Courseiva

CCNA Ceh Malware Social Network Questions

75 of 179 questions · Page 2/3 · Ceh Malware Social Network topic · Answers revealed

76
MCQeasy

A user reports that their computer is infected with ransomware. Which of the following is the BEST immediate action for the security team to take?

A.Disconnect the computer from the network
B.Pay the ransom to regain access
C.Run a full antivirus scan
D.Restore the system from a recent backup
AnswerA

Disconnecting the computer from the network is the immediate and most critical first step in containing a ransomware infection. This action severs the malware's ability to communicate with command-and-control (C2) servers, preventing further encryption key exchange, data exfiltration, or the reception of additional malicious instructions. Crucially, it also stops the ransomware from spreading laterally across the network to other systems or encrypting shared network drives, thereby limiting the scope of the compromise and preventing further damage.

Why this answer

Disconnecting the computer from the network is the best immediate action because it isolates the ransomware, preventing it from spreading laterally to other systems via SMB, RDP, or mapped drives. This containment step stops the encryption of additional network shares and halts any command-and-control (C2) communication the ransomware might be using to exfiltrate data or receive encryption keys.

Exam trap

Many candidates mistakenly prioritize running an antivirus scan or restoring from backup as the immediate step. However, the CEH exam emphasizes containment first to prevent lateral movement and further damage. Disconnecting from the network is critical to stop the spread of ransomware.

How to eliminate wrong answers

Option B is wrong because paying the ransom does not guarantee decryption and often funds criminal operations; there is no technical assurance the attacker will provide a working decryption key, and it may encourage further attacks. Option C is wrong because running a full antivirus scan while the ransomware is active can trigger the malware to accelerate encryption or delete files, and the scan itself may be ineffective if the ransomware has already modified system files or uses polymorphic code. Option D is wrong because restoring from a backup should only be done after the ransomware is fully removed and the system is verified clean; immediate restoration risks re-encrypting the backup if it is still connected to the network or if the ransomware persists in memory.

77
MCQhard

An attacker uses the Social Engineering Toolkit (SET) to craft a phishing email that appears to come from the company's CEO, requesting the recipient to urgently wire funds to a new vendor. This attack is BEST described as which type of social engineering?

A.Pretexting
B.Spear phishing
C.Whaling
D.Quid pro quo
AnswerC

Whaling is a specialized form of phishing attack specifically designed to target high-ranking individuals within an organization, such as CEOs, CFOs, or other senior executives. These attacks are often highly sophisticated, leveraging extensive research to craft convincing lures that exploit the target's position of authority and access to sensitive information or financial assets. The scenario involving the impersonation of a CEO directly aligns with the definition of whaling, as it targets a "big fish" with significant organizational power.

Why this answer

Whaling is a targeted phishing attack aimed at high-profile individuals like the CEO or CFO. In this scenario, the attacker uses SET to impersonate the CEO and requests an urgent wire transfer, which is a classic whaling tactic because it targets a senior executive (the recipient) with a business-critical request. The attack is not generic phishing but specifically targets a 'big fish' within the organization.

Exam trap

The EC-CEH exam often tests the distinction between spear phishing and whaling by making candidates think any targeted email is spear phishing, but the trap here is that whaling is a subset of spear phishing specifically targeting senior executives, so the correct answer is the more specific term when the target is a 'big fish' like the CEO.

How to eliminate wrong answers

Option A is wrong because pretexting involves creating a fabricated scenario (pretext) to steal information, not sending a phishing email with a malicious request for funds. Option B is wrong because spear phishing targets a specific individual or group but does not require the target to be a high-level executive; this attack specifically targets the CEO or CFO, making it whaling. Option D is wrong because quid pro quo involves offering a service or benefit in exchange for information, such as a fake tech support call, not a fraudulent email requesting a wire transfer.

78
MCQmedium

A user receives a phone call from someone claiming to be from IT support, asking for their password to perform a system update. This is an example of which social engineering technique?

A.Baiting
B.Pretexting
C.Phishing
D.Vishing
AnswerB

Pretexting involves an attacker fabricating a believable scenario and a false identity to manipulate a victim into divulging sensitive information. The attacker creates a detailed backstory, often impersonating someone in authority or a trusted entity, to establish a sense of legitimacy and urgency. This elaborate setup is designed to overcome the victim's skepticism and directly solicit specific data, like a password, through social engineering.

Why this answer

Pretexting is a social engineering technique where an attacker fabricates a scenario (pretext) to manipulate a target into divulging sensitive information. In this case, the caller creates a false identity (IT support) and a false reason (system update) to trick the user into revealing their password. This differs from other techniques because it relies on a constructed narrative rather than malicious software or direct impersonation via email or phone alone.

Exam trap

The trap here is that candidates confuse vishing (voice phishing) with pretexting, but the key differentiator is that pretexting involves a fabricated identity and scenario (pretext) to establish trust, whereas vishing is simply phishing conducted over voice without necessarily building a detailed false narrative.

How to eliminate wrong answers

Option A is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim into executing malware or revealing credentials, not a direct phone call requesting a password. Option C is wrong because phishing is a broad term for social engineering via electronic communication (typically email) that uses deceptive links or attachments, not a live voice call. Option D is wrong because vishing (voice phishing) is a subset of phishing that uses phone calls, but the specific technique here is pretexting because the attacker establishes a false identity and scenario (pretext) to gain trust, not just a generic request for information.

79
MCQmedium

An analyst is analyzing a suspicious file using VirusTotal and observes that only 3 out of 60 antivirus engines detect it as malicious. The file has been submitted before but with no detections. What should the analyst conclude?

A.The file is a clean file with a rare hash
B.The file is safe because most engines don't detect it
C.The file is likely a false positive
D.The file is likely malicious and requires further analysis
AnswerD

Low detection rate suggests it may be new malware; further analysis is warranted.

Why this answer

A detection rate of 3 out of 60 (5%) is extremely low, but the fact that the file was previously submitted with zero detections and now has three detections indicates that the antivirus engines have updated their signatures to identify it. This pattern is consistent with a new or polymorphic malware strain that initially evaded detection but is now being recognized by a few engines. A low detection rate does not guarantee safety; it often signals a targeted or zero-day threat that requires further analysis through sandboxing or dynamic analysis.

Exam trap

EC-Council often tests the misconception that a low detection rate (e.g., 3/60) means the file is safe, when in fact it indicates the file is likely malicious and requires further investigation, especially if the detection count has increased from zero.

How to eliminate wrong answers

Option A is wrong because a rare hash does not imply the file is clean; malware authors can generate unique hashes for each sample, and a file with a rare hash could still be malicious. Option B is wrong because the number of engines that do not detect a file is not a reliable indicator of safety; many engines may lack signatures for new or obfuscated malware, and relying solely on detection count is a common fallacy. Option C is wrong because a false positive occurs when an engine incorrectly flags a benign file, but here the file was previously undetected and now has three detections, which is more consistent with emerging malware than a false positive; false positives typically appear consistently across submissions, not as a new detection pattern.

80
MCQmedium

A security analyst notices repeated TCP SYN packets sent to a server without corresponding SYN-ACK replies. The source IP addresses are spoofed and appear to be random. Which type of attack is MOST likely occurring?

A.SYN flood
B.UDP flood
C.ICMP flood
D.Ping of Death
AnswerA

A SYN flood is a classic Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. Attackers send a large volume of TCP SYN requests to a target server, often with spoofed source IP addresses. The server responds with SYN-ACK packets and allocates resources to maintain a half-open connection, waiting for the final ACK that never arrives, eventually exhausting its connection table and preventing legitimate connections.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IP addresses to a target server. The server responds with SYN-ACK packets to the spoofed addresses, which never complete the handshake, causing the server to exhaust its memory and CPU resources by maintaining half-open connections. This matches the described behavior of repeated SYN packets without corresponding SYN-ACK replies.

Exam trap

The trap here is that candidates often confuse a SYN flood with a UDP flood because both are volumetric attacks, but the key differentiator is the use of TCP SYN packets and the spoofed source IPs targeting the handshake process, not just any protocol flood.

How to eliminate wrong answers

Option B (UDP flood) is wrong because it involves sending large numbers of UDP packets to random ports, not TCP SYN packets, and does not rely on the TCP handshake mechanism. Option C (ICMP flood) is wrong because it uses ICMP echo request (ping) packets to overwhelm the target, not TCP SYN packets. Option D (Ping of Death) is wrong because it involves sending a malformed ICMP packet larger than the maximum 65,535 bytes to cause a buffer overflow, not a flood of TCP SYN packets.

81
Multi-Selecthard

Which THREE of the following are examples of application-layer DDoS attacks? (Select 3)

Select 3 answers
A.Slowloris
B.HTTP flood
C.SYN flood
D.DNS amplification
E.UDP flood
AnswersA, B, D

Slowloris holds connections open to exhaust server resources.

Why this answer

Slowloris is an application-layer DDoS attack that targets web servers by opening multiple HTTP connections and keeping them alive with partial requests, sending headers slowly to exhaust the server's connection pool. It exploits the HTTP protocol's design where servers wait for complete requests before releasing resources, making it a classic Layer 7 attack.

Exam trap

The CEH exam often tests the distinction between Layer 4 (transport) and Layer 7 (application) attacks, and the trap here is that candidates confuse SYN flood or UDP flood as application-layer because they involve 'flooding,' but they operate at lower OSI layers.

82
MCQeasy

Which type of social engineering attack involves a malicious actor impersonating a legitimate organization in a voicemail message to trick the victim into revealing sensitive information?

A.SMiShing
B.Pharming
C.Baiting
D.Vishing
AnswerD

Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack that utilizes voice communication, typically over telephone calls or Voice over IP (VoIP), to trick individuals. Attackers often impersonate trusted entities like banks, government agencies, or technical support to manipulate victims into revealing sensitive personal or financial information, or to perform actions like installing malicious software. Its defining characteristic is the direct, real-time vocal interaction with the target.

Why this answer

Vishing (voice phishing) is the correct answer because it specifically involves using voice communication—such as a phone call or voicemail—to impersonate a legitimate organization and trick the victim into revealing sensitive information like passwords or credit card numbers. Unlike other social engineering attacks, vishing exploits the trust associated with voice interactions and often uses caller ID spoofing to appear as a trusted entity.

Exam trap

The trap here is that candidates often confuse vishing with SMiShing because both involve phishing via communication channels, but SMiShing uses SMS text messages while vishing uses voice calls or voicemail.

How to eliminate wrong answers

Option A is wrong because SMiShing (SMS phishing) uses text messages (SMS) rather than voicemail to deliver the malicious lure, typically containing a link to a phishing site. Option B is wrong because pharming redirects users from a legitimate website to a fraudulent one by manipulating DNS settings or host files, without direct impersonation via voicemail. Option C is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to trick the victim into installing malware or revealing credentials, not leaving a voicemail message.

83
MCQeasy

Which malware analysis approach involves running the suspicious file in a controlled environment to observe its behavior?

A.Dynamic analysis
B.Code review
C.Signature detection
D.Static analysis
AnswerA

Dynamic analysis involves executing the suspicious malware sample within a controlled environment, such as a sandbox or virtual machine, to observe its real-time behavior. This approach monitors system calls, network communications, file system modifications, and registry changes as the malware runs, providing critical insights into its operational characteristics and potential impact. By observing execution, analysts can understand how the malware interacts with its environment and what malicious actions it attempts.

Why this answer

Dynamic analysis is the correct approach because it involves executing the suspicious file in a controlled, isolated environment (such as a sandbox or virtual machine) to monitor its runtime behavior, including file system changes, registry modifications, network connections, and process injections. This allows analysts to observe actual malicious actions without risking the production environment, making it essential for understanding zero-day threats and obfuscated malware that static analysis might miss.

Exam trap

EC-Council often tests the misconception that static analysis is sufficient for all malware types, but the trap here is that candidates confuse 'static analysis' (which examines code without execution) with 'dynamic analysis' (which requires execution), leading them to pick static analysis when the question explicitly asks for observing behavior in a controlled environment.

How to eliminate wrong answers

Option B is wrong because code review is a manual or automated examination of the malware's source code or disassembled instructions without execution, which falls under static analysis and cannot reveal runtime behaviors like API calls or network traffic. Option C is wrong because signature detection relies on pre-defined patterns (e.g., hash values or byte sequences) to identify known malware, but it fails against polymorphic or novel malware that lacks matching signatures. Option D is wrong because static analysis examines the file's structure, strings, and code without execution, missing dynamic behaviors such as self-modification, anti-debugging tricks, or delayed payload activation.

84
Multi-Selecthard

Which THREE of the following are common methods used to mitigate DDoS attacks? (Select 3)

Select 3 answers
A.MAC flooding
B.Rate limiting
C.Scrubbing centers
D.ARP poisoning
E.Anycast network distribution
AnswersB, C, E

Rate limiting restricts the number of requests accepted from a source.

Why this answer

Rate limiting is a common mitigation technique that restricts the number of requests a server or network device will accept from a specific source within a given time window. By enforcing thresholds (e.g., packets per second), it prevents any single source from overwhelming the target, effectively reducing the impact of volumetric DDoS attacks.

Exam trap

EC-CEH often tests the distinction between attack techniques (like MAC flooding and ARP poisoning) and legitimate mitigation strategies, so candidates mistakenly select these as defenses because they are network-related terms.

85
MCQeasy

A security analyst receives an email that appears to be from the CEO, urgently requesting a wire transfer. The email address is slightly misspelled (ceo@cornpany.com instead of ceo@company.com). Which type of social engineering attack is this?

A.Vishing
B.Whaling
C.Spear phishing
D.Phishing
AnswerC

Targeted at a specific individual with personalized content.

Why this answer

Spear phishing is a targeted social engineering attack where the attacker customizes the message for a specific individual or organization, often using a spoofed or lookalike domain. In this scenario, the email is directed at a security analyst, impersonates the CEO, and uses a slightly misspelled domain (ceo@cornpany.com) to deceive the recipient, which is a classic spear phishing technique because it targets a specific role within the company.

Exam trap

The EC-CEH exam often tests the distinction between generic phishing and spear phishing by including a personalized element (like a specific name or role) to trick candidates into choosing the broader 'Phishing' option.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) involves voice calls or VoIP systems, not email-based attacks. Option B is wrong because whaling is a subtype of spear phishing that specifically targets high-level executives (e.g., CEO, CFO), but here the target is a security analyst, not the CEO themselves. Option D is wrong because phishing is a broad, untargeted attack sent to many recipients, whereas this email is personalized and directed at a specific individual, making it spear phishing.

86
MCQhard

During a penetration test, you run the command: 'macof -i eth0 -s 192.168.1.1 -d 192.168.2.1 -e 00:11:22:33:44:55'. What is the intended effect of this command?

A.Execute a SYN flood against the target
B.Perform MAC flooding to cause switch to fail open
C.Perform ARP poisoning
D.Spoof DNS responses
AnswerB

The command macof -i eth0 specifically performs MAC flooding by continuously sending frames with randomly generated source MAC addresses to exhaust the switch's Content Addressable Memory (CAM) table. When the CAM table overflows, the switch typically enters a "fail-open" mode, behaving like a hub by broadcasting all incoming traffic out of all ports. This allows an attacker connected to any port on the switch to capture and analyze all network traffic, effectively bypassing the switch's normal segmentation.

Why this answer

The `macof` tool generates a flood of random MAC addresses on the specified interface, overwhelming the switch's Content Addressable Memory (CAM) table. When the CAM table is full, the switch fails open and begins flooding all frames out all ports, effectively turning it into a hub. This allows the attacker to sniff traffic that would normally be isolated to specific switch ports.

Exam trap

The trap here is confusing MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets the ARP cache of hosts), as both involve spoofed MAC addresses but operate at different layers and with different mechanisms.

How to eliminate wrong answers

Option A is wrong because `macof` performs MAC flooding, not a SYN flood; a SYN flood targets a host's TCP stack with half-open connections, whereas `macof` targets the switch's CAM table. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate a victim's IP with the attacker's MAC, which is a different attack vector than flooding the switch with random MACs. Option D is wrong because DNS spoofing requires corrupting DNS responses or cache entries, which is unrelated to the layer-2 MAC flooding performed by `macof`.

87
MCQeasy

An organization experiences a DDoS attack where a large volume of DNS queries with spoofed source IPs are sent to open DNS resolvers, which then amplify the traffic to the victim. Which type of attack is this?

A.UDP flood
B.Smurf attack
C.SYN flood
D.DNS amplification
AnswerD

Uses open DNS resolvers to amplify traffic to the victim.

Why this answer

This is a DNS amplification attack, a type of DDoS that exploits open DNS resolvers. The attacker sends a small DNS query (e.g., ANY type) with a spoofed source IP (the victim's IP) to an open resolver, which responds with a much larger response (up to 50-100x the query size), flooding the victim. The key mechanism is the amplification factor combined with the spoofed source address, which directs the amplified traffic to the victim.

Exam trap

In EC-CEH, candidates often mistake DNS amplification for a basic UDP flood or Smurf attack. The key is to recognize the involvement of an open DNS resolver and the amplification factor, which are hallmarks of this attack.

How to eliminate wrong answers

Option A is wrong because a UDP flood is a generic attack where the attacker directly sends a high volume of UDP packets to the victim, without using a third-party reflector or amplification; this scenario specifically involves open DNS resolvers amplifying traffic. Option B is wrong because a Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP, causing all hosts on the network to reply to the victim; this attack uses DNS queries, not ICMP, and targets open resolvers, not broadcast addresses. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed IPs to exhaust server resources; this attack uses UDP-based DNS queries, not TCP SYN packets.

88
MCQmedium

An analyst uses the following command to capture traffic: tcpdump -i eth0 -w capture.pcap host 10.0.0.5 and port 80. After generating traffic from a web server at 10.0.0.5, the analyst examines the pcap with Wireshark. What type of traffic will appear in the capture?

A.All HTTP traffic on the network
B.HTTP traffic to and from 10.0.0.5
C.Only HTTP traffic originating from 10.0.0.5
D.All traffic from 10.0.0.5 on any port
AnswerB

The "host 10.0.0.5" filter inherently captures traffic where 10.0.0.5 is either the source or the destination IP address, encompassing both inbound and outbound communications. Coupled with "port 80", which identifies standard HTTP traffic, this command precisely targets all HTTP conversations involving the specified host, regardless of direction.

Why this answer

The command `tcpdump -i eth0 -w capture.pcap host 10.0.0.5 and port 80` captures only packets that match both conditions: the IP address is 10.0.0.5 (source or destination) and the port is 80 (source or destination). Since port 80 is the default HTTP port, this filter captures HTTP traffic to and from the web server at 10.0.0.5. The `host` keyword includes both directions, so the capture is not limited to traffic originating from the server.

Exam trap

The trap here is that candidates often assume `host` implies only traffic originating from the specified IP, but in BPF syntax, `host` captures bidirectional traffic unless modified with `src` or `dst`.

How to eliminate wrong answers

Option A is wrong because the filter restricts traffic to host 10.0.0.5 and port 80, not all HTTP traffic on the network; other hosts' HTTP traffic would be excluded. Option C is wrong because the `host` keyword captures traffic in both directions (to and from 10.0.0.5), not only traffic originating from that IP; the filter does not specify a source-only modifier like `src`. Option D is wrong because the filter includes `port 80`, which limits traffic to that specific port; traffic from 10.0.0.5 on any other port (e.g., SSH on port 22) would not be captured.

89
MCQhard

A system administrator notices unusual outbound traffic from a server on port 4444. The server has no legitimate service listening on that port. A malware analyst runs 'strings' on a suspicious binary and finds a reference to 'cmd.exe /c' and an IP address. What type of malware is MOST likely present?

A.Worm
B.Keylogger
C.Backdoor Trojan
D.Ransomware
AnswerC

A Backdoor Trojan is malware disguised as legitimate software that, once executed, creates a covert entry point into a compromised system, bypassing normal authentication mechanisms. The "unusual outbound traffic" combined with the execution of `cmd.exe /c` on a non-standard port like 4444 is a classic indicator of a Remote Access Trojan (RAT) or backdoor establishing a command-and-control (C2) channel. This setup allows an attacker to remotely issue commands and control the compromised machine, aligning perfectly with the observed remote shell activity.

Why this answer

The outbound traffic on port 4444, a common port for the Metasploit Meterpreter reverse shell, combined with the 'strings' output showing 'cmd.exe /c' (a command shell invocation) and an IP address, indicates a backdoor Trojan. This malware type establishes a covert reverse connection to an attacker's command-and-control server, allowing remote shell access without a legitimate service on the target port.

Exam trap

The trap here is that candidates may associate port 4444 with legitimate services like Kerberos or Blizzard games, but CEH expects you to recognize it as the default Metasploit reverse shell port, not a worm or ransomware indicator.

How to eliminate wrong answers

Option A is wrong because a worm self-propagates across networks without requiring a manual trigger or a specific reverse shell payload, and it typically uses exploit vectors like SMB or RDP, not a static outbound connection on port 4444. Option B is wrong because a keylogger captures keystrokes locally and sends logs via HTTP or SMTP, not by spawning 'cmd.exe /c' for interactive remote shell access. Option D is wrong because ransomware encrypts files and demands payment, often using HTTPS for C2 communication, not a raw TCP reverse shell on port 4444 with a command-line interface.

90
MCQmedium

A security analyst observes a gradual increase in network traffic from an internal host to an external IP address on port 443, with the host also connecting to a known command-and-control (C2) domain. Which type of malware is MOST likely responsible?

A.Ransomware
B.Worm
C.Boot sector virus
D.Backdoor Trojan
AnswerD

A backdoor Trojan establishes a covert communication channel, granting an attacker persistent remote access and control over the compromised system. This persistent access necessitates regular, often low-volume, communication with a Command and Control (C2) server to receive commands, exfiltrate data, or update its status. The observed 'gradual increase in network traffic' is highly indicative of such C2 activity, as the attacker intermittently interacts with the backdoor over time, leading to a subtle but sustained rise in outbound or inbound connections.

Why this answer

The gradual increase in traffic to an external IP on port 443 (HTTPS) combined with connections to a known C2 domain indicates a backdoor Trojan. Backdoor Trojans establish stealthy, encrypted command-and-control channels to exfiltrate data or receive instructions, often mimicking legitimate HTTPS traffic to evade detection. This behavior aligns with a backdoor Trojan's purpose of providing unauthorized remote access while blending into normal network activity.

Exam trap

The trap here is that candidates may associate port 443 with legitimate web traffic and overlook the gradual, stealthy nature of the C2 communication, instead choosing ransomware or worm due to their more dramatic behaviors.

How to eliminate wrong answers

Option A is wrong because ransomware typically exhibits rapid, widespread file encryption and ransom note delivery, not a gradual increase in C2 traffic on port 443. Option B is wrong because a worm self-replicates across networks without requiring a C2 channel for remote control; its primary behavior is propagation, not sustained encrypted communication with an external server. Option C is wrong because a boot sector virus infects the Master Boot Record (MBR) and activates during system boot, not by generating network traffic to a C2 domain over HTTPS.

91
MCQmedium

A security analyst notices a significant increase in outbound traffic from an internal server to multiple external IPs on port 443. The server is not a web server and should not be initiating such connections. Which type of malware is MOST likely causing this behavior?

A.A boot sector virus
B.A backdoor Trojan
C.A fileless virus
D.A worm
AnswerB

A backdoor Trojan is designed to provide covert remote access to a compromised system, often establishing persistent communication channels with Command and Control (C2) servers. This communication frequently occurs over encrypted protocols like HTTPS to evade detection and blend with legitimate network traffic. The observed significant increase in outbound HTTPS traffic to multiple IP addresses is highly characteristic of a backdoor Trojan actively exfiltrating data, receiving commands, or updating its C2 infrastructure.

Why this answer

A backdoor Trojan is designed to give an attacker remote control over an infected system, often using outbound connections on common ports like 443 (HTTPS) to blend in with normal traffic. Since the server is not a web server and should not be initiating outbound HTTPS connections, this anomalous behavior strongly indicates a backdoor Trojan is exfiltrating data or receiving commands via encrypted channels.

Exam trap

The trap here is that candidates confuse a worm's network propagation behavior with a backdoor Trojan's command-and-control traffic, but the key differentiator is that the server is not a web server and the connections are outbound to multiple external IPs on a common encrypted port, which is classic C2 exfiltration, not self-replication.

How to eliminate wrong answers

Option A is wrong because a boot sector virus infects the Master Boot Record (MBR) and typically activates during system boot, not by generating outbound network traffic to external IPs. Option C is wrong because a fileless virus operates in memory (e.g., using PowerShell or WMI) and does not persistently create outbound connections on port 443; its primary trait is avoiding disk writes, not initiating stealthy command-and-control traffic. Option D is wrong because a worm self-replicates across networks using vulnerabilities or weak credentials, often causing widespread scanning or payload delivery, but its hallmark is propagation, not establishing a persistent backdoor for outbound data exfiltration on a single non-web server.

92
MCQhard

A security team detects that an internal host is sending ARP replies claiming to have the IP address of the default gateway. Which tool is MOST likely being used to perform this attack?

A.Nmap
B.tcpdump
C.Wireshark
D.Ettercap
AnswerD

Ettercap is a comprehensive suite for man-in-the-middle (MITM) attacks on LANs, specifically designed for ARP poisoning. It actively injects forged ARP replies into the network, tricking hosts into believing the attacker's MAC address is associated with the gateway's IP, and vice-versa. This redirection allows Ettercap to intercept, analyze, and even modify traffic between victims, making it a primary tool for detecting and executing ARP-based attacks.

Why this answer

Ettercap is a dedicated man-in-the-middle (MITM) attack tool that includes built-in ARP poisoning functionality. It sends forged ARP replies to associate the attacker's MAC address with the default gateway's IP, redirecting traffic through the attacker's host. This matches the described behavior of claiming the gateway's IP address via ARP replies.

Exam trap

The trap here is that candidates confuse passive monitoring tools (tcpdump, Wireshark) with active attack tools, or mistake Nmap's scanning capabilities for ARP spoofing, when only Ettercap is specifically designed for MITM via ARP poisoning.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning and enumeration tool used for port discovery and service detection, not for generating forged ARP replies. Option B is wrong because tcpdump is a command-line packet capture utility that passively captures traffic; it cannot actively inject ARP replies. Option C is wrong because Wireshark is a graphical packet analyzer used for deep inspection of captured packets, not for crafting or sending malicious ARP packets.

93
MCQmedium

A penetration tester uses a tool to perform ARP poisoning and then launches a man-in-the-middle attack. The tool also allows session hijacking and sniffing. Which of the following tools is being used?

A.Wireshark
B.tcpdump
C.Ettercap
D.Nmap
AnswerC

Ettercap supports ARP poisoning, MITM, and sniffing.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on LANs, featuring built-in ARP poisoning, session hijacking, and sniffing capabilities. It actively intercepts traffic by spoofing ARP replies to redirect packets through the attacker's machine, enabling real-time manipulation of sessions. This matches the question's description of a tool that performs ARP poisoning, MITM attacks, session hijacking, and sniffing.

Exam trap

The trap here is that candidates often confuse Wireshark's passive sniffing capability with active MITM functionality, forgetting that Wireshark cannot perform ARP poisoning or session hijacking on its own.

How to eliminate wrong answers

Option A is wrong because Wireshark is a passive network protocol analyzer that captures and inspects packets but does not perform active attacks like ARP poisoning or session hijacking. Option B is wrong because tcpdump is a command-line packet capture tool that only dumps traffic for offline analysis, lacking any active manipulation or MITM capabilities. Option D is wrong because Nmap is a network discovery and security scanning tool used for port scanning and OS detection, not for ARP poisoning, session hijacking, or sniffing in an active MITM context.

94
MCQeasy

A system administrator receives a phone call from someone claiming to be from IT support, asking for the administrator's password to 'fix a server issue'. This is an example of which social engineering attack?

A.Vishing
B.Baiting
C.Phishing
D.Pretexting
AnswerD

Pretexting is a sophisticated social engineering attack where an attacker creates a believable, fabricated scenario, known as a 'pretext,' to manipulate a target into divulging sensitive information or performing a specific action. This often involves extensive research to build a convincing backstory and impersonate a legitimate individual or authority. The attacker maintains an interactive conversation, adapting the narrative to overcome skepticism and extract specific details, such as a password, under the guise of solving a problem or verifying identity.

Why this answer

Pretexting is a social engineering attack where the attacker fabricates a scenario (pretext) to manipulate the target into divulging sensitive information. In this case, the attacker impersonates IT support and invokes a fake server issue to create urgency, directly requesting the administrator's password. This aligns with the CEH definition of pretexting as a confidence-building deception, not a technical exploit.

Exam trap

The trap here is that candidates confuse the delivery method (phone call) with vishing, but the CEH exam distinguishes pretexting by the use of a fabricated scenario or false identity, regardless of the communication channel.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls to trick victims into revealing information, but the core attack here is the fabricated story (pretext), not the medium; vishing is a subset of phishing, and the question's emphasis is on the false identity and scenario. Option B is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim into a trap, not a direct request for credentials via a phone call. Option C is wrong because phishing typically uses electronic communication (email, SMS, or fake websites) to harvest credentials, not a live phone call with a constructed narrative; this is a voice-based pretexting scenario.

95
MCQmedium

During a penetration test, a security analyst runs the following command on a Linux system: ettercap -T -M arp:remote /192.168.1.1// /192.168.1.100//. What is the PRIMARY purpose of this command?

A.To spoof the DNS responses to redirect the target to a malicious site
B.To sniff all traffic on the network by enabling promiscuous mode on the interface
C.To perform a denial-of-service attack by flooding the network with ARP replies
D.To perform a man-in-the-middle attack between the gateway and the target host
AnswerD

The `ettercap -M arp:remote` command is specifically designed to execute a man-in-the-middle (MITM) attack by poisoning the ARP caches of both the target host and the network gateway. By sending forged ARP replies, the attacker's machine convinces the target that it is the gateway, and convinces the gateway that it is the target. This redirection ensures all traffic flowing between the target and the internet passes through the attacker, enabling interception and potential manipulation.

Why this answer

The command `ettercap -T -M arp:remote /192.168.1.1// /192.168.1.100//` uses ARP poisoning in remote mode to intercept traffic between the gateway (192.168.1.1) and the target host (192.168.1.100). By sending forged ARP replies to both devices, the attacker's machine becomes a man-in-the-middle, allowing it to capture, modify, or relay packets between them. The `-M arp:remote` flag specifically enables ARP poisoning for a MITM attack, not for DNS spoofing, promiscuous mode, or flooding.

Exam trap

The trap here is that candidates confuse ARP poisoning with DNS spoofing or assume the command is for passive sniffing, but the `-M arp:remote` flag explicitly indicates an active MITM attack, not a passive or flooding technique.

How to eliminate wrong answers

Option A is wrong because DNS spoofing requires a separate plugin (e.g., `ettercap -T -M arp:remote -P dns_spoof`) and is not the primary purpose of the base ARP poisoning command. Option B is wrong because enabling promiscuous mode is a passive operation (e.g., `ifconfig eth0 promisc`), while this command actively sends forged ARP packets to manipulate traffic flow. Option C is wrong because a denial-of-service attack via ARP flooding would require a different tool or flag (e.g., `arping -f` or `macof`), and the `-M arp:remote` flag is designed for bidirectional interception, not network saturation.

96
Multi-Selectmedium

Which TWO of the following are characteristics of a polymorphic virus?

Select 2 answers
A.It changes its code signature each time it infects a new file
B.It spreads via email attachments
C.It uses encryption with a variable key
D.It remains dormant until a specific date or time
E.It can infect the Master Boot Record (MBR)
AnswersA, C

Polymorphic malware is specifically designed to alter its internal structure and appearance with each new infection. This constant mutation means that the virus's binary code, and consequently its cryptographic hash or signature, changes every time it replicates. This characteristic is fundamental to its ability to evade signature-based antivirus detection systems, which rely on identifying fixed patterns.

Why this answer

A polymorphic virus changes its decryption routine and code signature each time it infects a new file, making signature-based detection difficult. This mutation is achieved by using a polymorphic engine that generates varied decryption loops while preserving the malicious payload.

Exam trap

The trap here is that candidates confuse the method of propagation (e.g., email) or activation trigger (e.g., date) with the core definition of polymorphism, which is solely about code mutation to evade signature detection.

97
MCQhard

An analyst captures network traffic and sees a large number of packets with source IP 10.0.0.1, destination IP 192.168.1.1, TCP SYN flag set, with sequence numbers that appear incremental. The destination responds with SYN-ACK but the source never completes the handshake. Which attack is MOST likely occurring?

A.ARP poisoning
B.SYN flood
C.ICMP flood
D.DNS amplification
AnswerB

SYN flood uses incomplete TCP handshakes to exhaust resources.

Why this answer

This behavior describes a classic SYN flood attack. The source (10.0.0.1) sends a high volume of TCP SYN packets with incremental sequence numbers to the target (192.168.1.1). The target responds with SYN-ACK packets, but the source never sends the final ACK to complete the three-way handshake.

This leaves the target with half-open connections that exhaust its connection table, denying service to legitimate traffic.

Exam trap

The trap here is that candidates may confuse a SYN flood with a TCP three-way handshake completion failure due to a firewall or routing issue, but the key indicator is the large number of SYN packets with no final ACK, which is the hallmark of a deliberate DoS attack, not a network glitch.

How to eliminate wrong answers

Option A is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host, not sending TCP SYN packets with incremental sequence numbers. Option C is wrong because an ICMP flood uses ICMP echo request (ping) packets, not TCP SYN packets, to overwhelm a target. Option D is wrong because DNS amplification exploits open DNS resolvers to send large DNS response packets to a spoofed victim IP, using UDP, not TCP SYN packets.

98
MCQeasy

Which type of malware is characterized by its ability to spread without requiring a host file and can replicate across networks automatically?

A.Virus
B.Trojan
C.Worm
D.Ransomware
AnswerC

A worm is a standalone malicious program designed to self-replicate and propagate autonomously across computer networks without requiring a host program or user intervention. It exploits network vulnerabilities or configuration weaknesses to spread from one system to another, consuming bandwidth and system resources. This self-replicating capability is its defining characteristic, allowing it to infect numerous machines rapidly.

Why this answer

A worm is a standalone malware program that replicates itself across networks without requiring a host file or user intervention. It exploits network vulnerabilities, such as unpatched services or weak credentials, to propagate automatically, often using protocols like SMB, RDP, or email transport mechanisms.

Exam trap

The trap here is that candidates often confuse a worm's self-replication with a virus's need for a host file, leading them to select 'Virus' because they associate malware spread with file infection, ignoring the worm's autonomous network propagation capability.

How to eliminate wrong answers

Option A is wrong because a virus requires a host file (e.g., an executable or document) to attach itself and relies on user action (e.g., opening a file) to spread, not automatic network replication. Option B is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on social engineering to trick users into executing it. Option D is wrong because ransomware encrypts files for extortion and typically spreads via email attachments or exploits, but it is not defined by autonomous network propagation without a host file.

99
Multi-Selectmedium

Which TWO of the following are examples of social engineering attacks? (Select two)

Select 2 answers
A.Pharming
B.Pretexting
C.SYN flood
D.Brute force attack
E.Vishing
AnswersB, E

Pretexting involves creating a fabricated scenario to obtain information.

Why this answer

Pretexting is a social engineering attack where the attacker creates a fabricated scenario (pretext) to trick a target into divulging sensitive information or performing an action. It relies on impersonation and psychological manipulation rather than technical exploitation, making it a classic example of human-based social engineering.

Exam trap

The trap here is that candidates may confuse pharming (a technical redirection attack) with social engineering, but pharming does not involve direct human interaction or psychological manipulation, which is the defining characteristic of social engineering attacks.

100
MCQhard

During a penetration test, an analyst uses a tool that sends forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This technique allows the attacker to intercept traffic. Which tool is commonly used for this purpose?

A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA

Ettercap performs ARP poisoning and MITM attacks.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on LAN. It supports ARP poisoning, where it sends forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This causes the target's traffic destined for the gateway to be sent to the attacker, allowing interception and modification of packets.

Exam trap

The trap here is that candidates often confuse passive sniffing tools (like Wireshark or tcpdump) with active attack tools, assuming any packet capture tool can also inject packets, but only dedicated MITM tools like Ettercap implement ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets passively; it does not send forged ARP replies or actively manipulate network traffic. Option C is wrong because Nmap is a network discovery and security scanning tool used for port scanning and service enumeration; it does not perform ARP spoofing or man-in-the-middle attacks. Option D is wrong because tcpdump is a command-line packet analyzer used for capturing and displaying network traffic; it lacks the ability to inject forged ARP packets or conduct active interception attacks.

101
MCQmedium

Which of the following is a characteristic of a polymorphic virus?

A.It changes its code pattern every time it infects a new file or system.
B.It spreads through network shares without requiring user interaction.
C.It remains dormant until a specific date or time.
D.It infects the master boot record of a hard drive.
AnswerA

Polymorphic viruses use encryption or other techniques to change their signature while preserving functionality.

Why this answer

A polymorphic virus is designed to evade signature-based detection by mutating its code—typically using an encryption engine and a mutation engine—so that each infection generates a functionally identical but byte-wise different payload. This constant change in the virus's signature pattern prevents antivirus software from recognizing it through static file hashes or fixed byte sequences.

Exam trap

The trap here is that candidates often confuse 'polymorphic' with 'metamorphic' viruses—polymorphic changes the decryptor but keeps the body constant, while metamorphic rewrites the entire code—or they mistakenly associate any self-changing behavior with worms or boot sector infections.

How to eliminate wrong answers

Option B is wrong because it describes a worm, not a virus; worms self-propagate across network shares without user interaction, whereas a virus requires a host file or system to attach to. Option C is wrong because it describes a logic bomb or time bomb, which remains dormant until a specific trigger (date/time) activates it, not a polymorphic virus. Option D is wrong because it describes a boot sector virus, which infects the master boot record (MBR) and loads before the OS, but does not inherently mutate its code pattern with each infection.

102
MCQmedium

A security analyst runs the command 'tcpdump -i eth0 -n host 10.0.0.5 and port 80' and sees many packets with the SYN flag set but no corresponding ACK. Which attack is likely occurring?

A.SYN flood
B.ICMP flood
C.UDP flood
D.Ping of Death
AnswerA

A SYN flood is characterized by an attacker sending a large volume of TCP SYN packets to a target server without completing the three-way handshake. The tcpdump -i eth0 -n host command would reveal a high rate of incoming TCP packets with the SYN flag set, directed at the specified host, but without corresponding SYN-ACK or ACK packets originating from the target. This pattern indicates numerous half-open connections accumulating on the target, exhausting its connection table resources.

Why this answer

The command captures TCP packets on port 80 with the SYN flag set but no corresponding ACK, which indicates that the target is receiving SYN requests but never completing the three-way handshake. This is the hallmark of a SYN flood attack, where the attacker sends a high volume of SYN packets to exhaust the server's connection queue, preventing legitimate connections.

Exam trap

The trap here is that candidates confuse a SYN flood with a generic 'flood' attack (like ICMP or UDP flood) because they focus on the word 'flood' rather than the specific TCP handshake behavior indicated by the SYN flag without ACK.

How to eliminate wrong answers

Option B is wrong because an ICMP flood involves sending a high volume of ICMP echo request (ping) packets, not TCP SYN packets, and would not be captured by a filter for port 80. Option C is wrong because a UDP flood targets UDP ports with a high volume of UDP datagrams, not TCP SYN packets, and would not match the 'port 80' filter (which is TCP-specific). Option D is wrong because a Ping of Death attack sends a malformed oversized ICMP packet to cause a buffer overflow, not TCP SYN packets, and is not related to incomplete handshakes.

103
Multi-Selectmedium

Which TWO of the following are characteristics of a polymorphic virus? (Select 2)

Select 2 answers
A.It spreads via email attachments only
B.It changes its code signature each time it replicates
C.It requires a host file to attach
D.It self-replicates without user interaction
E.It uses encryption to hide its payload
AnswersB, E

A defining characteristic of a polymorphic virus is its ability to alter its internal code structure and signature with each new infection or replication. This mutation is achieved through a polymorphic engine, which modifies the virus's instruction set and encryption key while preserving its malicious payload and functionality. This constant change makes it exceptionally challenging for traditional signature-based antivirus solutions to identify and block the malware consistently.

Why this answer

A polymorphic virus mutates its code signature—often by altering the decryption routine or using different encryption keys—each time it replicates, which allows it to evade signature-based detection by antivirus software. Option E is correct because polymorphic viruses typically use encryption to hide their payload, with a variable decryption engine that changes the encrypted form of the virus body upon each infection.

Exam trap

A common trap in CEH is confusing polymorphic and metamorphic viruses—candidates mistakenly think encryption alone defines polymorphism, but the key is that the decryption routine (not just the payload) changes with each replication, and they may also confuse host file requirement (parasitic) with the mutation characteristic.

104
Multi-Selectmedium

Which TWO of the following are techniques used in session hijacking? (Choose 2)

Select 2 answers
A.Cookie theft
B.MAC flooding
C.ARP poisoning
D.TCP sequence prediction
E.DNS spoofing
AnswersA, D

Stealing session cookies allows an attacker to impersonate a user.

Why this answer

Cookie theft is a session hijacking technique where an attacker captures a user's session cookie (e.g., via XSS, packet sniffing, or malware) and uses it to impersonate the user. Since HTTP is stateless, the server relies on the cookie to identify the session, so stealing it grants the attacker unauthorized access without needing credentials.

Exam trap

EC-CEH often tests the distinction between session hijacking (directly taking over an active session) and network-level attacks (like ARP poisoning or MAC flooding) that merely enable interception or sniffing, causing candidates to confuse enabling techniques with the hijacking technique itself.

105
MCQhard

An analyst runs the following command: `tcpdump -i eth0 src host 192.168.1.10 and dst port 80 -w http_traffic.pcap`. What is the primary purpose of this command?

A.To perform a man-in-the-middle attack on HTTP traffic
B.To capture all traffic on eth0 and display it in real-time
C.To capture only HTTP traffic from a specific source IP and save it to a file
D.To analyze the payload of HTTP packets in real-time
AnswerC

This option accurately describes the command's functionality. The `-i eth0` flag specifies the network interface for capture. The `src host 192.168.1.10` filter ensures only packets originating from that specific IP address are captured, while `dst port 80` further narrows the scope to only include HTTP traffic (standard port 80). Finally, the `-w capture.pcap` flag instructs tcpdump to save all filtered packets to a file named `capture.pcap` for subsequent offline analysis.

Why this answer

The command `tcpdump -i eth0 src host 192.168.1.10 and dst port 80 -w http_traffic.pcap` uses a BPF (Berkeley Packet Filter) expression to capture only packets originating from source IP 192.168.1.10 and destined for TCP port 80 (HTTP). The `-w` flag writes the filtered packets directly to a pcap file, not to standard output, making the primary purpose to capture and save specific HTTP traffic for later analysis.

Exam trap

The trap here is that candidates confuse the `-w` (write to file) option with `-r` (read from file) or assume tcpdump displays output in real-time by default, leading them to choose Option B, even though the filter and `-w` flag clearly indicate a targeted capture to a file.

How to eliminate wrong answers

Option A is wrong because tcpdump is a passive packet capture tool; it does not intercept, modify, or relay packets between two parties, which are required for a man-in-the-middle attack. Option B is wrong because the `-w` flag suppresses real-time display and writes to a file, and the filter `src host 192.168.1.10 and dst port 80` limits capture to specific traffic, not all traffic on eth0. Option D is wrong because tcpdump captures raw packet headers and payloads but does not perform application-layer payload analysis or reassembly; it simply records the bytes as seen on the wire.

106
MCQmedium

An organization wants to test its employees' susceptibility to social engineering by sending fake emails that appear to come from the IT department, requesting password resets. Which tool would be MOST effective for conducting this test?

A.Social Engineering Toolkit (SET)
B.Wireshark
C.Metasploit
D.Nmap
AnswerA

The Social Engineering Toolkit (SET) is purpose-built for simulating various social engineering attacks, making it the ideal choice for testing employee susceptibility. It provides modules for spear phishing, credential harvesting, web jacking, and infectious media generator attacks, directly targeting the human element. By deploying these simulated threats, organizations can assess how employees react to realistic social engineering tactics and identify areas for security awareness training improvement.

Why this answer

The Social Engineering Toolkit (SET) is specifically designed for social engineering attacks, including crafting convincing phishing emails that mimic internal departments like IT. It automates the creation of fake login pages and email templates, making it the most effective tool for testing employee susceptibility to password reset requests.

Exam trap

The trap here is that candidates often confuse Metasploit's exploit capabilities with social engineering, overlooking that SET is the dedicated tool for crafting and executing phishing campaigns, not just delivering payloads.

How to eliminate wrong answers

Option B (Wireshark) is wrong because it is a network protocol analyzer used for capturing and inspecting packets, not for generating social engineering attacks. Option C (Metasploit) is wrong because, while it can deliver payloads via exploits, its primary focus is on exploiting system vulnerabilities rather than crafting social engineering lures like fake IT emails. Option D (Nmap) is wrong because it is a network scanning tool used for port discovery and service enumeration, with no capability to create or send phishing emails.

107
MCQhard

An incident response team discovers a suspicious executable on a compromised workstation. They want to analyze the malware without executing it. Which of the following techniques would be MOST appropriate for this initial analysis?

A.Capturing network traffic with Wireshark during execution
B.Using the 'strings' command to extract embedded text
C.Monitoring process behavior with Process Monitor
D.Running the executable in a sandboxed environment
AnswerB

Using the 'strings' command is a quintessential static analysis method as it involves examining the binary file directly on disk without executing it. This command extracts sequences of printable ASCII or Unicode characters embedded within the executable, which can reveal valuable clues such as file paths, URLs, API function names, or error messages hardcoded by the malware author.

Why this answer

The 'strings' command extracts human-readable text from a binary file without executing it, making it ideal for static analysis. This technique can reveal indicators such as IP addresses, domain names, file paths, registry keys, or embedded commands that help classify the malware's purpose and capabilities without triggering its payload.

Exam trap

The trap here is that candidates confuse 'dynamic analysis' techniques (like sandboxing or process monitoring) with 'static analysis', failing to recognize that the question's constraint 'without executing it' eliminates any option that requires runtime behavior.

How to eliminate wrong answers

Option A is wrong because capturing network traffic with Wireshark during execution requires the malware to run, which violates the requirement to analyze without executing. Option C is wrong because Process Monitor monitors real-time process behavior, which also requires the executable to be running. Option D is wrong because running the executable in a sandboxed environment still involves execution, which the question explicitly prohibits.

108
MCQhard

An organization experiences a DDoS attack where the attacker sends many incomplete HTTP requests that keep connections open, exhausting the server's connection pool. Which attack technique is being used?

A.UDP flood
B.HTTP flood
C.SYN flood
D.Slowloris
AnswerD

Slowloris sends partial HTTP headers slowly, holding connections open until the server's limit is reached.

Why this answer

Slowloris is a DDoS attack that works by opening multiple connections to the target server and sending partial HTTP requests, never completing them. The server keeps these connections open waiting for the rest of the request, eventually exhausting the connection pool and denying service to legitimate users. This matches the description of incomplete HTTP requests keeping connections open.

Exam trap

In CEH, candidates often confuse a SYN flood (TCP layer, half-open connections) with Slowloris (HTTP layer, partial requests). Slowloris keeps connections open by sending incomplete HTTP headers, targeting the application layer, unlike SYN flood which operates at the transport layer.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends large volumes of UDP packets to random ports, overwhelming the server's bandwidth or processing capacity, not by keeping HTTP connections open. Option B is wrong because an HTTP flood sends complete, legitimate-looking HTTP requests at high volume to overwhelm the server's processing resources, not by leaving connections incomplete. Option C is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting the server's TCP connection backlog, not by sending incomplete HTTP requests.

109
MCQeasy

A user receives a phone call from someone claiming to be from IT support, asking for their password to troubleshoot an issue. Which social engineering technique is being used?

A.Phishing
B.Pretexting
C.Baiting
D.Vishing
AnswerB

Correct. The attacker uses a false pretext (IT support) to obtain sensitive information.

Why this answer

Pretexting is a social engineering technique where the attacker creates a fabricated scenario (pretext) to trick the victim into divulging sensitive information. In this case, the caller impersonates IT support to establish a false sense of authority and urgency, directly asking for the password. This differs from vishing, which is voice-based phishing but typically involves a generic, automated or scripted request rather than a crafted, interactive pretext.

Exam trap

The trap here is that candidates often confuse vishing with pretexting because both involve phone calls, but vishing is a subset of phishing that relies on automated or scripted voice messages, whereas pretexting involves a live, interactive social engineering scenario where the attacker fabricates a detailed identity and story.

How to eliminate wrong answers

Option A (Phishing) is wrong because phishing typically involves sending deceptive emails or messages with malicious links or attachments to harvest credentials, not a direct phone call asking for a password. Option C (Baiting) is wrong because baiting relies on offering something enticing (e.g., a free USB drive or download) to lure the victim into executing malware or revealing information, not a phone-based impersonation. Option D (Vishing) is wrong because while vishing is voice phishing, it usually uses spoofed caller IDs and automated messages to trick victims into calling back or entering credentials on a keypad, not a live, interactive conversation where the attacker builds a pretext to directly ask for a password.

110
MCQmedium

A security analyst observes a sudden surge in incoming UDP traffic to the company's DNS servers from multiple external IP addresses. The packets appear to be DNS queries with spoofed source IPs. Which type of DDoS attack is MOST likely occurring?

A.SYN flood
B.DNS amplification
C.UDP flood
D.ICMP flood
AnswerB

DNS amplification is a highly effective distributed denial-of-service (DDoS) attack where attackers send small UDP DNS queries with a spoofed source IP address (the victim's IP) to numerous open DNS resolvers. These resolvers then respond with much larger UDP packets containing DNS records, directed back to the spoofed victim. This technique leverages the amplification factor of DNS responses to overwhelm the target with a massive surge of incoming UDP traffic, typically on port 53.

Why this answer

The attack described involves DNS queries with spoofed source IPs sent to a DNS server, which then responds with large replies to the victim (the spoofed IP). This is a classic DNS amplification attack, a type of reflection-based DDoS that exploits the large response-to-query ratio (e.g., an ANY query can yield a response up to 70x larger) to overwhelm the target. The surge in incoming UDP traffic to the DNS server is the attacker's queries, while the amplified responses are directed at the spoofed victim.

Exam trap

The trap here is that candidates confuse a simple UDP flood (direct traffic) with a DNS amplification attack, missing the key indicator of spoofed source IPs and the reflection/amplification mechanism that distinguishes it.

How to eliminate wrong answers

Option A is wrong because a SYN flood targets the TCP three-way handshake by sending incomplete SYN packets, not UDP-based DNS queries with spoofed source IPs. Option C is wrong because a UDP flood is a direct volumetric attack where the attacker sends high volumes of UDP packets to a target, but it does not involve DNS query/response amplification or spoofed source IPs to reflect traffic off a legitimate server. Option D is wrong because an ICMP flood uses ICMP echo request (ping) packets, not UDP DNS queries, and does not leverage amplification or reflection from a DNS server.

111
MCQhard

A security analyst captures network traffic and sees a sequence of ARP replies with the same IP address mapping to different MAC addresses within a short period. Which attack is indicated?

A.DNS spoofing
B.ARP poisoning
C.DHCP starvation
D.MAC flooding
AnswerB

ARP poisoning, also known as ARP spoofing, is a man-in-the-middle attack where an attacker sends forged ARP reply messages onto a local area network. These malicious replies associate the attacker's MAC address with the IP address of another host, such as the default gateway or another workstation. By continuously sending these fake ARP replies, the attacker can trick multiple devices into updating their ARP caches with incorrect information, thereby redirecting traffic intended for the legitimate IP to the attacker's machine. This directly explains the observation of multiple ARP replies for one IP.

Why this answer

B is correct because ARP poisoning (also called ARP spoofing) involves sending forged ARP replies that map a target IP address (e.g., the default gateway) to the attacker's MAC address. The rapid sequence of ARP replies with the same IP but different MACs is a classic indicator of an active ARP poisoning attack, where the attacker floods the network to corrupt the ARP cache of hosts.

Exam trap

The trap here is that candidates confuse ARP poisoning with MAC flooding because both involve MAC addresses and network manipulation, but MAC flooding targets the switch's CAM table, not the host's ARP cache, and uses many different MACs, not the same IP mapped to multiple MACs.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS responses to redirect domain name lookups, not ARP tables; it operates at Layer 7 (application) using UDP port 53, not Layer 2/3 ARP messages. Option C is wrong because DHCP starvation floods a DHCP server with fake DISCOVER messages to exhaust its IP address pool, causing denial of service; it does not involve ARP replies or MAC-to-IP mapping changes. Option D is wrong because MAC flooding overwhelms a switch's CAM table with fake MAC addresses to force it into fail-open mode (hub mode), enabling packet sniffing; it does not target ARP caches or use ARP replies with the same IP to different MACs.

112
Multi-Selectmedium

A network administrator notices unusual traffic patterns: the internal DNS server is receiving large DNS queries with the source IP spoofed to appear as the internal DNS server itself. The queries appear to be amplification requests. Which TWO characteristics describe this attack?

Select 2 answers
A.It is a protocol-specific attack targeting TCP SYN packets
B.It relies on open DNS resolvers to amplify traffic
C.It exploits the ARP protocol to redirect traffic
D.It is a form of DDoS attack
E.It requires the attacker to be on the same subnet as the victim
AnswersB, D

This is correct because DNS amplification attacks exploit misconfigured or intentionally open DNS resolvers that are accessible on the internet. Attackers send small DNS queries to these resolvers, spoofing the victim's IP address as the source. The open resolvers then respond with significantly larger DNS records to the unsuspecting victim, effectively multiplying the attacker's initial traffic volume.

Why this answer

The attack described relies on open DNS resolvers to amplify traffic. The attacker sends small DNS queries with a spoofed source IP (the victim's DNS server), causing the open resolver to send large responses to the victim, thus amplifying the traffic volume. This is a classic DNS amplification attack, which is a type of reflection attack that exploits the UDP protocol and the fact that DNS response sizes can be significantly larger than query sizes.

Exam trap

The trap here is that candidates may confuse DNS amplification with other reflection attacks (e.g., NTP amplification) or mistakenly think the attacker must be on the same subnet, when in fact IP spoofing allows the attack to originate from anywhere.

113
MCQhard

A penetration tester wants to perform a stealth scan without completing the TCP three-way handshake. The target is a web server on port 80. The tester uses Nmap with the -sS flag. What is the expected behavior if the port is open?

A.The tester receives a SYN/ACK and sends an RST to tear down the connection.
B.The tester receives an RST, indicating the port is closed.
C.The tester receives no response, indicating a filtered port.
D.The tester receives a SYN/ACK and sends an ACK to establish the connection.
AnswerA

A SYN scan, often referred to as a half-open scan, initiates a TCP handshake by sending a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK packet. To avoid logging a full connection on the target system and thus maintain stealth, the penetration tester immediately sends an RST (reset) packet, tearing down the nascent connection before the three-way handshake completes. This allows port status determination without fully establishing a session.

Why this answer

The -sS flag in Nmap performs a SYN stealth scan, which sends a SYN packet to the target port. If the port is open, the target responds with a SYN/ACK, and the tester's operating system kernel automatically sends an RST to tear down the connection before the three-way handshake completes. This avoids establishing a full TCP connection, making the scan less detectable by some intrusion detection systems.

Exam trap

The trap here is that candidates may confuse the SYN scan with a full connect scan (-sT) and think an ACK is sent to complete the handshake, or they may mistakenly believe that receiving an RST indicates an open port.

How to eliminate wrong answers

Option B is wrong because receiving an RST indicates the port is closed, not open; in a SYN scan, a closed port responds with an RST. Option C is wrong because no response typically indicates a filtered port (e.g., blocked by a firewall), not the behavior of an open port. Option D is wrong because sending an ACK after receiving a SYN/ACK would complete the three-way handshake and establish a full connection, which defeats the purpose of a stealth scan and is not what Nmap's -sS does.

114
MCQmedium

Which DoS attack exploits the HTTP protocol by sending partial HTTP requests to keep connections open, exhausting server resources?

A.SYN flood
B.Slowloris
C.Ping of Death
D.UDP flood
AnswerB

Slowloris keeps HTTP connections open.

Why this answer

Slowloris is a DoS attack that exploits HTTP by opening multiple connections to the target web server and sending partial HTTP requests (e.g., incomplete headers) while never completing them. The server keeps each connection open, waiting for the rest of the request, eventually exhausting its connection pool and denying service to legitimate users.

Exam trap

EC-Council often tests the distinction between network-layer attacks (SYN flood, UDP flood) and application-layer attacks (Slowloris), so candidates mistakenly choose SYN flood because they associate 'partial requests' with TCP handshake manipulation rather than HTTP header manipulation.

How to eliminate wrong answers

Option A is wrong because SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting the server's half-open connection backlog, not HTTP protocol behavior. Option C is wrong because Ping of Death crashes a system by sending an oversized ICMP packet that exceeds the maximum IP packet size, causing buffer overflow, not HTTP connection exhaustion. Option D is wrong because UDP flood overwhelms a target with a high volume of UDP packets to random ports, consuming bandwidth and processing resources, not HTTP connections.

115
MCQmedium

An attacker calls a company's help desk, pretending to be a new employee who forgot his username and password. The attacker provides some employee details gleaned from social media and convinces the help desk to reset the password. Which social engineering technique is being used?

A.Tailgating
B.Quid pro quo
C.Baiting
D.Pretexting
AnswerD

The attacker uses a fabricated pretext to gain trust.

Why this answer

Pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to manipulate the target into performing an action. In this case, the attacker pretends to be a new employee, using details from social media to establish credibility, and convinces the help desk to reset credentials. This is a classic example of pretexting because the entire interaction is based on a false identity and fabricated story.

Exam trap

The trap here is confusing pretexting with baiting because both involve deception, but baiting relies on a lure (e.g., 'free movie download') while pretexting relies on a fabricated scenario (e.g., 'I am a new employee').

How to eliminate wrong answers

Option A is wrong because tailgating involves physically following an authorized person into a restricted area without proper authentication, not a phone-based impersonation. Option B is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), not simply pretending to be an employee. Option C is wrong because baiting uses a physical or digital lure (e.g., infected USB drive, free download) to trick the victim, not a fabricated identity or story.

116
MCQhard

During a penetration test, you capture the following output: 'HTTP/1.1 200 OK ... Set-Cookie: sessionid=abc123; path=/'. You then send a request with a modified cookie value 'sessionid=abc124' and receive a valid session. Which type of vulnerability has been exploited?

A.Cross-site scripting
B.SQL injection
C.Man-in-the-middle attack
D.Session hijacking via cookie prediction
AnswerD

Session hijacking via cookie prediction occurs when an attacker successfully guesses or calculates a valid session identifier (Session ID) that an application uses to maintain a user's authenticated state. By setting their own browser's cookie to this predicted, valid Session ID, the attacker can bypass the login process and assume the identity of the legitimate user, gaining unauthorized access to their active session. This method specifically exploits weak or predictable session ID generation algorithms.

Why this answer

The attacker successfully predicted or guessed a valid session identifier (sessionid=abc124) after observing the pattern of the original session cookie (sessionid=abc123). This is a classic session hijacking via cookie prediction attack, where weak or sequential session IDs allow an attacker to impersonate another user's session without needing to intercept traffic or inject code.

Exam trap

The trap here is that candidates may confuse session hijacking via cookie prediction with a man-in-the-middle attack, but MITM requires active interception of traffic, whereas cookie prediction relies solely on guessing or enumerating session IDs from observed patterns.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) requires injecting malicious scripts into a web page viewed by another user, not simply modifying a cookie value in a direct request. Option B is wrong because SQL injection involves manipulating SQL queries through input fields to extract or modify database data, not altering session cookies. Option C is wrong because a man-in-the-middle attack requires intercepting and potentially modifying traffic between the client and server, whereas here the attacker directly sends a modified request without needing to be positioned in the communication path.

117
MCQmedium

Which of the following is the BEST defense against a TCP SYN flood attack?

A.Ingress filtering
C.Rate limiting
D.SYN cookies
AnswerD

SYN cookies are a robust defense mechanism against TCP SYN floods, operating by enabling a server to respond to SYN requests without allocating resources for a half-open connection immediately. Instead, the server crafts an initial sequence number (ISN) for the SYN-ACK packet that encodes information about the connection, including the client's IP, port, and the server's ISN. Only when the client responds with a valid ACK packet, using the derived sequence number, does the server then reconstruct the connection state, effectively deferring resource allocation until the three-way handshake is complete and verified. This stateless approach prevents the server's connection table from being overwhelmed.

Why this answer

SYN cookies are the best defense against TCP SYN flood attacks because they allow the server to avoid allocating resources for half-open connections until the handshake is completed. When a SYN cookie is used, the server encodes connection state information into the initial sequence number (ISN) sent in the SYN-ACK, and only commits memory upon receiving a valid ACK from the client. This prevents the exhaustion of the SYN backlog queue, which is the primary target of a SYN flood.

Exam trap

The CEH exam often tests the misconception that rate limiting or ingress filtering alone can stop a SYN flood, but the key is that SYN cookies directly prevent the resource exhaustion of the TCP backlog queue, which is the core vulnerability exploited in this attack.

How to eliminate wrong answers

Option A is wrong because ingress filtering (RFC 2827/3704) prevents IP spoofing by dropping packets with source addresses not matching the expected inbound prefix, but it does not mitigate the volume of SYN packets or protect the server's connection queue once the attack reaches it. Option B is wrong because an intrusion detection system (IDS) can only detect and alert on a SYN flood pattern, not actively prevent it from consuming server resources; it lacks the ability to modify TCP handshake behavior or queue management. Option C is wrong because rate limiting can reduce the impact of a flood by capping incoming SYN packets, but it is a blunt instrument that may drop legitimate traffic and does not address the fundamental resource exhaustion of the SYN backlog; SYN cookies provide a more granular, per-connection defense.

118
MCQeasy

A security analyst discovers a file named invoice.exe in an email attachment. Static analysis with PEiD indicates the file is packed with UPX. What is the BEST next step in analyzing this malware?

A.Execute the packed file on a production server
B.Unpack the file with UPX and then perform static analysis
C.Submit the packed file directly to VirusTotal
D.Delete the file immediately
AnswerB

Unpacking reveals the original code for static analysis.

Why this answer

B is correct because UPX-packed executables cannot be properly analyzed statically; the code is compressed and obfuscated. Unpacking with the UPX tool restores the original binary, enabling accurate static analysis of imports, strings, and structure. This step is essential before any dynamic analysis or submission to sandboxes.

Exam trap

EC-CEH often tests the misconception that static analysis can be performed on packed binaries without unpacking, or that immediate deletion or submission to VirusTotal is the best response, ignoring the need for evidence preservation and thorough analysis.

How to eliminate wrong answers

Option A is wrong because executing packed malware on a production server risks infection and lateral movement, violating containment protocols. Option C is wrong because submitting a packed file to VirusTotal may yield incomplete detection results, as many AV engines may not unpack it correctly, and it could alert threat actors if the sample is unique. Option D is wrong because deleting the file immediately destroys evidence and prevents further analysis needed for incident response and threat intelligence.

119
MCQmedium

Which tool would a penetration tester MOST likely use to perform ARP poisoning and conduct a man-in-the-middle attack on a local network?

A.Wireshark
B.Nmap
C.tcpdump
D.Ettercap
AnswerD

Ettercap is a comprehensive suite for man-in-the-middle (MITM) attacks on a LAN, specifically designed to intercept traffic, perform live content filtering, and establish various forms of active and passive eavesdropping. Its core functionality includes robust ARP poisoning capabilities, allowing it to redirect traffic between two hosts through the attacker's machine by sending forged ARP replies. This enables the penetration tester to intercept, modify, and inject data into network communications, making it the ideal tool for demonstrating MITM vulnerabilities.

Why this answer

Ettercap is a dedicated suite for man-in-the-middle attacks on LANs, with built-in support for ARP poisoning. It actively sends forged ARP replies to associate the attacker's MAC address with the IP of a legitimate host, allowing interception of traffic between two hosts. This makes it the most direct and purpose-built tool for the task described.

Exam trap

EC-CEH often tests the distinction between passive monitoring tools (Wireshark, tcpdump) and active attack tools (Ettercap), leading candidates to mistakenly choose a packet sniffer when the question explicitly requires performing an active man-in-the-middle attack.

How to eliminate wrong answers

Option A is wrong because Wireshark is a passive packet analyzer that captures and inspects traffic but cannot inject or modify packets to perform ARP poisoning. Option B is wrong because Nmap is a network scanner used for host discovery and port enumeration, not for active interception or ARP cache manipulation. Option C is wrong because tcpdump is a command-line packet capture tool that, like Wireshark, passively dumps traffic and lacks the ability to send forged ARP packets to redirect flows.

120
MCQeasy

A security administrator notices that the network switch is broadcasting traffic to all ports as if it were a hub. The switch logs show a sudden flood of packets with random MAC addresses. Which attack is MOST likely occurring?

A.SYN flood
B.MAC flooding
C.ARP poisoning
D.DNS amplification
AnswerB

MAC flooding overwhelms a network switch's Content Addressable Memory (CAM) table by rapidly sending frames with unique, spoofed source MAC addresses. When the CAM table, which stores MAC-to-port mappings, becomes full, the switch can no longer learn new addresses and reverts to broadcasting all incoming frames out of every port within the VLAN. This effectively transforms the switch into a hub-like device, allowing an attacker to intercept traffic intended for other hosts.

Why this answer

B is correct because MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table. By sending a flood of packets with random source MAC addresses, the attacker fills the CAM table, forcing the switch to fail-open into hub mode (broadcasting all traffic to all ports) so that the attacker can capture frames not originally destined for their port.

Exam trap

The trap here is that candidates confuse MAC flooding with ARP poisoning because both involve MAC addresses, but MAC flooding targets the switch's CAM table at Layer 2, while ARP poisoning manipulates IP-to-MAC mappings at Layer 3.

How to eliminate wrong answers

Option A is wrong because a SYN flood is a denial-of-service attack that exhausts server resources by sending many TCP SYN requests without completing the handshake; it does not cause a switch to broadcast traffic. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC with the IP of a legitimate host, redirecting traffic at Layer 3, not flooding the switch's CAM table to cause hub-like behavior. Option D is wrong because a DNS amplification attack uses open DNS resolvers to flood a victim with large DNS response traffic, overwhelming the target's bandwidth, not affecting switch forwarding behavior.

121
MCQhard

A security analyst is analyzing a suspicious file and runs the command 'strings malware.exe | grep -i http'. The output shows several URLs ending with '.exe'. What does this indicate?

A.The malware may download additional payloads from remote servers
B.The malware has a keylogger component
C.The malware is a boot sector virus
D.The malware is a worm that spreads via email
AnswerA

The presence of HTTP URLs, particularly those ending with executable file extensions like .exe, is a strong indicator that the malware is designed to retrieve additional components. This behavior is characteristic of a downloader or dropper, which fetches secondary payloads from remote Command and Control (C2) servers to execute further malicious activities. Such multi-stage attacks are common, allowing the initial infection to be small and stealthy while dynamically loading more complex functionality.

Why this answer

The `strings` command extracts printable strings from a binary file, and `grep -i http` filters for HTTP-related content. The presence of URLs ending with `.exe` indicates that the malware contains embedded references to executable files hosted on remote servers, which is a common technique for downloading additional payloads or updates. This strongly suggests the malware has a downloader or dropper component that fetches further malicious code from those URLs.

Exam trap

The trap here is that candidates may assume any URL in a binary indicates a specific malware type (e.g., worm or keylogger), but the CEH exam tests the ability to infer functionality from evidence—HTTP URLs with `.exe` specifically point to remote payload download, not propagation or input capture.

How to eliminate wrong answers

Option B is wrong because the presence of HTTP URLs ending with `.exe` does not imply keylogging functionality; keyloggers typically capture keystrokes and would not necessarily contain such URLs. Option C is wrong because a boot sector virus infects the Master Boot Record (MBR) or Volume Boot Record (VBR) and would not typically contain HTTP URLs for downloading executables; its propagation is low-level and file-system independent. Option D is wrong because while a worm may spread via email, the output of `strings` showing HTTP URLs does not indicate email propagation mechanisms (e.g., SMTP, MAPI); worms that spread via email often contain email-related strings or scripting, not just HTTP download URLs.

122
MCQhard

A penetration tester uses a tool to spoof ARP replies, redirecting traffic through the tester's machine. The tester then captures credentials from the redirected traffic. Which tool is BEST suited for this task?

A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA

Ettercap is a comprehensive suite specifically designed for man-in-the-middle (MITM) attacks, making it the correct tool for ARP poisoning. It actively injects forged ARP replies into a local area network, associating the attacker's MAC address with the IP address of a legitimate host, such as the default gateway. This redirection allows Ettercap to intercept, modify, and forward traffic between the target and the intended destination, enabling sniffing and various active attacks.

Why this answer

Ettercap is the best tool for ARP spoofing because it is specifically designed for man-in-the-middle (MITM) attacks on local networks. It actively sends forged ARP replies to poison the ARP cache of target hosts, redirecting traffic through the attacker's machine, and includes built-in packet capture and credential extraction features.

Exam trap

The trap here is that candidates confuse passive sniffing tools like Wireshark or tcpdump with active MITM tools, assuming any packet capture tool can also perform ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Wireshark is a passive packet analyzer that cannot spoof ARP replies or redirect traffic; it only captures and inspects existing traffic. Option C is wrong because Nmap is a network discovery and port scanning tool that does not perform ARP spoofing or MITM traffic redirection. Option D is wrong because tcpdump is a command-line packet capture utility that lacks the ability to inject forged ARP packets or manipulate network traffic flow.

123
MCQmedium

A security analyst notices a high volume of ICMP Echo Reply packets on the network. The source IPs are varied, but the destination IP is the same. Which type of attack is MOST likely occurring?

A.UDP flood
B.Ping of Death
C.Smurf attack
D.ICMP flood
AnswerC

A Smurf attack is a classic distributed denial-of-service (DDoS) attack that leverages ICMP reflection and amplification. An attacker sends ICMP Echo Request packets with a spoofed source IP address (the victim's IP) to the IP broadcast address of a large network. All active hosts on that network then respond with ICMP Echo Reply packets to the spoofed source IP, overwhelming the victim with a massive flood of replies from numerous legitimate sources. This perfectly matches the observation of a high volume of ICMP echo replies from multiple sources.

Why this answer

The Smurf attack is a distributed denial-of-service (DDoS) attack that exploits ICMP by sending a large number of ICMP Echo Request packets with a spoofed source IP (the victim's IP) to a network's broadcast address. All devices on that network then respond with ICMP Echo Reply packets to the victim, overwhelming it. The scenario describes varied source IPs (the responding devices) and a single destination IP (the victim), which is the hallmark of a Smurf attack.

Exam trap

The trap here is that candidates confuse the Smurf attack with a standard ICMP flood, but the key differentiator is the amplification effect caused by the broadcast address and the spoofed source IP, which results in many replies from varied sources to a single destination.

How to eliminate wrong answers

Option A is wrong because a UDP flood uses UDP packets, not ICMP Echo Reply packets, and typically targets random or specific ports to exhaust resources. Option B is wrong because the Ping of Death involves sending a malformed ICMP Echo Request packet that exceeds the maximum IP packet size (65535 bytes), causing a buffer overflow, not a high volume of normal-sized Echo Replies. Option D is wrong because an ICMP flood directly sends a high volume of ICMP Echo Request packets from a single or multiple sources to overwhelm the target, but the key detail here is the varied source IPs of the *replies*, not the requests, which indicates the amplification effect of a Smurf attack.

124
MCQmedium

A security team observes that a switch's MAC address table is full, and the switch has started flooding unicast traffic to all ports. Which attack has MOST likely been performed?

A.MAC flooding
B.ARP poisoning
C.MAC spoofing
D.DHCP starvation
AnswerA

MAC flooding is an attack technique that overwhelms a network switch's Content Addressable Memory (CAM) table with a massive number of unique, fake MAC address-to-port mappings. By sending numerous Ethernet frames, each with a different spoofed source MAC address, the attacker forces the CAM table to fill up completely. Once the CAM table is full, the switch can no longer store new MAC-to-port associations and reverts to acting like a hub, broadcasting all incoming traffic out of every port. This allows an attacker to capture and analyze traffic intended for other devices on the network segment.

Why this answer

MAC flooding attacks exploit the limited size of a switch's CAM (Content Addressable Memory) table. By sending thousands of frames with random source MAC addresses, the attacker fills the table to capacity. Once full, the switch enters a fail-open state and begins flooding all unknown unicast traffic out every port, effectively turning it into a hub and allowing the attacker to capture traffic not destined for them.

Exam trap

The trap here is confusing MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets host ARP caches), as both involve MAC addresses and can lead to traffic interception, but they operate at different layers and use different mechanisms.

How to eliminate wrong answers

Option B (ARP poisoning) is wrong because it manipulates the ARP cache of hosts to associate the attacker's MAC with the IP of a legitimate device, causing traffic to be redirected; it does not fill the switch's MAC address table. Option C (MAC spoofing) is wrong because it involves impersonating a legitimate device's MAC address to bypass access controls or hijack a session, not to exhaust the CAM table. Option D (DHCP starvation) is wrong because it exhausts the pool of available IP addresses from a DHCP server by sending many DHCP discover messages with fake MAC addresses, preventing legitimate clients from obtaining IPs; it does not directly cause the switch to flood unicast traffic.

125
MCQmedium

Which of the following is a form of social engineering where an attacker physically follows an authorized person into a restricted area without proper authentication?

A.Pretexting
B.Baiting
C.Tailgating
D.Quid pro quo
AnswerC

Tailgating is physically following someone into a restricted area.

Why this answer

Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area, bypassing authentication mechanisms such as badge readers, PIN pads, or biometric scanners. The attacker exploits the natural courtesy of the authorized person holding the door open, thereby gaining physical access without any credential validation.

Exam trap

EC-Council often tests tailgating by contrasting it with pretexting or baiting, so the trap is confusing physical access attacks (tailgating) with psychological manipulation attacks (pretexting, baiting, quid pro quo) that do not require physical proximity.

How to eliminate wrong answers

Option A is wrong because pretexting involves fabricating a scenario or identity (e.g., impersonating IT support) to trick a target into divulging information, not physically following someone into a restricted area. Option B is wrong because baiting relies on offering something enticing (e.g., a malware-infected USB drive left in a parking lot) to lure a victim into performing an action, not physical proximity or door access. Option D is wrong because quid pro quo involves an attacker offering a service or benefit (e.g., 'free tech support') in exchange for sensitive information or access, not physically trailing an authorized person.

126
MCQhard

During a penetration test, you run the tool 'macof' against a switch. After a few seconds, the switch starts flooding frames out all ports. Which attack have you successfully executed, and what is the primary goal of this technique?

A.MAC flooding; to cause a switch to fail-open and act like a hub for sniffing
B.VLAN hopping; to gain access to a different VLAN
C.STP manipulation; to create a loop and cause a DoS
D.ARP poisoning; to intercept traffic between two hosts
AnswerA

macof floods with random MACs to exhaust CAM table, enabling sniffing.

Why this answer

The 'macof' tool is specifically designed to perform MAC flooding attacks by generating frames with random source MAC addresses. This overwhelms the switch's Content Addressable Memory (CAM) table, causing it to fail-open and flood all incoming frames out every port, effectively making it behave like a hub. This allows the attacker to sniff network traffic that would normally be isolated to specific switch ports.

Exam trap

The common trap is confusing MAC flooding with ARP poisoning; MAC flooding overloads the switch's CAM table, while ARP poisons the host's ARP cache.

How to eliminate wrong answers

Option B is wrong because VLAN hopping exploits switch tagging protocols (e.g., DTP or double-tagging) to access another VLAN, not by flooding MAC addresses. Option C is wrong because STP manipulation targets the Spanning Tree Protocol to create loops or reroute traffic, typically using BPDU attacks, not by exhausting CAM tables. Option D is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC with a legitimate IP address, enabling man-in-the-middle attacks, not by flooding random MACs to cause switch fail-open.

127
Multi-Selecteasy

Which TWO of the following are examples of session hijacking attacks? (Select 2)

Select 2 answers
A.DNS spoofing
B.Cookie theft
C.MAC flooding
D.TCP sequence prediction
E.ARP poisoning
AnswersB, D

Stealing session cookies allows an attacker to impersonate a user.

Why this answer

Both cookie theft and TCP sequence prediction are session hijacking attacks. Cookie theft involves stealing a session identifier (e.g., via XSS or sniffing) to impersonate the victim's authenticated web session. TCP sequence prediction targets the transport layer: an attacker predicts the sequence numbers used in a TCP connection to inject forged packets and hijack the session, taking over an established TCP connection.

These attacks directly take over an authenticated session, distinguishing them from other network attacks like ARP poisoning or DNS spoofing.

Exam trap

The trap here is that candidates confuse network-level attacks (like ARP poisoning or DNS spoofing) with session hijacking, but the CEH exam specifically defines session hijacking as the takeover of an authenticated TCP or application-layer session, which requires either stealing a session token (cookie theft) or predicting TCP sequence numbers.

128
MCQmedium

Which tool can be used to perform ARP poisoning to intercept traffic between a victim and the default gateway?

A.Wireshark
B.Ettercap
C.tcpdump
D.Nmap
AnswerB

Ettercap is a versatile and robust suite of tools specifically engineered for Man-in-the-Middle (MITM) attacks on local area networks. It excels at ARP poisoning by sending forged ARP replies to both the target host and the default gateway, effectively tricking them into routing traffic through the attacker's machine. This redirection allows for sniffing, content filtering, and other active manipulations of network communications.

Why this answer

Ettercap is a dedicated man-in-the-middle (MITM) attack tool that natively supports ARP poisoning. It sends forged ARP replies to both the victim and the default gateway, mapping the attacker's MAC address to the IP addresses of the other party. This allows the attacker to intercept, inspect, and modify traffic between the victim and the gateway.

Exam trap

The trap here is that candidates confuse passive sniffing tools (Wireshark, tcpdump) with active MITM tools, assuming any tool that can capture traffic can also perform ARP poisoning.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects packets passively; it cannot send forged ARP packets to poison a victim's ARP cache. Option C is wrong because tcpdump is a command-line packet capture tool that only dumps traffic on a network interface; it has no capability to inject or manipulate ARP replies. Option D is wrong because Nmap is a network discovery and security scanning tool used for port scanning and OS detection; it does not include ARP spoofing functionality.

129
MCQeasy

Which tool would an ethical hacker use to automatically generate a malicious USB drive that, when plugged in, executes a payload and connects back to the attacker?

A.Wireshark
B.Ettercap
C.USB Rubber Ducky
D.Metasploit
AnswerC

The USB Rubber Ducky is a specialized keystroke injection tool that emulates a standard human interface device (HID), specifically a keyboard, when plugged into a target system. This allows it to automatically and rapidly inject pre-programmed keystrokes and commands, bypassing many traditional security controls like antivirus software and firewalls. Its ability to deliver complex payloads at 'typing speed' makes it highly effective for automated USB-based attacks.

Why this answer

The USB Rubber Ducky is a keystroke injection tool that appears as a keyboard to the host computer. When plugged in, it automatically types a pre-programmed payload at high speed, which can download and execute a reverse shell or other malware, establishing a connection back to the attacker. This makes it the correct choice for automatically generating a malicious USB drive that executes a payload upon insertion.

Exam trap

The trap here is that candidates often confuse Metasploit as the tool for generating the USB drive itself, but Metasploit is used to create the payload, while the USB Rubber Ducky is the specific hardware tool that automates the injection process when the drive is plugged in.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets, not for generating malicious USB drives or executing payloads. Option B is wrong because Ettercap is a man-in-the-middle attack tool for network sniffing and ARP poisoning, not a USB-based attack tool. Option D is wrong because Metasploit is a penetration testing framework for developing and executing exploits, but it does not automatically generate a malicious USB drive that executes a payload when plugged in; while it can create payloads, the USB Rubber Ducky is the dedicated hardware tool for keystroke injection attacks.

130
MCQeasy

Which of the following is a type of malware that spreads by replicating itself across a network without requiring a host file?

A.Worm
B.Trojan
C.Ransomware
D.Virus
AnswerA

A worm is a standalone malware computer program that replicates itself to spread to other computers. Unlike a virus, it does not need to attach to an existing program or host file to propagate. Worms often exploit network vulnerabilities to spread autonomously across networks, consuming bandwidth and system resources, and can carry payloads like backdoors or ransomware. This self-contained, network-aware replication is its defining characteristic.

Why this answer

A worm is a standalone malware that replicates itself across a network by exploiting vulnerabilities or using network protocols (e.g., SMB, RDP, or email) without needing a host file. Unlike viruses, worms do not attach to existing programs; they self-propagate via network connections, often consuming bandwidth and creating backdoors.

Exam trap

The trap here is confusing a worm with a virus, as both self-replicate, but the key differentiator is that a worm does not require a host file and spreads via network protocols, while a virus must attach to a host file to propagate.

How to eliminate wrong answers

Option B (Trojan) is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution to install and typically requires a host file or system to operate. Option C (Ransomware) is wrong because ransomware encrypts files or locks systems for extortion and does not self-propagate across a network without user interaction or a host file. Option D (Virus) is wrong because a virus requires a host file (e.g., executable, script, or document) to attach to and replicate, whereas the question specifies propagation without a host file.

131
MCQmedium

A security analyst reviews logs and notices that an attacker crafted a packet with a source IP address matching the target's IP address, and sent it to a network's broadcast address. Which type of attack does this describe?

A.UDP flood
B.Ping of Death
C.Smurf attack
D.SYN flood
AnswerC

A Smurf attack is a classic distributed denial-of-service (DDoS) technique that leverages an intermediary network to amplify traffic against a victim. The attacker sends an ICMP echo request packet to a network's IP broadcast address, but with the source IP address spoofed to that of the intended victim. All hosts on the intermediary network that receive the broadcast then reply to the spoofed source IP, flooding the victim with numerous ICMP echo replies. This amplification effect can quickly overwhelm the victim's network resources.

Why this answer

The Smurf attack is a distributed denial-of-service (DDoS) attack that exploits ICMP echo request packets. The attacker spoofs the source IP address to be the target's IP and sends these packets to a network's broadcast address. All hosts on that network then reply to the target, overwhelming it with ICMP echo replies.

Exam trap

The trap here is that candidates confuse the Smurf attack with a simple ICMP flood or Ping of Death, but the key differentiator is the use of a broadcast address to amplify traffic, not just sending malformed or high-volume ICMP packets.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends a high volume of UDP packets to random ports on the target, exhausting its resources, and does not involve spoofing the target's IP as the source or using a broadcast address. Option B is wrong because a Ping of Death sends an oversized ICMP packet (greater than 65,535 bytes) to crash the target, not a broadcast-based amplification attack. Option D is wrong because a SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source IPs to exhaust the target's connection table, and it does not use broadcast addresses or ICMP.

132
Multi-Selectmedium

Which THREE of the following are valid methods for DDoS mitigation?

Select 3 answers
A.Rate limiting
B.Increasing server timeout values
C.Scrubbing centers
D.Disabling SYN cookies
E.Anycast routing
AnswersA, C, E

Rate limiting is a crucial DDoS mitigation technique that restricts the number of requests a server or application will accept from a specific source within a defined time window. By setting thresholds for connections, requests per second, or bandwidth usage, it prevents a single attacker or a small group of bots from overwhelming server resources. This method helps to differentiate between legitimate traffic spikes and malicious floods, allowing the system to maintain availability for valid users while shedding excessive, potentially harmful traffic.

Why this answer

Rate limiting is a valid DDoS mitigation method because it restricts the number of requests a server accepts from a single source within a given time window, preventing resource exhaustion. By enforcing thresholds (e.g., via iptables or application-layer rate limiters), it reduces the impact of volumetric attacks like HTTP floods without blocking legitimate traffic entirely.

Exam trap

The trap here is that candidates confuse mitigation techniques with configuration errors, such as thinking that increasing timeouts or disabling SYN cookies would help, when in fact these actions weaken defenses against specific attack vectors like SYN floods or slow HTTP attacks.

133
MCQmedium

A user reports that their system has become sluggish and they see pop-up advertisements even when no browser is open. Additionally, unknown processes are running in Task Manager. Which type of malware is most likely responsible?

A.Worm
B.Adware
C.Ransomware
D.Spyware
AnswerB

Adware is specifically designed to display unwanted advertisements, often in the form of pop-ups, banners, or injected ads within web pages. This constant display and the underlying processes required to generate these ads consume significant CPU and RAM, leading directly to noticeable system sluggishness. It frequently alters browser settings, making it a direct cause for both the reported performance degradation and persistent pop-ups.

Why this answer

Adware is designed to display unwanted advertisements, often in the form of pop-ups, and can degrade system performance by consuming CPU and memory resources. The presence of unknown processes in Task Manager indicates that the adware has installed additional components or bundled software that runs persistently, even when no browser is open, which is a hallmark of adware behavior.

Exam trap

The trap here is that candidates confuse 'adware' with 'spyware' because both can be bundled with free software, but adware's primary symptom is unwanted ads, not data theft, which is the key differentiator in this scenario.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads across networks without user interaction, and while it can cause sluggishness, it does not typically display pop-up advertisements. Option C is wrong because ransomware encrypts files or locks the system to demand a ransom, and it does not show pop-up ads or run unknown processes as its primary symptom. Option D is wrong because spyware is designed to covertly collect sensitive information (e.g., keystrokes, browsing habits) and does not usually generate pop-up advertisements; its presence is often hidden, not announced via ads.

134
MCQmedium

An attacker gains physical access to a restricted area by following an authorized employee through a secured door without swiping a badge. This technique is known as:

A.Tailgating
B.Pretexting
C.Quid pro quo
D.Baiting
AnswerA

Tailgating is following an authorized person through a secure entry.

Why this answer

Tailgating is a social engineering attack where an unauthorized person physically follows an authorized employee through a secured entry point (e.g., a badge-protected door) without presenting their own credentials. This exploits the human tendency to hold the door for others, bypassing electronic access control systems (e.g., RFID badge readers) that would otherwise deny entry. The CEH exam defines this as a physical breach of perimeter security, distinct from digital or verbal manipulation.

Exam trap

The trap here is confusing 'tailgating' with 'pretexting' because both involve deception, but tailgating is purely physical (following through a door) while pretexting is purely verbal (creating a false story).

How to eliminate wrong answers

Option B (Pretexting) is wrong because it involves fabricating a scenario (e.g., impersonating IT support) to trick a victim into divulging information, not physically following someone through a door. Option C (Quid pro quo) is wrong because it relies on offering a service or benefit (e.g., 'free antivirus scan') in exchange for credentials, not physical proximity. Option D (Baiting) is wrong because it uses a physical lure (e.g., an infected USB drive left in a parking lot) to compromise a system, not direct physical access by trailing an employee.

135
Multi-Selecthard

Which THREE of the following are indicators of a slowloris DDoS attack?

Select 3 answers
A.ICMP echo replies from random IPs
B.Normal traffic volume but connections remain open for a long time
C.Many half-open HTTP connections
D.Server logs showing incomplete HTTP requests
E.High volume of UDP packets
AnswersB, C, D

Slowloris is a low-bandwidth attack that does not generate a high volume of data packets. Instead, it exploits the server's connection handling by opening numerous legitimate-looking HTTP connections and then keeping them alive for extended durations. This is achieved by sending partial HTTP requests and periodically sending additional, non-terminating HTTP headers, preventing the server from timing out the connection and freeing up resources. The prolonged open state of these connections, despite minimal data transfer, exhausts the server's available connection pool.

Why this answer

B is correct because a Slowloris DDoS attack works by opening many connections to a target web server and keeping them open for as long as possible, sending partial HTTP requests to tie up server resources. This results in normal traffic volume but with connections that remain open for extended periods, preventing legitimate users from connecting.

Exam trap

The trap here is that candidates often associate DDoS attacks with high traffic volume, but Slowloris is a low-and-slow attack that uses normal traffic volume with persistent, incomplete connections, so they may incorrectly select high-volume options like A or E.

136
MCQeasy

An employee receives an SMS message that claims to be from the IT department, asking the employee to click a link to verify their email account. Which social engineering attack is this?

A.Vishing
B.Phishing
C.SMiShing
D.Whaling
AnswerC

SMiShing, a portmanteau of 'SMS' and 'phishing,' is a specific type of social engineering attack that utilizes text messages to deceive recipients. Attackers send fraudulent SMS messages, often containing malicious links that lead to credential harvesting sites or malware downloads, or instructing victims to call a fraudulent number. This method exploits the trust users place in their mobile devices and the immediacy of text messages to prompt quick, unthinking responses, making it the direct answer for an SMS-based attack.

Why this answer

C is correct because SMiShing (SMS phishing) specifically uses SMS text messages as the attack vector to deliver a malicious link or request, exactly as described in the scenario. Unlike email-based phishing, SMiShing exploits the trust users place in text messages and often bypasses email security filters.

Exam trap

The trap here is that candidates confuse 'phishing' as a generic term for all social engineering attacks, but the CEH exam distinguishes SMiShing as the specific term for SMS-based phishing.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls or voice messages, not SMS text messages. Option B is wrong because phishing typically refers to email-based attacks, not SMS-based attacks. Option D is wrong because whaling targets high-profile individuals (e.g., executives) with personalized attacks, not general employees via mass SMS.

137
MCQhard

A penetration tester runs the following command: `macof -i eth0 -s 192.168.1.100 -d 10.0.0.1`. Which attack is being performed?

A.DNS spoofing
B.ARP poisoning
C.MAC flooding
D.DHCP starvation
AnswerC

MAC flooding is an attack designed to overwhelm a network switch's MAC address table (CAM table) by sending a large number of frames with unique, spoofed source MAC addresses. When the CAM table becomes full, the switch often enters a "fail-open" mode, behaving like a hub by broadcasting all incoming traffic to all ports. The `macof` utility, part of the `dsniff` suite, automates this process by rapidly generating and sending thousands of frames with random source MAC and IP addresses, effectively causing the switch to flood traffic.

Why this answer

The `macof` tool is designed to flood a switch with packets containing random source MAC addresses, overwhelming the Content Addressable Memory (CAM) table. Once the CAM table is full, the switch enters a fail-open state and broadcasts all frames, allowing the attacker to sniff traffic that would normally be isolated to specific ports. This is a classic MAC flooding attack, not ARP poisoning or DHCP starvation.

Exam trap

In the CEH exam, candidates often confuse MAC flooding (which targets the switch's CAM table) with ARP poisoning (which targets host ARP caches). Both involve MAC addresses and can enable man-in-the-middle attacks, but the tool 'macof' specifically performs MAC flooding.

How to eliminate wrong answers

Option A is wrong because DNS spoofing involves corrupting DNS responses to redirect traffic, typically using tools like `dnsspoof` or `ettercap` with DNS filters, not `macof`. Option B is wrong because ARP poisoning manipulates ARP caches to associate a malicious MAC with a legitimate IP, using tools like `arpspoof` or `ettercap`; `macof` does not send ARP replies or requests. Option D is wrong because DHCP starvation floods a DHCP server with fake DHCPDISCOVER messages to exhaust its IP address pool, using tools like `yersinia` or `dhcpstarv`, not `macof`.

138
MCQmedium

An attacker uses the Social Engineering Toolkit (SET) to send a malicious email to employees of a company, claiming to be from IT support and urging them to click a link to reset their password. Which social engineering attack is being performed?

A.Vishing
B.Phishing
C.Baiting
D.SMiShing
AnswerB

Phishing is a prevalent cyberattack where adversaries employ deceptive emails to trick recipients into divulging confidential information or executing malicious actions. The Social Engineering Toolkit (SET) is frequently used to craft convincing fake login pages or deliver malware via email attachments, making it a classic vector for credential harvesting or system compromise. This method leverages trust and urgency to bypass security awareness and technical controls.

Why this answer

The Social Engineering Toolkit (SET) is used to craft and send fraudulent emails that appear to come from a trusted source (IT support), urging the recipient to click a link and enter credentials. This is a classic phishing attack because it uses email as the vector and relies on deception to steal sensitive information. Unlike vishing (voice) or SMiShing (SMS), the attack is executed via email, which is the defining characteristic of phishing.

Exam trap

The CEH exam often tests the distinction between phishing, vishing, and SMiShing by focusing on the delivery medium (email vs. voice vs. SMS), so candidates must remember that 'phishing' specifically refers to email-based social engineering.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses telephone calls or VoIP systems to trick victims, not email. Option C is wrong because baiting involves offering something enticing (e.g., a free USB drive or download) to lure the victim, not sending a deceptive email. Option D is wrong because SMiShing (SMS phishing) uses text messages (Short Message Service) as the attack vector, not email.

139
MCQmedium

An employee receives an email that appears to be from the CEO, requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ceo@cornpany.com instead of ceo@company.com). This is an example of which type of attack?

A.Whaling
B.Phishing
C.Pretexting
D.Spear phishing
AnswerD

Spear phishing is a highly targeted form of phishing that uses personalized information to increase the credibility and effectiveness of the attack. Attackers conduct reconnaissance to gather details about the target, such as their name, job title, company, and even internal relationships, to craft a convincing email. An email appearing to be from the CEO to a specific employee leverages this personalized context and perceived authority, making it a classic example of a spear phishing attempt designed to elicit a specific response.

Why this answer

Spear phishing is a targeted phishing attack aimed at a specific individual or organization, using personalized information to increase credibility. In this scenario, the attacker spoofs the CEO's identity and uses a misspelled domain (typosquatting) to trick the employee into performing a wire transfer, which is a classic spear phishing technique. Unlike generic phishing, spear phishing tailors the message to the victim's role and context, making it more effective.

Exam trap

The trap here is that candidates confuse 'whaling' with 'spear phishing' because both target specific individuals, but whaling specifically targets high-level executives, while spear phishing can target any individual within an organization, as in this case where the email impersonates the CEO rather than targeting them.

How to eliminate wrong answers

Option A is wrong because whaling is a specific type of spear phishing that targets high-profile executives (e.g., CEO, CFO) directly, but the question describes an email impersonating the CEO, not targeting the CEO. Option B is wrong because phishing is a broad, untargeted attack sent to many recipients, lacking the personalization and specific context (e.g., using the CEO's name and a misspelled domain) seen here. Option C is wrong because pretexting involves creating a fabricated scenario (pretext) to obtain information, often via phone or in person, and does not inherently rely on email spoofing or typosquatting like this example.

140
MCQmedium

During a penetration test, a tester captures network traffic and notices a large number of ARP replies claiming that 192.168.1.1 is at MAC address 00:11:22:33:44:55, which is different from the legitimate gateway MAC. Which attack is likely in progress?

A.Session hijacking
B.ARP poisoning
C.MAC flooding
D.DNS spoofing
AnswerB

Forged ARP replies bind the attacker's MAC to the gateway IP, allowing interception of traffic.

Why this answer

ARP poisoning (also known as ARP spoofing) is the correct answer because the attacker is sending forged ARP replies that associate the legitimate gateway IP (192.168.1.1) with an attacker-controlled MAC address (00:11:22:33:44:55). This causes victim hosts to update their ARP cache with the false mapping, redirecting traffic intended for the gateway to the attacker's machine, enabling man-in-the-middle (MITM) attacks.

Exam trap

The trap in this question is confusing ARP poisoning (which manipulates Layer 2 MAC-to-IP mappings via forged ARP replies) with MAC flooding (which overwhelms switch CAM tables with fake MAC addresses). The key clue is that the attacker is sending multiple ARP replies for a single target IP (the gateway) with a spoofed MAC, not a flood of different MACs.

How to eliminate wrong answers

Option A is wrong because session hijacking typically involves stealing or predicting session tokens (e.g., cookies or session IDs) after initial authentication, not manipulating ARP cache entries at Layer 2. Option C is wrong because MAC flooding is an attack that overwhelms a switch's CAM table with fake MAC addresses to force it into hub mode (flooding all traffic), not sending specific forged ARP replies to poison a single IP-to-MAC mapping. Option D is wrong because DNS spoofing corrupts DNS resolver caches with false IP-to-domain mappings (e.g., returning a malicious IP for www.example.com), not ARP cache entries for a gateway IP.

141
Multi-Selecthard

Which THREE of the following are effective DDoS mitigation techniques? (Select 3)

Select 3 answers
A.Rate limiting
B.Scrubbing centers
C.Blackholing all traffic to the target
D.IP spoofing
E.Anycast network distribution
AnswersA, B, E

Correct. Rate limiting can throttle attack traffic.

Why this answer

Rate limiting is effective because it restricts the number of requests a server will accept from a single IP address or session within a given time window, typically enforced via token bucket or leaky bucket algorithms. This prevents a single attacker or botnet node from overwhelming server resources, though it must be carefully tuned to avoid blocking legitimate users.

Exam trap

EC-CEH often tests the misconception that blackholing (null routing) is a viable mitigation technique, but candidates must remember it is a sacrificial measure that drops all traffic, not a selective defense, and is only used when the attack overwhelms all other defenses.

142
MCQhard

A penetration tester uses the following command to scan a target: nmap -sU -sV -p 53,161,162 10.0.0.1. Which of the following BEST describes what this scan will accomplish?

A.Full port scan of all 65535 UDP ports
B.Ping sweep and OS detection on the target
C.UDP scan on three ports with service version detection
D.TCP SYN scan on ports 53, 161, 162 with version detection
AnswerC

This option accurately describes the Nmap command's functionality. The -sU flag specifically instructs Nmap to perform a UDP port scan, targeting services that communicate via the User Datagram Protocol. Concurrently, the -sV flag enables service version detection, attempting to identify the application and its version running on any discovered open UDP ports. The -p 53,161,162 argument precisely limits this comprehensive scan to three specific UDP ports.

Why this answer

The `-sU` flag initiates a UDP scan, `-p 53,161,162` limits the scan to those three specific ports, and `-sV` enables service version detection. This combination performs a UDP scan on only the specified ports and attempts to identify the versions of services running on them.

Exam trap

The trap here is that candidates may confuse `-sU` (UDP scan) with `-sS` (TCP SYN scan) or assume that `-sV` implies OS detection, when in fact `-sV` is strictly for service version detection and OS detection requires the `-O` flag.

How to eliminate wrong answers

Option A is wrong because the command specifies `-p 53,161,162`, which limits the scan to only those three UDP ports, not all 65535 UDP ports. Option B is wrong because the command uses `-sU` (UDP scan) and `-sV` (version detection), not `-sn` (ping sweep) or `-O` (OS detection). Option D is wrong because `-sU` specifies a UDP scan, not a TCP SYN scan (which would use `-sS`), and the ports 53, 161, 162 are commonly associated with UDP services (DNS, SNMP).

143
MCQmedium

A penetration tester uses the Social Engineering Toolkit (SET) to create a malicious USB drive that autoruns when inserted. Which social engineering technique is being employed?

A.Tailgating
B.Baiting
C.Pretexting
D.Phishing
AnswerB

Baiting is a social engineering attack that leverages human curiosity or greed by leaving physical media, such as USB drives or CDs, infected with malware in public or semi-public locations. The attacker relies on the victim finding the device and inserting it into their computer, thereby executing the malicious payload. The Social Engineering Toolkit (SET) is specifically designed to create such malicious payloads and facilitate the setup for baiting attacks, making it a direct match for this technique.

Why this answer

Baiting is the correct answer because the penetration tester is using a physical device (USB drive) to exploit human curiosity or greed, enticing the target to insert it into a system. The Social Engineering Toolkit (SET) can create an autorun.inf file that triggers a payload upon insertion, which is a classic baiting attack that relies on the victim's action to compromise the system.

Exam trap

The trap here is that candidates confuse baiting with phishing because both involve tricking the user, but baiting specifically relies on a physical lure (like a USB drive) rather than a digital message or link.

How to eliminate wrong answers

Option A is wrong because tailgating involves an unauthorized person following an authorized individual into a restricted area without consent, not using a malicious USB drive. Option C is wrong because pretexting involves fabricating a scenario or identity to deceive a target into divulging information, such as impersonating IT support, not deploying a physical device. Option D is wrong because phishing is a digital social engineering technique that uses deceptive emails, messages, or websites to steal credentials or deliver malware, not a physical USB-based attack.

144
MCQeasy

Which malware type is characterized by self-replication across networks without needing a host file?

A.Worm
B.Trojan
C.Rootkit
D.Ransomware
AnswerA

Worms are a distinct category of malware known for their ability to self-replicate and propagate independently across computer networks without requiring user interaction. They exploit vulnerabilities in network protocols or services to spread from one system to another, consuming bandwidth and system resources. This autonomous replication is their defining characteristic, enabling rapid and widespread infection.

Why this answer

A worm is a standalone malware program that replicates itself across network connections without requiring a host file or user intervention. It exploits vulnerabilities in network protocols or services (e.g., SMB, RDP) to propagate autonomously, as seen with WannaCry's use of EternalBlue.

Exam trap

EC-CEH often tests the distinction between a worm and a virus, where the trap is that candidates confuse self-replication across networks (worm) with self-replication within a single system via host files (virus).

How to eliminate wrong answers

Option B is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution to install and typically requires a host file or program. Option C is wrong because a rootkit is designed to hide its presence and maintain privileged access, not to self-replicate across networks; it often modifies OS kernel structures. Option D is wrong because ransomware encrypts files or locks systems for extortion, and while some variants (e.g., WannaCry) use worm-like propagation, the defining characteristic of ransomware is the ransom demand, not self-replication without a host file.

145
MCQeasy

A user receives an email claiming to be from their bank, asking them to click a link and verify their account credentials. The email contains spelling errors and the link points to a suspicious domain. What type of social engineering attack is this?

A.Vishing
B.Whaling
C.Spear phishing
D.Phishing
AnswerD

Phishing is a broad social engineering technique characterized by mass-distributed, generic fraudulent communications, typically via email, designed to trick recipients into revealing sensitive information like login credentials, credit card numbers, or installing malware. These attacks often impersonate well-known entities such as banks, social media platforms, or online services, using urgent or alarming language to prompt immediate action. The email described, claiming to be from a bank and likely seeking credentials from a general user, perfectly aligns with the characteristics of a classic phishing campaign.

Why this answer

This scenario describes a mass, unsolicited email with generic content and a suspicious link, which is the classic definition of phishing. Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information, such as credentials, by impersonating a trusted entity. The presence of spelling errors and a suspicious domain are common indicators of a phishing attempt, not a targeted attack.

Exam trap

The trap here is that candidates often confuse 'phishing' with 'spear phishing' because both involve email, but the key differentiator is the level of targeting—phishing is mass and generic, while spear phishing is personalized and researched.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) is conducted over voice calls or VoIP, not via email with a clickable link. Option B is wrong because whaling targets high-profile executives or senior management with highly personalized content, not a generic email to a random user. Option C is wrong because spear phishing is a targeted attack against a specific individual or organization using personalized details, whereas this email is generic and lacks personalization.

146
Multi-Selecteasy

Which TWO of the following are types of malware analysis? (Select 2)

Select 2 answers
A.Penetration testing
B.Static analysis
C.Dynamic analysis
D.Network analysis
E.Code review
AnswersB, C

Static analysis involves examining malware without executing it, focusing on its internal structure and potential functionality. This method includes disassembling the executable, analyzing strings, inspecting header information, and reviewing embedded resources to infer the malware's capabilities, target APIs, and potential network indicators. It provides insights into the code logic and design before dynamic execution.

Why this answer

Static analysis examines malware without executing it, focusing on file structure, strings, and code signatures to identify malicious indicators. Dynamic analysis runs the malware in a controlled sandbox environment to observe runtime behavior, such as registry changes, network connections, and process injections. Both are fundamental malware analysis methodologies recognized by the CEH exam.

Exam trap

The CEH exam often tests the distinction between malware analysis types and other security activities like penetration testing or code review, tricking candidates who confuse 'analyzing malware' with 'testing for vulnerabilities' or 'reviewing source code.'

147
Multi-Selectmedium

Which TWO of the following are common indicators of a DNS spoofing attack? (Select 2)

Select 2 answers
A.High volume of DNS queries from a single source
B.ARP cache entries show unexpected MAC-IP mappings
C.The switch's CAM table is full
D.The resolved IP address for a domain does not match the legitimate server
E.Users are redirected to a malicious website despite typing the correct URL
AnswersD, E

When the IP address returned by a DNS query for a specific domain name differs from the legitimate server's actual IP, it is a primary indicator of DNS spoofing. An attacker has successfully intercepted or poisoned the DNS resolution process, substituting the correct IP with a malicious one. This manipulation ensures that subsequent client connections intended for the legitimate domain are instead directed to the attacker-controlled host.

Why this answer

DNS spoofing (cache poisoning) involves an attacker injecting forged DNS records into a resolver's cache. When a user's system queries a domain, the resolver returns the attacker-controlled IP address instead of the legitimate server's IP, causing traffic to be misdirected.

Exam trap

The trap here is confusing DNS spoofing with ARP spoofing or other network-layer attacks, as candidates may incorrectly associate unexpected MAC-IP mappings (Option B) with DNS manipulation rather than recognizing it as a distinct Layer 2 attack.

148
MCQeasy

An attacker sends an email to the CEO of a company, pretending to be a board member and requesting a wire transfer for a confidential acquisition. Which social engineering attack is this?

A.Whaling
B.Vishing
C.Spear phishing
D.Phishing
AnswerA

Whaling is a highly sophisticated form of phishing specifically designed to target high-profile individuals within an organization, such as CEOs, CFOs, or other senior executives. Attackers meticulously craft personalized emails, often impersonating a trusted entity or a critical business contact, to trick these high-value targets into divulging sensitive information or authorizing fraudulent transactions. The objective is typically significant financial gain or access to critical corporate data, leveraging the executive's authority and access.

Why this answer

Whaling is a targeted social engineering attack that specifically goes after high-profile individuals like C-suite executives or board members. In this scenario, the attacker impersonates a board member to trick the CEO into authorizing a wire transfer, which is a classic whaling tactic because it exploits the authority and trust associated with senior leadership.

Exam trap

The trap here is that candidates confuse whaling with spear phishing, but the CEH exam distinguishes whaling as a specific subtype targeting executives, while spear phishing is broader and can target any individual or role.

How to eliminate wrong answers

Option B (Vishing) is wrong because vishing is a voice-based phishing attack conducted over phone calls or VoIP, not via email. Option C (Spear phishing) is wrong because while spear phishing is targeted, it typically targets mid-level employees or specific groups, not exclusively high-ranking executives like a CEO; whaling is a subset of spear phishing focused on senior management. Option D (Phishing) is wrong because phishing is a broad, mass-email attack sent to many recipients, lacking the personalized targeting of a specific high-value individual like a CEO.

149
Multi-Selecthard

Which TWO of the following are features of a Remote Access Trojan (RAT)?

Select 2 answers
A.It encrypts files and demands ransom
B.It infects the Master Boot Record
C.It replicates itself across the network autonomously
D.It often includes a backdoor to bypass authentication
E.It provides the attacker with remote control over the infected system
AnswersD, E

A fundamental feature of many Remote Access Trojans (RATs) is the establishment of a backdoor. This backdoor provides a covert method for the attacker to regain access to the compromised system, often bypassing standard authentication mechanisms like usernames and passwords. This ensures persistent control, even if the initial exploit vector is patched or the user changes credentials, facilitating long-term surveillance or data exfiltration.

Why this answer

A Remote Access Trojan (RAT) is designed to provide an attacker with covert remote control over an infected system, often including a backdoor to bypass standard authentication mechanisms. This allows the attacker to execute commands, exfiltrate data, or use the system as a pivot point, which directly aligns with options D and E.

Exam trap

The trap here is that candidates may confuse a RAT with other malware types, such as ransomware (option A) or worms (option C), because they all involve malicious code, but the CEH exam specifically tests the unique remote-control and backdoor capabilities that define a RAT.

150
MCQhard

A security analyst runs the following command: 'python macof -i eth0 -n 1000'. Shortly after, the switch begins flooding traffic to all ports. What is the analyst trying to achieve?

A.DHCP starvation to exhaust IP addresses
B.STP manipulation to cause network loops
C.MAC flooding to force the switch into hub mode for sniffing
D.ARP cache poisoning to redirect traffic
AnswerC

The 'python macof' command correctly executes a MAC flooding attack. This attack rapidly generates and sends frames with unique, spoofed source MAC addresses, overwhelming the switch's Content Addressable Memory (CAM) table. Once the CAM table is full, the switch enters a 'fail-open' mode, behaving like a hub by broadcasting all incoming traffic to every port, thereby enabling an attacker to sniff network traffic.

Why this answer

The command 'python macof -i eth0 -n 1000' runs the macof tool, which generates a large number of frames with random source MAC addresses. This is a classic MAC flooding attack designed to overflow the switch's Content Addressable Memory (CAM) table. When the CAM table is full, the switch can no longer learn new MAC addresses and falls back to flooding all incoming frames out of every port, effectively behaving like a hub, which allows the attacker to sniff traffic that would normally be isolated.

Exam trap

The CEH exam often tests the distinction between MAC flooding (CAM table overflow) and ARP cache poisoning, so candidates may confuse the two because both involve MAC addresses, but MAC flooding targets the switch's forwarding table while ARP poisoning targets host ARP caches.

How to eliminate wrong answers

Option A is wrong because DHCP starvation exhausts IP addresses by sending many DHCP requests with fake MAC addresses, but the macof tool does not interact with DHCP servers; it floods the switch's CAM table with random MAC addresses. Option B is wrong because STP manipulation involves sending crafted Bridge Protocol Data Units (BPDUs) to cause loops or topology changes, whereas macof does not generate BPDUs or interact with Spanning Tree Protocol. Option D is wrong because ARP cache poisoning uses spoofed ARP replies to associate an attacker's MAC with a legitimate IP address, which is a different attack at Layer 2/3; macof only floods random MACs to overflow the CAM table, not to poison ARP caches.

← PreviousPage 2 of 3 · 179 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Ceh Malware Social Network questions.