Courseiva

CCNA Enumeration and System Hacking Questions

29 of 179 questions · Page 3/3 · Enumeration and System Hacking · Answers revealed

151
MCQmedium

A penetration tester gains access to a Linux server and attempts to escalate privileges. They run `sudo -l` and see that the user can run `/usr/bin/vim` as root without a password. Which privilege escalation technique should the tester use?

A.Perform token impersonation using SeImpersonatePrivilege
B.Use vim's shell escape via `:!bash` to get a root shell
C.Exploit a kernel vulnerability (CVE-2023-xxxx)
D.Abuse the SUID bit on vim
AnswerB

This is the correct approach because if vim is launched with sudo privileges, even if sudo is configured to require a password, the vim process itself will be running as root. Within vim, the :!bash command allows the user to execute an arbitrary shell command. Since vim is already running as root, the spawned bash shell will inherit these root privileges, effectively granting a root shell without needing to know the root password directly.

Why this answer

The `sudo -l` output shows that the user can run `/usr/bin/vim` as root without a password. Vim has a built-in shell escape feature: from within vim, typing `:!bash` (or `:!sh`) executes a shell with the privileges of the user running vim. Since vim is run via sudo as root, the spawned shell will be a root shell, directly escalating privileges without needing additional exploits.

Exam trap

CEH exams often test the distinction between sudo-based privilege escalation and SUID-based escalation; the trap here is that candidates may incorrectly focus on the SUID bit (Option D) when the actual vector is the sudo rule allowing arbitrary command execution via vim's shell escape.

How to eliminate wrong answers

Option A is wrong because token impersonation using SeImpersonatePrivilege is a Windows-specific privilege escalation technique (e.g., JuicyPotato), not applicable to Linux. Option C is wrong because exploiting a kernel vulnerability (CVE-2023-xxxx) is unnecessary when a simple sudo misconfiguration already grants root access; it is overkill and risks system instability. Option D is wrong because the SUID bit on vim is not relevant here; the user already has sudo permission to run vim as root, so the escalation vector is the sudo rule, not the SUID bit.

152
MCQhard

During a penetration test, the tester runs `enum4linux -U 192.168.1.20` and obtains a list of usernames. What service is being enumerated, and what is the primary risk associated with this information disclosure?

A.NFS; it can lead to unauthorized file access
B.SNMP; it can reveal community strings
C.SMB; it can facilitate password spraying or brute‑force attacks
D.LDAP; it can expose directory structure
AnswerC

enum4linux queries SMB (and NetBIOS) services, and the -U switch extracts account names via null or anonymous sessions. Valid usernames enable password spraying or brute-force attacks against authentication endpoints, so the disclosure directly satisfies the stem's risk requirement by narrowing the credential search space.

Why this answer

enum4linux is a tool that queries SMB (Server Message Block) services on a target, typically over TCP ports 139 or 445. The `-U` flag specifically enumerates users from the SAM database via the SMB protocol. The primary risk of obtaining a valid username list is that it enables password spraying or brute-force attacks against SMB authentication, which can lead to unauthorized access.

Exam trap

The CEH exam often tests the association between the specific enumeration tool and its corresponding service, so the trap here is confusing enum4linux with other enumeration tools like `snmpwalk` (SNMP) or `ldapsearch` (LDAP), leading candidates to pick a plausible-sounding but incorrect service.

How to eliminate wrong answers

Option A is wrong because NFS (Network File System) is enumerated with tools like `showmount` or `rpcinfo`, not enum4linux, and the risk of unauthorized file access is associated with NFS export misconfigurations, not username enumeration. Option B is wrong because SNMP (Simple Network Management Protocol) is enumerated with tools like `snmpwalk` or `onesixtyone`, and the risk of revealing community strings is unrelated to SMB username enumeration. Option D is wrong because LDAP (Lightweight Directory Access Protocol) is enumerated with tools like `ldapsearch` or `windapsearch`, and while it can expose directory structure, enum4linux does not interact with LDAP.

153
MCQeasy

A security analyst wants to enumerate NetBIOS names on a Windows network. Which built-in Windows command-line tool should they use?

A.nslookup
B.netstat
C.nbtstat
D.net view
AnswerC

`nbtstat` queries the NetBIOS name table and datagram services directly, returning local and remote NetBIOS names, their suffixes and cached entries. Its `-a`, `-A` and `-n` switches satisfy the stem's requirement to enumerate NetBIOS names on a Windows network, unlike tools that resolve DNS or inspect SMB sessions.

Why this answer

The nbtstat command is the correct built-in Windows tool for enumerating NetBIOS names because it directly queries and displays NetBIOS over TCP/IP (NetBT) statistics, name tables, and caches. NetBIOS name enumeration relies on the NBT protocol (RFC 1001/1002), and nbtstat -a or -A retrieves the remote machine's NetBIOS name table, which includes service types like file sharing, messaging, and workstation services.

Exam trap

The trap here is that candidates confuse 'net view' (which shows network shares) with NetBIOS name enumeration, but nbtstat is the specific tool for querying the NetBIOS name table and cache directly.

How to eliminate wrong answers

Option A (nslookup) is wrong because it is used for DNS queries (A, AAAA, MX, etc.) and has no capability to enumerate NetBIOS names, which operate at a different layer (NetBIOS session service over TCP/UDP 137-139). Option B (netstat) is wrong because it displays active TCP/UDP connections, listening ports, and routing tables, but it does not query or resolve NetBIOS names or name tables. Option D (net view) is wrong because while it lists shared resources on a network, it relies on the Server Message Block (SMB) protocol and does not directly enumerate the raw NetBIOS name table or cache; it is a higher-level command that uses NetBIOS indirectly but is not the tool for name enumeration.

154
MCQeasy

A security analyst wants to enumerate all users from an SMTP server. Which of the following SMTP commands can be used for user enumeration?

A.DATA
B.MAIL FROM
C.HELO
D.VRFY
AnswerD

The VRFY (Verify) command is specifically designed to query an SMTP server to determine if a particular mailbox or user exists on the system. When provided with a username or email address, the server typically responds with information indicating whether the user is valid, often including their full name or a success code. This direct validation capability makes VRFY a highly effective tool for enumerating valid user accounts on an SMTP server, which is precisely what the security analyst aims to achieve.

Why this answer

The VRFY command is used in SMTP to verify whether a mailbox exists on the server. By issuing VRFY followed by a username, the server typically responds with a 250 code if the user exists or a 550 code if not, enabling user enumeration. This is a recognized technique in security assessments to discover valid email accounts.

Exam trap

The trap here is that candidates often confuse VRFY with EXPN or think that HELO or MAIL FROM can be abused for enumeration, but only VRFY directly queries the server for user existence.

How to eliminate wrong answers

Option A is wrong because DATA is used to begin the transmission of the email body content, not for user enumeration. Option B is wrong because MAIL FROM specifies the sender's address in an SMTP transaction and does not query the server for user existence. Option C is wrong because HELO initiates the SMTP session by identifying the client to the server and provides no mechanism to enumerate users.

155
MCQmedium

An attacker uses a tool that sends crafted RCPT TO commands to an SMTP server to verify email addresses. Which SMTP enumeration technique is being used?

A.AUTH
B.RCPT TO
C.EXPN
D.VRFY
AnswerB

The RCPT TO:<address@domain.com> command is a fundamental SMTP instruction used to specify an intended recipient for an email. Attackers exploit this by sending numerous RCPT TO commands with guessed email addresses to a target mail server. The server's response, such as a 250 OK for a valid address or a 550 No such user here for an invalid one, allows for systematic enumeration of active email accounts. This method is highly effective for building target lists for further attacks.

Why this answer

The RCPT TO command is used in SMTP to specify the recipient of an email. By sending crafted RCPT TO commands to an SMTP server, an attacker can observe the server's response (e.g., '250 OK' for valid addresses vs. '550 No such user' for invalid ones) to enumerate valid email addresses. This technique directly exploits the SMTP protocol's recipient verification behavior.

Exam trap

The trap here is that candidates often confuse RCPT TO with VRFY, assuming VRFY is the primary enumeration command, but in practice, VRFY is frequently disabled, making RCPT TO the more reliable and commonly tested technique in CEH scenarios.

How to eliminate wrong answers

Option A is wrong because AUTH is an SMTP command used for authentication, not for verifying email addresses; it does not reveal whether a recipient exists. Option C is wrong because EXPN is used to expand mailing lists or aliases, returning all members of a list, not to verify individual email addresses. Option D is wrong because VRFY is used to verify if a user exists on the server, but it is often disabled or restricted for security reasons, whereas RCPT TO is more commonly available and effective for enumeration.

156
Multi-Selecteasy

Which TWO tools can be used to enumerate SMB shares and users on a Windows target? (Choose two.)

Select 2 answers
A.smbclient
B.enum4linux
C.nslookup
D.snmpwalk
E.ldapsearch
AnswersA, B

smbclient is a powerful command-line utility for interacting with SMB/CIFS shares on Linux/Unix systems. It can be used to list available shares on a target host using the `-L` option, and with appropriate credentials, it can also enumerate users by attempting to connect to specific shares or by leveraging null sessions if permitted. This makes it a primary tool for SMB enumeration.

Why this answer

smbclient (A) is correct because its -L and -N options let you list SMB shares and, with -U, authenticate to enumerate shares and users on a Windows host over TCP 445/139. enum4linux (B) is correct because it wraps smbclient, rpcclient, and nmblookup to pull share lists, user lists, and group/password-policy data from SMB/RPC on Windows targets. nslookup (C) is wrong because it only queries DNS records and cannot touch SMB. snmpwalk (D) is wrong because it walks SNMP OIDs (UDP 161) and does not enumerate SMB shares or users. ldapsearch (E) is wrong because it queries LDAP directories (TCP 389/636) rather than SMB/RPC services.

Exam trap

The trap here is that candidates may confuse LDAP-based enumeration (ldapsearch) with SMB-based enumeration, or assume SNMP tools like snmpwalk can enumerate SMB shares, when in fact only tools that directly communicate over SMB/RPC (like smbclient and enum4linux) are appropriate for this task.

157
MCQhard

An attacker uses SMTP commands to verify the existence of email accounts on a mail server. Which sequence of SMTP commands is used for this purpose?

A.EHLO, AUTH, STARTTLS
B.HELO, MAIL FROM, RCPT TO, DATA
C.NOOP, QUIT, RSET
D.VRFY, EXPN, RCPT TO
AnswerD

VRFY, EXPN, and RCPT TO are effective SMTP commands for enumerating valid user accounts and aliases on a mail server. VRFY (Verify) explicitly requests the server to confirm if a specified user or mailbox exists, often returning a 250 OK response for valid users or a 550 error for non-existent ones. EXPN (Expand) requests the server to expand a mailing list or alias, revealing the individual members or addresses it contains. RCPT TO, even without a subsequent DATA command, can be used to test for recipient validity by observing the server's response code (e.g., 250 OK vs. 550 User unknown).

Why this answer

The VRFY command asks the mail server to verify whether a given email address exists, EXPN expands a mailing list to reveal individual addresses, and RCPT TO (used in the SMTP transaction) can also be used to check address validity by observing the server's response. Together, these commands allow an attacker to enumerate valid email accounts on the server.

Exam trap

The trap here is that candidates often confuse the standard SMTP mail-sending sequence (HELO, MAIL FROM, RCPT TO, DATA) with the enumeration-specific commands, forgetting that VRFY and EXPN are explicitly designed for address verification.

How to eliminate wrong answers

Option A is wrong because EHLO, AUTH, and STARTTLS are used for SMTP session initiation, authentication, and encryption negotiation, not for verifying email account existence. Option B is wrong because HELO, MAIL FROM, RCPT TO, and DATA are the standard sequence for sending an email message, not specifically for enumeration, though RCPT TO can be abused for enumeration it is not the primary sequence. Option C is wrong because NOOP is a no-operation command, QUIT ends the session, and RSET resets the session; none of these commands verify email account existence.

158
Multi-Selecthard

Which THREE of the following are valid techniques for covering tracks after compromising a system? (Select 3 correct answers)

Select 3 answers
A.Clearing event logs using wevtutil
B.Exploiting SUID binaries to gain root
C.Installing a rootkit to hide malicious processes
D.Using timestomp to modify file timestamps
E.Disabling Windows Defender via Group Policy
AnswersA, C, D

Clearing event logs using `wevtutil` is a direct method of covering tracks by eliminating forensic evidence. The `wevtutil` command-line utility allows an attacker to clear specific Windows Event Logs, such as Security, System, or Application logs, which record system activities, security events, and application errors. By removing these logs, an attacker can erase records of their login attempts, command executions, file accesses, and other malicious actions, significantly hindering incident response and forensic investigations.

Why this answer

A is correct because wevtutil is a Windows command-line utility used to manage event logs. After compromising a system, an attacker can use 'wevtutil cl' followed by a log name (e.g., 'wevtutil cl System') to clear specific event logs, thereby erasing evidence of their activities. This is a direct and common technique for covering tracks by removing forensic artifacts.

Exam trap

EC-Council often tests the distinction between privilege escalation (gaining higher access) and covering tracks (hiding evidence), causing candidates to mistakenly select SUID exploitation as a track-covering technique.

159
Multi-Selecteasy

Which TWO of the following are enumeration techniques?

Select 2 answers
A.Buffer overflow
B.Cross-site scripting
C.LDAP enumeration
D.SQL injection
E.SMTP enumeration
AnswersC, E

LDAP enumeration is a technique used to query Lightweight Directory Access Protocol (LDAP) services to extract detailed information about an organization's directory structure. This process can reveal valid usernames, group memberships, organizational units, and even password policies by sending specific queries to the LDAP server. Attackers leverage this information to map out the internal network, identify potential targets for credential stuffing, or understand the hierarchy for privilege escalation attempts. It is a critical step in gathering intelligence about user and system resources.

Why this answer

LDAP enumeration (C) is a valid enumeration technique because it queries directory services on port 389 (or 636 for LDAPS) to extract information such as user accounts, group memberships, and organizational structure via anonymous or authenticated binds. SMTP enumeration (E) is also a valid enumeration technique, using commands like VRFY, EXPN, and RCPT TO to discover valid email addresses and usernames on a mail server. Both techniques focus on gathering information about a target rather than exploiting it.

In contrast, buffer overflow (A), cross-site scripting (B), and SQL injection (D) are exploitation or attack techniques that compromise or manipulate a system, not enumeration methods.

Exam trap

EC-Council often tests the distinction between enumeration (passive or active information gathering) and exploitation (active attacks that compromise systems), so candidates mistakenly classify buffer overflow, XSS, or SQL injection as enumeration techniques when they are actually attack vectors.

160
MCQmedium

After compromising a system, an attacker wants to erase their tracks. They clear the Windows Event Logs using `wevtutil cl` commands. However, the logs are forwarded to a remote SIEM. Which covering tracks technique would be MOST effective to avoid detection?

A.Modify specific event log entries to remove evidence of their actions
B.Disable Windows Event Log service (EventLog)
C.Use a rootkit to hide files and processes
D.Encrypt the log files
AnswerA

Modifying specific event log entries is the most sophisticated method for post-compromise evidence removal, as it allows for targeted deletion. Attackers employ specialized tools to parse event logs, identify incriminating entries related to their activities—such as failed logins, privilege escalation, or command execution—and then selectively delete or alter these records. This technique maintains the appearance of normal system operation by leaving benign log data intact, making detection by SIEMs or forensic analysts significantly more challenging than simply clearing all logs.

Why this answer

Modifying specific event log entries directly removes the incriminating evidence without disrupting the logging pipeline. Since logs are forwarded to a remote SIEM, simply clearing or disabling local logs would trigger an alert due to a gap in log forwarding. By surgically editing only the relevant entries (e.g., using PowerShell or API calls to alter Event Log records), the attacker avoids detection while the SIEM continues to receive logs, maintaining the appearance of normal operation.

Exam trap

The trap here is that candidates often assume clearing logs (wevtutil cl) is sufficient, but the question explicitly states logs are forwarded to a remote SIEM, making any disruption to the log stream (disabling, encrypting, or clearing) a red flag, whereas targeted modification of entries is stealthier and avoids breaking the forwarding pipeline.

How to eliminate wrong answers

Option B is wrong because disabling the Windows Event Log service (EventLog) would stop all log generation and forwarding, causing the SIEM to immediately detect a missing heartbeat or log gap, which is a strong indicator of compromise. Option C is wrong because a rootkit hides files and processes but does not alter or remove existing event log entries; the incriminating log data would still be present and forwarded to the SIEM. Option D is wrong because encrypting the log files would render them unreadable locally and likely break the forwarding pipeline, again creating a detectable anomaly in the SIEM's log stream.

161
Multi-Selecthard

Which THREE of the following are methods for covering tracks after compromising a system? (Select 3)

Select 3 answers
A.Installing a rootkit to hide files and processes
B.Escalating privileges to SYSTEM
C.Disabling antivirus software
D.Using steganography to hide stolen data in images
E.Clearing event logs
AnswersA, D, E

Installing a rootkit is a sophisticated method for covering tracks, as a rootkit is a collection of tools designed to obtain and maintain privileged access to a computer while actively hiding its presence. By modifying core operating system components, rootkits can conceal malicious files, running processes, network connections, and even user accounts from standard system utilities and security software. This makes it extremely difficult for forensic investigators to detect the attacker's activities and persistence mechanisms, effectively covering their tracks post-compromise.

Why this answer

Installing a rootkit is a classic method for covering tracks because it operates at the kernel or user level to intercept system calls (e.g., NtQuerySystemInformation on Windows) and hide malicious files, processes, registry keys, and network connections from standard enumeration tools like Task Manager or netstat. This prevents the victim from detecting the compromise during routine monitoring.

Exam trap

EC-CEH often tests the distinction between actions taken during the attack (privilege escalation, disabling AV) and actions taken after the attack to erase evidence (clearing logs, hiding files with rootkits, steganography), so candidates mistakenly select privilege escalation or AV disabling as track-covering methods.

162
Multi-Selecteasy

A penetration tester successfully gains access to a Linux server as a low-privilege user. The goal is to escalate to root. Which THREE methods could the tester use to achieve privilege escalation?

Select 3 answers
A.Enumerate SUID binaries with 'find / -perm -4000'
B.Exploit a vulnerable SUID binary to spawn a root shell
C.Use 'sudo -l' to list allowed commands and exploit misconfigurations
D.Check /etc/shadow for weak password hashes
E.Run a local kernel exploit that matches the kernel version
AnswersB, C, E

Exploiting a vulnerable SUID binary is a direct and highly effective privilege escalation technique. If a program designed to run with root privileges (due to its SUID bit) contains a flaw, such as a buffer overflow, path injection, or insecure file handling, an attacker can manipulate it to execute arbitrary code. This allows the attacker to spawn a shell with root permissions, effectively gaining full control over the system.

Why this answer

Option B is correct because a SUID binary executes with the file owner's privileges (typically root), so exploiting a vulnerable SUID program (e.g., via GTFOBins techniques or buffer overflow) can yield a root shell. Option C is correct because 'sudo -l' reveals the sudoers permissions for the current user, and misconfigurations such as NOPASSWD entries or allowed binaries like vim, find, or less can be abused to spawn a root shell. Option E is correct because a local kernel exploit matching the exact kernel version (verified with 'uname -r') can leverage a known vulnerability such as Dirty COW (CVE-2016-5195) or PwnKit to escalate to root.

Option A is not a privilege escalation method by itself; 'find / -perm -4000' is only an enumeration step that identifies SUID binaries, which must then be exploited as in option B. Option D does not belong because /etc/shadow is normally readable only by root, so a low-privilege user cannot read the hashes; even if obtained, cracking them yields credentials rather than a direct escalation path.

Exam trap

The trap here is that candidates mistake enumeration commands (like 'find / -perm -4000') for actual exploitation methods, or they assume /etc/shadow is accessible to low-privilege users without realizing it is root-protected.

163
MCQeasy

A security analyst runs the command `nbtstat -A 192.168.1.105` on a Windows machine. What information is the analyst most likely trying to gather?

A.The NetBIOS name table and MAC address of the remote host
B.The LDAP directory structure of the domain
C.The SNMP community strings of the target
D.The SMB shares available on the remote host
AnswerA

The `nbtstat -a` (or `-A`) command is specifically designed to display the NetBIOS name table of a remote computer, identified by its IP address. This table includes registered NetBIOS names, their types, and crucially, the MAC address associated with the network interface. It provides valuable information for identifying systems and services relying on NetBIOS over TCP/IP, making it a direct and effective reconnaissance tool for this protocol.

Why this answer

The `nbtstat -A` command performs a NetBIOS name table lookup against the specified IP address using the NetBIOS over TCP/IP (NBT) protocol. It returns the remote host's NetBIOS name table, which includes registered names and services, along with the MAC address of the network adapter. This is a standard enumeration technique to identify the hostname, logged-in user, and other NetBIOS-related information.

Exam trap

The trap here is that candidates confuse `nbtstat -A` with `net view` or `nbtstat -a`, mistakenly thinking it lists SMB shares or uses a hostname instead of an IP address, when in fact `-A` specifically targets a remote IP and returns the NetBIOS name table and MAC.

How to eliminate wrong answers

Option B is wrong because LDAP directory structure is queried using LDAP-specific tools like `ldapsearch` or `nslookup` with SRV records, not `nbtstat`. Option C is wrong because SNMP community strings are obtained via SNMP enumeration tools like `snmpwalk` or `snmpenum`, not through NetBIOS commands. Option D is wrong because SMB shares are enumerated using commands like `net view` or tools like `smbclient`, while `nbtstat` only reveals NetBIOS names and MAC addresses, not share listings.

164
Multi-Selecthard

Which TWO of the following are examples of hybrid password attacks? (Select 2 correct answers)

Select 2 answers
A.Using a wordlist to try every possible password in the list
B.Using a dictionary file and appending random numbers to each word
C.Using a set of rules with Hashcat to modify dictionary words (e.g., leet speak substitutions)
D.Generating all possible character combinations up to a certain length
E.Cracking passwords using precomputed rainbow tables
AnswersB, C

This is a classic example of a hybrid password attack, combining elements of a dictionary attack with a targeted brute-force component. By taking words from a dictionary file and systematically appending numerical sequences (e.g., 'password123', 'summer2024'), the attack efficiently targets common user password patterns that involve adding digits to memorable words. This method significantly expands the attack surface beyond a simple dictionary without resorting to a full, computationally expensive brute-force approach.

Why this answer

A hybrid password attack combines a dictionary or wordlist with additional modifications, such as appending random numbers to each word. This approach leverages common password patterns where users often add digits to a base word to meet complexity requirements, making it more effective than a simple dictionary attack.

Exam trap

EC-Council often tests the distinction between hybrid attacks and other attack types, and the trap here is that candidates may confuse a dictionary attack (Option A) with a hybrid attack, or mistake brute-force (Option D) or rainbow tables (Option E) as hybrid methods, when in fact hybrid attacks specifically combine a dictionary with rule-based modifications or appendages.

165
MCQeasy

Which SNMP community string is typically used for read-only access by default on many devices?

A.snmp
B.private
C.admin
D.public
AnswerD

The "public" community string is the universally recognized and default read-only community string for SNMPv1 and SNMPv2c agents. This string allows an SNMP manager to query and retrieve various operational statistics and configuration details from a network device's Management Information Base (MIB) without the ability to alter any settings. Due to its widespread default configuration, "public" is frequently targeted by attackers seeking to gather network intelligence.

Why this answer

The default read-only community string in SNMPv1 and SNMPv2c is 'public'. This string acts as a password that allows an SNMP manager to query device MIB objects for monitoring purposes without making configuration changes. It is widely documented in RFC 1157 and is the standard default across most networking equipment.

Exam trap

The trap here is that candidates often confuse 'public' with 'private', mistakenly thinking 'private' is the read-only string, when in fact 'private' is the default read-write community string.

How to eliminate wrong answers

Option A is wrong because 'snmp' is not a standard default community string; it is occasionally used as a custom string but never as a default. Option B is wrong because 'private' is the default read-write community string, granting write access to modify device configurations, not read-only. Option C is wrong because 'admin' is a common administrative username, not an SNMP community string; SNMP community strings are separate from device login credentials.

166
MCQhard

After gaining initial access to a Linux server, a penetration tester wants to maintain persistence by creating a backdoor. The tester decides to replace a common system binary with a trojanized version. Which of the following techniques is MOST likely to evade detection by file integrity monitoring (FIM) systems?

A.Replace the binary with a modified version that has the same file size and timestamp
B.Place the backdoor in a directory that is excluded from FIM monitoring
C.Use steganography to hide the backdoor inside an image file
D.Use a kernel-level rootkit that intercepts read operations to present the original binary's content
AnswerD

A kernel-level rootkit operates within the operating system's kernel, granting it the highest level of privilege and control. By hooking system calls, specifically `read()` operations, the rootkit can intercept requests from the FIM agent to read the compromised binary. Instead of returning the modified, malicious content, the rootkit presents the *original*, untampered content of the binary to the FIM system. This sophisticated deception ensures that the FIM system calculates the expected hash, thus reporting no integrity violation, while the malicious binary continues to execute its payload.

Why this answer

A kernel-level rootkit can intercept system calls (e.g., open, read) used by FIM tools to verify file integrity. When the FIM queries the trojanized binary, the rootkit returns the original, unmodified content, so the hash or checksum matches the baseline. This subverts detection at the kernel layer, bypassing user-space integrity checks entirely.

Exam trap

The trap here is that candidates often choose Option A, mistakenly believing that matching file size and timestamp is sufficient to evade FIM, but FIM relies on cryptographic hashes, not metadata, to detect changes.

How to eliminate wrong answers

Option A is wrong because simply matching file size and timestamp does not prevent FIM from detecting a changed cryptographic hash (e.g., SHA-256) of the binary; FIM tools compute hashes, not just metadata. Option B is wrong because placing the backdoor in an excluded directory is not a stealthy evasion technique—it relies on misconfiguration and would be obvious during a thorough audit or if the FIM policy is reviewed. Option C is wrong because steganography hides data within an image file, but replacing a system binary with an image would break system functionality and be immediately detected by FIM as a missing or altered binary.

167
MCQmedium

A security analyst runs the command: nbtstat -A 192.168.1.10. The output shows the table of names for the remote machine. Which of the following is the MOST likely purpose of this command?

A.To perform a DNS zone transfer
B.To enumerate SNMP community strings on the remote host
C.To enumerate NetBIOS names and services on the remote host
D.To enumerate SMB shares on the remote host
AnswerC

The command `nbtstat -a 192.168.1.10` (or `-A` for adapter status) is precisely used to query the NetBIOS name table of a remote host. This query retrieves a list of NetBIOS names registered by the target machine, including the computer name, workgroup/domain name, and services like the Messenger service or File and Print Sharing, along with their associated types and status. This provides valuable information about the remote system's identity and active NetBIOS services.

Why this answer

The `nbtstat -A` command performs a NetBIOS name table lookup against a remote IP address, displaying the registered NetBIOS names and their associated service types (e.g., workstation, server, messenger). This is a core technique for NetBIOS enumeration, which reveals the remote host's computer name, logged-in user, and running NetBIOS services, making option C correct.

Exam trap

The trap here is that candidates confuse `nbtstat -A` (NetBIOS name table enumeration) with SMB share enumeration (`net view` or `smbclient`), because both are associated with Windows file sharing, but they operate at different protocol layers and serve distinct enumeration purposes.

How to eliminate wrong answers

Option A is wrong because DNS zone transfers are performed using `nslookup` or `dig` with specific zone transfer flags, not `nbtstat` which operates at the NetBIOS over TCP/IP layer. Option B is wrong because SNMP community string enumeration is done via tools like `snmpwalk` or `snmpenum` targeting UDP port 161, while `nbtstat` uses NetBIOS name service on UDP port 137. Option D is wrong because enumerating SMB shares is typically accomplished with `net view`, `smbclient`, or `enum4linux`, not `nbtstat` which only retrieves NetBIOS name tables, not share lists.

168
MCQmedium

A security analyst reviews the following command output from a Linux system: `uid=0(root) gid=0(root) groups=0(root)`. The analyst suspects a privilege escalation attack. Which of the following techniques could have been used to achieve root access from a standard user account?

A.Token impersonation
B.Pass-the-hash attack
C.LLMNR/NBT-NS poisoning
D.SUID/GUID abuse
AnswerD

SUID (Set User ID) and SGID (Set Group ID) are special permissions in Linux that allow an executable file to run with the permissions of its owner (SUID) or group (SGID), rather than the user executing it. If a program owned by root has the SUID bit set, any user executing it will temporarily gain root privileges for the duration of that program's execution. Attackers can exploit misconfigured or vulnerable SUID/SGID binaries, such as those that allow arbitrary command execution or shell escapes, to elevate their privileges to root or another privileged user.

Why this answer

The command output shows the current user has UID 0, which is the root user. On Linux, SUID (Set User ID) and GUID (Group ID) bits allow executables to run with the permissions of the file owner (e.g., root). A standard user can exploit a misconfigured SUID binary (like `passwd` or a custom script) to execute commands with root privileges, achieving privilege escalation.

This is a classic Linux privilege escalation technique directly tied to the UID/GID output shown.

Exam trap

The trap here is that candidates confuse Windows-specific attacks (token impersonation, pass-the-hash, LLMNR poisoning) with Linux privilege escalation, failing to recognize that the `uid=0` output is a direct indicator of root access achieved via SUID/GUID abuse.

How to eliminate wrong answers

Option A is wrong because token impersonation is a Windows-specific attack that involves duplicating access tokens (e.g., via SeImpersonatePrivilege) and does not apply to Linux systems. Option B is wrong because pass-the-hash is a Windows network authentication attack that reuses NTLM hashes to authenticate without knowing the plaintext password; it is not relevant to Linux local privilege escalation. Option C is wrong because LLMNR/NBT-NS poisoning is a Windows network protocol attack used to intercept authentication requests on a local network, not a technique to escalate privileges on a local Linux system.

169
MCQeasy

Which of the following is a primary purpose of the enumeration phase in a penetration test?

A.To gather in-depth information about the target system and its resources
B.To exploit identified vulnerabilities and gain access
C.To perform a vulnerability scan on the target network
D.To delete logs and cover tracks after a successful compromise
AnswerA

Enumeration is the active process of extracting detailed information from a target system or network, such as user accounts, group memberships, network shares, running services, and open ports. This granular data provides critical intelligence to identify potential attack vectors and misconfigurations, laying the groundwork for subsequent vulnerability analysis and exploitation attempts. It moves beyond simple port scanning to actively query services for specific configuration details.

Why this answer

The enumeration phase is the active process of extracting detailed information about a target system, such as user accounts, network shares, services, and system policies, using direct queries. This phase goes beyond passive reconnaissance by establishing connections to the target to gather data that can be used to identify attack vectors. In a CEH context, enumeration is specifically defined as the step where the tester collects in-depth information about the target's resources and potential entry points.

Exam trap

The trap here is that candidates often confuse enumeration with vulnerability scanning, but enumeration focuses on gathering system-specific information (like user accounts and shares) rather than scanning for known vulnerabilities.

How to eliminate wrong answers

Option B is wrong because exploiting vulnerabilities and gaining access is the purpose of the exploitation phase, not enumeration. Option C is wrong because performing a vulnerability scan is part of the vulnerability assessment phase, which typically occurs after enumeration and before exploitation. Option D is wrong because deleting logs and covering tracks is an activity of the post-exploitation or covering tracks phase, which occurs after a successful compromise, not during enumeration.

170
MCQmedium

A penetration tester is performing SNMP enumeration against a network device and wants to retrieve the entire Management Information Base (MIB) tree. Which command should they use?

A.snmpwalk -v 2c -c public 192.168.1.1 .1
B.snmpset -v 2c -c private 192.168.1.1 1.3.6.1.2.1.1.0 s 'test'
C.snmpbulkwalk -v 2c -c public 192.168.1.1 .1
D.snmpget -v 2c -c public 192.168.1.1 1.3.6.1.2.1.1
AnswerA

This command correctly utilizes `snmpwalk` to perform comprehensive SNMP enumeration. The `-v 2c` flag specifies the use of SNMPv2c, a widely adopted version, and `-c public` employs the common default read-only community string. Crucially, initiating the walk with `.1` as the starting Object Identifier (OID) instructs `snmpwalk` to traverse and retrieve all available information from the entire Management Information Base (MIB) tree on the target device, which is the precise objective of thorough SNMP enumeration.

Why this answer

`snmpwalk` is specifically designed to retrieve a subtree of MIB objects by performing a series of GETNEXT requests starting from a given OID. Using `.1` as the root OID (which corresponds to the entire ISO tree) with the SNMPv2c community string 'public' will enumerate all accessible OIDs in the MIB tree, effectively dumping the entire Management Information Base.

Exam trap

The trap here is that candidates often confuse `snmpbulkwalk` as the correct answer because it is faster for large MIBs, but the CEH exam expects `snmpwalk` as the standard enumeration tool, and `snmpbulkwalk` may not be supported by all SNMP agents.

How to eliminate wrong answers

Option B is wrong because `snmpset` is used to modify SNMP objects, not to retrieve them; it requires write access (community 'private') and would fail to enumerate the MIB tree. Option C is wrong because `snmpbulkwalk` is optimized for bulk retrieval but is not the standard command for a full MIB tree walk; it uses GETBULK requests which may be blocked or behave differently on some devices, and the question asks for the command to use, not the most efficient one. Option D is wrong because `snmpget` retrieves only a single OID value (1.3.6.1.2.1.1) and does not walk the tree; it would return only the system description or a single scalar object, not the entire MIB.

171
MCQmedium

During a security assessment, an analyst runs 'enum4linux -a 10.0.0.5' and obtains a list of users, shares, and OS information. What protocol is enum4linux primarily using to gather this information?

A.NetBIOS
B.SNMP
C.LDAP
D.SMB/CIFS
AnswerD

Enum4linux is a powerful enumeration tool specifically designed to interact with the Server Message Block (SMB) and Common Internet File System (CIFS) protocols. It leverages various SMB functionalities, such as querying NetBIOS name services, enumerating shares, listing users, and extracting operating system information from Windows and Samba hosts. This direct interaction with SMB/CIFS allows it to gather critical reconnaissance data for security assessments.

Why this answer

enum4linux is a wrapper around tools from the Samba suite, primarily using the SMB/CIFS protocol to query Windows systems for information such as user lists, shares, and OS details. It leverages SMB's remote IPC mechanisms (e.g., via \pipe\lsarpc or \pipe\samr) to enumerate these data points, making D the correct answer.

Exam trap

The trap here is that candidates confuse the underlying protocol (SMB/CIFS) with the transport or name-resolution layer (NetBIOS), leading them to select Option A because enum4linux historically used NetBIOS name lookups, but the core enumeration protocol is SMB/CIFS.

How to eliminate wrong answers

Option A is wrong because NetBIOS is a session-layer protocol used for name resolution and service discovery, but enum4linux relies on SMB/CIFS over TCP/445 (or NetBIOS over TCP/139) to perform its enumeration; the tool itself is not primarily a NetBIOS scanner. Option B is wrong because SNMP (Simple Network Management Protocol) uses UDP ports 161/162 and is designed for managing network devices, not for enumerating Windows user accounts or shares via SMB. Option C is wrong because LDAP (Lightweight Directory Access Protocol) operates on TCP/389 and is used for querying directory services like Active Directory, but enum4linux does not use LDAP by default; it uses SMB RPC calls to extract information.

172
MCQmedium

During a penetration test, an analyst runs the command 'snmpwalk -v2c -c public 192.168.1.10' and receives a large amount of output. Which protocol and community string are being used?

A.SNMPv1 with community string public
B.SNMPv1 with community string private
C.SNMPv2c with community string public
D.SNMPv3 with user public
AnswerC

This option is correct because the command's `-v2c` flag precisely identifies SNMP version 2c, which offers significant improvements over SNMPv1, including enhanced bulk data transfer and more detailed error messages. Concurrently, the `-c public` flag accurately specifies the community string as 'public', a widely known default often targeted by attackers for initial reconnaissance during penetration tests.

Why this answer

The command 'snmpwalk -v2c -c public 192.168.1.10' explicitly specifies SNMP version 2c with the '-v2c' flag and the community string 'public' with the '-c' flag. SNMPv2c is the most common version for read-only queries, and 'public' is the default read-only community string. The large output indicates successful enumeration of the MIB tree, confirming the community string is correct.

Exam trap

The trap here is that candidates often confuse the '-v2c' flag with SNMPv1 or assume 'public' is always read-only, but the question tests the direct mapping of command-line arguments to protocol version and community string.

How to eliminate wrong answers

Option A is wrong because the command uses '-v2c', not '-v1', so SNMPv1 is not being used. Option B is wrong because it incorrectly specifies SNMPv1 and the community string 'private', which is typically used for read-write access, not the 'public' string shown in the command. Option D is wrong because SNMPv3 does not use community strings; it uses usernames and authentication/encryption parameters, and the command does not include any SNMPv3-specific flags like '-u' or '-l'.

173
Multi-Selectmedium

Which TWO of the following tools are capable of cracking password hashes offline? (Select 2)

Select 2 answers
A.Hashcat
B.Hydra
C.John the Ripper
D.Nmap
E.Wireshark
AnswersA, C

Hashcat is an advanced offline password recovery utility renowned for its unparalleled speed, primarily achieved through extensive GPU acceleration. It supports a vast array of hash types, including NTLM, MD5, SHA-1, and bcrypt, and offers diverse attack modes such as dictionary, brute-force, mask, and hybrid attacks. This makes it exceptionally effective for cracking password hashes extracted from compromised systems or databases, enabling rapid auditing of password security.

Why this answer

Hashcat is a high-performance password recovery tool that supports offline cracking of password hashes using GPU acceleration. It can process a wide range of hash types (e.g., MD5, SHA-1, bcrypt, NTLM) by comparing precomputed or brute-force generated hashes against a target hash file, all without interacting with a live authentication server.

Exam trap

The trap here is that candidates often confuse online brute-forcing tools (like Hydra) with offline hash crackers, because both are used for password attacks, but Hydra requires a live target service and cannot process a static hash file.

174
MCQeasy

Which of the following tools is specifically used to enumerate SMB shares and retrieve file listings from Windows systems?

A.ldapsearch
B.snmpwalk
C.smbclient
D.nmap
AnswerC

smbclient is a powerful command-line utility that acts as an SMB/CIFS client, similar to a Windows file explorer. It is specifically designed to interact with SMB servers, allowing users to list available shares on a target machine using the "-L" option, connect to specific shares, and browse, upload, or download files. Its direct capability to query and display network shares makes it the most appropriate tool for SMB enumeration.

Why this answer

smbclient is a tool from the Samba suite specifically designed to interact with SMB/CIFS shares. It allows an attacker to enumerate available shares on a Windows target and retrieve file listings by connecting to the SMB service (port 445 or 139) using commands like 'smbclient -L //target' or by mounting a share and listing its contents.

Exam trap

The trap here is that candidates often confuse nmap's ability to detect SMB services with the actual enumeration of shares and file listings, but nmap requires specific NSE scripts and does not provide the direct interactive file listing capability that smbclient offers.

How to eliminate wrong answers

Option A is wrong because ldapsearch is a tool for querying LDAP directory services (port 389/636), not for enumerating SMB shares or retrieving file listings from Windows systems. Option B is wrong because snmpwalk is used to retrieve SNMP MIB data (port 161/162) from network devices, not to interact with SMB shares. Option D is wrong because nmap is a port scanner and network mapper that can detect open SMB ports but cannot natively enumerate SMB shares or retrieve file listings without additional scripts (e.g., smb-enum-shares), and even then it is not the dedicated tool for direct file listing.

175
MCQeasy

Which password cracking method uses a precomputed table of hash chains to reverse password hashes quickly?

A.Hybrid attack
B.Rainbow table attack
C.Dictionary attack
D.Brute-force attack
AnswerB

A rainbow table attack utilizes a precomputed table of hash chains to reverse cryptographic hash functions efficiently. Instead of brute-forcing each hash, the attacker looks up the target hash within the table, which maps hashes back to their original plaintext passwords. This method exploits a time-memory tradeoff, allowing for rapid password recovery without needing to compute every possible password combination during the attack.

Why this answer

A rainbow table attack is correct because it uses precomputed tables of hash chains to reverse password hashes quickly. Instead of computing the hash for every possible password in real time, the attacker looks up the hash in the table to find the corresponding plaintext, drastically reducing the time needed for cracking.

Exam trap

The trap here is that candidates confuse rainbow tables with dictionary attacks, thinking both use precomputed lists, but rainbow tables specifically use hash chains to cover many passwords efficiently, not a simple list of words.

How to eliminate wrong answers

Option A is wrong because a hybrid attack combines dictionary words with variations (e.g., appending numbers or symbols) but does not use precomputed hash chains. Option C is wrong because a dictionary attack tries a list of likely passwords by hashing each one and comparing, without any precomputed table. Option D is wrong because a brute-force attack tries every possible character combination sequentially, computing hashes on the fly, which is computationally expensive and does not rely on precomputed tables.

176
MCQmedium

Which phase of the system hacking methodology (CHPSET) involves hiding files from the operating system using techniques such as rootkits or steganography?

A.Cracking passwords
B.Erasing tracks
C.Executing applications
D.Hiding files
AnswerD

Hiding files is a core activity within the "Maintaining Access" phase of system hacking, specifically represented by the 'H' in the CHIPSET acronym. This involves employing various techniques, such as rootkits, steganography, or manipulating file attributes and permissions, to conceal malicious tools, backdoors, or data staging areas from legitimate users, administrators, and security software, thereby ensuring persistence and operational secrecy on the compromised system.

Why this answer

The 'Hiding files' phase of the CHPSET (Cracking passwords, Hacking, Privilege escalation, Spying, Erasing tracks, Executing applications, Hiding files) methodology involves concealing malicious files from the operating system and security tools. Techniques such as rootkits (which hook system calls like NtQueryDirectoryFile to hide files from directory listings) and steganography (embedding data within innocent files like images or audio) are used to avoid detection. This phase directly follows 'Executing applications' and ensures the attacker's payload remains persistent and covert.

Exam trap

The trap here is that candidates confuse 'Erasing tracks' (clearing logs) with 'Hiding files' (concealing the files themselves), but the CEH CHPSET model separates these as distinct phases—'Hiding files' specifically refers to techniques like rootkits and steganography that hide the file from the OS, not just removing evidence of its execution.

How to eliminate wrong answers

Option A is wrong because 'Cracking passwords' is the initial phase of CHPSET, focused on gaining access through password attacks (e.g., brute force, rainbow tables), not hiding files. Option B is wrong because 'Erasing tracks' involves clearing logs (e.g., clearing Event Logs or using tools like `wevtutil`) to cover the attacker's footprint, not hiding files from the OS. Option C is wrong because 'Executing applications' refers to running the malicious payload (e.g., backdoor or keylogger) after privilege escalation, not the act of concealing files.

177
MCQeasy

Which tool is specifically designed to crack Windows LM and NTLM hashes using precomputed tables?

A.Ophcrack
B.John the Ripper
C.Cain & Abel
D.Hashcat
AnswerA

Ophcrack is purpose-built for cracking Windows LM and NTLM hashes, leveraging precomputed rainbow tables for highly efficient password recovery. Its specialization allows it to quickly reverse these specific hash formats by performing a time-memory trade-off, making it exceptionally fast for common passwords. The tool comes with pre-generated tables, significantly reducing the computational effort required compared to on-the-fly cracking methods.

Why this answer

Ophcrack is specifically designed to crack Windows LM and NTLM hashes using precomputed rainbow tables. It relies on the time-memory trade-off technique, where hashes are looked up in precomputed tables rather than computed on the fly, making it highly efficient for these specific hash types. The tool is bundled with free rainbow tables for LM hashes and supports NTLM through additional table sets.

Exam trap

The trap here is that candidates often confuse 'precomputed tables' with general cracking tools like Hashcat or John the Ripper, which can also use precomputed tables in some configurations, but Ophcrack is the only tool specifically designed and optimized for that purpose with Windows LM/NTLM hashes.

How to eliminate wrong answers

Option B (John the Ripper) is wrong because it is a general-purpose password cracker that uses brute-force, dictionary, or incremental modes, not precomputed tables as its primary or designed method for Windows hashes. Option C (Cain & Abel) is wrong because while it can capture and crack Windows hashes, it relies on dictionary, brute-force, or cryptanalysis attacks, not precomputed rainbow tables. Option D (Hashcat) is wrong because it is a high-speed GPU-based cracker that uses brute-force, dictionary, or rule-based attacks, and although it supports precomputed tables via the '--stdout' mode with hashcat-utils, it is not specifically designed for precomputed table attacks like Ophcrack.

178
MCQmedium

A penetration tester wants to enumerate users and groups from a Windows domain controller via LDAP without logging in. Which of the following tools is MOST appropriate for anonymous LDAP enumeration?

A.smbclient
B.ldapsearch
C.snmpwalk
D.enum4linux
AnswerB

ldapsearch is the correct tool because it is specifically designed for querying LDAP (Lightweight Directory Access Protocol) directories. It enables penetration testers to perform anonymous or authenticated queries to enumerate directory objects, including users, groups, and their associated attributes. This utility directly interacts with LDAP servers to retrieve the precise information required for user and group enumeration.

Why this answer

ldapsearch is the correct tool because it can perform anonymous LDAP queries against a Windows domain controller's LDAP service (port 389) without requiring authentication. By default, many Windows DCs allow anonymous binds to retrieve directory information such as user and group objects, making ldapsearch the most direct and appropriate choice for this task.

Exam trap

The trap here is that candidates confuse enum4linux (which uses SMB/RPC null sessions) with LDAP enumeration, but enum4linux does not perform anonymous LDAP queries and relies on different protocols and ports.

How to eliminate wrong answers

Option A is wrong because smbclient is used for SMB/CIFS file sharing and requires authentication to enumerate users or groups; it cannot perform LDAP queries. Option C is wrong because snmpwalk uses SNMP (UDP 161) to query MIB objects from network devices, not LDAP directory services, and is not designed for user/group enumeration from a domain controller. Option D is wrong because enum4linux is a wrapper tool that uses SMB, RPC, and NetBIOS to enumerate Windows systems, but it does not perform LDAP queries and typically requires some level of authentication or null session access, not anonymous LDAP binding.

179
Multi-Selecteasy

Which TWO of the following are common methods used to hide files on a compromised system? (Select two.)

Select 2 answers
A.Rootkits
B.Token impersonation
C.NTFS Alternate Data Streams
D.Log manipulation
E.Steganography
AnswersC, E

Why this answer

NTFS Alternate Data Streams (option C) are a Windows file-system feature that lets extra data be attached to an existing file without changing its visible size or content, so an attacker can hide payloads or exfiltrated data behind a legitimate-looking file. Steganography (option E) conceals data inside other files such as images, audio, or video, making the hidden content difficult to detect without specialized analysis. Rootkits (option A) are used to hide the presence of malware, processes, or files by subverting the OS, but they are not themselves a file-hiding method in the same direct sense as ADS or steganography.

Token impersonation (option B) is a privilege-escalation and lateral-movement technique that steals another user's access token, not a file-hiding method. Log manipulation (option D) is an anti-forensic technique for altering or deleting audit records, not for concealing files on disk.

Exam trap

EC-Council often tests the distinction between file-hiding techniques (like ADS and steganography) and broader evasion or cleanup methods (like rootkits and log manipulation), leading candidates to confuse rootkits as a file-hiding method when they are actually a system-level concealment tool.

← PreviousPage 3 of 3 · 179 questions total

Ready to test yourself?

Try a timed practice session using only Enumeration and System Hacking questions.