. When an ","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-web-application-allows-users-to-submit-feedback-that-is-st-0g9am","acceptedAnswer":{"@type":"Answer","text":"Stored XSS","comment":{"@type":"Comment","text":"Stored XSS, also known as Persistent XSS, is a severe web vulnerability where a malicious script is permanently saved on the target server, typically within a database, comment section, or feedback system. When a legitimate user, such as an administrator, later retrieves and views the compromised data, their browser executes the embedded script without their knowledge. This allows the attacker to compromise user sessions, deface websites, or redirect victims, making it a highly impactful vulnerability due to its persistence and widespread potential."}},"suggestedAnswer":[{"@type":"Answer","text":"Blind XSS","comment":{"@type":"Comment","text":"Blind XSS is a specific sub-type of Stored XSS where the attacker does not directly observe the execution of their injected payload, often because it triggers on an internal administrative interface or a backend system. While the scenario describes a script being stored and executed by an admin, which *could* be blind, the question's phrasing focuses on the storage and execution mechanism rather than the attacker's visibility. Therefore, 'Stored XSS' is the more general and directly applicable classification for the described vulnerability."}},{"@type":"Answer","text":"Reflected XSS","comment":{"@type":"Comment","text":"Reflected XSS, also known as Non-Persistent XSS, occurs when a malicious script injected into an HTTP request is immediately 'reflected' back in the server's response to the user's browser without being permanently stored on the server. The payload is typically delivered via a URL parameter or form submission and executed only once by the victim who clicks a crafted link. This mechanism fundamentally differs from the described scenario where the script is explicitly *stored* in a database for later, persistent execution."}},{"@type":"Answer","text":"DOM-based XSS","comment":{"@type":"Comment","text":"DOM-based XSS is a client-side vulnerability where the malicious payload is executed due to modifications of the Document Object Model (DOM) environment within the victim's browser, rather than being directly injected into the server's response. The server does not process or store the malicious script; instead, the vulnerability arises from client-side scripts mishandling user-controllable data that alters the DOM. The question explicitly states the script is 'stored' and 'executed when loaded by an admin,' indicating a server-side storage and retrieval mechanism, which contradicts the client-side nature of DOM-based XSS."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A penetration tester discovers that a web application includes the following code: 'include($_GET['page'] . '.php');' and the application is running on a Linux server. The tester attempts to exploit t","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-penetration-tester-discovers-that-a-web-application-includ-qfmpg","acceptedAnswer":{"@type":"Answer","text":"Local File Inclusion (LFI); it will not succeed because the '.php' extension is appended","comment":{"@type":"Comment","text":"Local File Inclusion (LFI) is the correct classification for this vulnerability, as it involves an attempt to include files present on the web server's local file system. However, the crucial detail preventing immediate success is the automatic appending of the \".php\" extension to the user-supplied input. This means an attempt to include a file like \"/etc/passwd\" would result in the application trying to include \"/etc/passwd.php\", which typically does not exist, thereby blocking direct access to the target file without further bypass techniques."}},"suggestedAnswer":[{"@type":"Answer","text":"Directory traversal; it will succeed because '../' bypasses restrictions","comment":{"@type":"Comment","text":"Directory traversal is a technique used to access files and directories stored outside the web root directory by manipulating file paths, typically using \"../\" sequences. However, in this scenario, the appended \".php\" extension fundamentally alters the target file path. An attempt to access \"/etc/passwd\" would result in the server trying to include \"/etc/passwd.php\", which is unlikely to exist or be the intended sensitive file, thus preventing successful traversal to read arbitrary system files."}},{"@type":"Answer","text":"Remote File Inclusion (RFI); it will succeed because the parameter is not filtered","comment":{"@type":"Comment","text":"Remote File Inclusion (RFI) specifically refers to the vulnerability where an attacker can include files hosted on a remote server into the vulnerable application. The scenario described involves attempting to include a local file, which falls under Local File Inclusion (LFI). Furthermore, even if it were an RFI attempt, the automatic appending of \".php\" would cause the server to request \"http://attacker.com/malicious.txt.php\", likely preventing the remote malicious file from being interpreted as intended."}},{"@type":"Answer","text":"Command injection; it will succeed if the server interprets PHP code","comment":{"@type":"Comment","text":"Command injection is a distinct vulnerability where an attacker injects operating system commands into a web application, causing the server to execute arbitrary shell commands. This scenario, however, describes an attempt to manipulate a file inclusion mechanism, not to execute system commands. The vulnerability type is file inclusion, which focuses on reading or executing files, not directly running OS commands through the application's backend."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"During a penetration test, you run the following command: nmap -sV -p 80 --script http-title 192.168.1.10. The output shows that port 80 is open and the HTTP title is 'Login Portal'. Which phase of th","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-penetration-test-you-run-the-following-command-nm-r2qpi","acceptedAnswer":{"@type":"Answer","text":"Scanning and enumeration","comment":{"@type":"Comment","text":"Scanning and enumeration is the phase where an attacker actively probes target systems to identify live hosts, open ports, running services, operating system types, and potential vulnerabilities. The nmap command is a quintessential tool for this phase, as it systematically sends various types of packets to map out the network landscape and gather detailed information about network services. This active interaction provides the crucial intelligence needed to identify potential entry points for subsequent exploitation attempts."}},"suggestedAnswer":[{"@type":"Answer","text":"Exploitation","comment":{"@type":"Comment","text":"Exploitation is the phase where identified vulnerabilities are actively leveraged to gain unauthorized access, elevate privileges, or execute arbitrary code on a target system. Running an nmap command, which is primarily a reconnaissance and discovery tool, merely gathers information about network services and open ports. It does not, by itself, involve the actual compromise or manipulation of a system's security flaws to achieve control."}},{"@type":"Answer","text":"Post-exploitation","comment":{"@type":"Comment","text":"Post-exploitation activities occur strictly after an attacker has successfully gained initial access to a target system. This phase involves actions like maintaining persistence, escalating privileges, exfiltrating data, and pivoting to other systems within the network. An nmap scan, however, is a pre-access activity focused on initial network discovery and service identification, preceding any actual compromise or subsequent actions within the compromised environment."}},{"@type":"Answer","text":"Footprinting","comment":{"@type":"Comment","text":"Footprinting is the initial, often passive, information gathering phase where an attacker collects publicly available data about a target without direct interaction with its systems. This typically involves techniques such as OSINT, WHOIS lookups, DNS queries, and social media analysis. In contrast, an nmap command actively sends packets to a target network or host, directly probing for live hosts, open ports, and service banners, making it an active reconnaissance method."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A forensic analyst examining a compromised Linux system finds the following entry in /var/log/auth.log: `Mar 15 10:23:45 server sshd[1234]: Accepted password for root from 10.0.0.5 port 54321 ssh2`. H","url":"https://courseiva.com/questions/ec-council/ec-ceh/a-forensic-analyst-examining-a-compromised-linux-system-find-ii012","acceptedAnswer":{"@type":"Answer","text":"Erasing tracks","comment":{"@type":"Comment","text":"Erasing tracks is a critical post-exploitation phase where an attacker attempts to remove or obscure any evidence of their presence and activities on a compromised system. This directly involves manipulating system logs, such as /var/log/auth.log or ~/.bash_history, by truncating, deleting, or modifying entries. Reducing logging levels or disabling logging services are also common techniques to prevent future actions from being recorded, thereby making forensic analysis significantly more challenging and hindering incident response efforts."}},"suggestedAnswer":[{"@type":"Answer","text":"Privilege escalation","comment":{"@type":"Comment","text":"Privilege escalation refers to the act of gaining higher access rights than initially obtained on a compromised system, such as moving from a regular user to root. While an attacker might alter logs *after* escalating privileges to hide their actions, the act of log alteration itself is not the escalation. It is a distinct post-exploitation activity aimed at maintaining persistence or evading detection, rather than the process of gaining elevated permissions."}},{"@type":"Answer","text":"Executing applications","comment":{"@type":"Comment","text":"Executing applications is a fundamental operation on any operating system, where a user or process runs a program to perform a specific task. An attacker will certainly execute various applications during an intrusion, such as malware, reconnaissance tools, or system utilities. However, the act of simply running an application does not inherently involve or describe the specific action of manipulating system logs to conceal evidence. Log manipulation is a separate, deliberate action often performed by specific tools or commands after other applications have achieved their primary objective."}},{"@type":"Answer","text":"Spying","comment":{"@type":"Comment","text":"Spying, in a cybersecurity context, typically involves reconnaissance, monitoring system activities, or exfiltrating sensitive data without detection. This could include observing user behavior, capturing network traffic, or copying files. While an attacker engaged in spying aims to remain undetected, the act of log tampering is a specific forensic countermeasure designed to *destroy* or *alter* existing evidence of past actions, rather than the ongoing passive observation or active data collection that defines spying."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"During a penetration test, you capture the following output: 'HTTP/1.1 200 OK ... Set-Cookie: sessionid=abc123; path=/'. You then send a request with a modified cookie value 'sessionid=abc124' and rec","url":"https://courseiva.com/questions/ec-council/ec-ceh/during-a-penetration-test-you-capture-the-following-output-kzywe","acceptedAnswer":{"@type":"Answer","text":"Session hijacking via cookie prediction","comment":{"@type":"Comment","text":"Session hijacking via cookie prediction occurs when an attacker successfully guesses or calculates a valid session identifier (Session ID) that an application uses to maintain a user's authenticated state. By setting their own browser's cookie to this predicted, valid Session ID, the attacker can bypass the login process and assume the identity of the legitimate user, gaining unauthorized access to their active session. This method specifically exploits weak or predictable session ID generation algorithms."}},"suggestedAnswer":[{"@type":"Answer","text":"Cross-site scripting","comment":{"@type":"Comment","text":"Cross-site scripting (XSS) involves injecting malicious client-side scripts, typically JavaScript, into web pages viewed by other users. This vulnerability arises from improper input validation and output encoding, allowing the script to execute within the victim's browser context. While XSS can be leveraged to steal session cookies, the direct manipulation of a cookie, as implied by the question, is not the primary mechanism or defining characteristic of an XSS attack itself."}},{"@type":"Answer","text":"SQL injection","comment":{"@type":"Comment","text":"SQL injection exploits vulnerabilities in an application's database queries, enabling an attacker to insert malicious SQL code into input fields. This can lead to unauthorized access, modification, or deletion of database contents, or even execution of arbitrary commands on the database server. The scenario described focuses on directly altering a session cookie, which is a client-side or application-level state manipulation, not a direct attack on the backend database query logic."}},{"@type":"Answer","text":"Man-in-the-middle attack","comment":{"@type":"Comment","text":"A Man-in-the-Middle (MitM) attack involves an attacker intercepting and potentially altering communications between two parties who believe they are directly communicating. This requires the attacker to position themselves between the client and server, often using techniques like ARP spoofing or DNS poisoning, to capture and manipulate data, including session cookies, as it traverses the network. The described action of directly modifying a cookie does not inherently involve network interception."}}]}]
Which TWO of the following are symmetric encryption algorithms?
Select 2 answers
A.Diffie-Hellman
B.RSA
C.AES
D.ECC
E.3DES
AnswersC, E
AES is a symmetric block cipher: encryption and decryption use the same secret key, satisfying the question's requirement for a symmetric algorithm. It operates on 128-bit blocks with 128-, 192- or 256-bit keys, unlike asymmetric algorithms such as RSA, which use a public/private key pair.
Why this answer
AES (Option C) is a symmetric block cipher standardized by NIST (FIPS 197) that uses the same secret key for both encryption and decryption, with key sizes of 128, 192, or 256 bits. 3DES (Option E) is also symmetric: it applies the DES cipher three times to each data block using a shared secret key (typically two or three 56-bit keys, giving 112 or 168 bits of effective key strength). In contrast, Diffie-Hellman (Option A) is a key-exchange protocol used to establish a shared secret over an insecure channel, not an encryption algorithm itself. RSA (Option B) and ECC (Option D) are asymmetric (public-key) cryptosystems, where encryption uses a public key and decryption uses a distinct private key, so they do not qualify as symmetric algorithms.
Exam trap
The trap here is that candidates often confuse key exchange protocols (like Diffie-Hellman) and asymmetric algorithms (like RSA and ECC) with symmetric encryption, because all are used in cryptography but serve fundamentally different roles in securing communications.
During a penetration test, you enumerate a Linux NFS server and discover that the /export directory is mounted with 'no_root_squash' and 'world_readable' permissions. Which of the following actions would allow you to escalate to root access on the NFS client?
A.Create a symbolic link to /etc/shadow on the server from the client
B.Use 'showmount -e' to list exports and then mount the share with 'mount -t nfs -o vers=3'
C.Mount the share, create a setuid binary owned by root, then execute it on the client
D.Run 'sudo nmap --script nfs-ls' to list files on the export
AnswerC
If the NFS server's export configuration includes `no_root_squash`, a client logged in as root can create files on the mounted share that retain root ownership on the server. By compiling a simple C program with the SUID bit set on this share, and then executing it on the client, the program will run with root privileges. This effectively escalates privileges on the client system by leveraging the server's trust in the client's root user, allowing arbitrary commands to execute as root.
Why this answer
Mounting an NFS export with 'no_root_squash' means that root on the client is treated as root on the server. By creating a setuid binary owned by root on the mounted share, any user on the client can execute that binary and gain root privileges on the client system, effectively escalating from a regular user to root.
Exam trap
The trap here is that candidates often confuse 'no_root_squash' with allowing direct access to sensitive files like /etc/shadow, but the actual exploit requires creating a setuid binary to escalate privileges on the client, not just reading server files.
How to eliminate wrong answers
Option A is wrong because creating a symbolic link to /etc/shadow on the server from the client would only allow reading the shadow file if the client user has appropriate permissions, but it does not provide root escalation on the client; the link is resolved on the server, not the client. Option B is wrong because 'showmount -e' and mounting with 'mount -t nfs -o vers=3' are standard enumeration and mounting steps that do not by themselves escalate privileges; they only provide access to the exported filesystem. Option D is wrong because 'sudo nmap --script nfs-ls' is used to list files on the NFS export, but it does not create a setuid binary or exploit the 'no_root_squash' setting to gain root on the client.
A penetration tester wants to perform a stealth scan without completing the TCP three-way handshake. The target is a web server on port 80. The tester uses Nmap with the -sS flag. What is the expected behavior if the port is open?
A.The tester receives a SYN/ACK and sends an RST to tear down the connection.
B.The tester receives an RST, indicating the port is closed.
C.The tester receives no response, indicating a filtered port.
D.The tester receives a SYN/ACK and sends an ACK to establish the connection.
AnswerA
A SYN scan, often referred to as a half-open scan, initiates a TCP handshake by sending a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK packet. To avoid logging a full connection on the target system and thus maintain stealth, the penetration tester immediately sends an RST (reset) packet, tearing down the nascent connection before the three-way handshake completes. This allows port status determination without fully establishing a session.
Why this answer
The -sS flag in Nmap performs a SYN stealth scan, which sends a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK, and the tester's operating system kernel automatically sends an RST to tear down the connection before the three-way handshake completes. This avoids establishing a full TCP connection, making the scan less detectable by some intrusion detection systems.
Exam trap
The trap here is that candidates may confuse the SYN scan with a full connect scan (-sT) and think an ACK is sent to complete the handshake, or they may mistakenly believe that receiving an RST indicates an open port.
How to eliminate wrong answers
Option B is wrong because receiving an RST indicates the port is closed, not open; in a SYN scan, a closed port responds with an RST. Option C is wrong because no response typically indicates a filtered port (e.g., blocked by a firewall), not the behavior of an open port. Option D is wrong because sending an ACK after receiving a SYN/ACK would complete the three-way handshake and establish a full connection, which defeats the purpose of a stealth scan and is not what Nmap's -sS does.
Which TWO of the following are valid methods for enumerating SMB shares on a target system? (Select 2)
Select 2 answers
A.smbclient -L //target -U ''
B.snmpwalk -v2c -c public target
C.nmap -sU -p 445 target
D.nbtstat -A target
E.enum4linux -a target
AnswersA, E
smbclient -L lists available shares.
Why this answer
`smbclient -L //target -U ''` attempts to list SMB shares on the target by connecting with a null session (empty username). This is a classic enumeration technique that exploits default or weak SMB configurations, allowing an attacker to retrieve share names without authentication.
Exam trap
The trap here is that candidates often confuse NetBIOS enumeration (using `nbtstat`) with SMB share enumeration, or they mistakenly think UDP scans on port 445 (which is TCP-only) are valid for SMB discovery.
Which of the following tools is specifically designed to automate the detection and exploitation of SQL injection vulnerabilities in web applications?
A.Burp Suite
B.Nikto
C.Metasploit
D.SQLMap
AnswerD
SQLMap is an open-source penetration testing tool specifically engineered to automate the process of detecting and exploiting SQL injection flaws in web applications. It supports a wide array of SQL injection techniques, including boolean-based blind, error-based, union query, stacked queries, and time-based blind, across various database management systems. Its specialized algorithms and extensive payload database make it highly efficient and effective for fully automating the identification and exploitation of SQL injection vulnerabilities.
Why this answer
SQLMap is an open-source penetration testing tool specifically designed to automate the detection and exploitation of SQL injection flaws in web applications. It supports a wide range of database backends, injection techniques (boolean-based, time-based, error-based, UNION, stacked queries), and post-exploitation actions such as dumping database contents. This makes it the correct answer for automated SQLi detection and exploitation.
Exam trap
CEH often tests the distinction between general web scanners (Burp, Nikto) and the purpose-built SQLi automation tool (SQLMap), so candidates must match the tool to the specific vulnerability class.
How to eliminate wrong answers
Option A is wrong because Burp Suite is a general-purpose web proxy and scanner that can detect some SQLi but is not specifically designed to automate SQL injection exploitation. Option B is wrong because Nikto is a web server scanner that identifies misconfigurations and known vulnerabilities but does not automate SQLi exploitation. Option C is wrong because Metasploit is a general exploitation framework that can leverage SQLi modules but is not purpose-built for automated SQLi detection and exploitation.
A penetration tester uses the SMTP commands VRFY and EXPN on a mail server. What is the tester MOST likely trying to accomplish?
A.To enumerate valid email addresses and distribution lists
B.To extract email content from the server
C.To perform a mail relay attack
D.To test for open relay
AnswerA
The SMTP commands VRFY (Verify) and EXPN (Expand) are powerful reconnaissance tools for penetration testers. VRFY is used to confirm the existence of a specific user or mailbox on the target mail server, returning either a valid user name or an error. EXPN, conversely, is designed to reveal the full membership of a mailing list or alias, providing a list of all individual recipients. Both commands, if not properly restricted, allow an attacker to enumerate valid email addresses and distribution lists, which is invaluable for targeted phishing, spam campaigns, or further social engineering efforts.
Why this answer
The VRFY command asks the mail server to verify whether a given email address exists, while EXPN requests the members of a mailing list or alias. By issuing these commands, the tester can enumerate valid user accounts and distribution lists on the server, which is a key step in building a target list for further attacks such as password guessing or phishing.
Exam trap
The trap here is that candidates confuse VRFY/EXPN with open relay testing, but open relay is verified using the RCPT TO command with an external domain, not address verification or list expansion.
How to eliminate wrong answers
Option B is wrong because VRFY and EXPN only return address existence or list membership, not the content of stored emails; extracting email content would require protocols like IMAP or POP3 with valid credentials. Option C is wrong because a mail relay attack involves using the server to send unauthorized email to external domains, which is tested with the SMTP 'RCPT TO' command, not VRFY or EXPN. Option D is wrong because testing for open relay is done by sending a test email with a RCPT TO pointing to an external domain and observing if the server accepts it without authentication; VRFY and EXPN do not test relay behavior.
After gaining initial access to a Windows server, a penetration tester wants to escalate privileges. The tester finds that the current user has the 'SeImpersonatePrivilege' enabled. Which attack technique could the tester use to abuse this privilege?
A.SUID bit abuse
B.Pass-the-Hash attack
C.Token impersonation via Juicy Potato
D.Log manipulation to hide tracks
AnswerC
Juicy Potato is a well-known Windows privilege escalation tool that exploits the SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege often held by services running as SYSTEM. It leverages specific COM server CLSIDs and a local NTLM relay attack to force a high-privileged process (e.g., BITS, Print Spooler) to authenticate back to a listener controlled by the low-privileged attacker. This process allows the attacker to capture and impersonate the SYSTEM user's security token, thereby escalating privileges to SYSTEM.
Why this answer
The SeImpersonatePrivilege allows a process to impersonate a user after obtaining a token. Juicy Potato (and its variants like RoguePotato) exploits this by coercing the SYSTEM account to connect to a malicious named pipe, capturing its token, and using it to spawn a process with SYSTEM privileges. This is a well-known privilege escalation technique on Windows systems where the user has the SeImpersonatePrivilege.
Exam trap
The trap here is that candidates confuse SeImpersonatePrivilege with other Windows privileges (like SeDebugPrivilege) or mistakenly associate it with Linux-based SUID attacks, leading them to choose option A or B.
How to eliminate wrong answers
Option A is wrong because SUID bit abuse is a Linux/Unix privilege escalation technique that relies on the set-user-ID permission bit, which has no equivalent on Windows. Option B is wrong because Pass-the-Hash is a lateral movement or credential reuse attack that uses NTLM hashes to authenticate, not a technique to abuse the SeImpersonatePrivilege for local privilege escalation. Option D is wrong because log manipulation is a post-exploitation stealth technique to cover tracks, not a method to escalate privileges using a specific user right.
A penetration tester uses SQLMap with the option '--technique=T --dbms=MySQL --level=5 --risk=3' against a login form. The tool returns results after a delay of several seconds per request. Which SQL injection technique is being used?
A.Out-of-band SQL injection
B.Time-based blind SQL injection
C.Error-based SQL injection
D.Boolean-based blind SQL injection
AnswerB
Time-based blind SQL injection is a technique where the attacker infers information by observing the time it takes for the database server to respond to specific queries. By introducing conditional delays (e.g., IF(condition, SLEEP(5), 0)), the presence or absence of a delay indicates whether the condition is true or false. The 'T' option in sqlmap explicitly instructs the tool to employ this method, making it the correct answer.
Why this answer
The 'T' in --technique stands for Time-based blind SQL injection. The delay indicates time-based injection where the database sleeps to cause a response delay.
A security analyst observes repeated log entries showing `EXPN` commands from an external IP address to the company's mail server. What is the MOST likely objective of this activity?
A.Testing SMTP authentication mechanisms
B.Attempting to perform a denial-of-service attack
C.Enumerating valid email addresses and mailing list members
D.Delivering spam emails through open relay
AnswerC
The `EXPN` (Expand) command in SMTP is specifically designed to request the server to return the actual delivery addresses for a given mailing list, alias, or even a single user. By issuing `EXPN <address>`, a security analyst or attacker can determine if an address is valid and, if it represents a list or alias, retrieve all the individual email addresses associated with it, aiding in reconnaissance and target identification.
Why this answer
The `EXPN` command is part of the SMTP protocol (RFC 5321) and is used to expand a mailing list or alias, revealing the individual email addresses that belong to it. By repeatedly issuing `EXPN` commands, an attacker can enumerate valid email addresses and mailing list members, which is a reconnaissance technique for gathering targets for phishing or social engineering. This aligns with the enumeration phase of system hacking, where the goal is to extract user and service information.
Exam trap
The trap here is that candidates confuse `EXPN` with `VRFY` (which verifies a single user) or assume any SMTP command is part of an attack delivery mechanism, rather than recognizing it as a reconnaissance technique for user enumeration.
How to eliminate wrong answers
Option A is wrong because `EXPN` does not test SMTP authentication; authentication is handled by commands like `AUTH` (e.g., LOGIN, PLAIN), and `EXPN` is typically available before or without authentication. Option B is wrong because a denial-of-service attack would involve flooding the server with high-volume traffic or exploiting resource exhaustion, not sending `EXPN` commands which are low-bandwidth and designed for information retrieval. Option D is wrong because delivering spam through open relay requires the server to accept mail for arbitrary recipients via `RCPT TO`, not `EXPN`; `EXPN` only expands aliases and does not inject messages.
A security analyst wants to gather information about a target domain without sending any packets to the target. Which technique should the analyst use?
A.Ping sweep
B.WHOIS lookup
C.Netcat banner grab
D.Nmap SYN scan
AnswerB
A WHOIS lookup queries publicly accessible databases maintained by domain registrars and regional internet registries (RIRs) to retrieve information like domain ownership, registration dates, and associated contact details. This process does not send any packets or requests directly to the target's network infrastructure or systems. Consequently, it leaves no trace on the target's logs, classifying it as a purely passive reconnaissance technique.
Why this answer
WHOIS lookup is a passive reconnaissance technique that queries public databases (e.g., RDAP or WHOIS servers) for domain registration details such as registrar, creation date, and administrative contacts. It requires no packets to be sent to the target domain's infrastructure, making it ideal for information gathering without direct interaction.
Exam trap
The trap here is that candidates confuse passive reconnaissance (no packets to the target) with active scanning techniques like ping sweeps or port scans, assuming any information gathering requires direct interaction.
How to eliminate wrong answers
Option A is wrong because a ping sweep sends ICMP Echo Request packets to multiple hosts, actively probing the target network. Option C is wrong because Netcat banner grabbing requires establishing a TCP connection to a target service (e.g., HTTP, FTP) to retrieve its banner, which involves sending packets. Option D is wrong because an Nmap SYN scan sends crafted TCP SYN packets to target ports to determine their state, actively interacting with the target.
A forensic analyst discovers that an attacker used a rootkit to hide malicious processes and files on a compromised Linux system. The rootkit also intercepts system calls to `open()` and `stat()` to return clean results. Which of the following techniques is the rootkit using to cover its tracks?
A.Steganography to conceal malicious files in image metadata
B.Token impersonation to gain administrator privileges
C.Syscall hooking to modify the return values of userland commands
D.Log manipulation by clearing entries in /var/log
AnswerC
Syscall hooking is a sophisticated technique employed by kernel-mode rootkits to achieve stealth by intercepting and modifying the behavior of system calls. When userland commands like `ls`, `ps`, or `netstat` attempt to query system information (e.g., `open()`, `read()`, `stat()`, `getdents()`), the rootkit's hook diverts these calls to its own code. It then filters out any references to its own files, processes, or network connections before returning manipulated, "clean" data to the calling application, effectively making its presence invisible to standard system utilities.
Why this answer
The rootkit intercepts system calls like `open()` and `stat()` to return clean results, which is a classic example of syscall hooking. By hooking these kernel-level functions, the rootkit can filter out any information about its own malicious files and processes, making them invisible to userland commands such as `ls`, `ps`, or `cat`. This technique operates at the kernel level, not in user space, allowing it to control what data is returned to any process that makes those syscalls.
Exam trap
The trap here is that candidates may confuse syscall hooking with log manipulation or steganography, not realizing that the question specifically describes intercepting system calls to return clean results, which is the hallmark of kernel-level rootkit hiding, not file-level or log-level concealment.
How to eliminate wrong answers
Option A is wrong because steganography hides data within other files (e.g., image metadata) but does not intercept system calls or hide running processes; it is a data concealment technique, not a rootkit hiding mechanism. Option B is wrong because token impersonation is a Windows-specific privilege escalation technique that involves duplicating access tokens, not a Linux rootkit method for hiding files or processes via syscall interception. Option D is wrong because log manipulation (clearing /var/log entries) removes evidence from log files but does not intercept system calls or hide active processes and files from commands like `ps` or `ls`; it is a post-exploitation cleanup step, not the core hiding technique described.
Which DoS attack exploits the HTTP protocol by sending partial HTTP requests to keep connections open, exhausting server resources?
A.SYN flood
B.Slowloris
C.Ping of Death
D.UDP flood
AnswerB
Slowloris opens many connections to the target web server and sends partial HTTP headers repeatedly, never completing requests. This holds sockets open, exhausting the server's connection pool and denying legitimate clients, matching the stem's partial-request, resource-exhaustion constraint.
Why this answer
Slowloris is a DoS attack that exploits HTTP by opening multiple connections to the target web server and sending partial HTTP requests (e.g., incomplete headers) while never completing them. The server keeps each connection open, waiting for the rest of the request, eventually exhausting its connection pool and denying service to legitimate users.
Exam trap
EC-Council often tests the distinction between network-layer attacks (SYN flood, UDP flood) and application-layer attacks (Slowloris), so candidates mistakenly choose SYN flood because they associate 'partial requests' with TCP handshake manipulation rather than HTTP header manipulation.
How to eliminate wrong answers
Option A is wrong because SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting the server's half-open connection backlog, not HTTP protocol behavior. Option C is wrong because Ping of Death crashes a system by sending an oversized ICMP packet that exceeds the maximum IP packet size, causing buffer overflow, not HTTP connection exhaustion. Option D is wrong because UDP flood overwhelms a target with a high volume of UDP packets to random ports, consuming bandwidth and processing resources, not HTTP connections.
During a penetration test, a security analyst discovers that a web application uses sequential numeric identifiers in URLs (e.g., /profile?id=100). By modifying the id parameter, the analyst can access another user's profile data without authorization. Which vulnerability is being exploited?
A.SQL injection
B.Insecure Direct Object Reference (IDOR)
C.Server-Side Request Forgery (SSRF)
D.Cross-Site Request Forgery (CSRF)
AnswerB
Insecure Direct Object Reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, directory, or database record, and fails to implement sufficient authorization checks. By manipulating parameters like 'id' in a URL or API request, an attacker can bypass authorization and access resources belonging to other users or system components. This direct manipulation of object identifiers to gain unauthorized access perfectly describes the scenario where changing an 'id' parameter reveals another user's data.
Why this answer
Insecure Direct Object Reference (IDOR) occurs when an application exposes an internal object identifier, such as a numeric id in a URL, and fails to verify that the requester is authorized to access that object. Changing the id to another user's value and retrieving their data is the classic IDOR exploitation pattern.
Exam trap
The trap is confusing IDOR with CSRF or SSRF because all involve manipulating requests, but IDOR specifically hinges on unauthorized access to an object via a client-controlled identifier.
How to eliminate wrong answers
Option A is wrong because SQL injection involves injecting SQL syntax into input to manipulate database queries, which is not what happens when simply changing an id parameter. Option C is wrong because SSRF tricks the server into making requests to internal or external resources, not accessing another user's record via an identifier. Option D is wrong because CSRF forces an authenticated user's browser to send unintended requests, whereas here the analyst directly modifies the identifier and receives unauthorized data.
A security analyst is reviewing HTTP response headers and notices the following: Set-Cookie: sessionId=abc123; SameSite=Lax. What is the primary purpose of the SameSite attribute?
A.To enforce HTTPS for cookie transmission
B.To prevent the cookie from being accessed by JavaScript
D.To ensure the cookie is only sent over HTTP and not FTP
AnswerC
The SameSite cookie attribute directly addresses Cross-Site Request Forgery (CSRF) attacks by restricting when a browser sends cookies with cross-site requests. By setting SameSite to Lax or Strict, the browser will not attach the session cookie to requests originating from a different site, effectively preventing an attacker's forged request from being authenticated by the victim's browser. This significantly reduces the risk of unauthorized actions being performed on behalf of the user without their explicit intent.
Why this answer
SameSite=Lax prevents the browser from sending the cookie in cross-site requests initiated by third-party websites, mitigating CSRF attacks.
A penetration tester captures the following output from a command: 'smb: \> ls \\192.168.1.20\C$'. The tester is able to list the contents of the C$ share without providing credentials. Which of the following is the MOST likely reason for this access?
A.The C$ share is intentionally shared with Everyone
B.The target is running a Samba server with weak permissions
C.The target has a null session vulnerability that allows access to admin shares
D.The tester is using a pass-the-hash attack
AnswerC
A null session is an unauthenticated connection to a Windows IPC$ share, primarily intended for anonymous enumeration of system information. In older Windows versions (e.g., NT, 2000, XP) or systems with specific misconfigurations, these null sessions could be exploited to gain unauthorized access to administrative shares like C$ without requiring any user credentials. This vulnerability directly explains how a penetration tester could access C$ in the absence of explicit authentication, aligning with the scenario.
Why this answer
The output shows the tester successfully listing the C$ share (a default administrative share) without providing credentials. This is a classic indicator of a null session vulnerability, where Windows allows unauthenticated access to IPC$ and, in some configurations, admin shares via SMB. The tester is leveraging the default null session to enumerate or access these shares, which is a well-known weakness in older Windows systems or misconfigured Samba servers.
Exam trap
The trap here is that candidates often confuse null session access with pass-the-hash or weak permissions, but the key clue is the absence of any credential usage in the command, which directly points to the null session vulnerability.
How to eliminate wrong answers
Option A is wrong because the C$ share is a hidden administrative share that is not shared with Everyone by default; it is only accessible to members of the Administrators group. Option B is wrong because while a Samba server with weak permissions could allow unauthorized access, the specific command accessing C$ without credentials points to a null session vulnerability, not merely weak permissions. Option D is wrong because a pass-the-hash attack requires a captured NTLM hash and is used to authenticate as a specific user, not to gain unauthenticated access to admin shares; the tester did not provide any credentials or hashes.
Which Burp Suite tool is specifically designed to automate customized attacks on web applications, such as brute-forcing login forms or fuzzing parameters?
A.Repeater
B.Proxy
C.Scanner
D.Intruder
AnswerD
Burp Intruder is specifically engineered for automating customized attacks against web applications, making it ideal for brute-forcing, fuzzing, and credential stuffing. It allows users to define specific insertion points within a request and then systematically iterate through custom payload lists, applying various attack types like Sniper, Battering Ram, Pitchfork, and Cluster Bomb. This precise control over payload generation and delivery makes it the tool of choice for automating targeted attack scenarios.
Why this answer
Burp Intruder is the tool for automating customized attacks like brute-forcing and fuzzing.
Which TWO of the following are valid methods for enumerating users on a SMTP server? (Select 2)
Select 2 answers
A.EXPN
B.MAIL FROM
C.RCPT TO
D.VRFY
E.AUTH
AnswersA, D
The SMTP EXPN (Expand) command is a valid method for enumerating users by requesting the expansion of a mailing list or alias. When a server processes an EXPN command for a known list, it typically returns the individual email addresses of all members, thereby revealing valid user accounts on the system. This direct disclosure of recipient lists makes it a powerful tool for reconnaissance during the enumeration phase.
Why this answer
EXPN (Expand) and VRFY (Verify) are SMTP commands defined in RFC 821 that allow an attacker to enumerate valid email addresses and mailing list members on a mail server. EXPN reveals the members of a mailing list, while VRFY confirms whether a specific mailbox exists. Both commands are often disabled in production to prevent user enumeration.
Exam trap
The trap here is that candidates confuse RCPT TO (which can indirectly reveal user existence through response codes) with a dedicated enumeration command, but the CEH exam specifically expects VRFY and EXPN as the two valid SMTP enumeration methods.
An attacker uses the VRFY command on an SMTP server to check the existence of email addresses. The server responds with '250 OK' for 'admin@company.com' and '550 No such user' for 'fake@company.com'. Which SMTP enumeration technique is being used?
A.EXPN enumeration
B.SMTP banner grabbing
C.RCPT TO enumeration
D.VRFY enumeration
AnswerD
The VRFY command asks the SMTP server to confirm whether a mailbox exists; replies of 250 for admin and 550 for fake reveal valid accounts. This is VRFY enumeration, distinguishing it from EXPN, RCPT TO or EHLO-based address harvesting.
Why this answer
The VRFY command is an SMTP command defined in RFC 821 that asks the server to verify whether a given email address exists. When the server responds with '250 OK' for a valid address and '550 No such user' for an invalid one, the attacker is directly using the VRFY command to enumerate valid users. This is explicitly known as VRFY enumeration.
Exam trap
The trap here is that candidates confuse VRFY with RCPT TO, but the question explicitly states the VRFY command is used, making 'VRFY enumeration' the only correct answer.
How to eliminate wrong answers
Option A is wrong because EXPN (Expand) is used to list members of a mailing list or alias, not to verify individual email addresses. Option B is wrong because SMTP banner grabbing involves reading the server's initial greeting banner to identify software/version, not sending VRFY commands. Option C is wrong because RCPT TO enumeration uses the RCPT TO command during the mail transaction to verify recipients, not the standalone VRFY command.
Which TWO of the following are password cracking techniques? (Select 2)
Select 2 answers
A.SQL injection
B.Rainbow table attack
C.Phishing
D.ARP spoofing
E.Dictionary attack
AnswersB, E
A Rainbow table attack is a precomputation technique used to reverse cryptographic hash functions, primarily for cracking passwords. It involves using large, precomputed tables that map hash values back to potential plaintext passwords, significantly reducing the time required compared to brute-force attacks. These tables store chains of hash values and their corresponding plaintext representations, allowing an attacker to quickly look up a given password hash and retrieve the original password, especially effective against unsalted hashes due to its time-memory tradeoff.
Why this answer
A rainbow table attack (B) is a password cracking technique that uses precomputed hash chains to reverse cryptographic hash functions and recover plaintext passwords quickly, trading computation time for storage space. A dictionary attack (E) is also a password cracking technique that systematically tries words from a predefined wordlist, often with mutations, against a password hash or login to guess the correct password. The other options are not password cracking techniques: SQL injection (A) is a web application injection attack that manipulates database queries, phishing (C) is a social engineering attack that tricks users into revealing credentials, and ARP spoofing (D) is a network attack that poisons ARP caches to intercept traffic.
Exam trap
The trap here is that candidates often confuse passive or indirect attacks (like phishing or ARP spoofing) with actual password cracking techniques, forgetting that cracking specifically involves recovering plaintext from hashed or encrypted representations.
An attacker calls a company's help desk, pretending to be a new employee who forgot his username and password. The attacker provides some employee details gleaned from social media and convinces the help desk to reset the password. Which social engineering technique is being used?
A.Tailgating
B.Quid pro quo
C.Baiting
D.Pretexting
AnswerD
Pretexting is the fabrication of a believable scenario or identity to manipulate the target into complying. The attacker invents a new-employee story, reinforces it with harvested employee details, and thereby convinces the help desk to reset credentials, exploiting trust in the invented pretext.
Why this answer
Pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to manipulate the target into performing an action. In this case, the attacker pretends to be a new employee, using details from social media to establish credibility, and convinces the help desk to reset credentials. This is a classic example of pretexting because the entire interaction is based on a false identity and fabricated story.
Exam trap
The trap here is confusing pretexting with baiting because both involve deception, but baiting relies on a lure (e.g., 'free movie download') while pretexting relies on a fabricated scenario (e.g., 'I am a new employee').
How to eliminate wrong answers
Option A is wrong because tailgating involves physically following an authorized person into a restricted area without proper authentication, not a phone-based impersonation. Option B is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), not simply pretending to be an employee. Option C is wrong because baiting uses a physical or digital lure (e.g., infected USB drive, free download) to trick the victim, not a fabricated identity or story.
A web application allows users to submit feedback that is stored in a database and later displayed to administrators. An attacker submits feedback containing <script>alert('stored')</script>. When an admin views the feedback page, the script executes. Which type of XSS is this?
A.Blind XSS
B.Reflected XSS
C.Stored XSS
D.DOM-based XSS
AnswerC
Stored XSS, also known as Persistent XSS, is a severe web vulnerability where a malicious script is permanently saved on the target server, typically within a database, comment section, or feedback system. When a legitimate user, such as an administrator, later retrieves and views the compromised data, their browser executes the embedded script without their knowledge. This allows the attacker to compromise user sessions, deface websites, or redirect victims, making it a highly impactful vulnerability due to its persistence and widespread potential.
Why this answer
Stored XSS occurs when malicious script is persisted on the server (e.g., in a database, comment field, or log) and later served to other users without proper output encoding. Here, the attacker's <script> payload is saved as feedback and executed when the admin views the page, which is the defining characteristic of stored (persistent) XSS. The payload executes in the admin's browser session, potentially stealing cookies or performing actions as the admin.
Exam trap
CEH often tests the confusion between stored and reflected XSS — candidates see a script tag and assume reflected, but the key differentiator is whether the payload is persisted server-side (stored) or echoed back from the immediate request (reflected).
How to eliminate wrong answers
Option A is wrong because blind XSS is a variant of stored XSS where the attacker cannot see the immediate result and the payload fires in a different application context (e.g., admin panel or log viewer) — while related, the question describes a straightforward stored scenario where the payload is stored and displayed on the same feedback page. Option B is wrong because reflected XSS requires the payload to be included in the immediate request (e.g., a URL parameter) and reflected back in the response without server-side storage; here the payload is stored in a database. Option D is wrong because DOM-based XSS occurs entirely client-side when JavaScript reads from a source like location.hash and writes to a sink like innerHTML, without server-side involvement; the question explicitly states the feedback is stored in a database and later displayed.
A penetration tester discovers that a web application includes the following code: 'include($_GET['page'] . '.php');' and the application is running on a Linux server. The tester attempts to exploit this by accessing 'index.php?page=../../etc/passwd'. What type of attack is this, and will it succeed?
A.Directory traversal; it will succeed because '../' bypasses restrictions
B.Remote File Inclusion (RFI); it will succeed because the parameter is not filtered
C.Command injection; it will succeed if the server interprets PHP code
D.Local File Inclusion (LFI); it will not succeed because the '.php' extension is appended
AnswerD
Local File Inclusion (LFI) is the correct classification for this vulnerability, as it involves an attempt to include files present on the web server's local file system. However, the crucial detail preventing immediate success is the automatic appending of the ".php" extension to the user-supplied input. This means an attempt to include a file like "/etc/passwd" would result in the application trying to include "/etc/passwd.php", which typically does not exist, thereby blocking direct access to the target file without further bypass techniques.
Why this answer
This is a Local File Inclusion (LFI) vulnerability. The appended '.php' extension prevents reading '/etc/passwd' because the file would be interpreted as '/etc/passwd.php', which does not exist.
During a penetration test, you run the following command: nmap -sV -p 80 --script http-title 192.168.1.10. The output shows that port 80 is open and the HTTP title is 'Login Portal'. Which phase of the penetration testing methodology does this activity represent?
A.Exploitation
B.Post-exploitation
C.Footprinting
D.Scanning and enumeration
AnswerD
Scanning and enumeration is the phase where an attacker actively probes target systems to identify live hosts, open ports, running services, operating system types, and potential vulnerabilities. The nmap command is a quintessential tool for this phase, as it systematically sends various types of packets to map out the network landscape and gather detailed information about network services. This active interaction provides the crucial intelligence needed to identify potential entry points for subsequent exploitation attempts.
Why this answer
The nmap command with -sV (service version detection) and --script http-title performs service fingerprinting and banner grabbing on port 80, which is a core activity of the scanning and enumeration phase. This phase follows footprinting and involves actively probing target systems to discover open ports, running services, and application details like the HTTP title 'Login Portal'. It does not involve exploiting vulnerabilities (exploitation) or maintaining access (post-exploitation), nor is it passive information gathering (footprinting).
Exam trap
EC-Council often tests the distinction between footprinting and scanning/enumeration, where candidates mistakenly classify any information-gathering activity as footprinting, but the key differentiator is whether the activity involves direct interaction with the target system (scanning) versus passive collection (footprinting).
How to eliminate wrong answers
Option A is wrong because exploitation involves actively leveraging a vulnerability to gain unauthorized access, such as using a buffer overflow or SQL injection, whereas this command only gathers information about the service. Option B is wrong because post-exploitation occurs after successful exploitation and focuses on maintaining access, privilege escalation, or data exfiltration; scanning port 80 is a pre-exploitation reconnaissance step. Option C is wrong because footprinting is the initial passive or semi-passive information gathering phase (e.g., WHOIS, DNS lookups, social engineering), while this nmap command actively sends packets to the target to enumerate services, which is scanning and enumeration.
A forensic analyst examining a compromised Linux system finds the following entry in /var/log/auth.log: `Mar 15 10:23:45 server sshd[1234]: Accepted password for root from 10.0.0.5 port 54321 ssh2`. However, the analyst also notices that /var/log/auth.log has been truncated and the /etc/ssh/sshd_config file contains `LogLevel QUIET`. Which attack phase is most likely being obscured?
A.Privilege escalation
B.Executing applications
C.Spying
D.Erasing tracks
AnswerD
Erasing tracks is a critical post-exploitation phase where an attacker attempts to remove or obscure any evidence of their presence and activities on a compromised system. This directly involves manipulating system logs, such as /var/log/auth.log or ~/.bash_history, by truncating, deleting, or modifying entries. Reducing logging levels or disabling logging services are also common techniques to prevent future actions from being recorded, thereby making forensic analysis significantly more challenging and hindering incident response efforts.
Why this answer
The presence of `LogLevel QUIET` in sshd_config suppresses all authentication log entries, and the truncation of /var/log/auth.log indicates an attempt to remove evidence of unauthorized access. Together, these actions are classic examples of erasing tracks, as the attacker is modifying logs and configuration to hide their activities from forensic analysis.
Exam trap
The trap here is that candidates may confuse log manipulation with privilege escalation or execution phases, but the CEH exam specifically tests the 'Erasing Tracks' phase (part of the System Hacking domain) where attackers modify or delete logs, alter timestamps, or disable auditing to avoid detection.
How to eliminate wrong answers
Option A is wrong because privilege escalation involves gaining higher-level permissions (e.g., via SUID exploits or kernel vulnerabilities), not manipulating SSH logging or truncating auth logs. Option B is wrong because executing applications refers to running malicious code or tools on the system, which is a separate phase after access is obtained. Option C is wrong because spying (or exfiltration) involves covertly monitoring or stealing data, whereas the evidence here points to covering up the intrusion itself, not ongoing surveillance.
During a penetration test, you capture the following output: 'HTTP/1.1 200 OK ... Set-Cookie: sessionid=abc123; path=/'. You then send a request with a modified cookie value 'sessionid=abc124' and receive a valid session. Which type of vulnerability has been exploited?
A.Cross-site scripting
B.SQL injection
C.Man-in-the-middle attack
D.Session hijacking via cookie prediction
AnswerD
Session hijacking via cookie prediction occurs when an attacker successfully guesses or calculates a valid session identifier (Session ID) that an application uses to maintain a user's authenticated state. By setting their own browser's cookie to this predicted, valid Session ID, the attacker can bypass the login process and assume the identity of the legitimate user, gaining unauthorized access to their active session. This method specifically exploits weak or predictable session ID generation algorithms.
Why this answer
The attacker successfully predicted or guessed a valid session identifier (sessionid=abc124) after observing the pattern of the original session cookie (sessionid=abc123). This is a classic session hijacking via cookie prediction attack, where weak or sequential session IDs allow an attacker to impersonate another user's session without needing to intercept traffic or inject code.
Exam trap
The trap here is that candidates may confuse session hijacking via cookie prediction with a man-in-the-middle attack, but MITM requires active interception of traffic, whereas cookie prediction relies solely on guessing or enumerating session IDs from observed patterns.
How to eliminate wrong answers
Option A is wrong because cross-site scripting (XSS) requires injecting malicious scripts into a web page viewed by another user, not simply modifying a cookie value in a direct request. Option B is wrong because SQL injection involves manipulating SQL queries through input fields to extract or modify database data, not altering session cookies. Option C is wrong because a man-in-the-middle attack requires intercepting and potentially modifying traffic between the client and server, whereas here the attacker directly sends a modified request without needing to be positioned in the communication path.
Which of the following is the BEST defense against a TCP SYN flood attack?
A.Ingress filtering
B.Intrusion detection system
C.Rate limiting
D.SYN cookies
AnswerD
SYN cookies are a robust defense mechanism against TCP SYN floods, operating by enabling a server to respond to SYN requests without allocating resources for a half-open connection immediately. Instead, the server crafts an initial sequence number (ISN) for the SYN-ACK packet that encodes information about the connection, including the client's IP, port, and the server's ISN. Only when the client responds with a valid ACK packet, using the derived sequence number, does the server then reconstruct the connection state, effectively deferring resource allocation until the three-way handshake is complete and verified. This stateless approach prevents the server's connection table from being overwhelmed.
Why this answer
SYN cookies are the best defense against TCP SYN flood attacks because they allow the server to avoid allocating resources for half-open connections until the handshake is completed. When a SYN cookie is used, the server encodes connection state information into the initial sequence number (ISN) sent in the SYN-ACK, and only commits memory upon receiving a valid ACK from the client. This prevents the exhaustion of the SYN backlog queue, which is the primary target of a SYN flood.
Exam trap
The CEH exam often tests the misconception that rate limiting or ingress filtering alone can stop a SYN flood, but the key is that SYN cookies directly prevent the resource exhaustion of the TCP backlog queue, which is the core vulnerability exploited in this attack.
How to eliminate wrong answers
Option A is wrong because ingress filtering (RFC 2827/3704) prevents IP spoofing by dropping packets with source addresses not matching the expected inbound prefix, but it does not mitigate the volume of SYN packets or protect the server's connection queue once the attack reaches it. Option B is wrong because an intrusion detection system (IDS) can only detect and alert on a SYN flood pattern, not actively prevent it from consuming server resources; it lacks the ability to modify TCP handshake behavior or queue management. Option C is wrong because rate limiting can reduce the impact of a flood by capping incoming SYN packets, but it is a blunt instrument that may drop legitimate traffic and does not address the fundamental resource exhaustion of the SYN backlog; SYN cookies provide a more granular, per-connection defense.
An analyst notices that a web application's login page returns a generic 'Invalid credentials' message regardless of whether the username is valid. This is an example of which security control?
A.Anti-CSRF token
B.Account lockout policy
C.Generic error messages
D.Rate limiting
AnswerC
Generic error messages, such as "Invalid username or password," are a crucial defense against username enumeration vulnerabilities. By providing the exact same response regardless of whether the submitted username is valid but the password is wrong, or if the username itself does not exist in the system, the application denies attackers the ability to differentiate between these two states. This ambiguity prevents an attacker from systematically testing a list of potential usernames to identify which ones are registered within the system.
Why this answer
The login page returns a generic 'Invalid credentials' message regardless of whether the username is valid. This is a deliberate security control known as generic error messages, which prevents username enumeration by not revealing whether an account exists. By using the same message for both invalid usernames and incorrect passwords, attackers cannot easily determine valid usernames, thus reducing the attack surface for brute-force or credential-stuffing attacks.
Exam trap
CEH often tests the confusion between different security controls that mitigate brute-force attacks, such as account lockout, rate limiting, and generic error messages, and candidates may incorrectly choose account lockout or rate limiting when the scenario specifically describes identical error messages for all failed logins.
How to eliminate wrong answers
Option A is wrong because anti-CSRF tokens are used to prevent cross-site request forgery attacks by ensuring that requests originate from the legitimate application, not to obscure authentication error messages. Option B is wrong because account lockout policies lock accounts after a number of failed login attempts, which is a different control that does not directly address the information leakage from error messages. Option D is wrong because rate limiting restricts the number of requests from a single source over time to mitigate brute-force attacks, but it does not control the content of error messages returned to the user.
A penetration tester is reviewing the difference between a white-box, black-box, and gray-box assessment for a client's new e-commerce platform. The client wants the most realistic simulation of an external attacker with no inside knowledge, but also wants the tester to spend time efficiently rather than performing lengthy reconnaissance. Which assessment type best matches the client's stated priorities?
A.Black-box assessment
B.White-box assessment
C.Gray-box assessment
D.Double-blind assessment
AnswerC
Gray-box testing balances realism and efficiency by giving the tester partial information, such as user-level credentials or architecture diagrams, while still requiring discovery of many attack paths. This simulates an attacker with some insider knowledge and reduces wasted reconnaissance time. It matches the client's desire for realistic external simulation without the full overhead of black-box work.
Why this answer
Gray-box testing supplies the tester with partial knowledge, such as a standard user account or network diagrams, which simulates an attacker who has some insider access while cutting down on time-consuming discovery. This matches the client's dual goal: realistic external-style testing and efficient use of the testing window. Full-knowledge and no-knowledge assessments each satisfy only one of those priorities.
Exam trap
The trap here is equating realism exclusively with black-box testing and overlooking that gray-box testing can be both realistic and time-efficient.
You are a penetration tester for a security firm. Your client, Acme Corp, has requested an external reconnaissance assessment. They have provided their primary domain 'acme.com'. You begin by performing passive footprinting using public sources. After gathering initial information, you want to identify their email servers, subdomains, and any exposed services. You also want to map their network infrastructure without directly interacting with their systems to avoid detection. Which course of action should you take next?
A.Call Acme Corp's IT help desk posing as an employee to ask about their email server configuration.
B.Use Shodan to search for Acme Corp's IP ranges and perform DNS enumeration to discover subdomains and mail servers.
C.Perform a traceroute to Acme Corp's web server to map the network path.
D.Run an Nmap scan against the entire IP range of Acme Corp to identify open ports and services.
AnswerB
Using Shodan to search for IP ranges and performing DNS enumeration are both passive reconnaissance techniques. Shodan queries publicly indexed internet-connected devices, providing information without direct interaction with the target. Similarly, DNS enumeration, when querying public DNS records (e.g., A, MX, NS records), retrieves publicly available information without sending traffic directly to the target's internal network, making it a stealthy and permissible initial step.
Why this answer
Shodan allows passive identification of exposed services, including email servers and subdomains, by querying its indexed data of internet-facing devices without sending any packets to Acme Corp's systems. DNS enumeration can then be performed passively using public DNS records (e.g., MX, NS, A records) to map subdomains and mail servers, fulfilling the requirement to avoid direct interaction and detection.
Exam trap
EC-Council often tests the distinction between passive and active reconnaissance, and the trap here is that candidates may confuse Shodan (passive) with Nmap (active), or think traceroute is passive because it's a common network diagnostic tool.
How to eliminate wrong answers
Option A is wrong because calling the help desk is active social engineering, not passive reconnaissance, and directly interacts with the client's personnel, which violates the requirement to avoid detection. Option C is wrong because traceroute sends ICMP or UDP packets that directly interact with Acme Corp's routers and firewalls, which is active probing and can be logged or trigger alerts. Option D is wrong because running an Nmap scan sends crafted packets to target systems, which is active scanning that directly interacts with Acme Corp's network and can be detected by intrusion detection systems.
A security analyst discovers a file named invoice.exe in an email attachment. Static analysis with PEiD indicates the file is packed with UPX. What is the BEST next step in analyzing this malware?
A.Execute the packed file on a production server
B.Unpack the file with UPX and then perform static analysis
C.Submit the packed file directly to VirusTotal
D.Delete the file immediately
AnswerB
UPX packing compresses and obscures the original executable, so strings and imports reveal little until the layer is removed. Unpacking restores the original code, enabling meaningful static analysis of imports, strings and PE structure before any dynamic execution is attempted.
Why this answer
B is correct because UPX-packed executables cannot be properly analyzed statically; the code is compressed and obfuscated. Unpacking with the UPX tool restores the original binary, enabling accurate static analysis of imports, strings, and structure. This step is essential before any dynamic analysis or submission to sandboxes.
Exam trap
EC-CEH often tests the misconception that static analysis can be performed on packed binaries without unpacking, or that immediate deletion or submission to VirusTotal is the best response, ignoring the need for evidence preservation and thorough analysis.
How to eliminate wrong answers
Option A is wrong because executing packed malware on a production server risks infection and lateral movement, violating containment protocols. Option C is wrong because submitting a packed file to VirusTotal may yield incomplete detection results, as many AV engines may not unpack it correctly, and it could alert threat actors if the sample is unique. Option D is wrong because deleting the file immediately destroys evidence and prevents further analysis needed for incident response and threat intelligence.
A security analyst runs 'strings malware.exe' and finds several URLs and IP addresses. The analyst then uploads the file to VirusTotal and gets a detection ratio of 5/70. What type of analysis has been performed?
A.Static analysis
B.Memory analysis
C.Reverse engineering
D.Dynamic analysis
AnswerA
Extracting printable strings from a binary without executing it is static analysis, satisfying the stem's non-execution constraint. VirusTotal scanning inspects the file's bytes and signatures rather than running it, so both techniques remain static. Dynamic analysis would require executing malware.exe in a sandbox and observing runtime behaviour such as network connections.
Why this answer
The analyst used the 'strings' command to extract readable text from the binary without executing it, and then uploaded the file to VirusTotal for signature-based scanning. Both actions examine the file's static properties (embedded strings, hash-based detection) without running the code, which defines static analysis. Dynamic analysis would require executing the malware in a sandbox to observe runtime behavior.
Exam trap
EC-CEH often tests the distinction between static and dynamic analysis by describing actions that involve file inspection (like 'strings' and VirusTotal uploads) and expecting candidates to recognize that no execution occurred, thus ruling out dynamic analysis.
How to eliminate wrong answers
Option B is wrong because memory analysis involves examining RAM dumps (e.g., using Volatility) to find artifacts of running processes, injected code, or network connections, not static file inspection. Option C is wrong because reverse engineering typically involves disassembling or decompiling the binary (e.g., with IDA Pro or Ghidra) to understand its logic, not just running 'strings' or checking VirusTotal signatures. Option D is wrong because dynamic analysis requires executing the malware in a controlled environment (sandbox) to monitor API calls, registry changes, and network traffic, which was not performed here.
During a penetration test, the tester successfully cracks a password hash using a hybrid attack. Which THREE characteristics describe a hybrid attack? (Select three.)
Select 3 answers
A.Applies mutations like appending numbers or symbols
B.Tries every possible combination of characters
C.Combines dictionary and brute-force mutations
D.Relies on precomputed hash chains
E.Uses a wordlist as a base
AnswersA, C, E
This technique involves taking words from a dictionary or wordlist and systematically modifying them using predefined rulesets. Common mutations include appending numbers (e.g., "password123"), prepending or appending special characters (e.g., "!password", "password!"), or changing case (e.g., "Password"). This method significantly expands the attack surface beyond simple dictionary words, effectively targeting users who create passwords by slightly altering common terms.
Why this answer
A hybrid attack applies mutations such as appending numbers or symbols to dictionary words, which is a core characteristic of this attack type. This technique combines the efficiency of a wordlist with the flexibility of brute-force modifications, making it effective against passwords that follow common patterns like 'password123'.
Exam trap
The trap here is that candidates often confuse hybrid attacks with pure brute-force or rainbow table attacks, failing to recognize that hybrid attacks specifically combine a wordlist with rule-based mutations.
A security analyst observes that a web application's login page responds with different HTTP status codes and response times for valid versus invalid usernames. This information leakage could be used to perform which type of authentication attack?
A.Username enumeration
B.Credential stuffing
C.Password spraying
D.Brute force attack
AnswerA
Username enumeration is an attack where an attacker attempts to discover valid usernames by observing differences in application responses (e.g., distinct error messages, varying HTTP status codes, or even subtle timing discrepancies) when submitting valid versus invalid usernames. For instance, a "User not found" message for an invalid username compared to an "Incorrect password" message for a valid one clearly indicates a username's existence, allowing an attacker to compile a list of active accounts. This technique is a critical precursor to many other credential-based attacks.
Why this answer
Username enumeration occurs when an application's responses (status codes, error messages, or timing) differ based on whether a submitted username exists. Attackers exploit this discrepancy to build a list of valid usernames before launching targeted password attacks. The scenario explicitly describes different HTTP status codes and response times for valid versus invalid usernames, which is the textbook signature of username enumeration.
Exam trap
CEH often tests the distinction between enumeration (discovering valid usernames via response differences) and password attacks (stuffing, spraying, brute force), tempting candidates to pick a password attack when the question describes information leakage.
How to eliminate wrong answers
Option B is wrong because credential stuffing uses previously breached username/password pairs against a login form; it does not rely on distinguishing valid from invalid usernames via response differences. Option C is wrong because password spraying tries a small number of common passwords across many accounts to avoid lockouts; it is a password-guessing technique, not an information-leakage attack. Option D is wrong because brute force systematically tries many passwords against a single account; while it may benefit from knowing a valid username, the described behavior (differential responses) is the enumeration vulnerability itself, not the brute-force attack.
Refer to the exhibit. A penetration tester executed the SQL injection payload and received the response shown. What is the most likely outcome of this attack?
A.The attacker extracted hashed passwords that can be cracked offline
B.The attacker successfully performed a blind SQL injection to enumerate the database structure
C.The attacker caused a denial of service by sending an invalid query
D.The attacker modified the database records to update user passwords
AnswerA
The exhibit clearly shows the successful execution of a UNION SELECT SQL injection query, resulting in the direct retrieval of sensitive user data, specifically username and corresponding password hash pairs. These extracted hashes, likely MD5 given their typical format in such vulnerabilities, are highly susceptible to offline cracking techniques like dictionary attacks or rainbow tables. Once cracked, these plaintext passwords can then be used for further unauthorized access or credential stuffing attacks against other services.
Why this answer
The response shows a successful SQL injection that returned password hashes (likely from the `password` column) in the output. This indicates the attacker exploited a vulnerable parameter to extract hashed credentials from the database, which can then be cracked offline using tools like Hashcat or John the Ripper. The presence of hash strings in the response confirms data extraction, not modification or denial of service.
Exam trap
EC-Council often tests the distinction between in-band (error-based/UNION) SQL injection, which returns data directly, and blind SQL injection, which does not return visible data; candidates mistakenly choose blind when the response clearly shows extracted values.
How to eliminate wrong answers
Option B is wrong because blind SQL injection does not return visible data in the response; it relies on true/false or time-based inferences, whereas the exhibit shows actual hash values. Option C is wrong because a denial of service would result in an error, timeout, or empty response, not a structured output containing hashes. Option D is wrong because modifying database records (e.g., UPDATE statements) would not return the existing password hashes in the response; the attacker would see confirmation of modification or no data at all.
Which THREE of the following are effective DDoS mitigation techniques?
Select 3 answers
A.IP blacklisting
B.Increasing server resources
C.Scrubbing centers
D.Rate limiting
E.Anycast routing
AnswersC, D, E
Scrubbing centers are specialized, high-capacity network infrastructures designed to filter and clean malicious traffic before it reaches the protected target. These centers ingest all incoming traffic, analyze it for known attack patterns and anomalies across various layers, and then forward only the legitimate, clean traffic to the origin server. This offloads the attack burden from the target's infrastructure, ensuring service continuity.
Why this answer
Scrubbing centers (C) are correct because they divert and filter malicious traffic through specialized cleaning appliances before forwarding only legitimate traffic to the origin, which is a core DDoS mitigation strategy. Rate limiting (D) is correct because it caps the number of requests or connections per source or service, preventing volumetric and application-layer floods from overwhelming resources. Anycast routing (E) is correct because it distributes traffic across multiple geographically dispersed nodes sharing the same IP, dispersing attack volume and enabling closer filtering and absorption.
IP blacklisting (A) is not effective as a primary DDoS mitigation because attackers spoof or rotate source IPs, making blocklists trivial to bypass. Increasing server resources (B) only raises the attack threshold temporarily and does not stop the flood, so it is not a true mitigation technique.
Exam trap
The CEH exam often tests the misconception that IP blacklisting is a viable DDoS mitigation technique, but candidates must remember that blacklisting is ineffective against distributed, spoofed-source attacks where the attacker can easily change IP addresses.
A security auditor runs SNMPwalk against a network device using the default community string 'public' and obtains extensive system information. Which THREE of the following are effective countermeasures to prevent unauthorized SNMP enumeration?
Select 3 answers
A.Disable SNMP entirely on all devices
B.Implement an access control list (ACL) limiting SNMP access to management hosts
C.Set the community string to 'private' for read-only access
D.Change the community string from 'public' to a complex string
E.Upgrade SNMP to version 3 with authentication and encryption
AnswersB, D, E
Implementing an Access Control List (ACL) on network devices or firewalls is a highly effective security measure. An ACL can be configured to permit SNMP queries only from specific, authorized IP addresses belonging to network management stations. This significantly reduces the attack surface by preventing unauthorized hosts from even attempting to enumerate device information via `snmpwalk`, thereby mitigating the risk without disabling essential monitoring capabilities.
Why this answer
Option B is correct because an ACL restricting SNMP access to specific management host IP addresses prevents unauthorized hosts from querying the SNMP agent, blocking enumeration from untrusted sources. Option D is correct because changing the default 'public' community string to a complex, non-guessable value removes the trivially known credential that allowed the auditor's SNMPwalk to succeed. Option E is correct because SNMPv3 with authentication (authNoPriv/authPriv) and encryption (priv) eliminates cleartext community-string authentication and provides cryptographic verification of users, preventing unauthorized enumeration.
Option A, while it would stop SNMP enumeration, is not an effective general countermeasure since it disables legitimate management/monitoring functionality rather than securing it. Option C is incorrect because 'private' is itself a well-known default community string and using it for read-only access still leaves the device vulnerable to trivial enumeration.
Exam trap
The CEH exam often tests the misconception that changing the community string to another well-known default like 'private' is a valid security measure, when in fact any default string is easily guessed and should be replaced with a complex, unique string.
A penetration tester uses a tool to intercept and modify HTTP/HTTPS requests in real-time between the browser and the web application. Which tool is being used?
A.SQLMap
B.Burp Suite Proxy
C.Nmap
D.Metasploit
AnswerB
Burp Suite Proxy is a core component of the Burp Suite platform, specifically engineered to sit between a web browser and a target web server. It functions as an intercepting HTTP/S proxy, allowing a penetration tester to view, modify, and replay individual requests and responses in real-time before they reach their destination. This capability is fundamental for identifying vulnerabilities by manipulating parameters, headers, and other traffic components.
Why this answer
Burp Suite Proxy is the industry-standard tool for intercepting, inspecting, and modifying HTTP/HTTPS traffic between a browser and a web application in real time. It acts as a man-in-the-middle proxy with a CA certificate installed in the browser to decrypt TLS, enabling request/response tampering during penetration tests.
Exam trap
CEH often tests the distinction between interception proxies (Burp, ZAP) and exploitation/scanner tools (SQLMap, Metasploit, Nmap) — candidates may pick SQLMap because it also targets web apps, but it does not intercept traffic.
How to eliminate wrong answers
Option A is wrong because SQLMap automates SQL injection detection and exploitation; it does not provide interactive HTTP/HTTPS interception and modification. Option C is wrong because Nmap is a network scanner for host discovery, port scanning, and service/version detection — it does not intercept application-layer traffic. Option D is wrong because Metasploit is an exploitation framework for delivering payloads and managing sessions, not a browser proxy for real-time HTTP manipulation.
Blind SQL injection extracts data without visible output or errors, relying on boolean true/false responses or deliberate time delays to infer database contents. This distinct technique satisfies the question's requirement for a recognised SQL injection category, alongside in-band and out-of-band variants.
Why this answer
Blind SQL injection (C) is a recognized SQLi type where the attacker gets no direct data in the response and instead infers information via boolean true/false queries or time delays (e.g., WAITFOR DELAY, SLEEP). In-band SQL injection (D) is the classic SQLi category where results are returned through the same channel used to inject, typically via error-based or UNION-based techniques. Out-of-band SQL injection (E) is also a valid SQLi type that uses a different channel (e.g., DNS or HTTP requests via xp_dirtree or UTL_HTTP) to exfiltrate data when in-band and blind methods are not viable.
The other options do not belong: DOM-based SQL injection (A) is not a SQLi category (DOM-based is a type of XSS), and stored SQL injection (B) is not a standard SQLi classification (stored XSS is a distinct vulnerability).
Exam trap
The trap here is that candidates often confuse 'DOM-based' (an XSS attack) with a SQL injection type, or mistakenly think 'Stored SQL injection' is a primary category, when the CEH exam strictly recognizes in-band, blind, and out-of-band as the three main types of SQL injection attacks.
Which tool would a penetration tester MOST likely use to perform ARP poisoning and conduct a man-in-the-middle attack on a local network?
A.Wireshark
B.Nmap
C.tcpdump
D.Ettercap
AnswerD
Ettercap is a comprehensive suite for man-in-the-middle (MITM) attacks on a LAN, specifically designed to intercept traffic, perform live content filtering, and establish various forms of active and passive eavesdropping. Its core functionality includes robust ARP poisoning capabilities, allowing it to redirect traffic between two hosts through the attacker's machine by sending forged ARP replies. This enables the penetration tester to intercept, modify, and inject data into network communications, making it the ideal tool for demonstrating MITM vulnerabilities.
Why this answer
Ettercap is a dedicated suite for man-in-the-middle attacks on LANs, with built-in support for ARP poisoning. It actively sends forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host, allowing interception of traffic between two hosts. This makes it the most direct and purpose-built tool for the task described.
Exam trap
EC-CEH often tests the distinction between passive monitoring tools (Wireshark, tcpdump) and active attack tools (Ettercap), leading candidates to mistakenly choose a packet sniffer when the question explicitly requires performing an active man-in-the-middle attack.
How to eliminate wrong answers
Option A is wrong because Wireshark is a passive packet analyzer that captures and inspects traffic but cannot inject or modify packets to perform ARP poisoning. Option B is wrong because Nmap is a network scanner used for host discovery and port enumeration, not for active interception or ARP cache manipulation. Option C is wrong because tcpdump is a command-line packet capture tool that, like Wireshark, passively dumps traffic and lacks the ability to send forged ARP packets to redirect flows.
A security administrator notices that the network switch is broadcasting traffic to all ports as if it were a hub. The switch logs show a sudden flood of packets with random MAC addresses. Which attack is MOST likely occurring?
A.SYN flood
B.MAC flooding
C.ARP poisoning
D.DNS amplification
AnswerB
MAC flooding overwhelms a network switch's Content Addressable Memory (CAM) table by rapidly sending frames with unique, spoofed source MAC addresses. When the CAM table, which stores MAC-to-port mappings, becomes full, the switch can no longer learn new addresses and reverts to broadcasting all incoming frames out of every port within the VLAN. This effectively transforms the switch into a hub-like device, allowing an attacker to intercept traffic intended for other hosts.
Why this answer
B is correct because MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table. By sending a flood of packets with random source MAC addresses, the attacker fills the CAM table, forcing the switch to fail-open into hub mode (broadcasting all traffic to all ports) so that the attacker can capture frames not originally destined for their port.
Exam trap
The trap here is that candidates confuse MAC flooding with ARP poisoning because both involve MAC addresses, but MAC flooding targets the switch's CAM table at Layer 2, while ARP poisoning manipulates IP-to-MAC mappings at Layer 3.
How to eliminate wrong answers
Option A is wrong because a SYN flood is a denial-of-service attack that exhausts server resources by sending many TCP SYN requests without completing the handshake; it does not cause a switch to broadcast traffic. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC with the IP of a legitimate host, redirecting traffic at Layer 3, not flooding the switch's CAM table to cause hub-like behavior. Option D is wrong because a DNS amplification attack uses open DNS resolvers to flood a victim with large DNS response traffic, overwhelming the target's bandwidth, not affecting switch forwarding behavior.
Which TWO of the following are common defense measures against wireless de-authentication attacks? (Select 2)
Select 2 answers
A.Changing the default SSID
B.Enabling 802.11w (Management Frame Protection)
C.Implementing MAC address filtering
D.Using WPA3 instead of WPA2
E.Disabling SSID broadcast
AnswersB, D
IEEE 802.11w introduces Management Frame Protection (MFP), which cryptographically protects certain 802.11 management frames, including deauthentication and disassociation frames. This protection ensures that only legitimate, authenticated devices can send these frames, preventing an attacker from spoofing a deauthentication request. By validating the source and integrity of these critical frames, 802.11w effectively mitigates deauthentication attacks.
Why this answer
Option B is correct because 802.11w (Management Frame Protection, MFP) cryptographically protects unicast and broadcast management frames, including de-authentication and disassociation frames, so spoofed de-auth frames injected by an attacker are rejected by clients and APs. Option D is correct because WPA3 mandates Management Frame Protection (MFP) as part of its certification, meaning de-authentication frames are authenticated and forged de-auth attacks are mitigated by design, unlike WPA2 where MFP is optional. Option A is not a defense against de-authentication attacks, since changing the default SSID only obscures the network name and does not protect management frames.
Option C is not effective because MAC addresses are transmitted in the clear and can be spoofed, and MAC filtering does nothing to stop forged de-auth frames. Option E is not a defense either, as hiding the SSID is trivially bypassed by monitoring client probe requests and does not authenticate management frames.
Exam trap
CEH often tests the misconception that hiding the SSID or filtering MACs provides meaningful wireless security, when in fact only cryptographic protections like 802.11w and WPA3 actually defend against frame-spoofing attacks.
A security analyst is analyzing a suspicious file and runs the command 'strings malware.exe | grep -i http'. The output shows several URLs ending with '.exe'. What does this indicate?
A.The malware may download additional payloads from remote servers
B.The malware has a keylogger component
C.The malware is a boot sector virus
D.The malware is a worm that spreads via email
AnswerA
The presence of HTTP URLs, particularly those ending with executable file extensions like .exe, is a strong indicator that the malware is designed to retrieve additional components. This behavior is characteristic of a downloader or dropper, which fetches secondary payloads from remote Command and Control (C2) servers to execute further malicious activities. Such multi-stage attacks are common, allowing the initial infection to be small and stealthy while dynamically loading more complex functionality.
Why this answer
The `strings` command extracts printable strings from a binary file, and `grep -i http` filters for HTTP-related content. The presence of URLs ending with `.exe` indicates that the malware contains embedded references to executable files hosted on remote servers, which is a common technique for downloading additional payloads or updates. This strongly suggests the malware has a downloader or dropper component that fetches further malicious code from those URLs.
Exam trap
The trap here is that candidates may assume any URL in a binary indicates a specific malware type (e.g., worm or keylogger), but the CEH exam tests the ability to infer functionality from evidence—HTTP URLs with `.exe` specifically point to remote payload download, not propagation or input capture.
How to eliminate wrong answers
Option B is wrong because the presence of HTTP URLs ending with `.exe` does not imply keylogging functionality; keyloggers typically capture keystrokes and would not necessarily contain such URLs. Option C is wrong because a boot sector virus infects the Master Boot Record (MBR) or Volume Boot Record (VBR) and would not typically contain HTTP URLs for downloading executables; its propagation is low-level and file-system independent. Option D is wrong because while a worm may spread via email, the output of `strings` showing HTTP URLs does not indicate email propagation mechanisms (e.g., SMTP, MAPI); worms that spread via email often contain email-related strings or scripting, not just HTTP download URLs.
In an IoT environment, a researcher finds that the firmware of a smart lock can be extracted via UART and reversed to reveal hardcoded encryption keys. Which type of vulnerability is this?
A.Insecure firmware update mechanism
B.Insufficient entropy in random number generation
C.Use of deprecated cryptographic algorithm
D.Hardcoded backdoor credentials
AnswerD
A hardcoded encryption key embedded directly into device firmware functions as a universal master key, effectively creating an intentional or unintentional backdoor. Its discovery allows any attacker to decrypt communications, authenticate as a legitimate device, or gain unauthorized control, bypassing standard security protocols. This vulnerability provides persistent, privileged access, much like a set of secret credentials known only to the firmware developer, but now exposed.
Why this answer
Hardcoded keys in firmware are a classic example of a backdoor or hardcoded credential vulnerability, allowing attackers to decrypt traffic or authenticate without proper authorization.
A penetration tester uses a tool to spoof ARP replies, redirecting traffic through the tester's machine. The tester then captures credentials from the redirected traffic. Which tool is BEST suited for this task?
A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA
Ettercap is a comprehensive suite specifically designed for man-in-the-middle (MITM) attacks, making it the correct tool for ARP poisoning. It actively injects forged ARP replies into a local area network, associating the attacker's MAC address with the IP address of a legitimate host, such as the default gateway. This redirection allows Ettercap to intercept, modify, and forward traffic between the target and the intended destination, enabling sniffing and various active attacks.
Why this answer
Ettercap is the best tool for ARP spoofing because it is specifically designed for man-in-the-middle (MITM) attacks on local networks. It actively sends forged ARP replies to poison the ARP cache of target hosts, redirecting traffic through the attacker's machine, and includes built-in packet capture and credential extraction features.
Exam trap
The trap here is that candidates confuse passive sniffing tools like Wireshark or tcpdump with active MITM tools, assuming any packet capture tool can also perform ARP spoofing.
How to eliminate wrong answers
Option B is wrong because Wireshark is a passive packet analyzer that cannot spoof ARP replies or redirect traffic; it only captures and inspects existing traffic. Option C is wrong because Nmap is a network discovery and port scanning tool that does not perform ARP spoofing or MITM traffic redirection. Option D is wrong because tcpdump is a command-line packet capture utility that lacks the ability to inject forged ARP packets or manipulate network traffic flow.
A malware analyst wants to examine a suspicious executable without executing it. The goal is to extract strings, view the PE header, and check for known signatures. Which approach is the analyst using?
A.Static analysis
B.Dynamic analysis
C.Heuristic analysis
D.Reverse engineering
AnswerA
Static analysis inspects the binary's code and structure without running it, allowing extraction of strings, PE header fields and signature matches. This directly satisfies the constraint of examining the executable without executing it, unlike dynamic or behavioural analysis.
Why this answer
Static analysis involves examining a binary without executing it. The analyst extracts strings (e.g., using `strings`), views the PE header (e.g., with `pefile` or `dumpbin`), and checks for known signatures (e.g., YARA rules or antivirus hashes). This approach is safe and preserves the original state of the file.
Exam trap
The CEH exam often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse 'reverse engineering' as a synonym for static analysis, but reverse engineering is a superset that includes both static and dynamic methods, whereas the question specifically describes non-execution inspection.
How to eliminate wrong answers
Option B is wrong because dynamic analysis requires executing the malware in a sandbox or debugger to observe runtime behavior, not static inspection. Option C is wrong because heuristic analysis uses behavioral patterns or rules to detect unknown malware, often during execution or scanning, not by directly examining the PE header or strings. Option D is wrong because reverse engineering is a broader process that may include static analysis but typically involves deeper disassembly or decompilation (e.g., with IDA Pro or Ghidra) to understand logic, not just extracting strings and checking signatures.
A penetration tester obtains a list of password hashes and uses RainbowCrack. Which statement BEST describes how RainbowCrack works?
A.It uses a dictionary attack with word mangling rules
B.It uses online password guessing against the target service
C.It uses a brute-force attack by trying all possible character combinations
D.It uses time-memory trade-off with precomputed hash chains
AnswerD
This option is correct because rainbow tables are a prime example of a time-memory trade-off technique in cryptography. They involve a significant upfront investment in computational time to precompute vast tables (requiring substantial memory storage) containing chains of hashes and their corresponding plaintext values. This extensive precomputation allows for extremely rapid lookup and cracking of captured password hashes later, as the system avoids the need to recompute every possible password combination for each target hash.
Why this answer
RainbowCrack implements a time-memory trade-off attack by precomputing hash chains for a given set of passwords and storing them in rainbow tables. When a password hash is provided, the tool looks up the hash in these tables to reverse it, avoiding the need to recompute hashes for every possible password. This makes it far faster than brute-force for cracking hashes, provided the password is covered by the precomputed chains.
Exam trap
EC-Council often tests the distinction between offline hash-cracking tools (like RainbowCrack) and online password-guessing attacks, so the trap here is confusing a precomputed table attack (time-memory trade-off) with a brute-force or dictionary attack that computes hashes in real time.
How to eliminate wrong answers
Option A is wrong because a dictionary attack with word mangling rules (e.g., using John the Ripper or Hashcat with rules) does not rely on precomputed tables; it generates candidate passwords on the fly and hashes them. Option B is wrong because RainbowCrack works offline against captured hashes, not by guessing passwords against a live service (that would be an online brute-force or password spraying attack). Option C is wrong because a brute-force attack tries all possible character combinations sequentially, which is computationally expensive and does not use the time-memory trade-off or precomputed hash chains that define RainbowCrack.
Which TWO of the following describe the state of a port when Nmap reports it as 'filtered'? (Select 2)
Select 2 answers
A.The port is closed and the target sends a RST packet
B.The port is open and a service is listening
C.A firewall is dropping the probe packets
D.A firewall is responding with ICMP unreachable errors
E.The port is open but no service is responding
AnswersC, D
When a firewall is configured to silently drop probe packets, the scanning host receives no response whatsoever within the timeout period. This lack of any acknowledgment, reset, or error message prevents Nmap from determining the true state of the port behind the firewall. Consequently, Nmap marks the port as "filtered," indicating that the probes are being intercepted or discarded by an intermediary device, making the port's actual open or closed status ambiguous.
Why this answer
Nmap reports a port as 'filtered' when it cannot determine whether the port is open or closed because probe packets are being dropped or blocked. Option C is correct because a firewall dropping probe packets (e.g., via a DROP rule in iptables or an ACL) prevents Nmap from receiving any response, leading to a 'filtered' state. Option D is correct because a firewall responding with ICMP unreachable errors (e.g., ICMP Type 3 Code 13, 'Communication Administratively Prohibited') also causes Nmap to classify the port as 'filtered', as the response indicates a filtering device is interfering.
Exam trap
The trap here is that candidates often confuse 'filtered' with 'closed' or 'open', not realizing that 'filtered' specifically indicates a firewall or filter is interfering with the probe, rather than the port's actual listening state.
A security analyst runs the following command: 'smbclient -L //192.168.1.50 -N'. What is the purpose of this command?
A.Connect to the remote host's SMB share with a null password
B.Perform a dictionary attack on SMB passwords
C.Enumerate users via SMB
D.List available SMB shares on the remote host anonymously
AnswerD
The `smbclient -L <hostname>` command is precisely used to query a remote SMB server and list all available shares, printers, and other network resources it is exporting. When executed without specifying a username or password, it defaults to attempting an anonymous or guest login, effectively listing shares without requiring authentication. This is a common reconnaissance technique to discover potential targets and map out the network's shared infrastructure.
Why this answer
The `smbclient -L` command lists the available SMB shares on a remote host. The `-N` flag suppresses the password prompt, effectively performing an anonymous (null session) enumeration of shares. This is a standard technique in the enumeration phase to discover accessible resources without authentication.
Exam trap
The trap here is confusing the `-L` (list shares) option with connecting to a share (`//server/share`), leading candidates to mistakenly think the command is attempting an anonymous login to a specific share.
How to eliminate wrong answers
Option A is wrong because `-L` lists shares, it does not connect to a specific share; connecting would use `//server/share` without `-L`. Option B is wrong because `smbclient` does not perform dictionary attacks natively; tools like `hydra` or `medusa` are used for that purpose. Option C is wrong because while SMB null sessions can enumerate users (e.g., via `enum4linux` or `rpcclient`), `smbclient -L` specifically lists shares, not users.
Which of the following is a common defense against clickjacking attacks?
A.CSRF tokens
B.Content Security Policy (CSP) with 'frame-ancestors' directive
C.SameSite cookies
D.Input validation
AnswerB
The `Content-Security-Policy` (CSP) header with the `frame-ancestors` directive explicitly defines which origins are permitted to embed the current resource in a frame, iframe, object, or embed tag. By restricting framing to 'self' or specific trusted domains (e.g., `frame-ancestors 'self'`), this policy directly prevents malicious external websites from embedding the target page. This robust defense effectively mitigates clickjacking attacks by controlling the contexts in which a page can be framed, thereby preventing UI redressing.
Why this answer
Clickjacking attacks trick users into clicking on a hidden or disguised element on a page that is embedded in a malicious frame. The Content Security Policy (CSP) directive 'frame-ancestors' is a modern and effective defense against clickjacking. It allows the server to specify which origins are permitted to embed the page in frames, providing granular control.
For example, 'frame-ancestors none' blocks all embedding, while 'frame-ancestors self' allows same-origin framing only. This directive supersedes the older X-Frame-Options header, which only supports DENY or SAMEORIGIN and is less flexible. Therefore, CSP with 'frame-ancestors' is the correct choice among the given options.
A security analyst notices that a web application uses sequential numeric IDs for user accounts (e.g., /profile?id=1001). By changing the ID to 1002, the analyst can view another user's profile. Which vulnerability is present?
A.SQL injection
B.IDOR
C.Directory traversal
D.CSRF
AnswerB
Insecure Direct Object Reference (IDOR) vulnerabilities arise when an application exposes a direct reference to an internal implementation object, such as a file, directory, or database record, without sufficient authorization checks. By simply changing a numeric ID in the URL, the security analyst is directly accessing another object that they should not be authorized to view or modify, demonstrating a clear failure in access control for that specific resource.
Why this answer
This is an IDOR (Insecure Direct Object Reference) vulnerability, where direct access to objects is not properly restricted.
An ethical hacker runs the command shown in the exhibit. Which of the following conclusions can be drawn from the output?
A.The domain has two mail exchange servers
B.The DNS server is configured to block zone transfers
C.Mail is automatically forwarded to a backup server
D.The domain has an SPF record configured
AnswerA
When a DNS lookup tool, such as `nslookup`, is used to query for Mail Exchange (MX) records, the response lists the servers designated to receive email for that domain. The presence of two distinct MX records in the output explicitly indicates that the domain has two separate mail exchange servers configured. Each record points to a specific host responsible for handling incoming mail, often with a preference value to guide delivery order.
Why this answer
The output shows two MX records for the domain, each with a preference value (10 and 20). MX records specify mail exchange servers, and the presence of two distinct entries indicates the domain has two mail exchange servers. The lower preference value (10) is the primary server, and the higher value (20) is a secondary or backup server.
Exam trap
The trap here is that candidates may assume multiple MX records imply automatic forwarding or failover, but in reality, the secondary server only receives mail if the primary is unreachable, and forwarding is a separate server-side configuration.
How to eliminate wrong answers
Option B is wrong because the output does not show any attempt to perform a zone transfer (e.g., using `dig axfr` or `nslookup -type=axfr`), nor does it include an error message or response indicating a zone transfer block; it only displays MX records. Option C is wrong because mail forwarding to a backup server is not automatically determined by the presence of multiple MX records; the backup server is explicitly configured with a higher preference value, and forwarding behavior depends on the mail server configuration, not the DNS records alone. Option D is wrong because the output shows only MX records, not TXT records; SPF records are stored in TXT records (or SPF RR type, though deprecated), and no TXT record is displayed in the output.
During a penetration test, you discover that the target organization uses a cloud-based email service. Which technique would allow you to gather employee email addresses and potentially infer internal organizational structure?
A.Perform a WHOIS lookup on the domain
B.Attempt a DNS zone transfer
C.Run an nmap scan against the mail server
D.Use Google dorking to find publicly exposed email lists
AnswerD
Google dorking involves using advanced search operators to find specific information that is publicly indexed but not easily discoverable through regular searches. By crafting precise queries, such as `site:target.com filetype:xls "email"` or `inurl:contact intitle:"staff directory" @target.com`, an attacker can uncover publicly exposed documents, spreadsheets, or web pages containing lists of employee email addresses that the organization inadvertently left accessible. This is a highly effective OSINT technique for email harvesting.
Why this answer
Google dorking (advanced search operators) can uncover publicly exposed documents, such as PDFs or spreadsheets, that contain employee email addresses. These documents are often indexed by search engines and can reveal email patterns (e.g., first.last@company.com) and departmental groupings, allowing inference of the internal organizational structure without interacting directly with the target's infrastructure.
Exam trap
The trap here is that candidates often confuse active reconnaissance techniques (like DNS zone transfer or nmap scanning) with passive information gathering, assuming they are the primary way to collect email addresses, when in fact publicly indexed documents via Google dorking are a simpler and more effective passive method.
How to eliminate wrong answers
Option A is wrong because WHOIS lookup returns domain registration details (registrant, admin contact, name servers) but not employee email addresses or organizational structure. Option B is wrong because DNS zone transfer (AXFR request) is typically disabled on modern DNS servers; even if successful, it reveals hostnames and IP addresses, not employee email addresses. Option C is wrong because an nmap scan against the mail server identifies open ports and services (e.g., SMTP, IMAP) but does not extract email addresses or organizational hierarchy.
Which of the following is a common indicator of a stored (persistent) Cross-Site Scripting (XSS) attack?
A.A script executes in the victim's browser without any server interaction
B.A script is permanently stored on the server and executed when users view a page
C.A script is executed when a user submits a form with malicious input
D.A script executes only after clicking a manipulated URL
AnswerB
Stored XSS occurs when attacker-supplied script is persisted server-side, for example in a database or comment field, and then served to every visitor viewing the affected page. That permanent server-side storage and execution on page view is the defining indicator distinguishing it from reflected XSS.
Why this answer
Stored (persistent) XSS occurs when malicious script is permanently stored on the server (e.g., in a database, comment field, or forum post) and is served to every user who views the affected page. The script executes in the victim's browser without requiring any additional interaction, as it is part of the page's HTML response from the server.
Exam trap
The trap here is that candidates confuse stored XSS with reflected XSS, mistakenly thinking that any script execution without user interaction (Option A) is stored XSS, when in fact stored XSS specifically requires the payload to be persisted on the server and served to multiple users.
How to eliminate wrong answers
Option A is wrong because it describes reflected XSS or DOM-based XSS, where the script executes without server interaction (e.g., via client-side JavaScript manipulation), but stored XSS requires the server to serve the stored payload. Option C is wrong because it describes a reflected XSS scenario where the script executes immediately upon form submission, not after being stored and later retrieved. Option D is wrong because it describes reflected XSS where the payload is in a manipulated URL and executes only after the victim clicks that link, not a persistent server-side storage.
A security analyst runs `nbtstat -A 192.168.1.50` from a Windows command prompt and receives output showing a table with names like 'WORKGROUP<00>', 'PC01<20>', and 'USER<03>'. What is the MOST likely purpose of this command?
A.Perform a reverse DNS lookup
B.Display the NetBIOS name table of the remote host
C.Test connectivity to the remote host using ICMP
D.Enumerate DNS records for the domain
AnswerB
The `nbtstat -a <IP_address>` command is precisely used to display the NetBIOS name table of a remote host identified by its IP address. This utility queries the specified remote machine directly to retrieve the NetBIOS names it has registered, including its computer name, workgroup or domain name, and any services actively listening for NetBIOS connections. This functionality directly matches the described action of querying a remote host's NetBIOS name table.
Why this answer
The `nbtstat -A` command performs a NetBIOS name table lookup against a remote host using its IP address. The output shows NetBIOS names and their associated suffixes (e.g., <00> for Workstation service, <20> for File Server service, <03> for Messenger service), which are used for NetBIOS over TCP/IP (NBT) name resolution and service discovery. This is the correct purpose because the command specifically queries the remote host's NetBIOS name table, not DNS or ICMP.
Exam trap
The trap here is that candidates confuse `nbtstat -A` with DNS-related commands or ICMP-based tools, because they see an IP address in the command and assume it is performing a reverse lookup or connectivity test, rather than recognizing it as a NetBIOS-specific enumeration technique.
How to eliminate wrong answers
Option A is wrong because `nbtstat -A` does not perform a reverse DNS lookup; reverse DNS lookups are done with `nslookup` or `dig -x` and query PTR records in DNS, not NetBIOS names. Option C is wrong because testing connectivity using ICMP is the function of the `ping` command, not `nbtstat`, which operates at the NetBIOS session layer over TCP/UDP ports 137-139. Option D is wrong because enumerating DNS records for a domain is performed with tools like `nslookup`, `dig`, or `dnsrecon`, not with `nbtstat`, which only deals with NetBIOS names and their associated IP addresses on a local network segment.
A security analyst detects a file named 'invoice.pdf.exe' in an email attachment. When the file is submitted to VirusTotal, multiple engines detect it as a Trojan. The analyst wants to perform dynamic analysis to observe its behavior. Which approach is BEST?
A.Disassemble the file using IDA Pro to understand its code
B.Run 'strings' on the file and analyze the output
C.Execute the file in a sandboxed environment and monitor system calls
D.Submit the file again to VirusTotal for a second opinion
AnswerC
Dynamic analysis requires running the malware so its behaviour can be observed. A sandbox isolates execution while capturing system calls, file and registry changes, revealing payload activity that static inspection of the double extension cannot.
Why this answer
Dynamic analysis involves executing malware in a controlled, isolated environment (sandbox) to observe its runtime behavior, such as file system changes, registry modifications, network connections, and process injections. Option C directly enables this by running the Trojan and monitoring system calls, which is the best approach to understand its actual impact and propagation methods.
Exam trap
EC-CEH often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse 'submitting to VirusTotal' (a static, signature-based check) with actual behavioral observation, or think disassembly is sufficient to understand runtime behavior.
How to eliminate wrong answers
Option A is wrong because disassembling with IDA Pro is static analysis, which does not reveal runtime behavior like network traffic or self-modifying code. Option B is wrong because running 'strings' only extracts readable text from the binary, missing encrypted, packed, or obfuscated payloads and dynamic actions. Option D is wrong because resubmitting to VirusTotal provides no new behavioral data—it only repeats signature-based detection without observing execution.
A security analyst notices a high volume of ICMP Echo Reply packets on the network. The source IPs are varied, but the destination IP is the same. Which type of attack is MOST likely occurring?
A.UDP flood
B.Ping of Death
C.Smurf attack
D.ICMP flood
AnswerC
A Smurf attack is a classic distributed denial-of-service (DDoS) attack that leverages ICMP reflection and amplification. An attacker sends ICMP Echo Request packets with a spoofed source IP address (the victim's IP) to the IP broadcast address of a large network. All active hosts on that network then respond with ICMP Echo Reply packets to the spoofed source IP, overwhelming the victim with a massive flood of replies from numerous legitimate sources. This perfectly matches the observation of a high volume of ICMP echo replies from multiple sources.
Why this answer
The Smurf attack is a distributed denial-of-service (DDoS) attack that exploits ICMP by sending a large number of ICMP Echo Request packets with a spoofed source IP (the victim's IP) to a network's broadcast address. All devices on that network then respond with ICMP Echo Reply packets to the victim, overwhelming it. The scenario describes varied source IPs (the responding devices) and a single destination IP (the victim), which is the hallmark of a Smurf attack.
Exam trap
The trap here is that candidates confuse the Smurf attack with a standard ICMP flood, but the key differentiator is the amplification effect caused by the broadcast address and the spoofed source IP, which results in many replies from varied sources to a single destination.
How to eliminate wrong answers
Option A is wrong because a UDP flood uses UDP packets, not ICMP Echo Reply packets, and typically targets random or specific ports to exhaust resources. Option B is wrong because the Ping of Death involves sending a malformed ICMP Echo Request packet that exceeds the maximum IP packet size (65535 bytes), causing a buffer overflow, not a high volume of normal-sized Echo Replies. Option D is wrong because an ICMP flood directly sends a high volume of ICMP Echo Request packets from a single or multiple sources to overwhelm the target, but the key detail here is the varied source IPs of the *replies*, not the requests, which indicates the amplification effect of a Smurf attack.
Which cloud security assessment tool is specifically designed to audit AWS environments for misconfigurations and provides a detailed report of findings?
A.ScoutSuite
B.Pacu
C.Metasploit
D.Nmap
AnswerA
ScoutSuite is an open-source multi-cloud auditing tool designed to assess the security posture of cloud environments like AWS, Azure, GCP, and Alibaba Cloud. It systematically gathers configuration data and identifies potential vulnerabilities, misconfigurations, and compliance deviations, presenting them in a comprehensive report. This tool specifically focuses on detecting issues such as overly permissive IAM policies, unencrypted storage buckets, and publicly exposed resources, making it ideal for proactive cloud security assessments.
Why this answer
ScoutSuite is an open-source tool that audits cloud environments (AWS, Azure, GCP) for security misconfigurations. It generates a comprehensive HTML report. Pacu is an exploitation framework, not an audit tool.
Which TWO of the following are effective countermeasures against SNMP enumeration attacks? (Select 2)
Select 2 answers
A.Restrict SNMP access to trusted IP addresses using ACLs
B.Disable SNMP on all devices
C.Change default community strings to strong, unique values
D.Enable SNMPv3 with default passwords
E.Use SNMPv1 with community string 'private'
AnswersA, C
ACLs limit which source addresses may query the SNMP agent, so unauthorised hosts cannot reach UDP port 161 to harvest community strings, device details or routing tables. This directly satisfies the stem's requirement to block enumeration by restricting access to trusted management stations only.
Why this answer
Option A is correct because applying ACLs to restrict SNMP access to trusted IP addresses limits who can query the SNMP agent, preventing unauthorized enumeration from untrusted hosts. Option C is correct because changing default community strings (such as 'public' and 'private') to strong, unique values removes the easily guessed credentials that attackers use to enumerate SNMP data. Option B is not the best countermeasure because disabling SNMP entirely is impractical in environments where it is needed for legitimate monitoring and management.
Option D is incorrect because enabling SNMPv3 with default passwords still leaves weak, guessable credentials that undermine SNMPv3's security features. Option E is incorrect because SNMPv1 with the community string 'private' uses a well-known default credential and lacks encryption and strong authentication, making enumeration easier.
Exam trap
Candidates often select 'Disable SNMP' (option B) as a universal solution, but the CEH exam expects recognition that SNMP is often necessary for monitoring; realistic countermeasures are restrictive ACLs and strong community strings. Also, avoid confusing 'changing community strings' alone as sufficient—ACLs are equally important.
Which TWO of the following are valid enumeration techniques used to identify user accounts on a system? (Select 2)
Select 2 answers
A.Port scanning with nmap
B.DNS zone transfer
C.SMTP VRFY command
D.SNMPwalk of the entire MIB
E.SMB enumeration using enum4linux
AnswersC, E
The SMTP VRFY (Verify) command is a legacy feature of the Simple Mail Transfer Protocol used to confirm the existence of a specific user or mailbox on an SMTP server. An attacker can issue `VRFY username` to determine if a given username is valid, typically receiving a "250 OK" response for existing users or a "550 No such user" for non-existent ones. This direct query allows for effective enumeration of valid email addresses and associated user accounts.
Why this answer
SMTP VRFY (option C) is a valid user-enumeration technique because the SMTP VRFY command asks the mail server to verify whether a given mailbox or username exists, and servers that respond with 250/251 confirm the account while 550 indicates it does not exist. SMB enumeration with enum4linux (option E) is also valid because it queries SMB/RPC services (such as SAMR and LSA) to extract usernames, groups, shares, and password policy information from Windows and Samba hosts. Port scanning with nmap (option A) only identifies open ports and services, not user accounts, so it is not an enumeration technique for accounts.
A DNS zone transfer (option B) can reveal hostnames and subdomains but does not enumerate system user accounts. SNMPwalk of the entire MIB (option D) gathers device and system information via OIDs but does not directly enumerate user accounts on the target system.
Exam trap
EC-CEH often tests the distinction between service discovery (e.g., port scanning) and actual user enumeration, leading candidates to mistakenly select nmap or DNS zone transfer as valid user enumeration techniques.
A penetration tester finds that a Linux binary has the SUID bit set and is owned by root. Which of the following does this indicate?
A.The binary is immutable and cannot be deleted
B.The binary can be executed only by the root user
C.The binary is a symbolic link to a root-owned file
D.The binary will run with root privileges when executed by any user
AnswerD
When the SUID (Set User ID) bit is set on an executable file, and that file is owned by the root user, any user who executes this binary will temporarily assume the effective user ID of the file owner. This means the program will run with root privileges for the duration of its execution, allowing it to perform actions that would normally require root access. This mechanism is crucial for system utilities that need elevated permissions to function correctly for all users.
Why this answer
When the SUID (Set User ID) bit is set on a binary owned by root, the binary executes with the effective user ID of the file owner (root), regardless of which user runs it. This allows any user to run the binary with root privileges, which is why option D is correct. The SUID bit is represented by an 's' in the owner's execute position (e.g., -rwsr-xr-x).
Exam trap
The trap here is that candidates often confuse the SUID bit with execution restrictions (option B) or file immutability (option A), but the SUID bit specifically grants privilege escalation, not access control or file protection.
How to eliminate wrong answers
Option A is wrong because the SUID bit does not make a file immutable; immutability is controlled by the 'chattr +i' command, which sets the immutable attribute (i flag) on a Linux filesystem. Option B is wrong because the SUID bit allows any user to execute the binary, not just root; execution restrictions are enforced by file permissions (e.g., 700 for owner-only execute). Option C is wrong because the SUID bit is a permission attribute on the binary itself, not a property of symbolic links; symbolic links inherit the permissions of the target file, but the SUID bit is set on the binary, not the link.
A penetration tester has obtained a low-privilege shell on a Windows Server 2019 host during an internal assessment. While enumerating local accounts, the tester notices the account 'svc_backup' is a member of the Backup Operators group. The tester wants to leverage this membership to extract the SAM database and obtain local password hashes. Which action should the tester take to accomplish this goal?
A.Extract password hashes by dumping the LSASS process memory using Task Manager and analyzing the dump with Mimikatz.
B.Use the Backup Operators privilege to copy the SAM and SYSTEM files by enabling the SeBackupPrivilege and using a tool like robocopy or diskshadow to access the files.
C.Run 'reg save HKLM\SAM C:\Temp\sam.hiv' and 'reg save HKLM\SYSTEM C:\Temp\system.hiv' directly from the low-privilege shell.
D.Use Windows Task Scheduler to create a task that runs as SYSTEM and copies the SAM and SYSTEM registry hives to a readable location.
AnswerB
Backup Operators have the SeBackupPrivilege, which allows reading files regardless of ACLs. The tester can enable this privilege and use tools like robocopy with /b or diskshadow to copy the SAM and SYSTEM hives, then extract hashes offline. This is the intended method for this scenario.
Why this answer
Backup Operators possess the SeBackupPrivilege, which permits reading any file on the system by bypassing ACL checks. By enabling this privilege and using tools like robocopy with the /b switch or diskshadow, the tester can copy the SAM and SYSTEM registry hives. These hives can then be processed offline to extract local password hashes, effectively escalating privileges or enabling lateral movement.
Exam trap
The trap here is assuming that Backup Operators can directly run reg save or access LSASS, when in fact they must specifically leverage SeBackupPrivilege to copy protected files.
Which of the following is the BEST defense against Cross-Site Request Forgery (CSRF) attacks?
A.SameSite cookies
B.Input validation
C.Output encoding
D.CSRF tokens
AnswerD
CSRF tokens are unique, unpredictable, and secret values generated by the server and embedded into forms or URLs for state-changing operations. When a user submits a request, the server verifies that the token included in the request matches the one stored in the user's session. This mechanism effectively prevents CSRF attacks because an attacker cannot forge a valid request without knowing the user's unique, session-specific token, which is not accessible to them.
Why this answer
CSRF tokens are the most robust defense against Cross-Site Request Forgery because they require the client to include a unique, unpredictable token in state-changing requests. The server validates the token, ensuring the request originated from the legitimate application. This prevents attackers from forging requests because they cannot guess or obtain the token.
Exam trap
CEH often tests the difference between CSRF and XSS defenses, tricking candidates into selecting input validation or output encoding when the question specifically asks about CSRF.
How to eliminate wrong answers
Option A is wrong because SameSite cookies are a defense-in-depth measure that can help mitigate CSRF, but they are not foolproof (e.g., they may not work on older browsers or with certain configurations) and are not the best defense. Option B is wrong because input validation does not prevent CSRF; it addresses injection attacks. Option C is wrong because output encoding prevents XSS, not CSRF.
A security team observes that a switch's MAC address table is full, and the switch has started flooding unicast traffic to all ports. Which attack has MOST likely been performed?
A.MAC flooding
B.ARP poisoning
C.MAC spoofing
D.DHCP starvation
AnswerA
MAC flooding is an attack technique that overwhelms a network switch's Content Addressable Memory (CAM) table with a massive number of unique, fake MAC address-to-port mappings. By sending numerous Ethernet frames, each with a different spoofed source MAC address, the attacker forces the CAM table to fill up completely. Once the CAM table is full, the switch can no longer store new MAC-to-port associations and reverts to acting like a hub, broadcasting all incoming traffic out of every port. This allows an attacker to capture and analyze traffic intended for other devices on the network segment.
Why this answer
MAC flooding attacks exploit the limited size of a switch's CAM (Content Addressable Memory) table. By sending thousands of frames with random source MAC addresses, the attacker fills the table to capacity. Once full, the switch enters a fail-open state and begins flooding all unknown unicast traffic out every port, effectively turning it into a hub and allowing the attacker to capture traffic not destined for them.
Exam trap
The trap here is confusing MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets host ARP caches), as both involve MAC addresses and can lead to traffic interception, but they operate at different layers and use different mechanisms.
How to eliminate wrong answers
Option B (ARP poisoning) is wrong because it manipulates the ARP cache of hosts to associate the attacker's MAC with the IP of a legitimate device, causing traffic to be redirected; it does not fill the switch's MAC address table. Option C (MAC spoofing) is wrong because it involves impersonating a legitimate device's MAC address to bypass access controls or hijack a session, not to exhaust the CAM table. Option D (DHCP starvation) is wrong because it exhausts the pool of available IP addresses from a DHCP server by sending many DHCP discover messages with fake MAC addresses, preventing legitimate clients from obtaining IPs; it does not directly cause the switch to flood unicast traffic.
A security analyst detects multiple failed authentication attempts on a cloud-based SSH server from a single IP address. The analyst implements a rule to block that IP. However, the attacks continue from different IPs. Which additional control should be implemented to reduce the attack surface?
A.Disable password authentication and use SSH key-based authentication.
B.Install fail2ban to automatically block IPs after failures.
C.Implement rate-limiting on SSH connections per IP.
D.Change the SSH port to a non-standard port.
AnswerA
SSH key-based authentication significantly enhances security against brute-force attacks by relying on cryptographic key pairs instead of guessable passwords. The private key, stored securely on the client, is mathematically linked to a public key on the server, making it virtually impossible to guess or brute-force due to its immense length and complexity. This method eliminates the vulnerability to dictionary attacks and common password cracking techniques, providing a robust defense.
Why this answer
Disabling password authentication and enforcing SSH key-based authentication eliminates the attack vector of brute-forcing passwords entirely. Since the attacker is using multiple IPs to perform credential stuffing, blocking individual IPs (as done initially) or using tools like fail2ban only treats the symptom, not the root cause. Key-based authentication uses asymmetric cryptography (RSA/ECDSA/Ed25519) and is not susceptible to online guessing attacks, thus permanently reducing the attack surface.
Exam trap
The trap here is that candidates focus on reactive IP-blocking solutions (fail2ban, rate-limiting) or obscurity (port changing) instead of recognizing that the fundamental vulnerability is the use of passwords, which must be eliminated at the protocol level.
How to eliminate wrong answers
Option B (fail2ban) is wrong because it only blocks IPs after repeated failures, but the attacker is rotating through many IPs, so each new IP can still attempt logins before being blocked. Option C (rate-limiting per IP) is wrong because it similarly assumes a single source; with distributed IPs, each IP stays under the rate limit, allowing the attack to continue. Option D (changing the SSH port) is wrong because it only obscures the service via security through obscurity; an attacker scanning all ports will quickly discover the new port, and the password-based authentication remains vulnerable.
Which of the following is a form of social engineering where an attacker physically follows an authorized person into a restricted area without proper authentication?
A.Pretexting
B.Baiting
C.Tailgating
D.Quid pro quo
AnswerC
Tailgating exploits physical proximity and social trust: the attacker walks through a secured door immediately behind an authenticated employee, bypassing badge checks entirely. This matches the stem's physical-following constraint, unlike phishing or pretexting, which rely on remote deception.
Why this answer
Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area, bypassing authentication mechanisms such as badge readers, PIN pads, or biometric scanners. The attacker exploits the natural courtesy of the authorized person holding the door open, thereby gaining physical access without any credential validation.
Exam trap
EC-Council often tests tailgating by contrasting it with pretexting or baiting, so the trap is confusing physical access attacks (tailgating) with psychological manipulation attacks (pretexting, baiting, quid pro quo) that do not require physical proximity.
How to eliminate wrong answers
Option A is wrong because pretexting involves fabricating a scenario or identity (e.g., impersonating IT support) to trick a target into divulging information, not physically following someone into a restricted area. Option B is wrong because baiting relies on offering something enticing (e.g., a malware-infected USB drive left in a parking lot) to lure a victim into performing an action, not physical proximity or door access. Option D is wrong because quid pro quo involves an attacker offering a service or benefit (e.g., 'free tech support') in exchange for sensitive information or access, not physically trailing an authorized person.
A penetration tester needs to discover live hosts on a target subnet but must avoid sending any TCP packets, because the client's IDS only alerts on TCP-based probes. The tester decides to use Nmap with a host-discovery technique that relies on ICMP echo requests. Which Nmap option should the tester use?
A.nmap -sn -PS 192.168.10.0/24
B.nmap -sn -PU 192.168.10.0/24
C.nmap -sn -PA 192.168.10.0/24
D.nmap -sn -PE 192.168.10.0/24
AnswerD
The -PE option enables ICMP echo request discovery, which sends only ICMP packets and no TCP segments, satisfying the requirement to avoid TCP-based probes. Combined with -sn, Nmap performs host discovery without port scanning, identifying live hosts on the subnet purely through ICMP replies and ARP for local targets, which keeps the traffic consistent with the IDS constraint.
Why this answer
ICMP echo request discovery is enabled with the -PE option in Nmap. When combined with -sn, it performs host discovery without port scanning, sending only ICMP packets. This satisfies the scenario's constraint of avoiding TCP probes that would trigger the client's IDS, while still identifying live hosts on the subnet through ICMP replies.
Exam trap
The trap here is assuming that any -sn command avoids TCP traffic, when in fact the default host-discovery behavior and several -P options (PS, PA) still send TCP packets that would trigger the IDS.
During a penetration test, you run the tool 'macof' against a switch. After a few seconds, the switch starts flooding frames out all ports. Which attack have you successfully executed, and what is the primary goal of this technique?
A.MAC flooding; to cause a switch to fail-open and act like a hub for sniffing
B.VLAN hopping; to gain access to a different VLAN
C.STP manipulation; to create a loop and cause a DoS
D.ARP poisoning; to intercept traffic between two hosts
AnswerA
macof floods the switch's CAM table with spoofed source MACs, exhausting its capacity. The switch then fails open, flooding frames out every port like a hub, letting the attacker sniff traffic that would normally be unicast to specific ports.
Why this answer
The 'macof' tool is specifically designed to perform MAC flooding attacks by generating frames with random source MAC addresses. This overwhelms the switch's Content Addressable Memory (CAM) table, causing it to fail-open and flood all incoming frames out every port, effectively making it behave like a hub. This allows the attacker to sniff network traffic that would normally be isolated to specific switch ports.
Exam trap
The common trap is confusing MAC flooding with ARP poisoning; MAC flooding overloads the switch's CAM table, while ARP poisons the host's ARP cache.
How to eliminate wrong answers
Option B is wrong because VLAN hopping exploits switch tagging protocols (e.g., DTP or double-tagging) to access another VLAN, not by flooding MAC addresses. Option C is wrong because STP manipulation targets the Spanning Tree Protocol to create loops or reroute traffic, typically using BPDU attacks, not by exhausting CAM tables. Option D is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC with a legitimate IP address, enabling man-in-the-middle attacks, not by flooding random MACs to cause switch fail-open.
Which TWO of the following are examples of session hijacking attacks? (Select 2)
Select 2 answers
A.DNS spoofing
B.Cookie theft
C.MAC flooding
D.TCP sequence prediction
E.ARP poisoning
AnswersB, D
Cookie theft hijacks an established session by stealing the session identifier, letting the attacker replay it to impersonate the victim without re-authenticating. This directly satisfies the session-hijacking criterion, since the attacker takes over an already-authenticated session rather than cracking credentials.
Why this answer
Cookie theft (B) is a session hijacking attack because an attacker who steals a valid session cookie (e.g., via XSS or sniffing an unencrypted HTTP session) can replay it to impersonate the victim and take over the authenticated session. TCP sequence prediction (D) is also session hijacking: by predicting the ISN (initial sequence number) of a TCP connection, an attacker can inject spoofed packets and desynchronize or take over an established session. DNS spoofing (A), MAC flooding (C), and ARP poisoning (E) are supporting or denial-of-service attacks — DNS spoofing redirects name resolution, MAC flooding overflows a switch's CAM table, and ARP poisoning enables MITM traffic interception — but none of them by themselves constitute session hijacking.
Exam trap
The trap here is that candidates confuse network-level attacks (like ARP poisoning or DNS spoofing) with session hijacking, but the CEH exam specifically defines session hijacking as the takeover of an authenticated TCP or application-layer session, which requires either stealing a session token (cookie theft) or predicting TCP sequence numbers.
Which tool can be used to perform ARP poisoning to intercept traffic between a victim and the default gateway?
A.Wireshark
B.Ettercap
C.tcpdump
D.Nmap
AnswerB
Ettercap is a versatile and robust suite of tools specifically engineered for Man-in-the-Middle (MITM) attacks on local area networks. It excels at ARP poisoning by sending forged ARP replies to both the target host and the default gateway, effectively tricking them into routing traffic through the attacker's machine. This redirection allows for sniffing, content filtering, and other active manipulations of network communications.
Why this answer
Ettercap is a dedicated man-in-the-middle (MITM) attack tool that natively supports ARP poisoning. It sends forged ARP replies to both the victim and the default gateway, mapping the attacker's MAC address to the IP addresses of the other party. This allows the attacker to intercept, inspect, and modify traffic between the victim and the gateway.
Exam trap
The trap here is that candidates confuse passive sniffing tools (Wireshark, tcpdump) with active MITM tools, assuming any tool that can capture traffic can also perform ARP poisoning.
How to eliminate wrong answers
Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects packets passively; it cannot send forged ARP packets to poison a victim's ARP cache. Option C is wrong because tcpdump is a command-line packet capture tool that only dumps traffic on a network interface; it has no capability to inject or manipulate ARP replies. Option D is wrong because Nmap is a network discovery and security scanning tool used for port scanning and OS detection; it does not include ARP spoofing functionality.
A penetration tester finds that a web application includes files based on user input without proper validation. The tester supplies 'http://attacker.com/malicious.txt' and the application includes its content. Which vulnerability is this?
A.Directory traversal
B.Remote File Inclusion (RFI)
C.Local File Inclusion (LFI)
D.Server-Side Request Forgery (SSRF)
AnswerB
Remote File Inclusion (RFI) occurs when a web application dynamically includes a file from a remote server, typically specified by a URL in user-controlled input. This vulnerability allows an attacker to inject and execute malicious code hosted on their own server within the context of the vulnerable web application. The application fetches the remote file (e.g., via HTTP) and processes its content as if it were a local script, leading to potential arbitrary code execution.
Why this answer
The scenario describes a web application that includes files based on user input without proper validation, and the tester supplies a remote URL (http://attacker.com/malicious.txt) which the application then includes. This is the definition of Remote File Inclusion (RFI), where an attacker can include a file from a remote server, often leading to remote code execution. RFI is possible when the application uses user-supplied input in file inclusion functions (e.g., include, require in PHP) and allows remote URLs.
The key indicator is the inclusion of a file from an external domain, which is RFI.
Exam trap
CEH often tests the confusion between RFI and LFI, where candidates might see 'file inclusion' and pick LFI without noting that the supplied input is a remote URL, which specifically indicates RFI.
How to eliminate wrong answers
Option A is wrong because directory traversal (path traversal) involves accessing files outside the intended directory using sequences like '../', but it does not involve including remote files from external servers. Option C is wrong because Local File Inclusion (LFI) involves including files that reside on the local server, not remote ones; the tester supplied a remote URL, so it is not LFI. Option D is wrong because Server-Side Request Forgery (SSRF) involves the server making requests to internal or external resources, but it does not necessarily include the content of the file into the application's output; here, the application includes the content, which is characteristic of RFI.
During a cloud security audit, a tool reports that an AWS IAM role has a policy allowing 'ec2:RunInstances' with a condition 'aws:SourceIp': '0.0.0.0/0'. What is the most immediate risk?
A.An attacker can delete all EC2 instances
B.An attacker can launch expensive EC2 instances from any IP
C.An attacker can modify VPC security groups
D.An attacker can read data from any S3 bucket
AnswerB
The `ec2:RunInstances` action, when not constrained by specific `ec2:SourceIp` conditions or other limiting factors, allows an authenticated principal to launch new EC2 instances from any IP address. This capability includes selecting various instance types, potentially very expensive ones, leading to unauthorized resource consumption, significant cost overruns, and resource abuse for the AWS account owner.
Why this answer
The condition allows all IP addresses (0.0.0.0/0) to launch EC2 instances, meaning any user who can assume this role can create instances from anywhere, potentially for cryptocurrency mining or other malicious purposes.
Which TWO tools are commonly used for enumerating NFS exports on a target system? (Select 2 correct answers)
Select 2 answers
A.enum4linux
B.nmap (with script nfs-ls)
C.smbclient
D.showmount
E.ldapsearch
AnswersB, D
Nmap, a versatile network scanner, can be extended with its powerful Nmap Scripting Engine (NSE) to perform various enumeration tasks. The nfs-ls script, along with others like nfs-showmount and nfs-statfs, is specifically designed to interact with NFS services. It attempts to list exported directories and their permissions by querying the mount daemon (port 111) and the NFS server directly, providing detailed insights into available NFS shares.
Why this answer
Option B, nmap with the nfs-ls script, is correct because Nmap's NSE script nfs-ls queries an NFS server and lists the files and directories available through its exports, making it a valid enumeration tool for NFS. Option D, showmount, is correct because showmount -e <target> directly queries the target's mountd/rpcbind service and displays the list of exported file systems, which is the classic NFS enumeration command. The other options do not belong: enum4linux (A) and smbclient (C) target SMB/NetBIOS/Windows shares rather than NFS, and ldapsearch (E) queries LDAP directory services, not NFS exports.
Exam trap
The trap here is that candidates often confuse SMB enumeration tools (like enum4linux or smbclient) with NFS enumeration tools, because both involve file sharing, but they operate on entirely different protocols (SMB vs. NFS/RPC) and require distinct command sets.
You are an ethical hacker hired to assess the security of a mid-sized company's internal network. The company has three departments: Sales, Engineering, and HR, each on separate VLANs. The network uses a single firewall with default-deny rules, but inter-VLAN routing is allowed for specific ports (e.g., HR needs to access Sales database on TCP 1433). During reconnaissance, you discover that the Engineering VLAN has a web server running on port 80 that is accessible from all VLANs. You also find that the Sales VLAN has a file share (SMB) on port 445 that is accessible only from HR. The firewall logs show numerous failed SSH attempts from an external IP to the Engineering web server. Which action should you recommend as the most effective immediate step to reduce the attack surface?
A.Implement a password policy requiring complex passwords for all users.
B.Enable two-factor authentication on the web server.
C.Apply the latest security patches to the web server.
D.Restrict access to the Engineering web server to only the Engineering VLAN.
AnswerD
Restricting access to the Engineering web server solely to the Engineering VLAN directly implements the principle of least privilege at the network layer. This action significantly reduces the attack surface by ensuring the server is only reachable by authorized clients within its designated operational segment. By preventing unnecessary network connectivity from other VLANs, it drastically limits the opportunities for unauthorized reconnaissance and exploitation attempts, regardless of the server's internal security controls.
Why this answer
The Engineering web server is unnecessarily exposed to all VLANs, including potentially compromised segments. By restricting access to only the Engineering VLAN, you eliminate the attack surface from the Sales and HR VLANs, which is the most immediate and effective reduction in exposure. This aligns with the principle of least privilege and network segmentation, directly mitigating the risk of lateral movement from other VLANs.
Exam trap
The trap here is that candidates focus on the external SSH attacks (which are irrelevant to internal VLAN exposure) and choose patching or authentication improvements, missing that the core issue is unnecessary network-level access from other internal segments.
How to eliminate wrong answers
Option A is wrong because implementing a complex password policy does not address the immediate risk of the web server being accessible from all VLANs; it is a general security hygiene measure that does not reduce the current attack surface. Option B is wrong because enabling two-factor authentication on the web server would protect authentication but does not prevent unauthorized network-level access from other VLANs; the server remains reachable and could still be targeted by exploits or reconnaissance. Option C is wrong because applying the latest security patches, while important, does not reduce the attack surface; the server remains exposed to all VLANs, and a zero-day or unpatched vulnerability could still be exploited from any segment.
Which tool would an ethical hacker use to automatically generate a malicious USB drive that, when plugged in, executes a payload and connects back to the attacker?
A.Wireshark
B.Ettercap
C.USB Rubber Ducky
D.Metasploit
AnswerC
The USB Rubber Ducky is a specialized keystroke injection tool that emulates a standard human interface device (HID), specifically a keyboard, when plugged into a target system. This allows it to automatically and rapidly inject pre-programmed keystrokes and commands, bypassing many traditional security controls like antivirus software and firewalls. Its ability to deliver complex payloads at 'typing speed' makes it highly effective for automated USB-based attacks.
Why this answer
The USB Rubber Ducky is a keystroke injection tool that appears as a keyboard to the host computer. When plugged in, it automatically types a pre-programmed payload at high speed, which can download and execute a reverse shell or other malware, establishing a connection back to the attacker. This makes it the correct choice for automatically generating a malicious USB drive that executes a payload upon insertion.
Exam trap
The trap here is that candidates often confuse Metasploit as the tool for generating the USB drive itself, but Metasploit is used to create the payload, while the USB Rubber Ducky is the specific hardware tool that automates the injection process when the drive is plugged in.
How to eliminate wrong answers
Option A is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets, not for generating malicious USB drives or executing payloads. Option B is wrong because Ettercap is a man-in-the-middle attack tool for network sniffing and ARP poisoning, not a USB-based attack tool. Option D is wrong because Metasploit is a penetration testing framework for developing and executing exploits, but it does not automatically generate a malicious USB drive that executes a payload when plugged in; while it can create payloads, the USB Rubber Ducky is the dedicated hardware tool for keystroke injection attacks.