessment tool to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Automated vulnerability scanning

Open-source vulnerability scanner

Cloud-based vulnerability management

Network vulnerability scanner

Web server vulnerability scanner

Why these pairings

Correct matches: Nmap for network scanning, Nessus for vulnerability assessment, Metasploit for exploitation. Common confusions involve swapping scanning and vulnerability roles.

563
MCQhard

An incident response team discovers a suspicious executable on a compromised workstation. They want to analyze the malware without executing it. Which of the following techniques would be MOST appropriate for this initial analysis?

A.Capturing network traffic with Wireshark during execution
B.Using the 'strings' command to extract embedded text
C.Monitoring process behavior with Process Monitor
D.Running the executable in a sandboxed environment
AnswerB

Using the 'strings' command is a quintessential static analysis method as it involves examining the binary file directly on disk without executing it. This command extracts sequences of printable ASCII or Unicode characters embedded within the executable, which can reveal valuable clues such as file paths, URLs, API function names, or error messages hardcoded by the malware author.

Why this answer

The 'strings' command extracts human-readable text from a binary file without executing it, making it ideal for static analysis. This technique can reveal indicators such as IP addresses, domain names, file paths, registry keys, or embedded commands that help classify the malware's purpose and capabilities without triggering its payload.

Exam trap

The trap here is that candidates confuse 'dynamic analysis' techniques (like sandboxing or process monitoring) with 'static analysis', failing to recognize that the question's constraint 'without executing it' eliminates any option that requires runtime behavior.

How to eliminate wrong answers

Option A is wrong because capturing network traffic with Wireshark during execution requires the malware to run, which violates the requirement to analyze without executing. Option C is wrong because Process Monitor monitors real-time process behavior, which also requires the executable to be running. Option D is wrong because running the executable in a sandboxed environment still involves execution, which the question explicitly prohibits.

564
Multi-Selecteasy

Which TWO vulnerabilities are associated with buffer overflow attacks?

Select 2 answers
A.Arbitrary code execution
B.Stack smashing
C.Authentication bypass via SQL injection
D.Cross-site scripting (XSS)
E.Race condition
AnswersA, B

Buffer overflows enable arbitrary code execution by allowing an attacker to overwrite critical memory locations, such as return addresses on the stack or function pointers in data segments. By carefully crafting input that exceeds the buffer's capacity, malicious shellcode can be injected into memory. The overwritten control flow mechanism then redirects program execution to this injected code, granting the attacker full control over the compromised process.

Why this answer

Buffer overflow attacks occur when a program writes more data to a buffer than it can hold, overwriting adjacent memory. This can corrupt the stack and allow an attacker to inject and execute arbitrary code (option A) by overwriting the return address or function pointers. Stack smashing (option B) is a specific technique that deliberately corrupts the call stack to hijack control flow, often as part of a buffer overflow exploit.

Exam trap

The trap here is that candidates often confuse buffer overflow with other injection or concurrency flaws, but the CEH exam specifically pairs arbitrary code execution and stack smashing as the two direct consequences of a buffer overflow.

565
MCQhard

A penetration tester is analyzing a Windows 10 system and runs the following command to dump password hashes from the SAM database. The output shows hashes for local users but some are missing. Which step is most likely missing?

A.Run the tool as Administrator
B.Use reg.exe save to export SAM hive
C.Create a Volume Shadow Copy to access SAM file
D.Enable SeDebugPrivilege for the current process
AnswerC

Creating a Volume Shadow Copy (VSS) is the most effective and commonly used method to access the SAM file while the operating system is running. VSS creates a point-in-time, read-only snapshot of the entire volume, including files that are currently locked by the OS. This snapshot allows the penetration tester to access a consistent version of the SAM file from the shadow copy, effectively bypassing the exclusive lock maintained by the live operating system without interrupting its operations.

Why this answer

On Windows 10, the SAM file is locked by the operating system while the system is running, preventing direct read access even with Administrator privileges. Creating a Volume Shadow Copy (VSS) allows the penetration tester to access a point-in-time snapshot of the SAM file, bypassing the lock. This is the standard technique for dumping password hashes from a live system without rebooting or using a boot disk.

Exam trap

The trap here is that candidates assume Administrator privileges alone are sufficient to read the SAM file, overlooking the fact that Windows locks the file even for administrators, and that VSS is the required bypass.

How to eliminate wrong answers

Option A is wrong because running the tool as Administrator is necessary but not sufficient; the SAM file is still locked by the OS even for administrators. Option B is wrong because reg.exe save can export registry hives like SAM, but it requires the SeBackupPrivilege and still may fail if the hive is in use or if the tool does not handle the locked file correctly; VSS is the more reliable method. Option D is wrong because SeDebugPrivilege is used for debugging processes and accessing process memory, not for reading the locked SAM file directly; it does not bypass the file system lock.

566
MCQmedium

A security analyst notices that a web application returns different error messages for valid and invalid usernames during login. Which type of attack is this application MOST vulnerable to?

A.Directory traversal
B.Username enumeration
C.SQL injection
D.Cross-site scripting (XSS)
AnswerB

Username enumeration occurs when a web application's login mechanism provides distinct error messages or response times for valid usernames compared to invalid ones, even if the password is incorrect. For instance, "Invalid password for user 'admin'" versus "User 'admin' does not exist." This differential feedback allows an attacker to systematically test common usernames and compile a list of valid accounts, significantly aiding in subsequent brute-force or credential stuffing attacks.

Why this answer

The different error messages allow an attacker to enumerate valid usernames, which is a common precursor to brute-force or credential-stuffing attacks.

567
MCQmedium

An analyst sees the following in a log: Client sends a request to https://victim.com/api?url=http://169.254.169.254/latest/meta-data/. This is MOST indicative of which attack?

A.Cross-site scripting (XSS)
B.Server-side request forgery (SSRF)
C.Directory traversal
D.SQL injection
AnswerB

Server-side request forgery (SSRF) exploits a vulnerability where a web application is tricked into making requests to an arbitrary domain specified by the attacker. This allows an attacker to force the server to connect to internal services, such as metadata APIs, internal databases, or other hosts within the organization's private network, which are typically not directly accessible from the internet. The "client sends a reque" could be the initial malicious input that triggers the server to make an unintended internal request.

Why this answer

The IP 169.254.169.254 is the AWS metadata endpoint. SSRF attacks target internal services by manipulating the url parameter.

568
MCQhard

During a penetration test, an ethical hacker needs to evade an IDS that detects port scans based on the number of packets per second. Which technique would be most effective to avoid detection?

A.Use random source ports
B.Use a decoy scan
C.Slow down the scan rate
D.Use fragmented packets
AnswerC

Slowing down the scan rate directly reduces the number of packets sent per second (PPS) or connections attempted per minute. This strategic reduction keeps the scanning activity below the predefined thresholds set by rate-based Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), which are designed to detect anomalous traffic volumes. By maintaining a low packet rate, the ethical hacker can conduct reconnaissance without triggering alerts that would otherwise flag the activity as a potential port scan or denial-of-service attempt, thus evading detection.

Why this answer

Slowing down the scan rate reduces the number of packets sent per second below the IDS threshold, allowing the scan to blend in with normal traffic. IDS systems like Snort use packet-per-second (pps) counters to detect port scans; by spacing out packets over a longer period, the scan avoids triggering these rate-based alerts.

Exam trap

EC-Council often tests the misconception that fragmentation alone evades IDS, but candidates must remember that rate-based detection counts packets regardless of fragmentation, so slowing the scan is the direct countermeasure.

How to eliminate wrong answers

Option A is wrong because randomizing source ports does not affect the packet-per-second rate; the IDS still counts the same number of packets in the same time window, so detection is not avoided. Option B is wrong because a decoy scan (e.g., using -D in Nmap) sends spoofed packets from multiple IPs, but the total packet rate from the attacker's IP remains unchanged, so the IDS can still detect the scan based on pps. Option D is wrong because fragmented packets (e.g., using -f in Nmap) split TCP headers across multiple IP fragments, but the IDS can reassemble them and still count the total number of packets per second, so the rate-based detection is not bypassed.

569
MCQmedium

Which of the following tools is specifically designed to exploit WPS vulnerabilities on wireless networks?

A.John the Ripper
B.aircrack-ng
C.Kismet
D.Reaver
AnswerD

Reaver is a specialized tool explicitly designed to exploit a critical vulnerability in the Wi-Fi Protected Setup (WPS) protocol by performing a brute-force attack against the WPS registrar PIN. It leverages the fact that the 8-digit WPS PIN is validated in two halves, allowing an attacker to determine the first four digits and then the next three, with the last digit being a checksum. This significantly reduces the number of attempts required, making the brute-force attack feasible and highly effective against vulnerable WPS-enabled access points.

Why this answer

Reaver is specifically designed to exploit the WPS (Wi-Fi Protected Setup) PIN brute-force vulnerability. It targets the WPS registrar's lack of rate limiting and the fact that the PIN is split into two halves, making it feasible to guess the 8-digit PIN in under 10,000 attempts. This allows an attacker to recover the WPA/WPA2 pre-shared key without needing to crack the actual encryption.

Exam trap

The trap here is that candidates confuse aircrack-ng (which cracks WPA handshakes) with tools that exploit the WPS PIN vulnerability, but aircrack-ng has no WPS brute-force capability.

How to eliminate wrong answers

Option A is wrong because John the Ripper is a password cracking tool for offline hash files, not a wireless attack tool for exploiting WPS vulnerabilities. Option B is wrong because aircrack-ng is a suite for capturing and cracking WEP/WPA/WPA2 handshakes, but it does not target the WPS PIN brute-force mechanism. Option C is wrong because Kismet is a wireless network detector, sniffer, and intrusion detection system, not a tool for exploiting WPS vulnerabilities.

570
MCQhard

A penetration tester is testing an IIS web server and wants to exploit a WebDAV misconfiguration to upload a web shell. Which HTTP method should the tester check to determine if WebDAV is enabled and allows file uploads?

A.OPTIONS
B.MOVE
C.PUT
D.PROPFIND
AnswerA

The HTTP OPTIONS method is specifically designed to query a web server or resource about the communication options supported by the server for that particular URL. It provides a list of allowed HTTP methods (e.g., GET, HEAD, POST, PUT, DELETE, TRACE, CONNECT) in the 'Allow' header of its response. This is crucial for a penetration tester to discover if potentially vulnerable methods like PUT (for file upload) or WebDAV methods are enabled before attempting to exploit them.

Why this answer

The OPTIONS method is used to query the server about which HTTP methods are supported for a given resource. When WebDAV is enabled, the server's response to an OPTIONS request will include WebDAV-specific methods such as PUT, PROPFIND, MOVE, COPY, etc. This allows a penetration tester to quickly determine if WebDAV is enabled and if file uploads (via PUT) are allowed.

Therefore, OPTIONS is the correct method to check for WebDAV misconfiguration.

Exam trap

CEH often tests the misconception that PUT or PROPFIND directly indicates WebDAV is enabled, but the correct method to enumerate allowed methods is OPTIONS.

How to eliminate wrong answers

Option B (MOVE) is wrong because MOVE is a WebDAV method used to move a resource from one URI to another; it does not reveal whether WebDAV is enabled, and attempting it without prior knowledge may fail or not provide a complete list of allowed methods. Option C (PUT) is wrong because PUT is used to upload a file, but it does not indicate whether WebDAV is enabled; a server might allow PUT for other reasons (e.g., REST APIs), and a failed PUT does not confirm WebDAV is disabled. Option D (PROPFIND) is wrong because PROPFIND is a WebDAV method used to retrieve properties of a resource; while it can confirm WebDAV is enabled if it succeeds, it does not directly reveal whether file uploads are allowed, and it may require authentication or specific conditions.

571
MCQhard

A security engineer analyzes a cloud environment and finds that an S3 bucket named 'company-backups' is configured with a bucket policy that allows 'Principal': '*' and 'Action': 's3:GetObject'. Which of the following is the MOST likely risk?

A.An attacker can read any object in the bucket without authentication
B.An attacker can modify the bucket policy
C.An attacker can delete objects in the bucket
D.An attacker can enumerate all objects in the bucket
AnswerA

The bucket policy explicitly grants the "s3:GetObject" action to "Principal: *". This configuration means that any user, including unauthenticated internet users, can retrieve and read the content of any object within the bucket, provided they know the object's key. This effectively makes all objects publicly readable, posing a significant data exposure risk.

Why this answer

A bucket policy allowing anonymous GetObject makes all objects publicly readable, leading to data exposure.

572
Multi-Selectmedium

Which THREE of the following are valid Nmap port states?

Select 3 answers
A.Open
B.Filtered
C.Blocked
D.Stealth
E.Unfiltered
AnswersA, B, E

An open port has a service listening.

Why this answer

Nmap classifies a port as 'open' when it receives a SYN/ACK response to a SYN probe, indicating that an application is actively listening on that port. This is the standard TCP three-way handshake behavior defined in RFC 793, and it is the most fundamental port state in Nmap's scanning logic.

Exam trap

The trap here is that candidates confuse Nmap's scanning techniques (like stealth scan) with port states, or assume 'blocked' is a valid state when it is actually a synonym for 'filtered' that Nmap does not officially use.

573
MCQhard

An attacker uses 'rpcclient -U '' -N 192.168.1.10' followed by 'enumdomusers' and 'enumdomgroups'. What type of enumeration is being performed, and which protocol does it rely on?

A.LDAP enumeration over port 389
B.SMB/RPC enumeration over port 445
C.NetBIOS enumeration over port 139
D.SNMP enumeration over port 161
AnswerB

The `rpcclient` utility is a powerful tool for interacting with Microsoft Remote Procedure Call (MS-RPC) services, which are commonly transported over Server Message Block (SMB) on TCP port 445. The command `rpcclient -U n 192.168.1.10` attempts to establish a null session (unauthenticated connection) to the target, allowing an attacker to enumerate various system details like user lists, share information, and group memberships by making RPC calls. This makes it a primary method for SMB/RPC enumeration.

Why this answer

The `rpcclient` tool with the `-U '' -N` flags performs a null session connection to a Windows system over the SMB protocol. The subsequent `enumdomusers` and `enumdomgroups` commands enumerate domain users and groups via MS-RPC (Remote Procedure Call) functions, which are transported over SMB. By default, modern Windows systems use SMB over port 445, making option B the correct choice.

Exam trap

The trap here is that candidates confuse the underlying protocol (SMB/RPC on port 445) with the older NetBIOS session service (port 139), or mistakenly associate user/group enumeration solely with LDAP, not realizing that `rpcclient` uses MS-RPC over SMB.

How to eliminate wrong answers

Option A is wrong because LDAP enumeration typically uses `ldapsearch` or similar tools over port 389, not `rpcclient` commands like `enumdomusers`. Option C is wrong because NetBIOS enumeration uses `nbtstat` or `nbtscan` over port 139, and while older SMB could run over NetBIOS, the given command targets port 445 directly (default for modern SMB). Option D is wrong because SNMP enumeration uses tools like `snmpwalk` over UDP port 161, and `rpcclient` does not interact with SNMP at all.

574
MCQhard

An organization experiences a DDoS attack where the attacker sends many incomplete HTTP requests that keep connections open, exhausting the server's connection pool. Which attack technique is being used?

A.UDP flood
B.HTTP flood
C.SYN flood
D.Slowloris
AnswerD

Slowloris opens many partial HTTP requests, sending incomplete headers and never finishing them. The server holds each connection open awaiting the remainder, exhausting its connection pool while consuming minimal attacker bandwidth, matching the incomplete-request symptom described.

Why this answer

Slowloris is a DDoS attack that works by opening multiple connections to the target server and sending partial HTTP requests, never completing them. The server keeps these connections open waiting for the rest of the request, eventually exhausting the connection pool and denying service to legitimate users. This matches the description of incomplete HTTP requests keeping connections open.

Exam trap

In CEH, candidates often confuse a SYN flood (TCP layer, half-open connections) with Slowloris (HTTP layer, partial requests). Slowloris keeps connections open by sending incomplete HTTP headers, targeting the application layer, unlike SYN flood which operates at the transport layer.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends large volumes of UDP packets to random ports, overwhelming the server's bandwidth or processing capacity, not by keeping HTTP connections open. Option B is wrong because an HTTP flood sends complete, legitimate-looking HTTP requests at high volume to overwhelm the server's processing resources, not by leaving connections incomplete. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting the server's TCP connection backlog, not by sending incomplete HTTP requests.

575
MCQmedium

A security analyst issues the command `dnsenum example.com` and receives a list of subdomains, mail servers, and name servers. What information is revealed by the presence of multiple MX records?

A.The domain has been compromised
B.The domain uses a single mail server with multiple aliases
C.The domain uses multiple mail servers for load balancing and failover
D.The domain is participating in a DDoS attack
AnswerC

The presence of multiple Mail Exchanger (MX) records for a domain is a strong indicator of a resilient email infrastructure designed for both load balancing and failover. When multiple MX records exist, mail sending agents attempt delivery to the server with the lowest preference value first. If that server is unavailable or overloaded, they proceed to the next highest preference, ensuring email delivery continuity and distributing the incoming mail traffic across several servers. This configuration significantly enhances reliability and availability.

Why this answer

Multiple MX records in a DNS zone file indicate that the domain is configured with more than one mail exchange server. This setup provides redundancy and load balancing for email delivery, as defined in RFC 5321. The `dnsenum` tool enumerates these records from the DNS server, revealing the domain's email infrastructure design.

Exam trap

The trap here is that candidates may confuse multiple MX records with multiple A records for a single hostname, or incorrectly assume that any multiplicity in DNS records indicates a security issue, rather than recognizing it as a standard high-availability design.

How to eliminate wrong answers

Option A is wrong because the presence of multiple MX records is a standard configuration for resilience, not an indicator of compromise. Option B is wrong because multiple MX records point to distinct mail servers (with different hostnames or IPs), not a single server with multiple aliases (which would be CNAME records). Option D is wrong because multiple MX records are used for legitimate email routing, not for participating in a DDoS attack; DDoS involvement would be inferred from traffic patterns, not DNS record counts.

576
Multi-Selectmedium

Which TWO of the following are characteristics of a SYN flood attack? (Select 2)

Select 2 answers
A.It exploits the TCP three-way handshake
B.It uses UDP amplification
C.It sends a large number of ICMP echo requests
D.It requires the attacker to have a botnet
E.It results in a backlog of incomplete connections
AnswersA, E

A SYN flood abuses the TCP three-way handshake: the attacker sends many SYN packets, often with spoofed source addresses, so the server allocates half-open connections and replies with SYN-ACKs that are never completed, exhausting the backlog queue and denying service to legitimate clients.

Why this answer

Option A is correct because a SYN flood specifically abuses the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, and the server replies with SYN-ACK while waiting for the final ACK that never arrives. Option E is correct because those half-open connections accumulate in the server's SYN backlog queue, exhausting available connection slots and preventing legitimate clients from completing the handshake. Option B is incorrect because UDP amplification describes volumetric reflection attacks such as DNS or NTP amplification, not the TCP handshake-based SYN flood.

Option C is incorrect because a large volume of ICMP echo requests describes an ICMP flood or smurf-style attack, not a SYN flood. Option D is incorrect because a SYN flood can be launched from a single host with spoofed source IP addresses and does not inherently require a botnet.

Exam trap

The CEH exam often tests the misconception that a SYN flood requires a botnet or that it uses UDP amplification, but the core characteristic is the exploitation of the TCP three-way handshake and the resulting backlog of incomplete connections.

577
MCQhard

A penetration tester runs the following Nmap command: nmap -sU -sS -p 53,161,162,500 10.0.0.1 and receives no responses for UDP scans but standard results for TCP. The tester suspects the target is dropping all UDP packets. Which Nmap option could help increase the likelihood of UDP responses by fragmenting the probe?

A.-f
B.-T4
C.--reason
D.-Pn
AnswerA

The -f (fragment packets) Nmap option instructs Nmap to split the IP header of the probe packets into several smaller IP packets. This technique, known as IP fragmentation, can bypass simple stateless firewalls or intrusion detection systems (IDS) that only inspect the first fragment of a packet or are configured to drop packets exceeding a certain size. By breaking the packet into 8-byte chunks, it makes reassembly more complex for network security devices, potentially allowing the scan to proceed undetected.

Why this answer

The -f option fragments the probe packets into smaller IP fragments. When a target drops unfragmented UDP packets, fragmenting the probes can sometimes bypass simple packet filters or IDS/IPS that drop larger or complete UDP datagrams, increasing the chance that the target will process and respond to the fragments.

Exam trap

The trap here is that candidates often confuse -f (fragmentation) with -T4 (timing) or -Pn (no ping), assuming any option that makes the scan 'faster' or 'more aggressive' will also bypass packet drops, when in fact fragmentation is the specific technique to alter packet structure.

How to eliminate wrong answers

Option B is wrong because -T4 sets the timing template to aggressive, which increases scan speed but does not fragment packets or alter UDP probe structure. Option C is wrong because --reason simply displays the reason for Nmap's port state determination and has no effect on packet fragmentation or UDP response behavior. Option D is wrong because -Pn skips host discovery and treats the target as alive, but it does not fragment probes or change how UDP packets are constructed.

578
MCQeasy

Which tool is specifically designed to crack Windows LM and NTLM hashes using rainbow tables?

A.Hashcat
B.Ophcrack
C.RainbowCrack
D.John the Ripper
AnswerB

Ophcrack is a specialized tool explicitly engineered for cracking Windows LM and NTLM hashes by utilizing precomputed rainbow tables. It comes bundled with these tables, which significantly accelerate the process of recovering passwords, especially shorter or less complex ones, from these specific Windows authentication protocols. Its design is entirely centered around the time-memory tradeoff inherent in rainbow table attacks, making it highly effective for its intended purpose.

Why this answer

Ophcrack is specifically designed to crack Windows LM and NTLM hashes using precomputed rainbow tables. It leverages the time-memory trade-off technique to rapidly reverse these hashes without brute-forcing, making it the correct choice for this targeted use case.

Exam trap

The trap here is that candidates often confuse RainbowCrack (a general rainbow table tool) with Ophcrack (the Windows-specific rainbow table cracker), or assume that any GPU-based cracker like Hashcat is equally suited for this specific task.

How to eliminate wrong answers

Option A is wrong because Hashcat is a general-purpose password cracker that uses GPU acceleration and supports many hash types, but it is not specifically designed for rainbow table attacks on Windows LM/NTLM hashes. Option C is wrong because RainbowCrack is a tool that generates and uses rainbow tables for various hash algorithms, but it is not exclusively focused on Windows LM/NTLM hashes and lacks the integrated Windows-specific features of Ophcrack. Option D is wrong because John the Ripper is a versatile password cracking tool that supports many hash formats and modes (including brute-force and dictionary attacks), but it is not purpose-built for rainbow table attacks on Windows LM/NTLM hashes.

579
MCQhard

A security team uses ScoutSuite to assess their AWS environment. The tool reports that an S3 bucket policy allows access from any IP address. What is the MOST likely misconfiguration?

A.The bucket has versioning enabled
B.The bucket ACL grants 'FullControl' to 'AuthenticatedUsers' group
C.The bucket is encrypted with SSE-S3
D.The bucket policy uses 'Principal': '*' and 'Condition': {'IpAddress': {'aws:SourceIp': '0.0.0.0/0'}}
AnswerD

This bucket policy explicitly grants access to 'Principal': '*', which signifies *any* AWS identity or anonymous user. The accompanying 'Condition': {'IpAddress': {'aws:SourceIp': '0.0.0.0/0'}} further specifies that this broad access is permitted from *any* IPv4 address. The combination of allowing any principal from any IP address effectively overrides any other restrictions and renders the S3 bucket completely public and accessible to the entire internet, which is a critical security misconfiguration.

Why this answer

ScoutSuite identifies overly permissive bucket policies; allowing access from any IP (0.0.0.0/0) is a common misconfiguration.

580
MCQmedium

During a vulnerability assessment, a security analyst receives an alert from the IDS that a scan with fragmented packets and spoofed source IPs is targeting the internal network. Which Nmap command MOST likely caused this alert?

A.nmap -sS -O 192.168.1.1
B.nmap -sV -p 80 192.168.1.1
C.nmap -sU 192.168.1.1
D.nmap -f -D 10.0.0.1,10.0.0.2 192.168.1.1
AnswerD

This Nmap command employs two significant evasion techniques: -f for packet fragmentation and -D for decoy IP addresses. Packet fragmentation breaks the scan probes into smaller, non-standard-sized IP fragments, which can bypass simple stateful firewalls or IDS rules that only inspect the initial fragment. The -D option generates multiple decoy source IP addresses, making it difficult for an IDS to determine the actual scanner's IP from the network logs, effectively obscuring the attacker's origin and distributing the perceived attack source.

Why this answer

The `-f` flag fragments the packets into smaller IP fragments, and the `-D` flag performs a decoy scan by spoofing source IPs. This combination causes the IDS to detect fragmented packets with spoofed source addresses, matching the alert description.

Exam trap

The trap here is that candidates may confuse `-f` with other scan types like SYN or UDP scans, but the key is recognizing that fragmentation and spoofed source IPs are explicitly enabled by `-f` and `-D` respectively.

How to eliminate wrong answers

Option A is wrong because `-sS` (SYN scan) and `-O` (OS detection) do not fragment packets or spoof source IPs; they use raw packets with the real source IP. Option B is wrong because `-sV` (version detection) and `-p 80` target a single port without fragmentation or spoofing, generating normal TCP traffic. Option C is wrong because `-sU` (UDP scan) sends unfragmented UDP packets from the real source IP, not fragmented or spoofed traffic.

581
MCQeasy

A security analyst uses the nbtstat -a command against a target IP address. What information is the analyst MOST likely attempting to retrieve?

A.Active directory domain controllers
B.List of all open TCP ports
C.NetBIOS name table of the remote machine
D.The MAC address of the target
AnswerC

The `nbtstat -a <IP_address>` command is specifically used to query and display the NetBIOS name table of a remote machine. This table contains a list of NetBIOS names registered by the target host, including unique names (e.g., workstation name, messenger service) and group names (e.g., domain/workgroup name), along with their associated types and registration status. This information is crucial for understanding the remote machine's NetBIOS identity and services.

Why this answer

The nbtstat -a command is used to query the NetBIOS name table of a remote machine by its IP address. This table contains the NetBIOS names registered by the remote host, such as the computer name, workgroup/domain, and any services running over NetBIOS (e.g., file sharing). The analyst is most likely attempting to enumerate these names for reconnaissance or to identify potential targets for further exploitation.

Exam trap

The trap here is that candidates often confuse nbtstat -a with retrieving only the MAC address, because the output does display a MAC address line, but the command's primary function is to enumerate the NetBIOS name table.

How to eliminate wrong answers

Option A is wrong because nbtstat does not query Active Directory domain controllers; that would require tools like nslookup or dsquery. Option B is wrong because nbtstat does not list open TCP ports; port scanning is done with tools like Nmap or netstat. Option D is wrong because while nbtstat can display the MAC address in its output (under the 'MAC Address' field), the primary purpose of the -a switch is to retrieve the NetBIOS name table, not just the MAC address.

582
MCQhard

During a web application assessment, a tester intercepts a request and modifies the 'Referer' header. The application then performs a state-changing action without requiring a token. Which vulnerability is most likely present?

A.Cross-site scripting (XSS)
B.Server-side request forgery (SSRF)
C.Cross-site request forgery (CSRF)
D.Clickjacking
AnswerC

Cross-site request forgery (CSRF) exploits the trust a web application has in an authenticated user's browser. An attacker crafts a malicious web page or email that, when visited or opened by an authenticated user, forces their browser to send an unintended request to the vulnerable application. The application, failing to verify the request's true origin or intent, processes the forged request, often relying on session cookies. Manipulating or bypassing checks on the Referer header can be a technique used in CSRF attacks, as applications sometimes use it as a weak defense to ensure requests originate from the expected domain.

Why this answer

The scenario describes a state-changing action performed without a token, and the tester modifies the Referer header. This is characteristic of CSRF, where an attacker tricks a victim's browser into sending a forged request. The lack of a token and reliance on the Referer header for validation are common CSRF weaknesses.

Exam trap

CEH often tests the confusion between CSRF and XSS; candidates may pick XSS because it involves client-side attacks, but CSRF specifically targets state-changing actions without tokens.

How to eliminate wrong answers

Option A is wrong because XSS involves injecting scripts into web pages, not modifying headers to perform state-changing actions. Option B is wrong because SSRF involves the server making requests to internal resources, not the client's browser. Option D is wrong because clickjacking involves overlaying invisible frames to trick users into clicking, not header manipulation.

583
MCQhard

During a penetration test, a security analyst observes that Nmap SYN scans to a target server are not returning any results, but TCP connect scans succeed. The server is running an IDS. Which evasion technique is the analyst MOST likely encountering?

A.The IDS is dropping packets with the SYN flag set
B.The server is using a firewall that blocks all inbound SYN packets
C.The analyst's packets are being fragmented, causing them to be dropped
D.The target is using a honeypot that responds to all connection attempts
AnswerA

An Intrusion Detection System (IDS) can be specifically configured to identify and drop packets that only contain the SYN flag, a common characteristic of a SYN scan (half-open scan). This allows the IDS to detect and mitigate reconnaissance attempts without disrupting legitimate full TCP three-way handshakes, which are typical of a TCP connect scan. Therefore, SYN packets from a SYN scan would be dropped, while the full handshake of a connect scan might be permitted to proceed.

Why this answer

The IDS is configured to drop packets with only the SYN flag set, which is the hallmark of a SYN scan. This evasion technique forces the attacker to use a full TCP connect scan (which completes the three-way handshake) to bypass the IDS detection. The IDS drops the initial SYN packet, preventing the scan from receiving any response, while a full connect scan is allowed because it mimics legitimate traffic.

Exam trap

The trap here is that candidates often assume a firewall is blocking the SYN packets, but the question specifies an IDS is running, and the key distinction is that a firewall would block both scan types, while an IDS can selectively drop only half-open SYN packets to evade detection.

How to eliminate wrong answers

Option B is wrong because a firewall that blocks all inbound SYN packets would also block TCP connect scans, which rely on sending a SYN to initiate the handshake; the question states connect scans succeed, so this cannot be the case. Option C is wrong because packet fragmentation is an evasion technique used to bypass IDS/IPS signature matching, not to cause packets to be dropped; fragmented packets can still be reassembled and processed. Option D is wrong because a honeypot would respond to all connection attempts, including SYN scans, but the question states SYN scans return no results, indicating the packets are being dropped before reaching the target.

584
MCQeasy

A web application tester uses the following Burp Suite feature to automatically send multiple requests with different payloads to test for common vulnerabilities. Which feature is being used?

A.Intruder
B.Repeater
C.Proxy
D.Scanner
AnswerA

Intruder is the dedicated Burp Suite tool for automating customized attacks against web applications by systematically sending multiple requests with variable payloads. It allows testers to define specific insertion points within a request and iterate through a list of payloads, making it ideal for brute-forcing credentials, fuzzing input fields, and identifying injection vulnerabilities like SQLi or XSS with high precision and control over attack types.

Why this answer

Burp Intruder is designed to automate sending large numbers of requests with varying payloads, making it the tool for fuzzing, brute force, and injection testing. It lets testers define payload positions and payload sets, then iterates through them automatically. This matches the scenario of sending multiple requests with different payloads to test for vulnerabilities.

Exam trap

The trap is confusing Intruder with Scanner—both automate requests, but Intruder requires the tester to define payloads and positions, whereas Scanner uses built-in checks without user-supplied payloads.

How to eliminate wrong answers

Option B is wrong because Repeater is for manually editing and resending a single request repeatedly, not for automated bulk payload iteration. Option C is wrong because Proxy is for intercepting and inspecting traffic between the browser and server, not for automated payload testing. Option D is wrong because Scanner performs automated vulnerability scanning based on its own logic, but the question describes the tester supplying payloads—the defining feature of Intruder.

585
MCQmedium

A penetration tester has obtained a copy of the SAM database from a Windows system. The hashes extracted include both LM and NTLM hashes. Which of the following tools would be MOST efficient to crack the NTLM hashes using a dictionary attack with GPU acceleration?

A.John the Ripper
B.Ophcrack
C.Hashcat
D.RainbowCrack
AnswerC

Hashcat is the industry-standard tool for high-performance password recovery, leveraging highly optimized GPU acceleration to crack a vast array of hash types, including NTLM (mode 1000). Its architecture is specifically designed to maximize parallel processing on graphics cards, enabling exceptionally fast dictionary attacks, brute-force, and hybrid attacks. This unparalleled efficiency makes Hashcat the optimal choice for rapidly cracking NTLM hashes obtained from a SAM database dump, significantly reducing the time required compared to CPU-based or rainbow table methods.

Why this answer

Hashcat is the most efficient tool for GPU-accelerated dictionary attacks against NTLM hashes because it is purpose-built for high-speed password cracking using OpenCL and CUDA, directly leveraging GPU parallelism. It supports the NTLM hash mode (1000) and can process millions of hashes per second, far outperforming CPU-based tools like John the Ripper for this specific task.

Exam trap

The trap here is that candidates confuse Ophcrack's LM hash rainbow table capability with NTLM cracking, or assume John the Ripper's general-purpose nature makes it equally efficient for GPU-accelerated tasks, when Hashcat is the de facto standard for GPU-based password cracking.

How to eliminate wrong answers

Option A is wrong because John the Ripper, while capable of cracking NTLM hashes, primarily runs on CPU and does not natively support GPU acceleration as efficiently as Hashcat; its GPU support is limited and requires separate builds or patches. Option B is wrong because Ophcrack is a specialized tool for cracking LM hashes using rainbow tables, not NTLM hashes, and it does not support GPU acceleration or dictionary attacks. Option D is wrong because RainbowCrack is designed for rainbow table attacks, not dictionary attacks, and while it can use GPU acceleration, it is not optimized for NTLM hash cracking via dictionary methods.

586
MCQmedium

Refer to the exhibit. An analyst suspects that the downloaded file 'update.exe' may have been tampered with. The vendor's official website lists the SHA256 hash as 4e7c2a8f9b3d1e5f6a0c8b7d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f. What should the analyst conclude?

A.The file has been tampered with because the hash is from a different file.
B.The SHA256 hash is not reliable; the analyst should use MD5 instead.
C.The file is authentic and has not been tampered with.
D.The file is malicious because the hash is too long.
AnswerC

This statement is correct. When the cryptographic hash (e.g., SHA256) calculated from a downloaded file precisely matches the official, published hash value, it provides strong cryptographic assurance. This match confirms that the file's contents are identical to the original source and have not been altered, corrupted, or tampered with during transit or storage, thereby establishing its authenticity and integrity.

Why this answer

The SHA256 hash provided by the vendor exactly matches the hash of the downloaded file. SHA256 is a cryptographically strong hash function that produces a fixed 256-bit (64-character hexadecimal) output. A matching hash confirms the file's integrity and authenticity, indicating it has not been tampered with.

Exam trap

The trap here is that candidates may mistakenly think a hash that matches is suspicious or that SHA256 is unreliable, when in fact a matching hash is the definitive proof of file integrity; the exam tests whether you understand that hash length and format are fixed and correct for SHA256.

How to eliminate wrong answers

Option A is wrong because the hash matches the vendor's official hash, so it is not from a different file; a mismatch would indicate tampering. Option B is wrong because SHA256 is more secure and collision-resistant than MD5; MD5 is deprecated due to known vulnerabilities and should not be used for integrity verification. Option D is wrong because the hash length (64 hex characters) is exactly correct for SHA256; a 256-bit hash is always 64 characters in hexadecimal representation, so it is not 'too long'.

587
MCQmedium

During a network assessment, you use SNMPwalk against a target. Which of the following is a prerequisite for successful SNMP enumeration?

A.An open TCP port 161
B.The target must be running Linux
C.Knowledge of the SNMP community string
D.A valid username and password
AnswerC

For SNMPv1 and SNMPv2c, the community string serves as a clear-text password or authentication credential required to access the SNMP agent's Management Information Base (MIB). Without knowing the correct read-only or read-write community string, an `snmpwalk` utility cannot successfully query the device for its managed objects. This string effectively controls access permissions, allowing or denying the retrieval of system information and acting as the primary security mechanism for these older SNMP versions.

Why this answer

SNMP enumeration relies on the SNMP community string, which acts as a password-like credential for read or read/write access to MIB data. Without the correct community string (defaults are often 'public' for read-only and 'private' for read-write), SNMPwalk cannot authenticate with the target agent and will fail to retrieve any OID values.

Exam trap

The trap here is that candidates often confuse SNMP's UDP port 161 with TCP or assume SNMP requires a username/password like SSH, but the CEH exam emphasizes that the community string is the sole authentication token for SNMPv1/v2c enumeration.

How to eliminate wrong answers

Option A is wrong because SNMP uses UDP port 161, not TCP, for agent communication; SNMPwalk sends UDP packets, so an open TCP port 161 is irrelevant. Option B is wrong because SNMP enumeration is platform-agnostic—it works against any device running an SNMP agent, including Windows, routers, switches, and printers. Option D is wrong because SNMP does not use usernames and passwords; it uses community strings as a simple authentication mechanism, and valid credentials would only apply to protocols like SSH or Telnet, not SNMP.

588
MCQhard

A cloud security engineer notices that an S3 bucket named 'company-backup' is configured to allow 's3:GetObject' access to 'Principal: *'. Which attack is this misconfiguration MOST likely to enable?

A.Denial of service by deleting objects
B.SSRF attack to internal metadata
C.Privilege escalation via IAM role
D.Unauthorized data access and exfiltration
AnswerD

When an S3 bucket is configured for public read access, it means that the bucket policy explicitly permits the s3:GetObject action for the * principal (anonymous users). This configuration allows anyone on the internet to enumerate and download all objects stored within that bucket without requiring any authentication. This direct and unrestricted access inevitably leads to unauthorized data access and subsequent exfiltration, constituting a severe data breach where sensitive information can be freely downloaded.

Why this answer

When an S3 bucket allows GetObject access to any principal (public), anyone can list and download objects, leading to data exposure. This is a classic unauthorized data access scenario, not privileged escalation or DoS.

589
Multi-Selecthard

A penetration tester is tasked with performing privilege escalation on a Windows system. Which THREE of the following methods are commonly used for Windows privilege escalation? (Select 3)

Select 3 answers
A.SUID bit abuse
B.Token impersonation (e.g., SeImpersonatePrivilege)
C.Exploiting unquoted service paths
D.Pass-the-hash attack
E.Exploiting weak service permissions (e.g., service misconfigurations)
AnswersB, C, E

Token impersonation, particularly when a process holds the SeImpersonatePrivilege, allows a service or application to temporarily adopt the security context of another user or process. An attacker can exploit this by compromising a service running with this privilege, then using it to impersonate a higher-privileged user's token, such as an administrator or SYSTEM account. This enables the attacker to execute commands or access resources with elevated permissions, effectively achieving privilege escalation within the Windows system.

Why this answer

Token impersonation (B) is a classic Windows privilege escalation technique: if a service account holds SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege), tools like JuicyPotato, RoguePotato, or PrintSpoofer can impersonate a SYSTEM token to gain elevated privileges. Exploiting unquoted service paths (C) works because Windows resolves unquoted paths containing spaces by trying each possible executable name in order, so a low-privileged user who can write to an earlier directory in the path can plant a malicious binary that runs as the service account (often SYSTEM). Exploiting weak service permissions (E) is also valid on Windows, since misconfigured service DACLs allowing SERVICE_CHANGE_CONFIG or WRITE_DAC let an attacker reconfigure the service binary path or replace its executable to run code as the service's privileged account.

SUID bit abuse (A) is a Linux/Unix mechanism and does not exist on Windows filesystems, and pass-the-hash (D), while a Windows credential-reuse attack, is a lateral movement/authentication technique rather than a local privilege escalation method, so neither belongs here.

Exam trap

CEH often tests the distinction between privilege escalation (raising integrity level) and lateral movement (pass-the-hash), causing candidates to mistakenly select pass-the-hash as a privilege escalation method.

590
MCQmedium

A security analyst observes a sudden surge in incoming UDP traffic to the company's DNS servers from multiple external IP addresses. The packets appear to be DNS queries with spoofed source IPs. Which type of DDoS attack is MOST likely occurring?

A.SYN flood
B.DNS amplification
C.UDP flood
D.ICMP flood
AnswerB

DNS amplification is a highly effective distributed denial-of-service (DDoS) attack where attackers send small UDP DNS queries with a spoofed source IP address (the victim's IP) to numerous open DNS resolvers. These resolvers then respond with much larger UDP packets containing DNS records, directed back to the spoofed victim. This technique leverages the amplification factor of DNS responses to overwhelm the target with a massive surge of incoming UDP traffic, typically on port 53.

Why this answer

The attack described involves DNS queries with spoofed source IPs sent to a DNS server, which then responds with large replies to the victim (the spoofed IP). This is a classic DNS amplification attack, a type of reflection-based DDoS that exploits the large response-to-query ratio (e.g., an ANY query can yield a response up to 70x larger) to overwhelm the target. The surge in incoming UDP traffic to the DNS server is the attacker's queries, while the amplified responses are directed at the spoofed victim.

Exam trap

The trap here is that candidates confuse a simple UDP flood (direct traffic) with a DNS amplification attack, missing the key indicator of spoofed source IPs and the reflection/amplification mechanism that distinguishes it.

How to eliminate wrong answers

Option A is wrong because a SYN flood targets the TCP three-way handshake by sending incomplete SYN packets, not UDP-based DNS queries with spoofed source IPs. Option C is wrong because a UDP flood is a direct volumetric attack where the attacker sends high volumes of UDP packets to a target, but it does not involve DNS query/response amplification or spoofed source IPs to reflect traffic off a legitimate server. Option D is wrong because an ICMP flood uses ICMP echo request (ping) packets, not UDP DNS queries, and does not leverage amplification or reflection from a DNS server.

591
MCQeasy

A security analyst runs a vulnerability scan and finds that a server is vulnerable to CVE-2021-44228 (Log4j). Which of the following is the best immediate remediation step?

A.Update Log4j to version 2.17.1 or later
B.Remove the JndiLookup class from the Log4j jar
C.Disable JDBC appender in Log4j configuration
D.Block outbound traffic from the server to the internet
AnswerA

Updating Log4j to version 2.17.1 or later directly addresses the Log4Shell vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) by completely disabling JNDI lookups by default. This version ensures that untrusted input can no longer trigger remote code execution (RCE) via LDAP, RMI, or other JNDI-enabled services. Applying this patch is the most comprehensive and recommended solution, as it eliminates the underlying flaw rather than merely mitigating symptoms. It ensures the application's logging functionality remains secure and fully operational.

Why this answer

CVE-2021-44228 (Log4Shell) is a remote code execution vulnerability in Apache Log4j versions 2.0 through 2.14.1, triggered by JNDI lookups in log messages. Updating to Log4j 2.17.1 or later fully patches the flaw by disabling JNDI lookups by default and fixing the LDAP deserialization vector. This is the vendor-recommended immediate remediation step as it addresses the root cause without relying on workarounds.

Exam trap

The trap here is that candidates often choose Option B (removing JndiLookup) because it was widely publicized as a quick fix, but the CEH exam expects you to know that only a full version update to 2.17.1 or later is the complete and recommended remediation, as the class removal is version-dependent and does not address all attack surfaces.

How to eliminate wrong answers

Option B is wrong because removing the JndiLookup class from the Log4j JAR file is a temporary mitigation that only works for Log4j versions 2.10 to 2.14.1; it does not fix other attack vectors like JDBC appender or Thread Context Map lookups, and the fix is not persistent across updates. Option C is wrong because disabling the JDBC appender does not address the core JNDI lookup vulnerability; the JDBC appender is a separate feature and not the primary attack vector for CVE-2021-44228. Option D is wrong because blocking outbound traffic from the server is a network-level containment measure that may limit exfiltration but does not prevent the initial RCE exploitation; the vulnerability can still be triggered internally or via reverse connections.

592
MCQmedium

A security analyst observes a suspicious SUID binary /usr/bin/evil in a Linux system. Which type of vulnerability does this indicate, and what is the MOST likely objective of an attacker who placed it?

A.Information disclosure; read sensitive files
B.Privilege escalation; gain root access
C.Denial of service; crash the system
D.Buffer overflow; execute arbitrary code
AnswerB

A SUID (Set User ID) bit on an executable allows it to run with the permissions of its owner, regardless of the user executing it. If a binary is owned by the root user and has the SUID bit set, any user executing it will temporarily gain root privileges for the duration of that execution. This mechanism is specifically designed for privilege escalation, enabling a low-privileged user to perform actions typically reserved for root, such as gaining a root shell or modifying system configurations.

Why this answer

A SUID binary owned by root that is not part of the standard OS distribution (like /usr/bin/evil) is a classic indicator of a privilege escalation backdoor. The SUID bit allows any user who executes the binary to run it with the owner's permissions—in this case, root—so the attacker's objective is to gain root access by executing this binary.

Exam trap

EC-Council often tests the distinction between a vulnerability (like a buffer overflow) and an indicator of a completed exploit (like a SUID binary), causing candidates to confuse the attack vector with the attacker's objective.

How to eliminate wrong answers

Option A is wrong because information disclosure typically involves reading sensitive files via misconfigured permissions or services (e.g., world-readable /etc/shadow), not a custom SUID binary. Option C is wrong because a denial of service attack aims to crash or exhaust system resources, whereas a SUID binary is specifically designed to grant elevated privileges, not disrupt availability. Option D is wrong because a buffer overflow exploits memory corruption to execute arbitrary code, but the presence of a suspicious SUID binary itself does not indicate a buffer overflow; it indicates a pre-placed privilege escalation mechanism.

593
MCQmedium

During a penetration test, you run the command: nmap -sU -p 161,162 --script=snmp-brute 192.168.1.100. Which of the following is the PRIMARY goal of this scan?

A.Discover SNMP community strings via brute-force
B.Perform a ping sweep to discover live hosts
C.Identify open TCP ports and services on the target
D.Enumerate SNMP MIB tree values
AnswerA

This option correctly identifies the purpose of using Nmap's UDP scan (`-sU`) targeting the standard SNMP port (161) in conjunction with the `snmp-brute` NSE script. This script systematically attempts a list of common or custom community strings (like "public," "private," "manager") against the discovered SNMP agent. Successful brute-force reveals valid community strings, granting read or write access to the device's MIB, which is a critical step in reconnaissance and potential exploitation.

Why this answer

The command uses the `-sU` flag for a UDP scan and targets ports 161 and 162, which are the standard SNMP ports. The `--script=snmp-brute` script attempts to brute-force SNMP community strings (the equivalent of passwords for SNMPv1/v2c). Therefore, the primary goal is to discover valid community strings, which is option A.

Exam trap

The trap here is that candidates confuse the `snmp-brute` script with SNMP MIB enumeration or general service discovery, but the script's explicit purpose is to brute-force community strings, not to read MIB values or scan TCP ports.

How to eliminate wrong answers

Option B is wrong because a ping sweep typically uses ICMP echo requests (or TCP SYN to common ports) and does not involve scanning UDP ports 161/162 or running an SNMP brute-force script. Option C is wrong because `-sU` scans UDP ports, not TCP ports, and the script is specifically for SNMP brute-forcing, not service enumeration. Option D is wrong because enumerating SNMP MIB tree values is done with scripts like `snmp-info` or `snmp-interfaces`, not the `snmp-brute` script, which focuses on guessing community strings.

594
MCQhard

A company's internal PKI uses an offline root CA and an online issuing CA. A security engineer needs to revoke a compromised certificate issued by the online CA. Which CRL distribution point should the engineer update?

A.The CRL published by the certificate authority that signed the issuing CA's certificate
B.The CRL published by the intermediate CA, if any
C.The CRL published by the online issuing CA
D.The CRL published by the offline root CA
AnswerC

The online issuing CA is directly responsible for generating, signing, and managing the lifecycle of end-entity certificates within this PKI. When an end-entity certificate needs to be revoked, it is the issuing CA that records this revocation event and publishes it in its own Certificate Revocation List (CRL). Consequently, clients validating an end-entity certificate must consult the CRL published by the online issuing CA to ascertain its current revocation status.

Why this answer

The compromised certificate was issued by the online issuing CA, so only that CA has the authority to revoke it and publish the updated CRL. Clients validating the certificate will check the CRL distribution point (CDP) embedded in the certificate, which points to the issuing CA's CRL. Updating the CRL on the online issuing CA ensures that revocation status is immediately available to relying parties.

Exam trap

EC-Council often tests the misconception that the root CA must be involved in revocation of end-entity certificates, but in reality only the issuing CA that signed the certificate can revoke it and update its own CRL.

How to eliminate wrong answers

Option A is wrong because the CRL published by the CA that signed the issuing CA's certificate (the offline root CA) contains only revocation information for the issuing CA's certificate itself, not for end-entity certificates issued by the online CA. Option B is wrong because in this two-tier hierarchy there is no intermediate CA; even if one existed, the intermediate CA's CRL would cover certificates it issued, not those issued by the online issuing CA. Option D is wrong because the offline root CA is typically kept offline and does not publish a CRL for end-entity certificates; its CRL (if any) only covers subordinate CA certificates, not user or device certificates.

595
MCQhard

A security analyst captures network traffic and sees a sequence of ARP replies with the same IP address mapping to different MAC addresses within a short period. Which attack is indicated?

A.DNS spoofing
B.ARP poisoning
C.DHCP starvation
D.MAC flooding
AnswerB

ARP poisoning, also known as ARP spoofing, is a man-in-the-middle attack where an attacker sends forged ARP reply messages onto a local area network. These malicious replies associate the attacker's MAC address with the IP address of another host, such as the default gateway or another workstation. By continuously sending these fake ARP replies, the attacker can trick multiple devices into updating their ARP caches with incorrect information, thereby redirecting traffic intended for the legitimate IP to the attacker's machine. This directly explains the observation of multiple ARP replies for one IP.

Why this answer

B is correct because ARP poisoning (also called ARP spoofing) involves sending forged ARP replies that map a target IP address (e.g., the default gateway) to the attacker's MAC address. The rapid sequence of ARP replies with the same IP but different MACs is a classic indicator of an active ARP poisoning attack, where the attacker floods the network to corrupt the ARP cache of hosts.

Exam trap

The trap here is that candidates confuse ARP poisoning with MAC flooding because both involve MAC addresses and network manipulation, but MAC flooding targets the switch's CAM table, not the host's ARP cache, and uses many different MACs, not the same IP mapped to multiple MACs.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS responses to redirect domain name lookups, not ARP tables; it operates at Layer 7 (application) using UDP port 53, not Layer 2/3 ARP messages. Option C is wrong because DHCP starvation floods a DHCP server with fake DISCOVER messages to exhaust its IP address pool, causing denial of service; it does not involve ARP replies or MAC-to-IP mapping changes. Option D is wrong because MAC flooding overwhelms a switch's CAM table with fake MAC addresses to force it into fail-open mode (hub mode), enabling packet sniffing; it does not target ARP caches or use ARP replies with the same IP to different MACs.

596
MCQmedium

A penetration tester discovers that a web application's search functionality reflects user input directly in the page source without sanitization. The tester crafts a URL like http://example.com/search?q=<script>alert('XSS')</script> and the script executes. This is an example of which type of XSS?

A.Stored (persistent) XSS
B.Blind XSS
C.DOM-based XSS
D.Reflected XSS
AnswerD

Reflected XSS occurs when a malicious script, supplied in an HTTP request, is immediately and unsafely echoed back in the server's HTTP response. The server takes user-supplied input, often from a URL parameter, and directly embeds it into the HTML page without adequate sanitization or encoding. This causes the victim's browser to execute the script upon receiving the crafted response, making it a non-persistent, single-request attack.

Why this answer

Reflected XSS occurs when user-supplied input is immediately echoed back in the server's HTTP response without sanitization or encoding, and the browser executes it in the context of the victim's session. Here the payload in the q parameter is reflected in the page source and executes, which is the textbook definition of reflected (non-persistent) XSS. The attack requires the victim to click a crafted link, distinguishing it from stored XSS.

Exam trap

The trap is distinguishing reflected from DOM-based XSS: candidates see 'script executes in the browser' and pick DOM-based, but the key differentiator is whether the server reflected the payload in its response (reflected) or the client-side JS processed it (DOM-based).

How to eliminate wrong answers

Option A is wrong because stored (persistent) XSS requires the payload to be saved server-side (e.g., in a database or comment field) and served to other users later — here the input is only reflected in the immediate response. Option B is wrong because blind XSS is a variant of stored XSS where the payload fires in a backend/admin panel the attacker cannot see; it still requires persistence, which is absent here. Option C is wrong because DOM-based XSS executes entirely client-side when JavaScript sinks (e.g., innerHTML, document.write) process untrusted data from sources like location.hash — the server never reflects the payload in its response, which contradicts the scenario.

597
MCQhard

You are a penetration tester assessing a client's internal network. The client has provided you with a non-administrative domain user account. The target network consists of 200 Windows workstations and 5 Windows servers (one domain controller, one file server, two application servers, and one database server). All systems are fully patched and have host-based firewalls enabled. The client wants you to identify vulnerabilities that could be exploited from the internal network. After initial reconnaissance, you discover that all servers have SMB (port 445) open only to the domain controller and the file server has SMB open to all workstations. You have gained a foothold on a workstation via a phishing attack. From this workstation, you can reach the file server on port 445. What is the most effective next step to enumerate potential vulnerabilities on the file server?

A.Attempt to connect to the file server via RDP (port 3389) using the compromised user's credentials.
B.Use PsExec to execute commands remotely on the file server using the compromised user account.
C.Run a full vulnerability scan (e.g., Nessus) against the entire subnet to identify weaknesses.
D.Enumerate SMB shares and session information using `net view \\fileserver` and `smbclient -L //fileserver`.
AnswerD

Enumerating SMB shares and session information using `net view \\fileserver` (on Windows) or `smbclient -L //fileserver` (on Linux/Kali) is a highly effective and low-impact reconnaissance method. These commands leverage the Server Message Block (SMB) protocol, the file server's core service, to list accessible shares and potential misconfigurations like null sessions. This approach directly targets the server's primary function and is designed to work even with standard user permissions, providing valuable insights into accessible resources.

Why this answer

The client's objective is to enumerate potential vulnerabilities on the file server from the compromised workstation. Since SMB (port 445) is open between workstations and the file server, using `net view \\fileserver` and `smbclient -L //fileserver` allows you to list SMB shares, sessions, and other information without requiring administrative privileges or additional tools. This is a standard enumeration technique that reveals accessible resources, which can then be tested for misconfigurations or weak permissions.

Exam trap

The trap here is that candidates often assume a full vulnerability scan (Option C) is always the best next step, but in a stealthy penetration test with limited credentials, targeted SMB enumeration (Option D) is more effective and less likely to be detected.

How to eliminate wrong answers

Option A is wrong because RDP (port 3389) is not mentioned as open on the file server, and even if it were, connecting via RDP with a non-administrative user would not provide the necessary enumeration of SMB-based vulnerabilities. Option B is wrong because PsExec requires administrative privileges on the target system, and the compromised user is non-administrative, so the command would fail. Option C is wrong because running a full vulnerability scan (e.g., Nessus) against the entire subnet is noisy, time-consuming, and may trigger alerts; the question asks for the most effective next step after initial reconnaissance, and targeted SMB enumeration is more appropriate.

598
MCQmedium

A penetration tester wants to evade an IDS while scanning a target network. The tester uses the Nmap command: nmap -sS -f 10.10.10.1. What does the -f flag accomplish?

A.It increases the timing template to T5 (insane)
B.It uses an idle scan by bouncing off a zombie host
C.It sends packets with a spoofed source IP address
D.It fragments the IP packets into 8-byte fragments
AnswerD

Fragmenting IP packets into small segments, such as 8-byte fragments using the -f flag, is a classic IDS evasion technique. Many Intrusion Detection Systems struggle with the efficient and accurate reassembly of highly fragmented packets, especially if they arrive out of order or are unusually small. This difficulty can cause the IDS to miss the complete signature of a malicious payload or scan, allowing the fragmented traffic to bypass detection and reach the target.

Why this answer

The -f flag in Nmap instructs the tool to fragment the IP packets into 8-byte fragments (or smaller, depending on the MTU). This is a common evasion technique used to bypass Intrusion Detection Systems (IDS) and firewalls by splitting the TCP header across multiple packets, making it harder for signature-based detection to reassemble and match the scan pattern.

Exam trap

The trap here is that candidates often confuse the -f flag with other Nmap options like -T (timing), -sI (idle scan), or -S (spoofing), because they all start with a single dash and are used for evasion or stealth, but each has a distinct function.

How to eliminate wrong answers

Option A is wrong because the -f flag does not control timing; timing templates are set with -T0 through -T5 (e.g., -T5 for insane). Option B is wrong because an idle scan is performed using the -sI flag, not -f, and requires specifying a zombie host. Option C is wrong because spoofing a source IP address is achieved with the -S flag (e.g., -S 192.168.1.100), not -f.

599
MCQmedium

Which of the following OSINT techniques would be MOST effective for discovering email addresses and employee names associated with a target organization?

A.Nmap scan
B.theHarvester
C.WHOIS lookup
D.Shodan search
AnswerB

theHarvester is a dedicated OSINT tool specifically designed for gathering publicly available information, including email addresses, subdomains, hostnames, and employee names. It queries various public data sources like search engines (e.g., Google, Bing), PGP key servers, and social media platforms to aggregate this intelligence. This makes it exceptionally effective for passive reconnaissance aimed at collecting target organization email addresses without direct interaction.

Why this answer

theHarvester is specifically designed to gather emails, subdomains, IPs, and employee names from public sources like search engines, PGP key servers, and social networks.

600
Multi-Selectmedium

A network administrator notices unusual traffic patterns: the internal DNS server is receiving large DNS queries with the source IP spoofed to appear as the internal DNS server itself. The queries appear to be amplification requests. Which TWO characteristics describe this attack?

Select 2 answers
A.It is a protocol-specific attack targeting TCP SYN packets
B.It relies on open DNS resolvers to amplify traffic
C.It exploits the ARP protocol to redirect traffic
D.It is a form of DDoS attack
E.It requires the attacker to be on the same subnet as the victim
AnswersB, D

This is correct because DNS amplification attacks exploit misconfigured or intentionally open DNS resolvers that are accessible on the internet. Attackers send small DNS queries to these resolvers, spoofing the victim's IP address as the source. The open resolvers then respond with significantly larger DNS records to the unsuspecting victim, effectively multiplying the attacker's initial traffic volume.

Why this answer

The attack described relies on open DNS resolvers to amplify traffic. The attacker sends small DNS queries with a spoofed source IP (the victim's DNS server), causing the open resolver to send large responses to the victim, thus amplifying the traffic volume. This is a classic DNS amplification attack, which is a type of reflection attack that exploits the UDP protocol and the fact that DNS response sizes can be significantly larger than query sizes.

Exam trap

The trap here is that candidates may confuse DNS amplification with other reflection attacks (e.g., NTP amplification) or mistakenly think the attacker must be on the same subnet, when in fact IP spoofing allows the attack to originate from anywhere.

Page 7

Page 8 of 13

Page 9