Courseiva

CCNA Ceh Malware Social Network Questions

75 of 194 questions · Page 2/3 · Ceh Malware Social Network topic · Answers revealed

76
Multi-Selecthard

Which THREE of the following are effective techniques to prevent ARP poisoning attacks? (Choose three.)

Select 3 answers
A.Enabling DHCP snooping
B.Configuring port security on switches
C.Using static ARP entries
D.Disabling STP on all ports
E.Implementing Dynamic ARP Inspection (DAI)
AnswersB, C, E

Configuring port security on switches is an effective technique because it limits the number of MAC addresses that can be learned on a specific switch port. By restricting a port to a single, legitimate MAC address or a small, defined set, it prevents an attacker from introducing a new, spoofed MAC address to impersonate another device or the gateway, thereby mitigating ARP poisoning attempts that rely on MAC address changes.

Why this answer

Configuring port security on switches is effective against ARP poisoning because it limits the number of MAC addresses allowed on a port, preventing an attacker from flooding the network with spoofed MAC addresses. By restricting the port to a single or limited set of MAC addresses, it stops unauthorized devices from injecting fake ARP replies. This is a Layer 2 security control that directly mitigates the ability to perform ARP cache poisoning at the access edge.

Exam trap

The trap here is that candidates often confuse DHCP snooping as a direct ARP poisoning prevention technique, when in fact it only provides the binding table that DAI uses, and without DAI enabled, DHCP snooping alone does not inspect or block malicious ARP packets.

77
MCQmedium

During a social engineering engagement, an attacker calls an employee pretending to be from IT support and asks for their password to perform a system update. Which social engineering technique is being employed?

A.Phishing
B.Pretexting
C.Quid pro quo
D.Vishing
AnswerB

Pretexting involves the creation of a convincing, fabricated scenario or "pretext" to manipulate a target into revealing confidential information or performing a specific action. In this type of social engineering engagement, the attacker constructs a plausible backstory, such as impersonating IT support or a vendor, to establish trust and extract desired details directly from the target over the phone. This method precisely aligns with an attacker calling someone with a specific, made-up story to achieve their objective.

Why this answer

Pretexting is the correct answer because the attacker fabricates a scenario (pretext) by impersonating IT support to create a false sense of authority and urgency, thereby manipulating the employee into revealing their password. This technique relies on a fabricated story rather than a technical exploit, distinguishing it from other social engineering methods.

Exam trap

The trap here is that candidates often confuse pretexting with vishing because both involve phone calls, but the CEH exam distinguishes them by the presence of a fabricated scenario (pretext) versus a simple voice-based phishing attempt without an elaborate backstory.

How to eliminate wrong answers

Option A (Phishing) is wrong because phishing typically involves sending deceptive emails or messages with malicious links or attachments to harvest credentials, not a direct phone call with a fabricated identity. Option C (Quid pro quo) is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), whereas the attacker here simply asks for the password under a false pretense without offering anything in return. Option D (Vishing) is wrong because vishing is voice phishing that uses phone calls to trick victims into revealing sensitive information, but it is a subset of phishing and does not inherently involve the elaborate role-playing and fabricated scenario that defines pretexting; the key distinction is that pretexting builds a detailed false identity and context, while vishing may be more direct and less story-driven.

78
MCQmedium

During a penetration test, a tester uses a tool to perform ARP spoofing to intercept traffic between two hosts on the same subnet. Which tool is most commonly associated with this technique?

A.Wireshark
B.Ettercap
C.Metasploit
D.Nmap
AnswerB

Ettercap is a comprehensive suite specifically designed for performing man-in-the-middle (MITM) attacks on local area networks, with a core specialization in ARP spoofing (also known as ARP poisoning). It actively manipulates the ARP tables of target hosts and the network gateway by sending forged ARP replies, redirecting traffic through the attacker's machine. This capability enables various MITM activities, including sniffing, content filtering, and session hijacking, making it the ideal tool for actively performing such an attack during a penetration test.

Why this answer

Ettercap is the correct answer because it is a dedicated suite for man-in-the-middle attacks on LAN, with built-in ARP spoofing (poisoning) capabilities. It actively sends forged ARP replies to associate the tester's MAC address with the IP address of the target hosts, allowing interception of traffic between them on the same subnet. Other tools like Wireshark, Metasploit, and Nmap are not primarily designed for ARP spoofing.

Exam trap

The trap here is that candidates confuse passive sniffing tools like Wireshark with active interception tools, assuming that any packet capture tool can also perform ARP spoofing, but Wireshark lacks the injection capability required for this attack.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer (packet sniffer) that captures and inspects traffic passively; it does not inject or spoof ARP packets to intercept traffic. Option C is wrong because Metasploit is an exploitation framework focused on delivering payloads and post-exploitation modules; while it has auxiliary modules for ARP spoofing, it is not the most commonly associated tool for this specific technique. Option D is wrong because Nmap is a network discovery and security scanning tool that uses ARP pings for host discovery but does not perform ARP spoofing to intercept traffic between hosts.

79
Multi-Selectmedium

Which TWO of the following are valid techniques for session hijacking? (Select 2)

Select 2 answers
A.DNS spoofing
B.MAC flooding
C.TCP sequence prediction
D.Cookie theft
E.ARP poisoning
AnswersC, D

TCP sequence prediction lets an attacker forge packets by guessing the next sequence number, hijacking an established session without seeing the traffic. It exploits predictable initial sequence numbers, making it a valid session hijacking technique.

Why this answer

TCP sequence prediction (C) is a valid session hijacking technique because an attacker who can guess or infer the next expected TCP sequence and acknowledgment numbers can inject forged packets into an established TCP session, impersonating the legitimate client without ever seeing the authentication exchange. Cookie theft (D) is also valid because session cookies often serve as the bearer token for an authenticated HTTP session, so stealing a cookie (via XSS, sniffing, or malware) lets the attacker replay it and take over the victim's session. DNS spoofing (A), MAC flooding (B), and ARP poisoning (E) are not session hijacking techniques themselves: DNS spoofing redirects name resolution, MAC flooding overflows a switch's CAM table to force hub-like flooding, and ARP poisoning enables man-in-the-middle traffic interception — each may facilitate an attack, but none directly hijacks an existing session.

Exam trap

In the CEH exam, it's important to distinguish between direct session hijacking techniques (like TCP sequence prediction and cookie theft) and network-level attacks that enable interception but not direct hijacking.

80
MCQmedium

A penetration tester is performing a session hijacking attack. After capturing packets, the tester successfully predicts the TCP sequence numbers and injects packets to take over the session. Which type of attack is this?

A.MAC flooding
B.Cookie theft
C.TCP session hijacking
D.ARP poisoning
AnswerC

Predicting TCP sequence numbers lets the tester forge packets that the server accepts as belonging to the victim's established connection, bypassing authentication entirely. This is TCP session hijacking specifically, since the attacker takes over an existing session rather than guessing credentials or intercepting a new handshake.

Why this answer

TCP session hijacking involves an attacker predicting or spoofing TCP sequence numbers to inject malicious packets into an established TCP connection, effectively taking over the session without the need for authentication. This attack exploits the lack of built-in authentication in TCP's three-way handshake and sequence number generation, allowing the attacker to impersonate one of the communicating parties.

Exam trap

In EC-CEH, the trap is distinguishing TCP session hijacking (Layer 4, sequence number prediction) from application-layer session hijacking (e.g., session token theft or cookie theft). Candidates often confuse the mechanism of predicting sequence numbers with stealing session identifiers, leading them to choose Option B.

How to eliminate wrong answers

Option A is wrong because MAC flooding is a Layer 2 attack that overwhelms a switch's CAM table with fake MAC addresses, causing it to fail open and broadcast traffic, which is unrelated to TCP sequence number prediction. Option B is wrong because cookie theft typically involves stealing HTTP cookies (e.g., via XSS or packet sniffing) to impersonate a user's web session, not predicting TCP sequence numbers to inject packets. Option D is wrong because ARP poisoning is a Layer 2 attack that manipulates ARP tables to redirect traffic on a local network, not a TCP-level sequence number prediction and injection attack.

81
MCQhard

An attacker intercepts a TCP session between a client and a server. By analyzing sequence numbers, the attacker successfully predicts the next sequence number and injects malicious packets. Which attack is being performed?

A.DNS spoofing
B.ARP poisoning
C.Man-in-the-middle
D.Session hijacking
AnswerD

Session hijacking is the act of taking control of an already authenticated TCP session between two communicating parties. This is typically achieved by an attacker successfully predicting or sniffing the correct TCP sequence numbers (acknowledgment and sequence numbers) that the legitimate client and server expect. By injecting packets with the correct sequence numbers, the attacker can impersonate the client or server, effectively taking over the session and issuing commands or receiving data without the original client's knowledge.

Why this answer

The attacker is actively intercepting a TCP session, predicting sequence numbers, and injecting malicious packets, which is the definition of TCP session hijacking. This attack exploits the lack of authentication in TCP connections, where the attacker can take over an established session by correctly guessing or obtaining the next sequence number.

Exam trap

The trap here is that candidates confuse session hijacking with a generic man-in-the-middle attack, but the key differentiator is the specific act of predicting TCP sequence numbers to inject packets, which is a hallmark of session hijacking, not just passive interception.

How to eliminate wrong answers

Option A is wrong because DNS spoofing involves corrupting DNS responses to redirect traffic to a malicious server, not intercepting and injecting packets into an existing TCP session. Option B is wrong because ARP poisoning manipulates the ARP cache to associate an attacker's MAC address with a legitimate IP address, enabling local network interception, but it does not involve TCP sequence number prediction or packet injection into an established session. Option C is wrong because while a man-in-the-middle attack can involve interception, the specific technique described—predicting TCP sequence numbers to inject packets—is a form of session hijacking, not a generic MITM; MITM typically requires active relay of traffic, not just sequence number prediction.

82
MCQmedium

A penetration tester needs to perform ARP poisoning to intercept traffic between two hosts on the same subnet. Which tool would be the most appropriate choice for this task?

A.tcpdump
B.Ettercap
C.Nmap
D.Wireshark
AnswerB

Ettercap is a comprehensive suite designed specifically for man-in-the-middle (MITM) attacks on local area networks, including robust ARP poisoning capabilities. It actively intercepts traffic by sending forged ARP replies to trick hosts into associating the attacker's MAC address with the gateway's IP, and vice-versa. This allows the penetration tester to transparently relay, inspect, and modify network traffic between the target and the gateway, fulfilling the requirement for ARP poisoning.

Why this answer

Ettercap is the most appropriate tool for ARP poisoning because it is specifically designed for man-in-the-middle (MITM) attacks on a local area network (LAN). It automates ARP spoofing by sending forged ARP replies to both target hosts, poisoning their ARP caches so that traffic intended for the other host is redirected through the attacker's machine, enabling interception and modification of packets.

Exam trap

The trap here is that candidates often confuse passive sniffing tools like Wireshark or tcpdump with active attack tools, assuming that any tool that captures traffic can also perform ARP poisoning, but only dedicated MITM tools like Ettercap have the built-in ARP spoofing engine required for this task.

How to eliminate wrong answers

Option A is wrong because tcpdump is a packet capture and analysis tool; it cannot generate or inject forged ARP packets to perform poisoning. Option C is wrong because Nmap is a network discovery and port scanning tool; while it can detect hosts and services, it lacks the ability to conduct ARP spoofing or MITM attacks. Option D is wrong because Wireshark is a packet analyzer that passively captures and inspects traffic; it does not have the capability to send crafted ARP packets to manipulate ARP caches.

83
MCQhard

During a ransomware incident response, a forensic analyst recovers a suspicious file that appears to be a PE executable. The analyst wants to quickly check if the file is known malware without executing it. Which of the following is the BEST first step?

A.Disassemble the file using IDA Pro
B.Submit the file hash to VirusTotal
C.Perform static analysis using PEiD to identify compiler and packer
D.Run the file in a sandbox and observe its behavior
AnswerB

Submitting the file's cryptographic hash (e.g., SHA256) to VirusTotal is an optimal initial step because it leverages a vast, aggregated threat intelligence database. This service quickly checks the hash against numerous antivirus engines, sandboxes, and community submissions, providing immediate insight into whether the file is known malware, its common names, and associated behaviors without requiring local execution or extensive analysis. This rapid identification is critical for efficient incident response triage.

Why this answer

Submitting the file hash to VirusTotal is the best first step because it leverages aggregated antivirus engines and threat intelligence to quickly determine if the file is known malware, without any execution risk. This approach is fast, non-invasive, and provides immediate reputation data from over 70 security vendors, making it ideal for triage during incident response.

Exam trap

The trap here is that candidates often choose sandbox execution (Option D) or deep static analysis (Option A) because they seem thorough, but the CEH exam emphasizes the principle of 'least risk first' — using a hash lookup to avoid execution and save time during initial triage.

How to eliminate wrong answers

Option A is wrong because disassembling with IDA Pro is a deep static analysis technique that is time-consuming and unnecessary for a quick malware check; it should be performed only after initial triage confirms the file is suspicious. Option C is wrong because using PEiD to identify the compiler or packer, while useful for static analysis, does not directly answer whether the file is known malware and may miss packed or obfuscated samples that VirusTotal would detect. Option D is wrong because running the file in a sandbox introduces execution risk and is slower than a hash lookup; sandbox analysis is appropriate after confirming the file is not already known to antivirus engines.

84
MCQmedium

A security analyst notices an unusual spike in outbound traffic on UDP port 53 from a single internal host. The host is not a DNS server. Which type of malware is MOST likely responsible?

A.A worm that spreads via email attachments
B.A polymorphic virus
C.A DNS tunneling tool used for data exfiltration
D.A keylogger that sends captured keystrokes via HTTP
AnswerC

DNS tunneling is a sophisticated data exfiltration technique where malicious actors encode arbitrary data within DNS queries and responses, effectively creating a covert communication channel. This method leverages the legitimate and often unfiltered nature of DNS traffic (UDP port 53) to bypass firewalls and intrusion detection systems. A significant spike in outbound DNS traffic, especially with unusually large query sizes or frequent requests to suspicious domains, is a direct indicator of data being fragmented and transmitted out of the network via this covert channel.

Why this answer

DNS tunneling encapsulates non-DNS traffic (e.g., data exfiltration) within DNS queries and responses, typically using UDP port 53. Since the host is not a DNS server, the outbound spike on port 53 indicates it is likely tunneling data to an external command-and-control server, making option C correct.

Exam trap

The trap here is that candidates may associate any unusual outbound traffic with a generic malware type (like a worm or virus) rather than recognizing the specific protocol and port combination (UDP 53) as a classic indicator of DNS tunneling for data exfiltration.

How to eliminate wrong answers

Option A is wrong because a worm spreading via email attachments typically generates outbound SMTP (port 25) or HTTP traffic, not a sustained spike on UDP 53. Option B is wrong because a polymorphic virus changes its code signature to evade detection but does not inherently cause a specific outbound UDP 53 traffic pattern; its propagation and communication methods vary. Option D is wrong because a keylogger sending keystrokes via HTTP uses TCP port 80 or 443, not UDP port 53, and would not explain the DNS protocol anomaly.

85
MCQeasy

A user reports that their computer is infected with ransomware. Which of the following is the BEST immediate action for the security team to take?

A.Disconnect the computer from the network
B.Pay the ransom to regain access
C.Run a full antivirus scan
D.Restore the system from a recent backup
AnswerA

Disconnecting the computer from the network is the immediate and most critical first step in containing a ransomware infection. This action severs the malware's ability to communicate with command-and-control (C2) servers, preventing further encryption key exchange, data exfiltration, or the reception of additional malicious instructions. Crucially, it also stops the ransomware from spreading laterally across the network to other systems or encrypting shared network drives, thereby limiting the scope of the compromise and preventing further damage.

Why this answer

Disconnecting the computer from the network is the best immediate action because it isolates the ransomware, preventing it from spreading laterally to other systems via SMB, RDP, or mapped drives. This containment step stops the encryption of additional network shares and halts any command-and-control (C2) communication the ransomware might be using to exfiltrate data or receive encryption keys.

Exam trap

Many candidates mistakenly prioritize running an antivirus scan or restoring from backup as the immediate step. However, the CEH exam emphasizes containment first to prevent lateral movement and further damage. Disconnecting from the network is critical to stop the spread of ransomware.

How to eliminate wrong answers

Option B is wrong because paying the ransom does not guarantee decryption and often funds criminal operations; there is no technical assurance the attacker will provide a working decryption key, and it may encourage further attacks. Option C is wrong because running a full antivirus scan while the ransomware is active can trigger the malware to accelerate encryption or delete files, and the scan itself may be ineffective if the ransomware has already modified system files or uses polymorphic code. Option D is wrong because restoring from a backup should only be done after the ransomware is fully removed and the system is verified clean; immediate restoration risks re-encrypting the backup if it is still connected to the network or if the ransomware persists in memory.

86
MCQhard

An attacker uses the Social Engineering Toolkit (SET) to craft a phishing email that appears to come from the company's CEO, requesting the recipient to urgently wire funds to a new vendor. This attack is BEST described as which type of social engineering?

A.Pretexting
B.Spear phishing
C.Whaling
D.Quid pro quo
AnswerC

Whaling is a specialized form of phishing attack specifically designed to target high-ranking individuals within an organization, such as CEOs, CFOs, or other senior executives. These attacks are often highly sophisticated, leveraging extensive research to craft convincing lures that exploit the target's position of authority and access to sensitive information or financial assets. The scenario involving the impersonation of a CEO directly aligns with the definition of whaling, as it targets a "big fish" with significant organizational power.

Why this answer

Whaling is a targeted phishing attack aimed at high-profile individuals like the CEO or CFO. In this scenario, the attacker uses SET to impersonate the CEO and requests an urgent wire transfer, which is a classic whaling tactic because it targets a senior executive (the recipient) with a business-critical request. The attack is not generic phishing but specifically targets a 'big fish' within the organization.

Exam trap

The EC-CEH exam often tests the distinction between spear phishing and whaling by making candidates think any targeted email is spear phishing, but the trap here is that whaling is a subset of spear phishing specifically targeting senior executives, so the correct answer is the more specific term when the target is a 'big fish' like the CEO.

How to eliminate wrong answers

Option A is wrong because pretexting involves creating a fabricated scenario (pretext) to steal information, not sending a phishing email with a malicious request for funds. Option B is wrong because spear phishing targets a specific individual or group but does not require the target to be a high-level executive; this attack specifically targets the CEO or CFO, making it whaling. Option D is wrong because quid pro quo involves offering a service or benefit in exchange for information, such as a fake tech support call, not a fraudulent email requesting a wire transfer.

87
MCQmedium

A user receives a phone call from someone claiming to be from IT support, asking for their password to perform a system update. This is an example of which social engineering technique?

A.Baiting
B.Pretexting
C.Phishing
D.Vishing
AnswerB

Pretexting involves an attacker fabricating a believable scenario and a false identity to manipulate a victim into divulging sensitive information. The attacker creates a detailed backstory, often impersonating someone in authority or a trusted entity, to establish a sense of legitimacy and urgency. This elaborate setup is designed to overcome the victim's skepticism and directly solicit specific data, like a password, through social engineering.

Why this answer

Pretexting is a social engineering technique where an attacker fabricates a scenario (pretext) to manipulate a target into divulging sensitive information. In this case, the caller creates a false identity (IT support) and a false reason (system update) to trick the user into revealing their password. This differs from other techniques because it relies on a constructed narrative rather than malicious software or direct impersonation via email or phone alone.

Exam trap

The trap here is that candidates confuse vishing (voice phishing) with pretexting, but the key differentiator is that pretexting involves a fabricated identity and scenario (pretext) to establish trust, whereas vishing is simply phishing conducted over voice without necessarily building a detailed false narrative.

How to eliminate wrong answers

Option A is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim into executing malware or revealing credentials, not a direct phone call requesting a password. Option C is wrong because phishing is a broad term for social engineering via electronic communication (typically email) that uses deceptive links or attachments, not a live voice call. Option D is wrong because vishing (voice phishing) is a subset of phishing that uses phone calls, but the specific technique here is pretexting because the attacker establishes a false identity and scenario (pretext) to gain trust, not just a generic request for information.

88
MCQmedium

An analyst is analyzing a suspicious file using VirusTotal and observes that only 3 out of 60 antivirus engines detect it as malicious. The file has been submitted before but with no detections. What should the analyst conclude?

A.The file is a clean file with a rare hash
B.The file is safe because most engines don't detect it
C.The file is likely a false positive
D.The file is likely malicious and requires further analysis
AnswerD

Low detection counts do not prove benignity; three engines flagging the file indicates likely maliciousness. The earlier zero-detection submission suggests a new or modified variant evading signatures, so the analyst should treat it as suspicious and perform deeper dynamic and static analysis.

Why this answer

A detection rate of 3 out of 60 (5%) is extremely low, but the fact that the file was previously submitted with zero detections and now has three detections indicates that the antivirus engines have updated their signatures to identify it. This pattern is consistent with a new or polymorphic malware strain that initially evaded detection but is now being recognized by a few engines. A low detection rate does not guarantee safety; it often signals a targeted or zero-day threat that requires further analysis through sandboxing or dynamic analysis.

Exam trap

EC-Council often tests the misconception that a low detection rate (e.g., 3/60) means the file is safe, when in fact it indicates the file is likely malicious and requires further investigation, especially if the detection count has increased from zero.

How to eliminate wrong answers

Option A is wrong because a rare hash does not imply the file is clean; malware authors can generate unique hashes for each sample, and a file with a rare hash could still be malicious. Option B is wrong because the number of engines that do not detect a file is not a reliable indicator of safety; many engines may lack signatures for new or obfuscated malware, and relying solely on detection count is a common fallacy. Option C is wrong because a false positive occurs when an engine incorrectly flags a benign file, but here the file was previously undetected and now has three detections, which is more consistent with emerging malware than a false positive; false positives typically appear consistently across submissions, not as a new detection pattern.

89
MCQmedium

A security analyst notices repeated TCP SYN packets sent to a server without corresponding SYN-ACK replies. The source IP addresses are spoofed and appear to be random. Which type of attack is MOST likely occurring?

A.SYN flood
B.UDP flood
C.ICMP flood
D.Ping of Death
AnswerA

A SYN flood is a classic Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. Attackers send a large volume of TCP SYN requests to a target server, often with spoofed source IP addresses. The server responds with SYN-ACK packets and allocates resources to maintain a half-open connection, waiting for the final ACK that never arrives, eventually exhausting its connection table and preventing legitimate connections.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IP addresses to a target server. The server responds with SYN-ACK packets to the spoofed addresses, which never complete the handshake, causing the server to exhaust its memory and CPU resources by maintaining half-open connections. This matches the described behavior of repeated SYN packets without corresponding SYN-ACK replies.

Exam trap

The trap here is that candidates often confuse a SYN flood with a UDP flood because both are volumetric attacks, but the key differentiator is the use of TCP SYN packets and the spoofed source IPs targeting the handshake process, not just any protocol flood.

How to eliminate wrong answers

Option B (UDP flood) is wrong because it involves sending large numbers of UDP packets to random ports, not TCP SYN packets, and does not rely on the TCP handshake mechanism. Option C (ICMP flood) is wrong because it uses ICMP echo request (ping) packets to overwhelm the target, not TCP SYN packets. Option D (Ping of Death) is wrong because it involves sending a malformed ICMP packet larger than the maximum 65,535 bytes to cause a buffer overflow, not a flood of TCP SYN packets.

90
MCQeasy

Which type of social engineering attack involves a malicious actor impersonating a legitimate organization in a voicemail message to trick the victim into revealing sensitive information?

A.SMiShing
B.Pharming
C.Baiting
D.Vishing
AnswerD

Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack that utilizes voice communication, typically over telephone calls or Voice over IP (VoIP), to trick individuals. Attackers often impersonate trusted entities like banks, government agencies, or technical support to manipulate victims into revealing sensitive personal or financial information, or to perform actions like installing malicious software. Its defining characteristic is the direct, real-time vocal interaction with the target.

Why this answer

Vishing (voice phishing) is the correct answer because it specifically involves using voice communication—such as a phone call or voicemail—to impersonate a legitimate organization and trick the victim into revealing sensitive information like passwords or credit card numbers. Unlike other social engineering attacks, vishing exploits the trust associated with voice interactions and often uses caller ID spoofing to appear as a trusted entity.

Exam trap

The trap here is that candidates often confuse vishing with SMiShing because both involve phishing via communication channels, but SMiShing uses SMS text messages while vishing uses voice calls or voicemail.

How to eliminate wrong answers

Option A is wrong because SMiShing (SMS phishing) uses text messages (SMS) rather than voicemail to deliver the malicious lure, typically containing a link to a phishing site. Option B is wrong because pharming redirects users from a legitimate website to a fraudulent one by manipulating DNS settings or host files, without direct impersonation via voicemail. Option C is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to trick the victim into installing malware or revealing credentials, not leaving a voicemail message.

91
MCQeasy

Which malware analysis approach involves running the suspicious file in a controlled environment to observe its behavior?

A.Dynamic analysis
B.Code review
C.Signature detection
D.Static analysis
AnswerA

Dynamic analysis involves executing the suspicious malware sample within a controlled environment, such as a sandbox or virtual machine, to observe its real-time behavior. This approach monitors system calls, network communications, file system modifications, and registry changes as the malware runs, providing critical insights into its operational characteristics and potential impact. By observing execution, analysts can understand how the malware interacts with its environment and what malicious actions it attempts.

Why this answer

Dynamic analysis is the correct approach because it involves executing the suspicious file in a controlled, isolated environment (such as a sandbox or virtual machine) to monitor its runtime behavior, including file system changes, registry modifications, network connections, and process injections. This allows analysts to observe actual malicious actions without risking the production environment, making it essential for understanding zero-day threats and obfuscated malware that static analysis might miss.

Exam trap

EC-Council often tests the misconception that static analysis is sufficient for all malware types, but the trap here is that candidates confuse 'static analysis' (which examines code without execution) with 'dynamic analysis' (which requires execution), leading them to pick static analysis when the question explicitly asks for observing behavior in a controlled environment.

How to eliminate wrong answers

Option B is wrong because code review is a manual or automated examination of the malware's source code or disassembled instructions without execution, which falls under static analysis and cannot reveal runtime behaviors like API calls or network traffic. Option C is wrong because signature detection relies on pre-defined patterns (e.g., hash values or byte sequences) to identify known malware, but it fails against polymorphic or novel malware that lacks matching signatures. Option D is wrong because static analysis examines the file's structure, strings, and code without execution, missing dynamic behaviors such as self-modification, anti-debugging tricks, or delayed payload activation.

92
Multi-Selecthard

Which THREE of the following are common methods used to mitigate DDoS attacks? (Select 3)

Select 3 answers
A.MAC flooding
B.Rate limiting
C.Scrubbing centers
D.ARP poisoning
E.Anycast network distribution
AnswersB, C, E

Rate limiting caps the volume of requests a server or network accepts per source within a defined window, absorbing volumetric floods before they exhaust bandwidth or processing capacity. This directly satisfies the stem's mitigation requirement by throttling malicious traffic while permitting legitimate connections, a standard DDoS defence alongside traffic filtering and content delivery networks.

Why this answer

Rate limiting (B) is correct because it caps the number of requests or packets a client or service can send per unit time, so volumetric floods and application-layer floods are throttled before they exhaust server or bandwidth resources. Scrubbing centers (C) are correct because they divert incoming traffic to specialized cleaning facilities that filter out malicious DDoS packets via signature, anomaly, and behavioral analysis and forward only legitimate traffic to the origin. Anycast network distribution (E) is correct because advertising the same IP prefix from many geographically dispersed points of presence spreads attack traffic across the provider's global edge, absorbing and dispersing volumetric floods while bringing legitimate users to the nearest node.

MAC flooding (A) is not a mitigation but a Layer 2 switch attack that overflows the CAM table to force hub-like flooding, and ARP poisoning (D) is a Layer 2 man-in-the-middle attack that forges ARP replies to associate an attacker's MAC with a victim's IP, so neither belongs among DDoS mitigation methods.

Exam trap

EC-CEH often tests the distinction between attack techniques (like MAC flooding and ARP poisoning) and legitimate mitigation strategies, so candidates mistakenly select these as defenses because they are network-related terms.

93
MCQhard

During a penetration test, you run the command: 'macof -i eth0 -s 192.168.1.1 -d 192.168.2.1 -e 00:11:22:33:44:55'. What is the intended effect of this command?

A.Execute a SYN flood against the target
B.Perform MAC flooding to cause switch to fail open
C.Perform ARP poisoning
D.Spoof DNS responses
AnswerB

The command macof -i eth0 specifically performs MAC flooding by continuously sending frames with randomly generated source MAC addresses to exhaust the switch's Content Addressable Memory (CAM) table. When the CAM table overflows, the switch typically enters a "fail-open" mode, behaving like a hub by broadcasting all incoming traffic out of all ports. This allows an attacker connected to any port on the switch to capture and analyze all network traffic, effectively bypassing the switch's normal segmentation.

Why this answer

The `macof` tool generates a flood of random MAC addresses on the specified interface, overwhelming the switch's Content Addressable Memory (CAM) table. When the CAM table is full, the switch fails open and begins flooding all frames out all ports, effectively turning it into a hub. This allows the attacker to sniff traffic that would normally be isolated to specific switch ports.

Exam trap

The trap here is confusing MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets the ARP cache of hosts), as both involve spoofed MAC addresses but operate at different layers and with different mechanisms.

How to eliminate wrong answers

Option A is wrong because `macof` performs MAC flooding, not a SYN flood; a SYN flood targets a host's TCP stack with half-open connections, whereas `macof` targets the switch's CAM table. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate a victim's IP with the attacker's MAC, which is a different attack vector than flooding the switch with random MACs. Option D is wrong because DNS spoofing requires corrupting DNS responses or cache entries, which is unrelated to the layer-2 MAC flooding performed by `macof`.

94
MCQeasy

An organization experiences a DDoS attack where a large volume of DNS queries with spoofed source IPs are sent to open DNS resolvers, which then amplify the traffic to the victim. Which type of attack is this?

A.UDP flood
B.Smurf attack
C.SYN flood
D.DNS amplification
AnswerD

Attackers send DNS queries with spoofed source addresses to open resolvers; the resolvers return large responses to the victim, multiplying traffic volume. This reflection-and-amplification mechanism, exploiting the size disparity between query and response, matches the stem exactly.

Why this answer

This is a DNS amplification attack, a type of DDoS that exploits open DNS resolvers. The attacker sends a small DNS query (e.g., ANY type) with a spoofed source IP (the victim's IP) to an open resolver, which responds with a much larger response (up to 50-100x the query size), flooding the victim. The key mechanism is the amplification factor combined with the spoofed source address, which directs the amplified traffic to the victim.

Exam trap

In EC-CEH, candidates often mistake DNS amplification for a basic UDP flood or Smurf attack. The key is to recognize the involvement of an open DNS resolver and the amplification factor, which are hallmarks of this attack.

How to eliminate wrong answers

Option A is wrong because a UDP flood is a generic attack where the attacker directly sends a high volume of UDP packets to the victim, without using a third-party reflector or amplification; this scenario specifically involves open DNS resolvers amplifying traffic. Option B is wrong because a Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing all hosts on the network to reply to the victim; this attack uses DNS queries, not ICMP, and targets open resolvers, not broadcast addresses. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed IPs to exhaust server resources; this attack uses UDP-based DNS queries, not TCP SYN packets.

95
MCQmedium

An analyst uses the following command to capture traffic: tcpdump -i eth0 -w capture.pcap host 10.0.0.5 and port 80. After generating traffic from a web server at 10.0.0.5, the analyst examines the pcap with Wireshark. What type of traffic will appear in the capture?

A.All HTTP traffic on the network
B.HTTP traffic to and from 10.0.0.5
C.Only HTTP traffic originating from 10.0.0.5
D.All traffic from 10.0.0.5 on any port
AnswerB

The "host 10.0.0.5" filter inherently captures traffic where 10.0.0.5 is either the source or the destination IP address, encompassing both inbound and outbound communications. Coupled with "port 80", which identifies standard HTTP traffic, this command precisely targets all HTTP conversations involving the specified host, regardless of direction.

Why this answer

The command `tcpdump -i eth0 -w capture.pcap host 10.0.0.5 and port 80` captures only packets that match both conditions: the IP address is 10.0.0.5 (source or destination) and the port is 80 (source or destination). Since port 80 is the default HTTP port, this filter captures HTTP traffic to and from the web server at 10.0.0.5. The `host` keyword includes both directions, so the capture is not limited to traffic originating from the server.

Exam trap

The trap here is that candidates often assume `host` implies only traffic originating from the specified IP, but in BPF syntax, `host` captures bidirectional traffic unless modified with `src` or `dst`.

How to eliminate wrong answers

Option A is wrong because the filter restricts traffic to host 10.0.0.5 and port 80, not all HTTP traffic on the network; other hosts' HTTP traffic would be excluded. Option C is wrong because the `host` keyword captures traffic in both directions (to and from 10.0.0.5), not only traffic originating from that IP; the filter does not specify a source-only modifier like `src`. Option D is wrong because the filter includes `port 80`, which limits traffic to that specific port; traffic from 10.0.0.5 on any other port (e.g., SSH on port 22) would not be captured.

96
MCQhard

A system administrator notices unusual outbound traffic from a server on port 4444. The server has no legitimate service listening on that port. A malware analyst runs 'strings' on a suspicious binary and finds a reference to 'cmd.exe /c' and an IP address. What type of malware is MOST likely present?

A.Worm
B.Keylogger
C.Backdoor Trojan
D.Ransomware
AnswerC

A Backdoor Trojan is malware disguised as legitimate software that, once executed, creates a covert entry point into a compromised system, bypassing normal authentication mechanisms. The "unusual outbound traffic" combined with the execution of `cmd.exe /c` on a non-standard port like 4444 is a classic indicator of a Remote Access Trojan (RAT) or backdoor establishing a command-and-control (C2) channel. This setup allows an attacker to remotely issue commands and control the compromised machine, aligning perfectly with the observed remote shell activity.

Why this answer

The outbound traffic on port 4444, a common port for the Metasploit Meterpreter reverse shell, combined with the 'strings' output showing 'cmd.exe /c' (a command shell invocation) and an IP address, indicates a backdoor Trojan. This malware type establishes a covert reverse connection to an attacker's command-and-control server, allowing remote shell access without a legitimate service on the target port.

Exam trap

The trap here is that candidates may associate port 4444 with legitimate services like Kerberos or Blizzard games, but CEH expects you to recognize it as the default Metasploit reverse shell port, not a worm or ransomware indicator.

How to eliminate wrong answers

Option A is wrong because a worm self-propagates across networks without requiring a manual trigger or a specific reverse shell payload, and it typically uses exploit vectors like SMB or RDP, not a static outbound connection on port 4444. Option B is wrong because a keylogger captures keystrokes locally and sends logs via HTTP or SMTP, not by spawning 'cmd.exe /c' for interactive remote shell access. Option D is wrong because ransomware encrypts files and demands payment, often using HTTPS for C2 communication, not a raw TCP reverse shell on port 4444 with a command-line interface.

97
MCQmedium

A network administrator receives an alert that the switch's CAM table is full, causing the switch to flood frames out all ports. Which attack has likely occurred?

A.DNS spoofing
B.ARP poisoning
C.MAC flooding
D.SYN flood
AnswerC

MAC flooding overwhelms the switch's CAM table by sending numerous frames with spoofed source MAC addresses, exhausting its finite entry capacity. Once full, the switch cannot map addresses to ports and falls back to hub-like behaviour, flooding every frame out all ports — precisely the alert described in the stem.

Why this answer

MAC flooding (Option C) is the correct answer because it directly exploits the limited size of a switch's Content Addressable Memory (CAM) table. By sending a high volume of frames with unique, spoofed source MAC addresses, the attacker fills the CAM table, forcing the switch to fail open and flood all incoming frames out every port, effectively turning it into a hub. This allows the attacker to capture traffic that was not originally destined for their port.

Exam trap

In the EC-CEH exam, MAC flooding is often contrasted with ARP poisoning; the trap here is that candidates confuse the layer-2 CAM table overflow with layer-3 ARP cache manipulation, but ARP poisoning does not cause the switch to flood frames out all ports.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS resolution by injecting false A or AAAA records, redirecting users to malicious sites; it does not affect the switch's CAM table or cause frame flooding. Option B is wrong because ARP poisoning manipulates the IP-to-MAC mapping in a host's ARP cache to intercept traffic, but it does not fill the switch's CAM table; the switch still learns and forwards frames normally based on its CAM table entries. Option D is wrong because a SYN flood is a denial-of-service attack that exhausts a target's TCP connection resources by sending incomplete handshake requests; it has no impact on the switch's layer-2 forwarding table.

98
MCQmedium

A security analyst observes a gradual increase in network traffic from an internal host to an external IP address on port 443, with the host also connecting to a known command-and-control (C2) domain. Which type of malware is MOST likely responsible?

A.Ransomware
B.Worm
C.Boot sector virus
D.Backdoor Trojan
AnswerD

A backdoor Trojan establishes a covert communication channel, granting an attacker persistent remote access and control over the compromised system. This persistent access necessitates regular, often low-volume, communication with a Command and Control (C2) server to receive commands, exfiltrate data, or update its status. The observed 'gradual increase in network traffic' is highly indicative of such C2 activity, as the attacker intermittently interacts with the backdoor over time, leading to a subtle but sustained rise in outbound or inbound connections.

Why this answer

The gradual increase in traffic to an external IP on port 443 (HTTPS) combined with connections to a known C2 domain indicates a backdoor Trojan. Backdoor Trojans establish stealthy, encrypted command-and-control channels to exfiltrate data or receive instructions, often mimicking legitimate HTTPS traffic to evade detection. This behavior aligns with a backdoor Trojan's purpose of providing unauthorized remote access while blending into normal network activity.

Exam trap

The trap here is that candidates may associate port 443 with legitimate web traffic and overlook the gradual, stealthy nature of the C2 communication, instead choosing ransomware or worm due to their more dramatic behaviors.

How to eliminate wrong answers

Option A is wrong because ransomware typically exhibits rapid, widespread file encryption and ransom note delivery, not a gradual increase in C2 traffic on port 443. Option B is wrong because a worm self-replicates across networks without requiring a C2 channel for remote control; its primary behavior is propagation, not sustained encrypted communication with an external server. Option C is wrong because a boot sector virus infects the Master Boot Record (MBR) and activates during system boot, not by generating network traffic to a C2 domain over HTTPS.

99
MCQmedium

A security analyst notices a significant increase in outbound traffic from an internal server to multiple external IPs on port 443. The server is not a web server and should not be initiating such connections. Which type of malware is MOST likely causing this behavior?

A.A boot sector virus
B.A backdoor Trojan
C.A fileless virus
D.A worm
AnswerB

A backdoor Trojan is designed to provide covert remote access to a compromised system, often establishing persistent communication channels with Command and Control (C2) servers. This communication frequently occurs over encrypted protocols like HTTPS to evade detection and blend with legitimate network traffic. The observed significant increase in outbound HTTPS traffic to multiple IP addresses is highly characteristic of a backdoor Trojan actively exfiltrating data, receiving commands, or updating its C2 infrastructure.

Why this answer

A backdoor Trojan is designed to give an attacker remote control over an infected system, often using outbound connections on common ports like 443 (HTTPS) to blend in with normal traffic. Since the server is not a web server and should not be initiating outbound HTTPS connections, this anomalous behavior strongly indicates a backdoor Trojan is exfiltrating data or receiving commands via encrypted channels.

Exam trap

The trap here is that candidates confuse a worm's network propagation behavior with a backdoor Trojan's command-and-control traffic, but the key differentiator is that the server is not a web server and the connections are outbound to multiple external IPs on a common encrypted port, which is classic C2 exfiltration, not self-replication.

How to eliminate wrong answers

Option A is wrong because a boot sector virus infects the Master Boot Record (MBR) and typically activates during system boot, not by generating outbound network traffic to external IPs. Option C is wrong because a fileless virus operates in memory (e.g., using PowerShell or WMI) and does not persistently create outbound connections on port 443; its primary trait is avoiding disk writes, not initiating stealthy command-and-control traffic. Option D is wrong because a worm self-replicates across networks using vulnerabilities or weak credentials, often causing widespread scanning or payload delivery, but its hallmark is propagation, not establishing a persistent backdoor for outbound data exfiltration on a single non-web server.

100
MCQhard

A security team detects that an internal host is sending ARP replies claiming to have the IP address of the default gateway. Which tool is MOST likely being used to perform this attack?

A.Nmap
B.tcpdump
C.Wireshark
D.Ettercap
AnswerD

Ettercap is a comprehensive suite for man-in-the-middle (MITM) attacks on LANs, specifically designed for ARP poisoning. It actively injects forged ARP replies into the network, tricking hosts into believing the attacker's MAC address is associated with the gateway's IP, and vice-versa. This redirection allows Ettercap to intercept, analyze, and even modify traffic between victims, making it a primary tool for detecting and executing ARP-based attacks.

Why this answer

Ettercap is a dedicated man-in-the-middle (MITM) attack tool that includes built-in ARP poisoning functionality. It sends forged ARP replies to associate the attacker's MAC address with the default gateway's IP, redirecting traffic through the attacker's host. This matches the described behavior of claiming the gateway's IP address via ARP replies.

Exam trap

The trap here is that candidates confuse passive monitoring tools (tcpdump, Wireshark) with active attack tools, or mistake Nmap's scanning capabilities for ARP spoofing, when only Ettercap is specifically designed for MITM via ARP poisoning.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning and enumeration tool used for port discovery and service detection, not for generating forged ARP replies. Option B is wrong because tcpdump is a command-line packet capture utility that passively captures traffic; it cannot actively inject ARP replies. Option C is wrong because Wireshark is a graphical packet analyzer used for deep inspection of captured packets, not for crafting or sending malicious ARP packets.

101
MCQmedium

A penetration tester uses a tool to perform ARP poisoning and then launches a man-in-the-middle attack. The tool also allows session hijacking and sniffing. Which of the following tools is being used?

A.Wireshark
B.tcpdump
C.Ettercap
D.Nmap
AnswerC

Ettercap performs ARP poisoning to place the attacker between hosts, then relays traffic while capturing credentials and hijacking sessions, satisfying the stem's combined requirement for man-in-the-middle, sniffing and session hijacking. Its integrated plugin architecture handles all three natively, unlike single-purpose sniffers or poisoning utilities.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on LANs, featuring built-in ARP poisoning, session hijacking, and sniffing capabilities. It actively intercepts traffic by spoofing ARP replies to redirect packets through the attacker's machine, enabling real-time manipulation of sessions. This matches the question's description of a tool that performs ARP poisoning, MITM attacks, session hijacking, and sniffing.

Exam trap

The trap here is that candidates often confuse Wireshark's passive sniffing capability with active MITM functionality, forgetting that Wireshark cannot perform ARP poisoning or session hijacking on its own.

How to eliminate wrong answers

Option A is wrong because Wireshark is a passive network protocol analyzer that captures and inspects packets but does not perform active attacks like ARP poisoning or session hijacking. Option B is wrong because tcpdump is a command-line packet capture tool that only dumps traffic for offline analysis, lacking any active manipulation or MITM capabilities. Option D is wrong because Nmap is a network discovery and security scanning tool used for port scanning and OS detection, not for ARP poisoning, session hijacking, or sniffing in an active MITM context.

102
MCQeasy

A system administrator receives a phone call from someone claiming to be from IT support, asking for the administrator's password to 'fix a server issue'. This is an example of which social engineering attack?

A.Vishing
B.Baiting
C.Phishing
D.Pretexting
AnswerD

Pretexting is a sophisticated social engineering attack where an attacker creates a believable, fabricated scenario, known as a 'pretext,' to manipulate a target into divulging sensitive information or performing a specific action. This often involves extensive research to build a convincing backstory and impersonate a legitimate individual or authority. The attacker maintains an interactive conversation, adapting the narrative to overcome skepticism and extract specific details, such as a password, under the guise of solving a problem or verifying identity.

Why this answer

Pretexting is a social engineering attack where the attacker fabricates a scenario (pretext) to manipulate the target into divulging sensitive information. In this case, the attacker impersonates IT support and invokes a fake server issue to create urgency, directly requesting the administrator's password. This aligns with the CEH definition of pretexting as a confidence-building deception, not a technical exploit.

Exam trap

The trap here is that candidates confuse the delivery method (phone call) with vishing, but the CEH exam distinguishes pretexting by the use of a fabricated scenario or false identity, regardless of the communication channel.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls to trick victims into revealing information, but the core attack here is the fabricated story (pretext), not the medium; vishing is a subset of phishing, and the question's emphasis is on the false identity and scenario. Option B is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim into a trap, not a direct request for credentials via a phone call. Option C is wrong because phishing typically uses electronic communication (email, SMS, or fake websites) to harvest credentials, not a live phone call with a constructed narrative; this is a voice-based pretexting scenario.

103
MCQmedium

During a penetration test, a security analyst runs the following command on a Linux system: ettercap -T -M arp:remote /192.168.1.1// /192.168.1.100//. What is the PRIMARY purpose of this command?

A.To spoof the DNS responses to redirect the target to a malicious site
B.To sniff all traffic on the network by enabling promiscuous mode on the interface
C.To perform a denial-of-service attack by flooding the network with ARP replies
D.To perform a man-in-the-middle attack between the gateway and the target host
AnswerD

The `ettercap -M arp:remote` command is specifically designed to execute a man-in-the-middle (MITM) attack by poisoning the ARP caches of both the target host and the network gateway. By sending forged ARP replies, the attacker's machine convinces the target that it is the gateway, and convinces the gateway that it is the target. This redirection ensures all traffic flowing between the target and the internet passes through the attacker, enabling interception and potential manipulation.

Why this answer

The command `ettercap -T -M arp:remote /192.168.1.1// /192.168.1.100//` uses ARP poisoning in remote mode to intercept traffic between the gateway (192.168.1.1) and the target host (192.168.1.100). By sending forged ARP replies to both devices, the attacker's machine becomes a man-in-the-middle, allowing it to capture, modify, or relay packets between them. The `-M arp:remote` flag specifically enables ARP poisoning for a MITM attack, not for DNS spoofing, promiscuous mode, or flooding.

Exam trap

The trap here is that candidates confuse ARP poisoning with DNS spoofing or assume the command is for passive sniffing, but the `-M arp:remote` flag explicitly indicates an active MITM attack, not a passive or flooding technique.

How to eliminate wrong answers

Option A is wrong because DNS spoofing requires a separate plugin (e.g., `ettercap -T -M arp:remote -P dns_spoof`) and is not the primary purpose of the base ARP poisoning command. Option B is wrong because enabling promiscuous mode is a passive operation (e.g., `ifconfig eth0 promisc`), while this command actively sends forged ARP packets to manipulate traffic flow. Option C is wrong because a denial-of-service attack via ARP flooding would require a different tool or flag (e.g., `arping -f` or `macof`), and the `-M arp:remote` flag is designed for bidirectional interception, not network saturation.

104
MCQhard

An analyst captures network traffic and sees a large number of packets with source IP 10.0.0.1, destination IP 192.168.1.1, TCP SYN flag set, with sequence numbers that appear incremental. The destination responds with SYN-ACK but the source never completes the handshake. Which attack is MOST likely occurring?

A.ARP poisoning
B.SYN flood
C.ICMP flood
D.DNS amplification
AnswerB

The flood of SYN packets with spoofed or unused source addresses, followed by incomplete handshakes, exhausts the target's half-open connection table. The destination's SYN-ACKs go unanswered because no real client exists, which is the defining signature of a SYN flood.

Why this answer

This behavior describes a classic SYN flood attack. The source (10.0.0.1) sends a high volume of TCP SYN packets with incremental sequence numbers to the target (192.168.1.1). The target responds with SYN-ACK packets, but the source never sends the final ACK to complete the three-way handshake.

This leaves the target with half-open connections that exhaust its connection table, denying service to legitimate traffic.

Exam trap

The trap here is that candidates may confuse a SYN flood with a TCP three-way handshake completion failure due to a firewall or routing issue, but the key indicator is the large number of SYN packets with no final ACK, which is the hallmark of a deliberate DoS attack, not a network glitch.

How to eliminate wrong answers

Option A is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host, not sending TCP SYN packets with incremental sequence numbers. Option C is wrong because an ICMP flood uses ICMP echo request (ping) packets, not TCP SYN packets, to overwhelm a target. Option D is wrong because DNS amplification exploits open DNS resolvers to send large DNS response packets to a spoofed victim IP, using UDP, not TCP SYN packets.

105
MCQeasy

Which type of malware is characterized by its ability to spread without requiring a host file and can replicate across networks automatically?

A.Virus
B.Trojan
C.Worm
D.Ransomware
AnswerC

A worm is a standalone malicious program designed to self-replicate and propagate autonomously across computer networks without requiring a host program or user intervention. It exploits network vulnerabilities or configuration weaknesses to spread from one system to another, consuming bandwidth and system resources. This self-replicating capability is its defining characteristic, allowing it to infect numerous machines rapidly.

Why this answer

A worm is a standalone malware program that replicates itself across networks without requiring a host file or user intervention. It exploits network vulnerabilities, such as unpatched services or weak credentials, to propagate automatically, often using protocols like SMB, RDP, or email transport mechanisms.

Exam trap

The trap here is that candidates often confuse a worm's self-replication with a virus's need for a host file, leading them to select 'Virus' because they associate malware spread with file infection, ignoring the worm's autonomous network propagation capability.

How to eliminate wrong answers

Option A is wrong because a virus requires a host file (e.g., an executable or document) to attach itself and relies on user action (e.g., opening a file) to spread, not automatic network replication. Option B is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on social engineering to trick users into executing it. Option D is wrong because ransomware encrypts files for extortion and typically spreads via email attachments or exploits, but it is not defined by autonomous network propagation without a host file.

106
Multi-Selectmedium

Which TWO of the following are examples of social engineering attacks? (Select two)

Select 2 answers
A.Pharming
B.Pretexting
C.SYN flood
D.Brute force attack
E.Vishing
AnswersB, E

Pretexting is a social engineering attack where the attacker invents a fabricated scenario, often impersonating a trusted figure, to manipulate a victim into divulging information or performing actions. It relies on psychological manipulation rather than technical exploits, satisfying the question's requirement for a social engineering example.

Why this answer

Pretexting (B) is a social engineering attack because the attacker fabricates a believable scenario or false identity (a 'pretext') to manipulate a human target into divulging information or performing an action, exploiting trust rather than technical flaws. Vishing (E) is also social engineering, as it uses voice communication—typically a phone call or VoIP—to impersonate a trusted party and trick the victim into revealing credentials, payment data, or other sensitive information. The remaining options are technical attacks, not social engineering: pharming (A) redirects users to fraudulent websites via DNS poisoning or host file modification, SYN flood (C) is a network-layer denial-of-service attack abusing the TCP three-way handshake, and brute force (D) is a cryptographic or authentication attack that systematically tries keys or passwords.

Exam trap

The trap here is that candidates may confuse pharming (a technical redirection attack) with social engineering, but pharming does not involve direct human interaction or psychological manipulation, which is the defining characteristic of social engineering attacks.

107
MCQhard

During a penetration test, an analyst uses a tool that sends forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This technique allows the attacker to intercept traffic. Which tool is commonly used for this purpose?

A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA

Ettercap performs ARP poisoning by forging ARP replies that bind the attacker's MAC address to the gateway's IP, placing the attacker inline to intercept traffic. Its built-in sniffing and MITM plugins make it the standard tool for this gateway-spoofing scenario.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on LAN. It supports ARP poisoning, where it sends forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This causes the target's traffic destined for the gateway to be sent to the attacker, allowing interception and modification of packets.

Exam trap

The trap here is that candidates often confuse passive sniffing tools (like Wireshark or tcpdump) with active attack tools, assuming any packet capture tool can also inject packets, but only dedicated MITM tools like Ettercap implement ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets passively; it does not send forged ARP replies or actively manipulate network traffic. Option C is wrong because Nmap is a network discovery and security scanning tool used for port scanning and service enumeration; it does not perform ARP spoofing or man-in-the-middle attacks. Option D is wrong because tcpdump is a command-line packet analyzer used for capturing and displaying network traffic; it lacks the ability to inject forged ARP packets or conduct active interception attacks.

108
MCQmedium

A security analyst reviews a sandbox report for a suspicious executable. The report shows that the executable modified the Windows registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to add a new entry pointing to itself. This action is characteristic of which type of malware?

A.Logic bomb
B.Backdoor Trojan
C.Ransomware
D.Adware
AnswerB

Backdoor Trojans commonly use registry run keys for persistence.

Why this answer

The registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run is a standard autostart location used by Windows to launch programs at system boot. A backdoor Trojan commonly adds itself to this key to achieve persistence, ensuring it runs every time the system starts, which allows an attacker to maintain remote access. This behavior is a hallmark of backdoor Trojans, not other malware types.

Exam trap

The trap here is that candidates might associate any registry modification with ransomware or adware, but the specific action of adding itself to the Run key for persistence is most characteristic of a backdoor Trojan, not the other options.

How to eliminate wrong answers

Option A is wrong because a logic bomb is a piece of code that executes a malicious action when a specific condition is met (e.g., a date or file deletion), not a persistent autostart mechanism via registry modification. Option C is wrong because ransomware typically modifies registry keys to disable security features or alter system behavior (e.g., changing file associations or disabling recovery options), but its primary goal is encryption and ransom, not adding itself to Run for persistence—though some ransomware may do so, it is not the characteristic action described. Option D is wrong because adware usually modifies browser settings or injects advertisements, and while it may use registry Run keys for persistence, its core behavior is displaying ads, not establishing a backdoor for remote access.

109
MCQmedium

A security analyst runs the command 'tcpdump -i eth0 -n host 10.0.0.5 and port 80' and sees many packets with the SYN flag set but no corresponding ACK. Which attack is likely occurring?

A.SYN flood
B.ICMP flood
C.UDP flood
D.Ping of Death
AnswerA

A SYN flood is characterized by an attacker sending a large volume of TCP SYN packets to a target server without completing the three-way handshake. The tcpdump -i eth0 -n host command would reveal a high rate of incoming TCP packets with the SYN flag set, directed at the specified host, but without corresponding SYN-ACK or ACK packets originating from the target. This pattern indicates numerous half-open connections accumulating on the target, exhausting its connection table resources.

Why this answer

The command captures TCP packets on port 80 with the SYN flag set but no corresponding ACK, which indicates that the target is receiving SYN requests but never completing the three-way handshake. This is the hallmark of a SYN flood attack, where the attacker sends a high volume of SYN packets to exhaust the server's connection queue, preventing legitimate connections.

Exam trap

The trap here is that candidates confuse a SYN flood with a generic 'flood' attack (like ICMP or UDP flood) because they focus on the word 'flood' rather than the specific TCP handshake behavior indicated by the SYN flag without ACK.

How to eliminate wrong answers

Option B is wrong because an ICMP flood involves sending a high volume of ICMP echo request (ping) packets, not TCP SYN packets, and would not be captured by a filter for port 80. Option C is wrong because a UDP flood targets UDP ports with a high volume of UDP datagrams, not TCP SYN packets, and would not match the 'port 80' filter (which is TCP-specific). Option D is wrong because a Ping of Death attack sends a malformed oversized ICMP packet to cause a buffer overflow, not TCP SYN packets, and is not related to incomplete handshakes.

110
Multi-Selectmedium

Which TWO of the following are techniques used in session hijacking? (Choose 2)

Select 2 answers
A.Cookie theft
B.MAC flooding
C.ARP poisoning
D.TCP sequence prediction
E.DNS spoofing
AnswersA, D

Cookie theft directly enables session hijacking by capturing the session identifier stored in a browser cookie, allowing an attacker to impersonate the authenticated user without credentials. This satisfies the stem's requirement for a session hijacking technique, as possession of a valid session token grants immediate access to the victim's active session.

Why this answer

Cookie theft (A) is a session hijacking technique because an attacker who captures a valid session cookie — for example via XSS, sniffing an unencrypted HTTP session, or malware — can replay it to impersonate the authenticated user without knowing credentials. TCP sequence prediction (D) is also a session hijacking technique: the attacker guesses the next ISN/sequence and acknowledgment numbers to inject packets into an established TCP session, spoofing the victim's address and taking over the connection. MAC flooding (B) is a Layer 2 switch attack that overflows the CAM table to force hub-like flooding; it enables sniffing but is not itself session hijacking.

ARP poisoning (C) is a man-in-the-middle technique that redirects traffic by falsifying IP-to-MAC mappings; it can facilitate hijacking but is not the hijacking technique itself. DNS spoofing (E) forges DNS responses to redirect name resolution to a malicious host, which is a redirection/phishing technique rather than session hijacking.

Exam trap

EC-CEH often tests the distinction between session hijacking (directly taking over an active session) and network-level attacks (like ARP poisoning or MAC flooding) that merely enable interception or sniffing, causing candidates to confuse enabling techniques with the hijacking technique itself.

111
MCQhard

An analyst runs the following command: `tcpdump -i eth0 src host 192.168.1.10 and dst port 80 -w http_traffic.pcap`. What is the primary purpose of this command?

A.To perform a man-in-the-middle attack on HTTP traffic
B.To capture all traffic on eth0 and display it in real-time
C.To capture only HTTP traffic from a specific source IP and save it to a file
D.To analyze the payload of HTTP packets in real-time
AnswerC

This option accurately describes the command's functionality. The `-i eth0` flag specifies the network interface for capture. The `src host 192.168.1.10` filter ensures only packets originating from that specific IP address are captured, while `dst port 80` further narrows the scope to only include HTTP traffic (standard port 80). Finally, the `-w capture.pcap` flag instructs tcpdump to save all filtered packets to a file named `capture.pcap` for subsequent offline analysis.

Why this answer

The command `tcpdump -i eth0 src host 192.168.1.10 and dst port 80 -w http_traffic.pcap` uses a BPF (Berkeley Packet Filter) expression to capture only packets originating from source IP 192.168.1.10 and destined for TCP port 80 (HTTP). The `-w` flag writes the filtered packets directly to a pcap file, not to standard output, making the primary purpose to capture and save specific HTTP traffic for later analysis.

Exam trap

The trap here is that candidates confuse the `-w` (write to file) option with `-r` (read from file) or assume tcpdump displays output in real-time by default, leading them to choose Option B, even though the filter and `-w` flag clearly indicate a targeted capture to a file.

How to eliminate wrong answers

Option A is wrong because tcpdump is a passive packet capture tool; it does not intercept, modify, or relay packets between two parties, which are required for a man-in-the-middle attack. Option B is wrong because the `-w` flag suppresses real-time display and writes to a file, and the filter `src host 192.168.1.10 and dst port 80` limits capture to specific traffic, not all traffic on eth0. Option D is wrong because tcpdump captures raw packet headers and payloads but does not perform application-layer payload analysis or reassembly; it simply records the bytes as seen on the wire.

112
MCQmedium

An organization wants to test its employees' susceptibility to social engineering by sending fake emails that appear to come from the IT department, requesting password resets. Which tool would be MOST effective for conducting this test?

A.Social Engineering Toolkit (SET)
B.Wireshark
C.Metasploit
D.Nmap
AnswerA

The Social Engineering Toolkit (SET) is purpose-built for simulating various social engineering attacks, making it the ideal choice for testing employee susceptibility. It provides modules for spear phishing, credential harvesting, web jacking, and infectious media generator attacks, directly targeting the human element. By deploying these simulated threats, organizations can assess how employees react to realistic social engineering tactics and identify areas for security awareness training improvement.

Why this answer

The Social Engineering Toolkit (SET) is specifically designed for social engineering attacks, including crafting convincing phishing emails that mimic internal departments like IT. It automates the creation of fake login pages and email templates, making it the most effective tool for testing employee susceptibility to password reset requests.

Exam trap

The trap here is that candidates often confuse Metasploit's exploit capabilities with social engineering, overlooking that SET is the dedicated tool for crafting and executing phishing campaigns, not just delivering payloads.

How to eliminate wrong answers

Option B (Wireshark) is wrong because it is a network protocol analyzer used for capturing and inspecting packets, not for generating social engineering attacks. Option C (Metasploit) is wrong because, while it can deliver payloads via exploits, its primary focus is on exploiting system vulnerabilities rather than crafting social engineering lures like fake IT emails. Option D (Nmap) is wrong because it is a network scanning tool used for port discovery and service enumeration, with no capability to create or send phishing emails.

113
MCQhard

An incident response team discovers a suspicious executable on a compromised workstation. They want to analyze the malware without executing it. Which of the following techniques would be MOST appropriate for this initial analysis?

A.Capturing network traffic with Wireshark during execution
B.Using the 'strings' command to extract embedded text
C.Monitoring process behavior with Process Monitor
D.Running the executable in a sandboxed environment
AnswerB

Using the 'strings' command is a quintessential static analysis method as it involves examining the binary file directly on disk without executing it. This command extracts sequences of printable ASCII or Unicode characters embedded within the executable, which can reveal valuable clues such as file paths, URLs, API function names, or error messages hardcoded by the malware author.

Why this answer

The 'strings' command extracts human-readable text from a binary file without executing it, making it ideal for static analysis. This technique can reveal indicators such as IP addresses, domain names, file paths, registry keys, or embedded commands that help classify the malware's purpose and capabilities without triggering its payload.

Exam trap

The trap here is that candidates confuse 'dynamic analysis' techniques (like sandboxing or process monitoring) with 'static analysis', failing to recognize that the question's constraint 'without executing it' eliminates any option that requires runtime behavior.

How to eliminate wrong answers

Option A is wrong because capturing network traffic with Wireshark during execution requires the malware to run, which violates the requirement to analyze without executing. Option C is wrong because Process Monitor monitors real-time process behavior, which also requires the executable to be running. Option D is wrong because running the executable in a sandboxed environment still involves execution, which the question explicitly prohibits.

114
MCQhard

An organization experiences a DDoS attack where the attacker sends many incomplete HTTP requests that keep connections open, exhausting the server's connection pool. Which attack technique is being used?

A.UDP flood
B.HTTP flood
C.SYN flood
D.Slowloris
AnswerD

Slowloris opens many partial HTTP requests, sending incomplete headers and never finishing them. The server holds each connection open awaiting the remainder, exhausting its connection pool while consuming minimal attacker bandwidth, matching the incomplete-request symptom described.

Why this answer

Slowloris is a DDoS attack that works by opening multiple connections to the target server and sending partial HTTP requests, never completing them. The server keeps these connections open waiting for the rest of the request, eventually exhausting the connection pool and denying service to legitimate users. This matches the description of incomplete HTTP requests keeping connections open.

Exam trap

In CEH, candidates often confuse a SYN flood (TCP layer, half-open connections) with Slowloris (HTTP layer, partial requests). Slowloris keeps connections open by sending incomplete HTTP headers, targeting the application layer, unlike SYN flood which operates at the transport layer.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends large volumes of UDP packets to random ports, overwhelming the server's bandwidth or processing capacity, not by keeping HTTP connections open. Option B is wrong because an HTTP flood sends complete, legitimate-looking HTTP requests at high volume to overwhelm the server's processing resources, not by leaving connections incomplete. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting the server's TCP connection backlog, not by sending incomplete HTTP requests.

115
Multi-Selectmedium

Which TWO of the following are characteristics of a SYN flood attack? (Select 2)

Select 2 answers
A.It exploits the TCP three-way handshake
B.It uses UDP amplification
C.It sends a large number of ICMP echo requests
D.It requires the attacker to have a botnet
E.It results in a backlog of incomplete connections
AnswersA, E

A SYN flood abuses the TCP three-way handshake: the attacker sends many SYN packets, often with spoofed source addresses, so the server allocates half-open connections and replies with SYN-ACKs that are never completed, exhausting the backlog queue and denying service to legitimate clients.

Why this answer

Option A is correct because a SYN flood specifically abuses the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, and the server replies with SYN-ACK while waiting for the final ACK that never arrives. Option E is correct because those half-open connections accumulate in the server's SYN backlog queue, exhausting available connection slots and preventing legitimate clients from completing the handshake. Option B is incorrect because UDP amplification describes volumetric reflection attacks such as DNS or NTP amplification, not the TCP handshake-based SYN flood.

Option C is incorrect because a large volume of ICMP echo requests describes an ICMP flood or smurf-style attack, not a SYN flood. Option D is incorrect because a SYN flood can be launched from a single host with spoofed source IP addresses and does not inherently require a botnet.

Exam trap

The CEH exam often tests the misconception that a SYN flood requires a botnet or that it uses UDP amplification, but the core characteristic is the exploitation of the TCP three-way handshake and the resulting backlog of incomplete connections.

116
MCQmedium

A security analyst observes a sudden surge in incoming UDP traffic to the company's DNS servers from multiple external IP addresses. The packets appear to be DNS queries with spoofed source IPs. Which type of DDoS attack is MOST likely occurring?

A.SYN flood
B.DNS amplification
C.UDP flood
D.ICMP flood
AnswerB

DNS amplification is a highly effective distributed denial-of-service (DDoS) attack where attackers send small UDP DNS queries with a spoofed source IP address (the victim's IP) to numerous open DNS resolvers. These resolvers then respond with much larger UDP packets containing DNS records, directed back to the spoofed victim. This technique leverages the amplification factor of DNS responses to overwhelm the target with a massive surge of incoming UDP traffic, typically on port 53.

Why this answer

The attack described involves DNS queries with spoofed source IPs sent to a DNS server, which then responds with large replies to the victim (the spoofed IP). This is a classic DNS amplification attack, a type of reflection-based DDoS that exploits the large response-to-query ratio (e.g., an ANY query can yield a response up to 70x larger) to overwhelm the target. The surge in incoming UDP traffic to the DNS server is the attacker's queries, while the amplified responses are directed at the spoofed victim.

Exam trap

The trap here is that candidates confuse a simple UDP flood (direct traffic) with a DNS amplification attack, missing the key indicator of spoofed source IPs and the reflection/amplification mechanism that distinguishes it.

How to eliminate wrong answers

Option A is wrong because a SYN flood targets the TCP three-way handshake by sending incomplete SYN packets, not UDP-based DNS queries with spoofed source IPs. Option C is wrong because a UDP flood is a direct volumetric attack where the attacker sends high volumes of UDP packets to a target, but it does not involve DNS query/response amplification or spoofed source IPs to reflect traffic off a legitimate server. Option D is wrong because an ICMP flood uses ICMP echo request (ping) packets, not UDP DNS queries, and does not leverage amplification or reflection from a DNS server.

117
MCQhard

A security analyst captures network traffic and sees a sequence of ARP replies with the same IP address mapping to different MAC addresses within a short period. Which attack is indicated?

A.DNS spoofing
B.ARP poisoning
C.DHCP starvation
D.MAC flooding
AnswerB

ARP poisoning, also known as ARP spoofing, is a man-in-the-middle attack where an attacker sends forged ARP reply messages onto a local area network. These malicious replies associate the attacker's MAC address with the IP address of another host, such as the default gateway or another workstation. By continuously sending these fake ARP replies, the attacker can trick multiple devices into updating their ARP caches with incorrect information, thereby redirecting traffic intended for the legitimate IP to the attacker's machine. This directly explains the observation of multiple ARP replies for one IP.

Why this answer

B is correct because ARP poisoning (also called ARP spoofing) involves sending forged ARP replies that map a target IP address (e.g., the default gateway) to the attacker's MAC address. The rapid sequence of ARP replies with the same IP but different MACs is a classic indicator of an active ARP poisoning attack, where the attacker floods the network to corrupt the ARP cache of hosts.

Exam trap

The trap here is that candidates confuse ARP poisoning with MAC flooding because both involve MAC addresses and network manipulation, but MAC flooding targets the switch's CAM table, not the host's ARP cache, and uses many different MACs, not the same IP mapped to multiple MACs.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS responses to redirect domain name lookups, not ARP tables; it operates at Layer 7 (application) using UDP port 53, not Layer 2/3 ARP messages. Option C is wrong because DHCP starvation floods a DHCP server with fake DISCOVER messages to exhaust its IP address pool, causing denial of service; it does not involve ARP replies or MAC-to-IP mapping changes. Option D is wrong because MAC flooding overwhelms a switch's CAM table with fake MAC addresses to force it into fail-open mode (hub mode), enabling packet sniffing; it does not target ARP caches or use ARP replies with the same IP to different MACs.

118
Multi-Selectmedium

A network administrator notices unusual traffic patterns: the internal DNS server is receiving large DNS queries with the source IP spoofed to appear as the internal DNS server itself. The queries appear to be amplification requests. Which TWO characteristics describe this attack?

Select 2 answers
A.It is a protocol-specific attack targeting TCP SYN packets
B.It relies on open DNS resolvers to amplify traffic
C.It exploits the ARP protocol to redirect traffic
D.It is a form of DDoS attack
E.It requires the attacker to be on the same subnet as the victim
AnswersB, D

This is correct because DNS amplification attacks exploit misconfigured or intentionally open DNS resolvers that are accessible on the internet. Attackers send small DNS queries to these resolvers, spoofing the victim's IP address as the source. The open resolvers then respond with significantly larger DNS records to the unsuspecting victim, effectively multiplying the attacker's initial traffic volume.

Why this answer

The attack described relies on open DNS resolvers to amplify traffic. The attacker sends small DNS queries with a spoofed source IP (the victim's DNS server), causing the open resolver to send large responses to the victim, thus amplifying the traffic volume. This is a classic DNS amplification attack, which is a type of reflection attack that exploits the UDP protocol and the fact that DNS response sizes can be significantly larger than query sizes.

Exam trap

The trap here is that candidates may confuse DNS amplification with other reflection attacks (e.g., NTP amplification) or mistakenly think the attacker must be on the same subnet, when in fact IP spoofing allows the attack to originate from anywhere.

119
MCQhard

A penetration tester wants to perform a stealth scan without completing the TCP three-way handshake. The target is a web server on port 80. The tester uses Nmap with the -sS flag. What is the expected behavior if the port is open?

A.The tester receives a SYN/ACK and sends an RST to tear down the connection.
B.The tester receives an RST, indicating the port is closed.
C.The tester receives no response, indicating a filtered port.
D.The tester receives a SYN/ACK and sends an ACK to establish the connection.
AnswerA

A SYN scan, often referred to as a half-open scan, initiates a TCP handshake by sending a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK packet. To avoid logging a full connection on the target system and thus maintain stealth, the penetration tester immediately sends an RST (reset) packet, tearing down the nascent connection before the three-way handshake completes. This allows port status determination without fully establishing a session.

Why this answer

The -sS flag in Nmap performs a SYN stealth scan, which sends a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK, and the tester's operating system kernel automatically sends an RST to tear down the connection before the three-way handshake completes. This avoids establishing a full TCP connection, making the scan less detectable by some intrusion detection systems.

Exam trap

The trap here is that candidates may confuse the SYN scan with a full connect scan (-sT) and think an ACK is sent to complete the handshake, or they may mistakenly believe that receiving an RST indicates an open port.

How to eliminate wrong answers

Option B is wrong because receiving an RST indicates the port is closed, not open; in a SYN scan, a closed port responds with an RST. Option C is wrong because no response typically indicates a filtered port (e.g., blocked by a firewall), not the behavior of an open port. Option D is wrong because sending an ACK after receiving a SYN/ACK would complete the three-way handshake and establish a full connection, which defeats the purpose of a stealth scan and is not what Nmap's -sS does.

120
MCQmedium

Which DoS attack exploits the HTTP protocol by sending partial HTTP requests to keep connections open, exhausting server resources?

A.SYN flood
B.Slowloris
C.Ping of Death
D.UDP flood
AnswerB

Slowloris opens many connections to the target web server and sends partial HTTP headers repeatedly, never completing requests. This holds sockets open, exhausting the server's connection pool and denying legitimate clients, matching the stem's partial-request, resource-exhaustion constraint.

Why this answer

Slowloris is a DoS attack that exploits HTTP by opening multiple connections to the target web server and sending partial HTTP requests (e.g., incomplete headers) while never completing them. The server keeps each connection open, waiting for the rest of the request, eventually exhausting its connection pool and denying service to legitimate users.

Exam trap

EC-Council often tests the distinction between network-layer attacks (SYN flood, UDP flood) and application-layer attacks (Slowloris), so candidates mistakenly choose SYN flood because they associate 'partial requests' with TCP handshake manipulation rather than HTTP header manipulation.

How to eliminate wrong answers

Option A is wrong because SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting the server's half-open connection backlog, not HTTP protocol behavior. Option C is wrong because Ping of Death crashes a system by sending an oversized ICMP packet that exceeds the maximum IP packet size, causing buffer overflow, not HTTP connection exhaustion. Option D is wrong because UDP flood overwhelms a target with a high volume of UDP packets to random ports, consuming bandwidth and processing resources, not HTTP connections.

121
MCQmedium

An attacker calls a company's help desk, pretending to be a new employee who forgot his username and password. The attacker provides some employee details gleaned from social media and convinces the help desk to reset the password. Which social engineering technique is being used?

A.Tailgating
B.Quid pro quo
C.Baiting
D.Pretexting
AnswerD

Pretexting is the fabrication of a believable scenario or identity to manipulate the target into complying. The attacker invents a new-employee story, reinforces it with harvested employee details, and thereby convinces the help desk to reset credentials, exploiting trust in the invented pretext.

Why this answer

Pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to manipulate the target into performing an action. In this case, the attacker pretends to be a new employee, using details from social media to establish credibility, and convinces the help desk to reset credentials. This is a classic example of pretexting because the entire interaction is based on a false identity and fabricated story.

Exam trap

The trap here is confusing pretexting with baiting because both involve deception, but baiting relies on a lure (e.g., 'free movie download') while pretexting relies on a fabricated scenario (e.g., 'I am a new employee').

How to eliminate wrong answers

Option A is wrong because tailgating involves physically following an authorized person into a restricted area without proper authentication, not a phone-based impersonation. Option B is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), not simply pretending to be an employee. Option C is wrong because baiting uses a physical or digital lure (e.g., infected USB drive, free download) to trick the victim, not a fabricated identity or story.

122
MCQhard

During a penetration test, you capture the following output: 'HTTP/1.1 200 OK ... Set-Cookie: sessionid=abc123; path=/'. You then send a request with a modified cookie value 'sessionid=abc124' and receive a valid session. Which type of vulnerability has been exploited?

A.Cross-site scripting
B.SQL injection
C.Man-in-the-middle attack
D.Session hijacking via cookie prediction
AnswerD

Session hijacking via cookie prediction occurs when an attacker successfully guesses or calculates a valid session identifier (Session ID) that an application uses to maintain a user's authenticated state. By setting their own browser's cookie to this predicted, valid Session ID, the attacker can bypass the login process and assume the identity of the legitimate user, gaining unauthorized access to their active session. This method specifically exploits weak or predictable session ID generation algorithms.

Why this answer

The attacker successfully predicted or guessed a valid session identifier (sessionid=abc124) after observing the pattern of the original session cookie (sessionid=abc123). This is a classic session hijacking via cookie prediction attack, where weak or sequential session IDs allow an attacker to impersonate another user's session without needing to intercept traffic or inject code.

Exam trap

The trap here is that candidates may confuse session hijacking via cookie prediction with a man-in-the-middle attack, but MITM requires active interception of traffic, whereas cookie prediction relies solely on guessing or enumerating session IDs from observed patterns.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) requires injecting malicious scripts into a web page viewed by another user, not simply modifying a cookie value in a direct request. Option B is wrong because SQL injection involves manipulating SQL queries through input fields to extract or modify database data, not altering session cookies. Option C is wrong because a man-in-the-middle attack requires intercepting and potentially modifying traffic between the client and server, whereas here the attacker directly sends a modified request without needing to be positioned in the communication path.

123
MCQmedium

Which of the following is the BEST defense against a TCP SYN flood attack?

A.Ingress filtering
C.Rate limiting
D.SYN cookies
AnswerD

SYN cookies are a robust defense mechanism against TCP SYN floods, operating by enabling a server to respond to SYN requests without allocating resources for a half-open connection immediately. Instead, the server crafts an initial sequence number (ISN) for the SYN-ACK packet that encodes information about the connection, including the client's IP, port, and the server's ISN. Only when the client responds with a valid ACK packet, using the derived sequence number, does the server then reconstruct the connection state, effectively deferring resource allocation until the three-way handshake is complete and verified. This stateless approach prevents the server's connection table from being overwhelmed.

Why this answer

SYN cookies are the best defense against TCP SYN flood attacks because they allow the server to avoid allocating resources for half-open connections until the handshake is completed. When a SYN cookie is used, the server encodes connection state information into the initial sequence number (ISN) sent in the SYN-ACK, and only commits memory upon receiving a valid ACK from the client. This prevents the exhaustion of the SYN backlog queue, which is the primary target of a SYN flood.

Exam trap

The CEH exam often tests the misconception that rate limiting or ingress filtering alone can stop a SYN flood, but the key is that SYN cookies directly prevent the resource exhaustion of the TCP backlog queue, which is the core vulnerability exploited in this attack.

How to eliminate wrong answers

Option A is wrong because ingress filtering (RFC 2827/3704) prevents IP spoofing by dropping packets with source addresses not matching the expected inbound prefix, but it does not mitigate the volume of SYN packets or protect the server's connection queue once the attack reaches it. Option B is wrong because an intrusion detection system (IDS) can only detect and alert on a SYN flood pattern, not actively prevent it from consuming server resources; it lacks the ability to modify TCP handshake behavior or queue management. Option C is wrong because rate limiting can reduce the impact of a flood by capping incoming SYN packets, but it is a blunt instrument that may drop legitimate traffic and does not address the fundamental resource exhaustion of the SYN backlog; SYN cookies provide a more granular, per-connection defense.

124
MCQeasy

A security analyst discovers a file named invoice.exe in an email attachment. Static analysis with PEiD indicates the file is packed with UPX. What is the BEST next step in analyzing this malware?

A.Execute the packed file on a production server
B.Unpack the file with UPX and then perform static analysis
C.Submit the packed file directly to VirusTotal
D.Delete the file immediately
AnswerB

UPX packing compresses and obscures the original executable, so strings and imports reveal little until the layer is removed. Unpacking restores the original code, enabling meaningful static analysis of imports, strings and PE structure before any dynamic execution is attempted.

Why this answer

B is correct because UPX-packed executables cannot be properly analyzed statically; the code is compressed and obfuscated. Unpacking with the UPX tool restores the original binary, enabling accurate static analysis of imports, strings, and structure. This step is essential before any dynamic analysis or submission to sandboxes.

Exam trap

EC-CEH often tests the misconception that static analysis can be performed on packed binaries without unpacking, or that immediate deletion or submission to VirusTotal is the best response, ignoring the need for evidence preservation and thorough analysis.

How to eliminate wrong answers

Option A is wrong because executing packed malware on a production server risks infection and lateral movement, violating containment protocols. Option C is wrong because submitting a packed file to VirusTotal may yield incomplete detection results, as many AV engines may not unpack it correctly, and it could alert threat actors if the sample is unique. Option D is wrong because deleting the file immediately destroys evidence and prevents further analysis needed for incident response and threat intelligence.

125
MCQmedium

A security analyst runs 'strings malware.exe' and finds several URLs and IP addresses. The analyst then uploads the file to VirusTotal and gets a detection ratio of 5/70. What type of analysis has been performed?

A.Static analysis
B.Memory analysis
C.Reverse engineering
D.Dynamic analysis
AnswerA

Extracting printable strings from a binary without executing it is static analysis, satisfying the stem's non-execution constraint. VirusTotal scanning inspects the file's bytes and signatures rather than running it, so both techniques remain static. Dynamic analysis would require executing malware.exe in a sandbox and observing runtime behaviour such as network connections.

Why this answer

The analyst used the 'strings' command to extract readable text from the binary without executing it, and then uploaded the file to VirusTotal for signature-based scanning. Both actions examine the file's static properties (embedded strings, hash-based detection) without running the code, which defines static analysis. Dynamic analysis would require executing the malware in a sandbox to observe runtime behavior.

Exam trap

EC-CEH often tests the distinction between static and dynamic analysis by describing actions that involve file inspection (like 'strings' and VirusTotal uploads) and expecting candidates to recognize that no execution occurred, thus ruling out dynamic analysis.

How to eliminate wrong answers

Option B is wrong because memory analysis involves examining RAM dumps (e.g., using Volatility) to find artifacts of running processes, injected code, or network connections, not static file inspection. Option C is wrong because reverse engineering typically involves disassembling or decompiling the binary (e.g., with IDA Pro or Ghidra) to understand its logic, not just running 'strings' or checking VirusTotal signatures. Option D is wrong because dynamic analysis requires executing the malware in a controlled environment (sandbox) to monitor API calls, registry changes, and network traffic, which was not performed here.

126
Multi-Selecthard

Which THREE of the following are effective DDoS mitigation techniques?

Select 3 answers
A.IP blacklisting
B.Increasing server resources
C.Scrubbing centers
D.Rate limiting
E.Anycast routing
AnswersC, D, E

Scrubbing centers are specialized, high-capacity network infrastructures designed to filter and clean malicious traffic before it reaches the protected target. These centers ingest all incoming traffic, analyze it for known attack patterns and anomalies across various layers, and then forward only the legitimate, clean traffic to the origin server. This offloads the attack burden from the target's infrastructure, ensuring service continuity.

Why this answer

Scrubbing centers (C) are correct because they divert and filter malicious traffic through specialized cleaning appliances before forwarding only legitimate traffic to the origin, which is a core DDoS mitigation strategy. Rate limiting (D) is correct because it caps the number of requests or connections per source or service, preventing volumetric and application-layer floods from overwhelming resources. Anycast routing (E) is correct because it distributes traffic across multiple geographically dispersed nodes sharing the same IP, dispersing attack volume and enabling closer filtering and absorption.

IP blacklisting (A) is not effective as a primary DDoS mitigation because attackers spoof or rotate source IPs, making blocklists trivial to bypass. Increasing server resources (B) only raises the attack threshold temporarily and does not stop the flood, so it is not a true mitigation technique.

Exam trap

The CEH exam often tests the misconception that IP blacklisting is a viable DDoS mitigation technique, but candidates must remember that blacklisting is ineffective against distributed, spoofed-source attacks where the attacker can easily change IP addresses.

127
MCQmedium

Which tool would a penetration tester MOST likely use to perform ARP poisoning and conduct a man-in-the-middle attack on a local network?

A.Wireshark
B.Nmap
C.tcpdump
D.Ettercap
AnswerD

Ettercap is a comprehensive suite for man-in-the-middle (MITM) attacks on a LAN, specifically designed to intercept traffic, perform live content filtering, and establish various forms of active and passive eavesdropping. Its core functionality includes robust ARP poisoning capabilities, allowing it to redirect traffic between two hosts through the attacker's machine by sending forged ARP replies. This enables the penetration tester to intercept, modify, and inject data into network communications, making it the ideal tool for demonstrating MITM vulnerabilities.

Why this answer

Ettercap is a dedicated suite for man-in-the-middle attacks on LANs, with built-in support for ARP poisoning. It actively sends forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host, allowing interception of traffic between two hosts. This makes it the most direct and purpose-built tool for the task described.

Exam trap

EC-CEH often tests the distinction between passive monitoring tools (Wireshark, tcpdump) and active attack tools (Ettercap), leading candidates to mistakenly choose a packet sniffer when the question explicitly requires performing an active man-in-the-middle attack.

How to eliminate wrong answers

Option A is wrong because Wireshark is a passive packet analyzer that captures and inspects traffic but cannot inject or modify packets to perform ARP poisoning. Option B is wrong because Nmap is a network scanner used for host discovery and port enumeration, not for active interception or ARP cache manipulation. Option C is wrong because tcpdump is a command-line packet capture tool that, like Wireshark, passively dumps traffic and lacks the ability to send forged ARP packets to redirect flows.

128
MCQeasy

A security administrator notices that the network switch is broadcasting traffic to all ports as if it were a hub. The switch logs show a sudden flood of packets with random MAC addresses. Which attack is MOST likely occurring?

A.SYN flood
B.MAC flooding
C.ARP poisoning
D.DNS amplification
AnswerB

MAC flooding overwhelms a network switch's Content Addressable Memory (CAM) table by rapidly sending frames with unique, spoofed source MAC addresses. When the CAM table, which stores MAC-to-port mappings, becomes full, the switch can no longer learn new addresses and reverts to broadcasting all incoming frames out of every port within the VLAN. This effectively transforms the switch into a hub-like device, allowing an attacker to intercept traffic intended for other hosts.

Why this answer

B is correct because MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table. By sending a flood of packets with random source MAC addresses, the attacker fills the CAM table, forcing the switch to fail-open into hub mode (broadcasting all traffic to all ports) so that the attacker can capture frames not originally destined for their port.

Exam trap

The trap here is that candidates confuse MAC flooding with ARP poisoning because both involve MAC addresses, but MAC flooding targets the switch's CAM table at Layer 2, while ARP poisoning manipulates IP-to-MAC mappings at Layer 3.

How to eliminate wrong answers

Option A is wrong because a SYN flood is a denial-of-service attack that exhausts server resources by sending many TCP SYN requests without completing the handshake; it does not cause a switch to broadcast traffic. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC with the IP of a legitimate host, redirecting traffic at Layer 3, not flooding the switch's CAM table to cause hub-like behavior. Option D is wrong because a DNS amplification attack uses open DNS resolvers to flood a victim with large DNS response traffic, overwhelming the target's bandwidth, not affecting switch forwarding behavior.

129
MCQhard

A security analyst is analyzing a suspicious file and runs the command 'strings malware.exe | grep -i http'. The output shows several URLs ending with '.exe'. What does this indicate?

A.The malware may download additional payloads from remote servers
B.The malware has a keylogger component
C.The malware is a boot sector virus
D.The malware is a worm that spreads via email
AnswerA

The presence of HTTP URLs, particularly those ending with executable file extensions like .exe, is a strong indicator that the malware is designed to retrieve additional components. This behavior is characteristic of a downloader or dropper, which fetches secondary payloads from remote Command and Control (C2) servers to execute further malicious activities. Such multi-stage attacks are common, allowing the initial infection to be small and stealthy while dynamically loading more complex functionality.

Why this answer

The `strings` command extracts printable strings from a binary file, and `grep -i http` filters for HTTP-related content. The presence of URLs ending with `.exe` indicates that the malware contains embedded references to executable files hosted on remote servers, which is a common technique for downloading additional payloads or updates. This strongly suggests the malware has a downloader or dropper component that fetches further malicious code from those URLs.

Exam trap

The trap here is that candidates may assume any URL in a binary indicates a specific malware type (e.g., worm or keylogger), but the CEH exam tests the ability to infer functionality from evidence—HTTP URLs with `.exe` specifically point to remote payload download, not propagation or input capture.

How to eliminate wrong answers

Option B is wrong because the presence of HTTP URLs ending with `.exe` does not imply keylogging functionality; keyloggers typically capture keystrokes and would not necessarily contain such URLs. Option C is wrong because a boot sector virus infects the Master Boot Record (MBR) or Volume Boot Record (VBR) and would not typically contain HTTP URLs for downloading executables; its propagation is low-level and file-system independent. Option D is wrong because while a worm may spread via email, the output of `strings` showing HTTP URLs does not indicate email propagation mechanisms (e.g., SMTP, MAPI); worms that spread via email often contain email-related strings or scripting, not just HTTP download URLs.

130
MCQhard

A penetration tester uses a tool to spoof ARP replies, redirecting traffic through the tester's machine. The tester then captures credentials from the redirected traffic. Which tool is BEST suited for this task?

A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA

Ettercap is a comprehensive suite specifically designed for man-in-the-middle (MITM) attacks, making it the correct tool for ARP poisoning. It actively injects forged ARP replies into a local area network, associating the attacker's MAC address with the IP address of a legitimate host, such as the default gateway. This redirection allows Ettercap to intercept, modify, and forward traffic between the target and the intended destination, enabling sniffing and various active attacks.

Why this answer

Ettercap is the best tool for ARP spoofing because it is specifically designed for man-in-the-middle (MITM) attacks on local networks. It actively sends forged ARP replies to poison the ARP cache of target hosts, redirecting traffic through the attacker's machine, and includes built-in packet capture and credential extraction features.

Exam trap

The trap here is that candidates confuse passive sniffing tools like Wireshark or tcpdump with active MITM tools, assuming any packet capture tool can also perform ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Wireshark is a passive packet analyzer that cannot spoof ARP replies or redirect traffic; it only captures and inspects existing traffic. Option C is wrong because Nmap is a network discovery and port scanning tool that does not perform ARP spoofing or MITM traffic redirection. Option D is wrong because tcpdump is a command-line packet capture utility that lacks the ability to inject forged ARP packets or manipulate network traffic flow.

131
MCQmedium

A malware analyst wants to examine a suspicious executable without executing it. The goal is to extract strings, view the PE header, and check for known signatures. Which approach is the analyst using?

A.Static analysis
B.Dynamic analysis
C.Heuristic analysis
D.Reverse engineering
AnswerA

Static analysis inspects the binary's code and structure without running it, allowing extraction of strings, PE header fields and signature matches. This directly satisfies the constraint of examining the executable without executing it, unlike dynamic or behavioural analysis.

Why this answer

Static analysis involves examining a binary without executing it. The analyst extracts strings (e.g., using `strings`), views the PE header (e.g., with `pefile` or `dumpbin`), and checks for known signatures (e.g., YARA rules or antivirus hashes). This approach is safe and preserves the original state of the file.

Exam trap

The CEH exam often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse 'reverse engineering' as a synonym for static analysis, but reverse engineering is a superset that includes both static and dynamic methods, whereas the question specifically describes non-execution inspection.

How to eliminate wrong answers

Option B is wrong because dynamic analysis requires executing the malware in a sandbox or debugger to observe runtime behavior, not static inspection. Option C is wrong because heuristic analysis uses behavioral patterns or rules to detect unknown malware, often during execution or scanning, not by directly examining the PE header or strings. Option D is wrong because reverse engineering is a broader process that may include static analysis but typically involves deeper disassembly or decompilation (e.g., with IDA Pro or Ghidra) to understand logic, not just extracting strings and checking signatures.

132
MCQhard

A security analyst detects a file named 'invoice.pdf.exe' in an email attachment. When the file is submitted to VirusTotal, multiple engines detect it as a Trojan. The analyst wants to perform dynamic analysis to observe its behavior. Which approach is BEST?

A.Disassemble the file using IDA Pro to understand its code
B.Run 'strings' on the file and analyze the output
C.Execute the file in a sandboxed environment and monitor system calls
D.Submit the file again to VirusTotal for a second opinion
AnswerC

Dynamic analysis requires running the malware so its behaviour can be observed. A sandbox isolates execution while capturing system calls, file and registry changes, revealing payload activity that static inspection of the double extension cannot.

Why this answer

Dynamic analysis involves executing malware in a controlled, isolated environment (sandbox) to observe its runtime behavior, such as file system changes, registry modifications, network connections, and process injections. Option C directly enables this by running the Trojan and monitoring system calls, which is the best approach to understand its actual impact and propagation methods.

Exam trap

EC-CEH often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse 'submitting to VirusTotal' (a static, signature-based check) with actual behavioral observation, or think disassembly is sufficient to understand runtime behavior.

How to eliminate wrong answers

Option A is wrong because disassembling with IDA Pro is static analysis, which does not reveal runtime behavior like network traffic or self-modifying code. Option B is wrong because running 'strings' only extracts readable text from the binary, missing encrypted, packed, or obfuscated payloads and dynamic actions. Option D is wrong because resubmitting to VirusTotal provides no new behavioral data—it only repeats signature-based detection without observing execution.

133
MCQmedium

A security analyst notices a high volume of ICMP Echo Reply packets on the network. The source IPs are varied, but the destination IP is the same. Which type of attack is MOST likely occurring?

A.UDP flood
B.Ping of Death
C.Smurf attack
D.ICMP flood
AnswerC

A Smurf attack is a classic distributed denial-of-service (DDoS) attack that leverages ICMP reflection and amplification. An attacker sends ICMP Echo Request packets with a spoofed source IP address (the victim's IP) to the IP broadcast address of a large network. All active hosts on that network then respond with ICMP Echo Reply packets to the spoofed source IP, overwhelming the victim with a massive flood of replies from numerous legitimate sources. This perfectly matches the observation of a high volume of ICMP echo replies from multiple sources.

Why this answer

The Smurf attack is a distributed denial-of-service (DDoS) attack that exploits ICMP by sending a large number of ICMP Echo Request packets with a spoofed source IP (the victim's IP) to a network's broadcast address. All devices on that network then respond with ICMP Echo Reply packets to the victim, overwhelming it. The scenario describes varied source IPs (the responding devices) and a single destination IP (the victim), which is the hallmark of a Smurf attack.

Exam trap

The trap here is that candidates confuse the Smurf attack with a standard ICMP flood, but the key differentiator is the amplification effect caused by the broadcast address and the spoofed source IP, which results in many replies from varied sources to a single destination.

How to eliminate wrong answers

Option A is wrong because a UDP flood uses UDP packets, not ICMP Echo Reply packets, and typically targets random or specific ports to exhaust resources. Option B is wrong because the Ping of Death involves sending a malformed ICMP Echo Request packet that exceeds the maximum IP packet size (65535 bytes), causing a buffer overflow, not a high volume of normal-sized Echo Replies. Option D is wrong because an ICMP flood directly sends a high volume of ICMP Echo Request packets from a single or multiple sources to overwhelm the target, but the key detail here is the varied source IPs of the *replies*, not the requests, which indicates the amplification effect of a Smurf attack.

134
MCQmedium

A security team observes that a switch's MAC address table is full, and the switch has started flooding unicast traffic to all ports. Which attack has MOST likely been performed?

A.MAC flooding
B.ARP poisoning
C.MAC spoofing
D.DHCP starvation
AnswerA

MAC flooding is an attack technique that overwhelms a network switch's Content Addressable Memory (CAM) table with a massive number of unique, fake MAC address-to-port mappings. By sending numerous Ethernet frames, each with a different spoofed source MAC address, the attacker forces the CAM table to fill up completely. Once the CAM table is full, the switch can no longer store new MAC-to-port associations and reverts to acting like a hub, broadcasting all incoming traffic out of every port. This allows an attacker to capture and analyze traffic intended for other devices on the network segment.

Why this answer

MAC flooding attacks exploit the limited size of a switch's CAM (Content Addressable Memory) table. By sending thousands of frames with random source MAC addresses, the attacker fills the table to capacity. Once full, the switch enters a fail-open state and begins flooding all unknown unicast traffic out every port, effectively turning it into a hub and allowing the attacker to capture traffic not destined for them.

Exam trap

The trap here is confusing MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets host ARP caches), as both involve MAC addresses and can lead to traffic interception, but they operate at different layers and use different mechanisms.

How to eliminate wrong answers

Option B (ARP poisoning) is wrong because it manipulates the ARP cache of hosts to associate the attacker's MAC with the IP of a legitimate device, causing traffic to be redirected; it does not fill the switch's MAC address table. Option C (MAC spoofing) is wrong because it involves impersonating a legitimate device's MAC address to bypass access controls or hijack a session, not to exhaust the CAM table. Option D (DHCP starvation) is wrong because it exhausts the pool of available IP addresses from a DHCP server by sending many DHCP discover messages with fake MAC addresses, preventing legitimate clients from obtaining IPs; it does not directly cause the switch to flood unicast traffic.

135
MCQmedium

Which of the following is a form of social engineering where an attacker physically follows an authorized person into a restricted area without proper authentication?

A.Pretexting
B.Baiting
C.Tailgating
D.Quid pro quo
AnswerC

Tailgating exploits physical proximity and social trust: the attacker walks through a secured door immediately behind an authenticated employee, bypassing badge checks entirely. This matches the stem's physical-following constraint, unlike phishing or pretexting, which rely on remote deception.

Why this answer

Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area, bypassing authentication mechanisms such as badge readers, PIN pads, or biometric scanners. The attacker exploits the natural courtesy of the authorized person holding the door open, thereby gaining physical access without any credential validation.

Exam trap

EC-Council often tests tailgating by contrasting it with pretexting or baiting, so the trap is confusing physical access attacks (tailgating) with psychological manipulation attacks (pretexting, baiting, quid pro quo) that do not require physical proximity.

How to eliminate wrong answers

Option A is wrong because pretexting involves fabricating a scenario or identity (e.g., impersonating IT support) to trick a target into divulging information, not physically following someone into a restricted area. Option B is wrong because baiting relies on offering something enticing (e.g., a malware-infected USB drive left in a parking lot) to lure a victim into performing an action, not physical proximity or door access. Option D is wrong because quid pro quo involves an attacker offering a service or benefit (e.g., 'free tech support') in exchange for sensitive information or access, not physically trailing an authorized person.

136
MCQhard

During a penetration test, you run the tool 'macof' against a switch. After a few seconds, the switch starts flooding frames out all ports. Which attack have you successfully executed, and what is the primary goal of this technique?

A.MAC flooding; to cause a switch to fail-open and act like a hub for sniffing
B.VLAN hopping; to gain access to a different VLAN
C.STP manipulation; to create a loop and cause a DoS
D.ARP poisoning; to intercept traffic between two hosts
AnswerA

macof floods the switch's CAM table with spoofed source MACs, exhausting its capacity. The switch then fails open, flooding frames out every port like a hub, letting the attacker sniff traffic that would normally be unicast to specific ports.

Why this answer

The 'macof' tool is specifically designed to perform MAC flooding attacks by generating frames with random source MAC addresses. This overwhelms the switch's Content Addressable Memory (CAM) table, causing it to fail-open and flood all incoming frames out every port, effectively making it behave like a hub. This allows the attacker to sniff network traffic that would normally be isolated to specific switch ports.

Exam trap

The common trap is confusing MAC flooding with ARP poisoning; MAC flooding overloads the switch's CAM table, while ARP poisons the host's ARP cache.

How to eliminate wrong answers

Option B is wrong because VLAN hopping exploits switch tagging protocols (e.g., DTP or double-tagging) to access another VLAN, not by flooding MAC addresses. Option C is wrong because STP manipulation targets the Spanning Tree Protocol to create loops or reroute traffic, typically using BPDU attacks, not by exhausting CAM tables. Option D is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC with a legitimate IP address, enabling man-in-the-middle attacks, not by flooding random MACs to cause switch fail-open.

137
Multi-Selecteasy

Which TWO of the following are examples of session hijacking attacks? (Select 2)

Select 2 answers
A.DNS spoofing
B.Cookie theft
C.MAC flooding
D.TCP sequence prediction
E.ARP poisoning
AnswersB, D

Cookie theft hijacks an established session by stealing the session identifier, letting the attacker replay it to impersonate the victim without re-authenticating. This directly satisfies the session-hijacking criterion, since the attacker takes over an already-authenticated session rather than cracking credentials.

Why this answer

Cookie theft (B) is a session hijacking attack because an attacker who steals a valid session cookie (e.g., via XSS or sniffing an unencrypted HTTP session) can replay it to impersonate the victim and take over the authenticated session. TCP sequence prediction (D) is also session hijacking: by predicting the ISN (initial sequence number) of a TCP connection, an attacker can inject spoofed packets and desynchronize or take over an established session. DNS spoofing (A), MAC flooding (C), and ARP poisoning (E) are supporting or denial-of-service attacks — DNS spoofing redirects name resolution, MAC flooding overflows a switch's CAM table, and ARP poisoning enables MITM traffic interception — but none of them by themselves constitute session hijacking.

Exam trap

The trap here is that candidates confuse network-level attacks (like ARP poisoning or DNS spoofing) with session hijacking, but the CEH exam specifically defines session hijacking as the takeover of an authenticated TCP or application-layer session, which requires either stealing a session token (cookie theft) or predicting TCP sequence numbers.

138
MCQmedium

Which tool can be used to perform ARP poisoning to intercept traffic between a victim and the default gateway?

A.Wireshark
B.Ettercap
C.tcpdump
D.Nmap
AnswerB

Ettercap is a versatile and robust suite of tools specifically engineered for Man-in-the-Middle (MITM) attacks on local area networks. It excels at ARP poisoning by sending forged ARP replies to both the target host and the default gateway, effectively tricking them into routing traffic through the attacker's machine. This redirection allows for sniffing, content filtering, and other active manipulations of network communications.

Why this answer

Ettercap is a dedicated man-in-the-middle (MITM) attack tool that natively supports ARP poisoning. It sends forged ARP replies to both the victim and the default gateway, mapping the attacker's MAC address to the IP addresses of the other party. This allows the attacker to intercept, inspect, and modify traffic between the victim and the gateway.

Exam trap

The trap here is that candidates confuse passive sniffing tools (Wireshark, tcpdump) with active MITM tools, assuming any tool that can capture traffic can also perform ARP poisoning.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects packets passively; it cannot send forged ARP packets to poison a victim's ARP cache. Option C is wrong because tcpdump is a command-line packet capture tool that only dumps traffic on a network interface; it has no capability to inject or manipulate ARP replies. Option D is wrong because Nmap is a network discovery and security scanning tool used for port scanning and OS detection; it does not include ARP spoofing functionality.

139
MCQeasy

Which tool would an ethical hacker use to automatically generate a malicious USB drive that, when plugged in, executes a payload and connects back to the attacker?

A.Wireshark
B.Ettercap
C.USB Rubber Ducky
D.Metasploit
AnswerC

The USB Rubber Ducky is a specialized keystroke injection tool that emulates a standard human interface device (HID), specifically a keyboard, when plugged into a target system. This allows it to automatically and rapidly inject pre-programmed keystrokes and commands, bypassing many traditional security controls like antivirus software and firewalls. Its ability to deliver complex payloads at 'typing speed' makes it highly effective for automated USB-based attacks.

Why this answer

The USB Rubber Ducky is a keystroke injection tool that appears as a keyboard to the host computer. When plugged in, it automatically types a pre-programmed payload at high speed, which can download and execute a reverse shell or other malware, establishing a connection back to the attacker. This makes it the correct choice for automatically generating a malicious USB drive that executes a payload upon insertion.

Exam trap

The trap here is that candidates often confuse Metasploit as the tool for generating the USB drive itself, but Metasploit is used to create the payload, while the USB Rubber Ducky is the specific hardware tool that automates the injection process when the drive is plugged in.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets, not for generating malicious USB drives or executing payloads. Option B is wrong because Ettercap is a man-in-the-middle attack tool for network sniffing and ARP poisoning, not a USB-based attack tool. Option D is wrong because Metasploit is a penetration testing framework for developing and executing exploits, but it does not automatically generate a malicious USB drive that executes a payload when plugged in; while it can create payloads, the USB Rubber Ducky is the dedicated hardware tool for keystroke injection attacks.

140
MCQeasy

Which of the following is a type of malware that spreads by replicating itself across a network without requiring a host file?

A.Worm
B.Trojan
C.Ransomware
D.Virus
AnswerA

A worm is a standalone malware computer program that replicates itself to spread to other computers. Unlike a virus, it does not need to attach to an existing program or host file to propagate. Worms often exploit network vulnerabilities to spread autonomously across networks, consuming bandwidth and system resources, and can carry payloads like backdoors or ransomware. This self-contained, network-aware replication is its defining characteristic.

Why this answer

A worm is a standalone malware that replicates itself across a network by exploiting vulnerabilities or using network protocols (e.g., SMB, RDP, or email) without needing a host file. Unlike viruses, worms do not attach to existing programs; they self-propagate via network connections, often consuming bandwidth and creating backdoors.

Exam trap

The trap here is confusing a worm with a virus, as both self-replicate, but the key differentiator is that a worm does not require a host file and spreads via network protocols, while a virus must attach to a host file to propagate.

How to eliminate wrong answers

Option B (Trojan) is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution to install and typically requires a host file or system to operate. Option C (Ransomware) is wrong because ransomware encrypts files or locks systems for extortion and does not self-propagate across a network without user interaction or a host file. Option D (Virus) is wrong because a virus requires a host file (e.g., executable, script, or document) to attach to and replicate, whereas the question specifies propagation without a host file.

141
MCQmedium

A security analyst reviews logs and notices that an attacker crafted a packet with a source IP address matching the target's IP address, and sent it to a network's broadcast address. Which type of attack does this describe?

A.UDP flood
B.Ping of Death
C.Smurf attack
D.SYN flood
AnswerC

A Smurf attack is a classic distributed denial-of-service (DDoS) technique that leverages an intermediary network to amplify traffic against a victim. The attacker sends an ICMP echo request packet to a network's IP broadcast address, but with the source IP address spoofed to that of the intended victim. All hosts on the intermediary network that receive the broadcast then reply to the spoofed source IP, flooding the victim with numerous ICMP echo replies. This amplification effect can quickly overwhelm the victim's network resources.

Why this answer

The Smurf attack is a distributed denial-of-service (DDoS) attack that exploits ICMP echo request packets. The attacker spoofs the source IP address to be the target's IP and sends these packets to a network's broadcast address. All hosts on that network then reply to the target, overwhelming it with ICMP echo replies.

Exam trap

The trap here is that candidates confuse the Smurf attack with a simple ICMP flood or Ping of Death, but the key differentiator is the use of a broadcast address to amplify traffic, not just sending malformed or high-volume ICMP packets.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends a high volume of UDP packets to random ports on the target, exhausting its resources, and does not involve spoofing the target's IP as the source or using a broadcast address. Option B is wrong because a Ping of Death sends an oversized ICMP packet (greater than 65,535 bytes) to crash the target, not a broadcast-based amplification attack. Option D is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source IPs to exhaust the target's connection table, and it does not use broadcast addresses or ICMP.

142
Multi-Selectmedium

Which THREE of the following are valid methods for DDoS mitigation?

Select 3 answers
A.Rate limiting
B.Increasing server timeout values
C.Scrubbing centers
D.Disabling SYN cookies
E.Anycast routing
AnswersA, C, E

Rate limiting is a crucial DDoS mitigation technique that restricts the number of requests a server or application will accept from a specific source within a defined time window. By setting thresholds for connections, requests per second, or bandwidth usage, it prevents a single attacker or a small group of bots from overwhelming server resources. This method helps to differentiate between legitimate traffic spikes and malicious floods, allowing the system to maintain availability for valid users while shedding excessive, potentially harmful traffic.

Why this answer

Rate limiting is a valid DDoS mitigation method because it restricts the number of requests a server accepts from a single source within a given time window, preventing resource exhaustion. By enforcing thresholds (e.g., via iptables or application-layer rate limiters), it reduces the impact of volumetric attacks like HTTP floods without blocking legitimate traffic entirely.

Exam trap

The trap here is that candidates confuse mitigation techniques with configuration errors, such as thinking that increasing timeouts or disabling SYN cookies would help, when in fact these actions weaken defenses against specific attack vectors like SYN floods or slow HTTP attacks.

143
MCQmedium

A user reports that their system has become sluggish and they see pop-up advertisements even when no browser is open. Additionally, unknown processes are running in Task Manager. Which type of malware is most likely responsible?

A.Worm
B.Adware
C.Ransomware
D.Spyware
AnswerB

Adware is specifically designed to display unwanted advertisements, often in the form of pop-ups, banners, or injected ads within web pages. This constant display and the underlying processes required to generate these ads consume significant CPU and RAM, leading directly to noticeable system sluggishness. It frequently alters browser settings, making it a direct cause for both the reported performance degradation and persistent pop-ups.

Why this answer

Adware is designed to display unwanted advertisements, often in the form of pop-ups, and can degrade system performance by consuming CPU and memory resources. The presence of unknown processes in Task Manager indicates that the adware has installed additional components or bundled software that runs persistently, even when no browser is open, which is a hallmark of adware behavior.

Exam trap

The trap here is that candidates confuse 'adware' with 'spyware' because both can be bundled with free software, but adware's primary symptom is unwanted ads, not data theft, which is the key differentiator in this scenario.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads across networks without user interaction, and while it can cause sluggishness, it does not typically display pop-up advertisements. Option C is wrong because ransomware encrypts files or locks the system to demand a ransom, and it does not show pop-up ads or run unknown processes as its primary symptom. Option D is wrong because spyware is designed to covertly collect sensitive information (e.g., keystrokes, browsing habits) and does not usually generate pop-up advertisements; its presence is often hidden, not announced via ads.

144
MCQmedium

An attacker gains physical access to a restricted area by following an authorized employee through a secured door without swiping a badge. This technique is known as:

A.Tailgating
B.Pretexting
C.Quid pro quo
D.Baiting
AnswerA

Tailgating exploits the human element of physical security: the attacker gains entry by closely following an authorised employee through a secured door, bypassing badge authentication entirely. The stem's constraint is unauthorised physical access without credentials, which tailgating satisfies precisely.

Why this answer

Tailgating is a social engineering attack where an unauthorized person physically follows an authorized employee through a secured entry point (e.g., a badge-protected door) without presenting their own credentials. This exploits the human tendency to hold the door for others, bypassing electronic access control systems (e.g., RFID badge readers) that would otherwise deny entry. The CEH exam defines this as a physical breach of perimeter security, distinct from digital or verbal manipulation.

Exam trap

The trap here is confusing 'tailgating' with 'pretexting' because both involve deception, but tailgating is purely physical (following through a door) while pretexting is purely verbal (creating a false story).

How to eliminate wrong answers

Option B (Pretexting) is wrong because it involves fabricating a scenario (e.g., impersonating IT support) to trick a victim into divulging information, not physically following someone through a door. Option C (Quid pro quo) is wrong because it relies on offering a service or benefit (e.g., 'free antivirus scan') in exchange for credentials, not physical proximity. Option D (Baiting) is wrong because it uses a physical lure (e.g., an infected USB drive left in a parking lot) to compromise a system, not direct physical access by trailing an employee.

145
Multi-Selecthard

Which THREE of the following are indicators of a slowloris DDoS attack?

Select 3 answers
A.ICMP echo replies from random IPs
B.Normal traffic volume but connections remain open for a long time
C.Many half-open HTTP connections
D.Server logs showing incomplete HTTP requests
E.High volume of UDP packets
AnswersB, C, D

Slowloris is a low-bandwidth attack that does not generate a high volume of data packets. Instead, it exploits the server's connection handling by opening numerous legitimate-looking HTTP connections and then keeping them alive for extended durations. This is achieved by sending partial HTTP requests and periodically sending additional, non-terminating HTTP headers, preventing the server from timing out the connection and freeing up resources. The prolonged open state of these connections, despite minimal data transfer, exhausts the server's available connection pool.

Why this answer

B is correct because a Slowloris DDoS attack works by opening many connections to a target web server and keeping them open for as long as possible, sending partial HTTP requests to tie up server resources. This results in normal traffic volume but with connections that remain open for extended periods, preventing legitimate users from connecting.

Exam trap

The trap here is that candidates often associate DDoS attacks with high traffic volume, but Slowloris is a low-and-slow attack that uses normal traffic volume with persistent, incomplete connections, so they may incorrectly select high-volume options like A or E.

146
MCQeasy

An employee receives an SMS message that claims to be from the IT department, asking the employee to click a link to verify their email account. Which social engineering attack is this?

A.Vishing
B.Phishing
C.SMiShing
D.Whaling
AnswerC

SMiShing, a portmanteau of 'SMS' and 'phishing,' is a specific type of social engineering attack that utilizes text messages to deceive recipients. Attackers send fraudulent SMS messages, often containing malicious links that lead to credential harvesting sites or malware downloads, or instructing victims to call a fraudulent number. This method exploits the trust users place in their mobile devices and the immediacy of text messages to prompt quick, unthinking responses, making it the direct answer for an SMS-based attack.

Why this answer

C is correct because SMiShing (SMS phishing) specifically uses SMS text messages as the attack vector to deliver a malicious link or request, exactly as described in the scenario. Unlike email-based phishing, SMiShing exploits the trust users place in text messages and often bypasses email security filters.

Exam trap

The trap here is that candidates confuse 'phishing' as a generic term for all social engineering attacks, but the CEH exam distinguishes SMiShing as the specific term for SMS-based phishing.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls or voice messages, not SMS text messages. Option B is wrong because phishing typically refers to email-based attacks, not SMS-based attacks. Option D is wrong because whaling targets high-profile individuals (e.g., executives) with personalized attacks, not general employees via mass SMS.

147
MCQhard

A penetration tester runs the following command: `macof -i eth0 -s 192.168.1.100 -d 10.0.0.1`. Which attack is being performed?

A.DNS spoofing
B.ARP poisoning
C.MAC flooding
D.DHCP starvation
AnswerC

MAC flooding is an attack designed to overwhelm a network switch's MAC address table (CAM table) by sending a large number of frames with unique, spoofed source MAC addresses. When the CAM table becomes full, the switch often enters a "fail-open" mode, behaving like a hub by broadcasting all incoming traffic to all ports. The `macof` utility, part of the `dsniff` suite, automates this process by rapidly generating and sending thousands of frames with random source MAC and IP addresses, effectively causing the switch to flood traffic.

Why this answer

The `macof` tool is designed to flood a switch with packets containing random source MAC addresses, overwhelming the Content Addressable Memory (CAM) table. Once the CAM table is full, the switch enters a fail-open state and broadcasts all frames, allowing the attacker to sniff traffic that would normally be isolated to specific ports. This is a classic MAC flooding attack, not ARP poisoning or DHCP starvation.

Exam trap

In the CEH exam, candidates often confuse MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets host ARP caches). Both involve MAC addresses and can enable man-in-the-middle attacks, but the tool 'macof' specifically performs MAC flooding.

How to eliminate wrong answers

Option A is wrong because DNS spoofing involves corrupting DNS responses to redirect traffic, typically using tools like `dnsspoof` or `ettercap` with DNS filters, not `macof`. Option B is wrong because ARP poisoning manipulates ARP caches to associate a malicious MAC with a legitimate IP, using tools like `arpspoof` or `ettercap`; `macof` does not send ARP replies or requests. Option D is wrong because DHCP starvation floods a DHCP server with fake DHCPDISCOVER messages to exhaust its IP address pool, using tools like `yersinia` or `dhcpstarv`, not `macof`.

148
MCQmedium

An attacker uses the Social Engineering Toolkit (SET) to send a malicious email to employees of a company, claiming to be from IT support and urging them to click a link to reset their password. Which social engineering attack is being performed?

A.Vishing
B.Phishing
C.Baiting
D.SMiShing
AnswerB

Phishing is a prevalent cyberattack where adversaries employ deceptive emails to trick recipients into divulging confidential information or executing malicious actions. The Social Engineering Toolkit (SET) is frequently used to craft convincing fake login pages or deliver malware via email attachments, making it a classic vector for credential harvesting or system compromise. This method leverages trust and urgency to bypass security awareness and technical controls.

Why this answer

The Social Engineering Toolkit (SET) is used to craft and send fraudulent emails that appear to come from a trusted source (IT support), urging the recipient to click a link and enter credentials. This is a classic phishing attack because it uses email as the vector and relies on deception to steal sensitive information. Unlike vishing (voice) or SMiShing (SMS), the attack is executed via email, which is the defining characteristic of phishing.

Exam trap

The CEH exam often tests the distinction between phishing, vishing, and SMiShing by focusing on the delivery medium (email vs. voice vs. SMS), so candidates must remember that 'phishing' specifically refers to email-based social engineering.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses telephone calls or VoIP systems to trick victims, not email. Option C is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim, not sending a deceptive email. Option D is wrong because SMiShing (SMS phishing) uses text messages (Short Message Service) as the attack vector, not email.

149
MCQmedium

An employee receives an email that appears to be from the CEO, requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ceo@cornpany.com instead of ceo@company.com). This is an example of which type of attack?

A.Whaling
B.Phishing
C.Pretexting
D.Spear phishing
AnswerD

Spear phishing is a highly targeted form of phishing that uses personalized information to increase the credibility and effectiveness of the attack. Attackers conduct reconnaissance to gather details about the target, such as their name, job title, company, and even internal relationships, to craft a convincing email. An email appearing to be from the CEO to a specific employee leverages this personalized context and perceived authority, making it a classic example of a spear phishing attempt designed to elicit a specific response.

Why this answer

Spear phishing is a targeted phishing attack aimed at a specific individual or organization, using personalized information to increase credibility. In this scenario, the attacker spoofs the CEO's identity and uses a misspelled domain (typosquatting) to trick the employee into performing a wire transfer, which is a classic spear phishing technique. Unlike generic phishing, spear phishing tailors the message to the victim's role and context, making it more effective.

Exam trap

The trap here is that candidates confuse 'whaling' with 'spear phishing' because both target specific individuals, but whaling specifically targets high-level executives, while spear phishing can target any individual within an organization, as in this case where the email impersonates the CEO rather than targeting them.

How to eliminate wrong answers

Option A is wrong because whaling is a specific type of spear phishing that targets high-profile executives (e.g., CEO, CFO) directly, but the question describes an email impersonating the CEO, not targeting the CEO. Option B is wrong because phishing is a broad, untargeted attack sent to many recipients, lacking the personalization and specific context (e.g., using the CEO's name and a misspelled domain) seen here. Option C is wrong because pretexting involves creating a fabricated scenario (pretext) to obtain information, often via phone or in person, and does not inherently rely on email spoofing or typosquatting like this example.

150
MCQmedium

During a penetration test, a tester captures network traffic and notices a large number of ARP replies claiming that 192.168.1.1 is at MAC address 00:11:22:33:44:55, which is different from the legitimate gateway MAC. Which attack is likely in progress?

A.Session hijacking
B.ARP poisoning
C.MAC flooding
D.DNS spoofing
AnswerB

ARP poisoning floods the segment with forged ARP replies binding the gateway IP to an attacker MAC, so victims send traffic to the attacker instead of the real router. The mismatched MAC in the captured replies is the defining signature.

Why this answer

ARP poisoning (also known as ARP spoofing) is the correct answer because the attacker is sending forged ARP replies that associate the legitimate gateway IP (192.168.1.1) with an attacker-controlled MAC address (00:11:22:33:44:55). This causes victim hosts to update their ARP cache with the false mapping, redirecting traffic intended for the gateway to the attacker's machine, enabling man-in-the-middle (MITM) attacks.

Exam trap

The trap in this question is confusing ARP poisoning (which manipulates Layer 2 MAC-to-IP mappings via forged ARP replies) with MAC flooding (which overwhelms switch CAM tables with fake MAC addresses). The key clue is that the attacker is sending multiple ARP replies for a single target IP (the gateway) with a spoofed MAC, not a flood of different MACs.

How to eliminate wrong answers

Option A is wrong because session hijacking typically involves stealing or predicting session tokens (e.g., cookies or session IDs) after initial authentication, not manipulating ARP cache entries at Layer 2. Option C is wrong because MAC flooding is an attack that overwhelms a switch's CAM table with fake MAC addresses to force it into hub mode (flooding all traffic), not sending specific forged ARP replies to poison a single IP-to-MAC mapping. Option D is wrong because DNS spoofing corrupts DNS resolver caches with false IP-to-domain mappings (e.g., returning a malicious IP for www.example.com), not ARP cache entries for a gateway IP.

← PreviousPage 2 of 3 · 194 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Ceh Malware Social Network questions.