Courseiva

CCNA Ceh Malware Social Network Questions

44 of 194 questions · Page 3/3 · Ceh Malware Social Network topic · Answers revealed

151
MCQmedium

A network administrator notices that the switch's CAM table is full, causing the switch to flood all incoming traffic out of all ports. Which attack is MOST likely occurring?

A.ARP poisoning
B.DHCP starvation
C.DNS spoofing
D.MAC flooding
AnswerD

MAC flooding overwhelms the switch's CAM table with forged source MAC addresses, exhausting its capacity. Once full, the switch cannot map addresses to ports and floods all incoming frames out of every port, satisfying the described symptom of indiscriminate flooding.

Why this answer

MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table by sending thousands of frames with unique, random source MAC addresses. Once the CAM table is full, the switch enters a fail-open state and begins flooding all incoming frames out every port, effectively turning it into a hub and allowing the attacker to sniff traffic. This directly matches the scenario where a full CAM table causes flooding.

Exam trap

In EC-CEH exams, MAC flooding (which fills the CAM table) is often confused with ARP poisoning (which poisons the ARP cache). Both can lead to traffic interception, but the cause differs: MAC flooding exploits the switch's learning mechanism, while ARP poisoning manipulates the host's ARP table.

How to eliminate wrong answers

Option A is wrong because ARP poisoning manipulates the IP-to-MAC mappings in a host's ARP cache to redirect traffic, not by filling the switch's CAM table. Option B is wrong because DHCP starvation exhausts the pool of available IP addresses from a DHCP server, causing denial of service for new clients, but it does not fill the switch's CAM table or cause port flooding. Option C is wrong because DNS spoofing corrupts DNS resolution to redirect users to malicious sites, and it has no effect on the switch's MAC address table or flooding behavior.

152
Multi-Selecthard

Which THREE of the following are effective DDoS mitigation techniques? (Select 3)

Select 3 answers
A.Rate limiting
B.Scrubbing centers
C.Blackholing all traffic to the target
D.IP spoofing
E.Anycast network distribution
AnswersA, B, E

Correct. Rate limiting can throttle attack traffic.

Why this answer

Rate limiting is effective because it restricts the number of requests a server will accept from a single IP address or session within a given time window, typically enforced via token bucket or leaky bucket algorithms. This prevents a single attacker or botnet node from overwhelming server resources, though it must be carefully tuned to avoid blocking legitimate users.

Exam trap

EC-CEH often tests the misconception that blackholing (null routing) is a viable mitigation technique, but candidates must remember it is a sacrificial measure that drops all traffic, not a selective defense, and is only used when the attack overwhelms all other defenses.

153
MCQmedium

A penetration tester is authorized to test a company's wireless network. After capturing the WPA2 4-way handshake, the tester attempts to crack it offline but fails because the passphrase is long and complex. The tester then decides to create a rogue access point that mimics the corporate SSID and captures the handshake from a connecting client. Which attack is the tester performing?

A.WPS PIN brute force
B.Evil twin
C.Deauthentication attack
D.KRACK attack
AnswerB

An evil twin is a rogue access point that impersonates a legitimate Wi-Fi network to trick clients into connecting. Once the victim connects, the attacker can capture the WPA2 handshake or credentials. This matches the scenario where the tester creates a fake AP with the corporate SSID to capture the handshake from a connecting client.

Why this answer

The tester sets up a rogue access point with the same SSID as the corporate network to trick a client into connecting, thereby capturing the WPA2 handshake. This is the definition of an evil twin attack. The other options describe different wireless attacks that do not match the scenario's details.

Exam trap

The trap here is confusing an evil twin with a deauthentication attack, since both can be used to capture a handshake, but only the evil twin involves a rogue access point mimicking a legitimate SSID.

154
MCQhard

A penetration tester uses the following command to scan a target: nmap -sU -sV -p 53,161,162 10.0.0.1. Which of the following BEST describes what this scan will accomplish?

A.Full port scan of all 65535 UDP ports
B.Ping sweep and OS detection on the target
C.UDP scan on three ports with service version detection
D.TCP SYN scan on ports 53, 161, 162 with version detection
AnswerC

This option accurately describes the Nmap command's functionality. The -sU flag specifically instructs Nmap to perform a UDP port scan, targeting services that communicate via the User Datagram Protocol. Concurrently, the -sV flag enables service version detection, attempting to identify the application and its version running on any discovered open UDP ports. The -p 53,161,162 argument precisely limits this comprehensive scan to three specific UDP ports.

Why this answer

The `-sU` flag initiates a UDP scan, `-p 53,161,162` limits the scan to those three specific ports, and `-sV` enables service version detection. This combination performs a UDP scan on only the specified ports and attempts to identify the versions of services running on them.

Exam trap

The trap here is that candidates may confuse `-sU` (UDP scan) with `-sS` (TCP SYN scan) or assume that `-sV` implies OS detection, when in fact `-sV` is strictly for service version detection and OS detection requires the `-O` flag.

How to eliminate wrong answers

Option A is wrong because the command specifies `-p 53,161,162`, which limits the scan to only those three UDP ports, not all 65535 UDP ports. Option B is wrong because the command uses `-sU` (UDP scan) and `-sV` (version detection), not `-sn` (ping sweep) or `-O` (OS detection). Option D is wrong because `-sU` specifies a UDP scan, not a TCP SYN scan (which would use `-sS`), and the ports 53, 161, 162 are commonly associated with UDP services (DNS, SNMP).

155
MCQmedium

A penetration tester uses the Social Engineering Toolkit (SET) to create a malicious USB drive that autoruns when inserted. Which social engineering technique is being employed?

A.Tailgating
B.Baiting
C.Pretexting
D.Phishing
AnswerB

Baiting is a social engineering attack that leverages human curiosity or greed by leaving physical media, such as USB drives or CDs, infected with malware in public or semi-public locations. The attacker relies on the victim finding the device and inserting it into their computer, thereby executing the malicious payload. The Social Engineering Toolkit (SET) is specifically designed to create such malicious payloads and facilitate the setup for baiting attacks, making it a direct match for this technique.

Why this answer

Baiting is the correct answer because the penetration tester is using a physical device (USB drive) to exploit human curiosity or greed, enticing the target to insert it into a system. The Social Engineering Toolkit (SET) can create an autorun.inf file that triggers a payload upon insertion, which is a classic baiting attack that relies on the victim's action to compromise the system.

Exam trap

The trap here is that candidates confuse baiting with phishing because both involve tricking the user, but baiting specifically relies on a physical lure (like a USB drive) rather than a digital message or link.

How to eliminate wrong answers

Option A is wrong because tailgating involves an unauthorized person following an authorized individual into a restricted area without consent, not using a malicious USB drive. Option C is wrong because pretexting involves fabricating a scenario or identity to deceive a target into divulging information, such as impersonating IT support, not deploying a physical device. Option D is wrong because phishing is a digital social engineering technique that uses deceptive emails, messages, or websites to steal credentials or deliver malware, not a physical USB-based attack.

156
MCQeasy

Which malware type is characterized by self-replication across networks without needing a host file?

A.Worm
B.Trojan
C.Rootkit
D.Ransomware
AnswerA

Worms are a distinct category of malware known for their ability to self-replicate and propagate independently across computer networks without requiring user interaction. They exploit vulnerabilities in network protocols or services to spread from one system to another, consuming bandwidth and system resources. This autonomous replication is their defining characteristic, enabling rapid and widespread infection.

Why this answer

A worm is a standalone malware program that replicates itself across network connections without requiring a host file or user intervention. It exploits vulnerabilities in network protocols or services (e.g., SMB, RDP) to propagate autonomously, as seen with WannaCry's use of EternalBlue.

Exam trap

EC-CEH often tests the distinction between a worm and a virus, where the trap is that candidates confuse self-replication across networks (worm) with self-replication within a single system via host files (virus).

How to eliminate wrong answers

Option B is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution to install and typically requires a host file or program. Option C is wrong because a rootkit is designed to hide its presence and maintain privileged access, not to self-replicate across networks; it often modifies OS kernel structures. Option D is wrong because ransomware encrypts files or locks systems for extortion, and while some variants (e.g., WannaCry) use worm-like propagation, the defining characteristic of ransomware is the ransom demand, not self-replication without a host file.

157
MCQeasy

A user receives an email claiming to be from their bank, asking them to click a link and verify their account credentials. The email contains spelling errors and the link points to a suspicious domain. What type of social engineering attack is this?

A.Vishing
B.Whaling
C.Spear phishing
D.Phishing
AnswerD

Phishing is a broad social engineering technique characterized by mass-distributed, generic fraudulent communications, typically via email, designed to trick recipients into revealing sensitive information like login credentials, credit card numbers, or installing malware. These attacks often impersonate well-known entities such as banks, social media platforms, or online services, using urgent or alarming language to prompt immediate action. The email described, claiming to be from a bank and likely seeking credentials from a general user, perfectly aligns with the characteristics of a classic phishing campaign.

Why this answer

This scenario describes a mass, unsolicited email with generic content and a suspicious link, which is the classic definition of phishing. Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information, such as credentials, by impersonating a trusted entity. The presence of spelling errors and a suspicious domain are common indicators of a phishing attempt, not a targeted attack.

Exam trap

The trap here is that candidates often confuse 'phishing' with 'spear phishing' because both involve email, but the key differentiator is the level of targeting—phishing is mass and generic, while spear phishing is personalized and researched.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) is conducted over voice calls or VoIP, not via email with a clickable link. Option B is wrong because whaling targets high-profile executives or senior management with highly personalized content, not a generic email to a random user. Option C is wrong because spear phishing is a targeted attack against a specific individual or organization using personalized details, whereas this email is generic and lacks personalization.

158
Multi-Selecteasy

Which TWO of the following are types of malware analysis? (Select 2)

Select 2 answers
A.Penetration testing
B.Static analysis
C.Dynamic analysis
D.Network analysis
E.Code review
AnswersB, C

Static analysis involves examining malware without executing it, focusing on its internal structure and potential functionality. This method includes disassembling the executable, analyzing strings, inspecting header information, and reviewing embedded resources to infer the malware's capabilities, target APIs, and potential network indicators. It provides insights into the code logic and design before dynamic execution.

Why this answer

Static analysis examines malware without executing it, focusing on file structure, strings, and code signatures to identify malicious indicators. Dynamic analysis runs the malware in a controlled sandbox environment to observe runtime behavior, such as registry changes, network connections, and process injections. Both are fundamental malware analysis methodologies recognized by the CEH exam.

Exam trap

The CEH exam often tests the distinction between malware analysis types and other security activities like penetration testing or code review, tricking candidates who confuse 'analyzing malware' with 'testing for vulnerabilities' or 'reviewing source code.'

159
Multi-Selectmedium

Which TWO of the following are common indicators of a DNS spoofing attack? (Select 2)

Select 2 answers
A.High volume of DNS queries from a single source
B.ARP cache entries show unexpected MAC-IP mappings
C.The switch's CAM table is full
D.The resolved IP address for a domain does not match the legitimate server
E.Users are redirected to a malicious website despite typing the correct URL
AnswersD, E

When the IP address returned by a DNS query for a specific domain name differs from the legitimate server's actual IP, it is a primary indicator of DNS spoofing. An attacker has successfully intercepted or poisoned the DNS resolution process, substituting the correct IP with a malicious one. This manipulation ensures that subsequent client connections intended for the legitimate domain are instead directed to the attacker-controlled host.

Why this answer

DNS spoofing (cache poisoning) involves an attacker injecting forged DNS records into a resolver's cache. When a user's system queries a domain, the resolver returns the attacker-controlled IP address instead of the legitimate server's IP, causing traffic to be misdirected.

Exam trap

The trap here is confusing DNS spoofing with ARP spoofing or other network-layer attacks, as candidates may incorrectly associate unexpected MAC-IP mappings (Option B) with DNS manipulation rather than recognizing it as a distinct Layer 2 attack.

160
MCQeasy

An attacker sends an email to the CEO of a company, pretending to be a board member and requesting a wire transfer for a confidential acquisition. Which social engineering attack is this?

A.Whaling
B.Vishing
C.Spear phishing
D.Phishing
AnswerA

Whaling is a highly sophisticated form of phishing specifically designed to target high-profile individuals within an organization, such as CEOs, CFOs, or other senior executives. Attackers meticulously craft personalized emails, often impersonating a trusted entity or a critical business contact, to trick these high-value targets into divulging sensitive information or authorizing fraudulent transactions. The objective is typically significant financial gain or access to critical corporate data, leveraging the executive's authority and access.

Why this answer

Whaling is a targeted social engineering attack that specifically goes after high-profile individuals like C-suite executives or board members. In this scenario, the attacker impersonates a board member to trick the CEO into authorizing a wire transfer, which is a classic whaling tactic because it exploits the authority and trust associated with senior leadership.

Exam trap

The trap here is that candidates confuse whaling with spear phishing, but the CEH exam distinguishes whaling as a specific subtype targeting executives, while spear phishing is broader and can target any individual or role.

How to eliminate wrong answers

Option B (Vishing) is wrong because vishing is a voice-based phishing attack conducted over phone calls or VoIP, not via email. Option C (Spear phishing) is wrong because while spear phishing is targeted, it typically targets mid-level employees or specific groups, not exclusively high-ranking executives like a CEO; whaling is a subset of spear phishing focused on senior management. Option D (Phishing) is wrong because phishing is a broad, mass-email attack sent to many recipients, lacking the personalized targeting of a specific high-value individual like a CEO.

161
Multi-Selecthard

Which TWO of the following are features of a Remote Access Trojan (RAT)?

Select 2 answers
A.It encrypts files and demands ransom
B.It infects the Master Boot Record
C.It replicates itself across the network autonomously
D.It often includes a backdoor to bypass authentication
E.It provides the attacker with remote control over the infected system
AnswersD, E

A fundamental feature of many Remote Access Trojans (RATs) is the establishment of a backdoor. This backdoor provides a covert method for the attacker to regain access to the compromised system, often bypassing standard authentication mechanisms like usernames and passwords. This ensures persistent control, even if the initial exploit vector is patched or the user changes credentials, facilitating long-term surveillance or data exfiltration.

Why this answer

A Remote Access Trojan (RAT) is designed to provide an attacker with covert remote control over an infected system, often including a backdoor to bypass standard authentication mechanisms. This allows the attacker to execute commands, exfiltrate data, or use the system as a pivot point, which directly aligns with options D and E.

Exam trap

The trap here is that candidates may confuse a RAT with other malware types, such as ransomware (option A) or worms (option C), because they all involve malicious code, but the CEH exam specifically tests the unique remote-control and backdoor capabilities that define a RAT.

162
MCQeasy

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

A.Ransomware
B.Spyware
C.Keylogger
D.Adware
AnswerA

Ransomware employs asymmetric encryption to lock files with a public key while the private decryption key remains solely with the attacker, directly satisfying the stem’s constraint of demanding payment for decryption. This contrasts with other malware types that may delete, exfiltrate, or corrupt data without encrypting it for ransom.

Why this answer

Ransomware is a type of malware that encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands payment, typically in cryptocurrency, for the decryption key. This matches the description of encrypting files and demanding payment for the decryption key, which is the defining characteristic of ransomware.

Exam trap

The trap here is that candidates may confuse ransomware with spyware or adware because all three are types of malware, but only ransomware specifically uses file encryption as a mechanism for extortion, not data theft or advertising.

How to eliminate wrong answers

Option B (Spyware) is wrong because spyware is designed to covertly gather information about the user, such as keystrokes, browsing habits, or credentials, and does not encrypt files or demand payment. Option C (Keylogger) is wrong because a keylogger specifically records keystrokes to capture sensitive data like passwords, but it does not encrypt files or issue a ransom demand. Option D (Adware) is wrong because adware automatically displays or downloads advertisements, often generating revenue for its creator, and lacks the file-encryption and extortion functionality of ransomware.

163
MCQhard

A security analyst runs the following command: 'python macof -i eth0 -n 1000'. Shortly after, the switch begins flooding traffic to all ports. What is the analyst trying to achieve?

A.DHCP starvation to exhaust IP addresses
B.STP manipulation to cause network loops
C.MAC flooding to force the switch into hub mode for sniffing
D.ARP cache poisoning to redirect traffic
AnswerC

The 'python macof' command correctly executes a MAC flooding attack. This attack rapidly generates and sends frames with unique, spoofed source MAC addresses, overwhelming the switch's Content Addressable Memory (CAM) table. Once the CAM table is full, the switch enters a 'fail-open' mode, behaving like a hub by broadcasting all incoming traffic to every port, thereby enabling an attacker to sniff network traffic.

Why this answer

The command 'python macof -i eth0 -n 1000' runs the macof tool, which generates a large number of frames with random source MAC addresses. This is a classic MAC flooding attack designed to overflow the switch's Content Addressable Memory (CAM) table. When the CAM table is full, the switch can no longer learn new MAC addresses and falls back to flooding all incoming frames out of every port, effectively behaving like a hub, which allows the attacker to sniff traffic that would normally be isolated.

Exam trap

The CEH exam often tests the distinction between MAC flooding (CAM table overflow) and ARP cache poisoning, so candidates may confuse the two because both involve MAC addresses, but MAC flooding targets the switch's forwarding table while ARP poisoning targets host ARP caches.

How to eliminate wrong answers

Option A is wrong because DHCP starvation exhausts IP addresses by sending many DHCP requests with fake MAC addresses, but the macof tool does not interact with DHCP servers; it floods the switch's CAM table with random MAC addresses. Option B is wrong because STP manipulation involves sending crafted Bridge Protocol Data Units (BPDUs) to cause loops or topology changes, whereas macof does not generate BPDUs or interact with Spanning Tree Protocol. Option D is wrong because ARP cache poisoning uses spoofed ARP replies to associate an attacker's MAC with a legitimate IP address, which is a different attack at Layer 2/3; macof only floods random MACs to overflow the CAM table, not to poison ARP caches.

164
MCQhard

During a penetration test, you execute a command that sends a large number of spoofed ICMP echo request packets to a subnet's broadcast address. This results in a flood of replies to the target system. Which attack have you performed?

A.Ping of Death
B.Smurf attack
C.UDP flood
D.ICMP flood
AnswerB

A Smurf attack exploits ICMP by sending spoofed echo requests to a subnet's broadcast address, causing every host to reply to the victim. This matches the stem's constraint exactly: the spoofed source is the target, and the amplified replies flood it, achieving traffic amplification through broadcast reflection.

Why this answer

The Smurf attack works by sending a large number of ICMP echo request packets with a spoofed source IP (the victim's address) to a subnet's broadcast address. All hosts on that subnet receive the request and reply to the spoofed source, overwhelming the victim with ICMP echo replies. This amplifies traffic because a single request triggers many responses, making it a classic amplification DDoS attack.

Exam trap

Candidates often confuse Smurf attack with a standard ICMP flood. The critical distinction is that a Smurf attack uses a subnet broadcast address and spoofs the victim's IP, causing all hosts in the subnet to reply to the victim, amplifying traffic. A simple ICMP flood sends many pings directly to the target without amplification.

In CEH, this amplification and spoofing is the key to recognizing the Smurf attack.

How to eliminate wrong answers

Option A is wrong because Ping of Death involves sending a malformed ICMP packet larger than 65,535 bytes to cause a buffer overflow, not spoofed broadcast traffic. Option C is wrong because a UDP flood uses UDP packets (often to random ports) to exhaust resources, not ICMP echo requests to a broadcast address. Option D is wrong because an ICMP flood typically sends a high volume of ICMP packets directly to a target without spoofing or broadcast amplification, whereas the Smurf attack specifically exploits the broadcast address for amplification.

165
MCQmedium

A penetration tester uses a tool to perform a man-in-the-middle attack by sending forged DNS responses that redirect users to a malicious website. Which tool is MOST likely being used to perform DNS spoofing?

A.Nmap
B.Wireshark
C.Ettercap
D.tcpdump
AnswerC

Ettercap is a comprehensive and versatile suite specifically designed for Man-in-the-Middle attacks on switched LANs. It excels by implementing robust ARP spoofing to redirect traffic between two hosts through the attacker's machine, effectively placing itself in the middle. Beyond simple interception, Ettercap includes powerful plugins for active manipulation, such as DNS spoofing, content filtering, and packet injection, making it a primary tool for intercepting, analyzing, and altering network communications in real-time. Its integrated framework directly supports the actions needed for a successful MITM attack.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks, including ARP poisoning and DNS spoofing. It can intercept DNS requests and forge fake responses to redirect victims to a malicious IP, making it the correct tool for DNS spoofing.

Exam trap

The trap here is that candidates often confuse packet capture tools (Wireshark, tcpdump) with active attack tools, forgetting that DNS spoofing requires injecting forged packets, not just passive observation.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning and discovery tool, not designed to forge DNS responses or perform MITM attacks. Option B is wrong because Wireshark is a packet analyzer used for passive traffic capture and inspection, not for injecting forged DNS packets. Option D is wrong because tcpdump is a command-line packet capture tool that only captures and displays packets; it cannot actively spoof DNS responses.

166
MCQmedium

A user receives a text message claiming their bank account is locked and requiring them to click a link to verify. This social engineering method is called:

A.Phishing
B.Whaling
C.Vishing
D.SMiShing
AnswerD

SMiShing is the precise term for a phishing attack conducted via Short Message Service (SMS) text messages. In this method, attackers send deceptive text messages, often containing malicious links or requests for personal information, to mobile phone users. The goal is to trick recipients into clicking links that install malware, redirect to fraudulent websites, or directly provide sensitive data, perfectly matching the described scenario of a text message claiming bank account issues.

Why this answer

SMiShing (SMS phishing) is the correct term because the attack vector is a text message (SMS) that tricks the user into clicking a malicious link. Unlike email-based phishing, SMiShing exploits the higher trust users often place in SMS messages and the limited security controls on mobile devices.

Exam trap

The CEH exam often tests the distinction between phishing (email), vishing (voice), and SMiShing (SMS) by presenting a scenario that clearly involves a text message, leading candidates to mistakenly choose 'Phishing' due to its broader familiarity.

How to eliminate wrong answers

Option A is wrong because phishing generally refers to email-based social engineering attacks, not SMS. Option B is wrong because whaling targets high-profile executives or individuals, not generic bank account users. Option C is wrong because vishing uses voice calls (VoIP or phone) to deceive victims, not text messages.

167
MCQmedium

An organization is experiencing repeated DDoS attacks that consume all available bandwidth. Which mitigation technique is MOST effective for handling such volumetric attacks?

A.Blackholing all traffic to the target IP
B.Anycast network distribution
C.Rate limiting on the firewall
D.Scrubbing centers
AnswerD

Scrubbing centres divert incoming traffic to dedicated facilities that filter and clean malicious volumetric floods before forwarding legitimate packets, absorbing the bandwidth-saturating load upstream. This preserves the organisation's own internet link, which on-premises filtering cannot achieve during a bandwidth-exhaustion attack.

Why this answer

Scrubbing centers (Option D) are the most effective mitigation for volumetric DDoS attacks because they use specialized hardware and software to filter malicious traffic from legitimate traffic before it reaches the target network. Unlike simpler methods, scrubbing centers can handle massive bandwidth floods by redirecting traffic through high-capacity filtering nodes that inspect packets, drop attack traffic based on signatures or behavioral analysis, and forward only clean traffic. This approach is specifically designed for volumetric attacks that saturate bandwidth, as it offloads the filtering burden from the target's own infrastructure.

Exam trap

A common mistake is to assume that anycast distribution (Option B) mitigates volumetric attacks by spreading traffic across servers. However, anycast only distributes the load; it does not filter malicious traffic. Volumetric attacks require actual traffic scrubbing to remove malicious data, which is provided by scrubbing centers (Option D).

How to eliminate wrong answers

Option A is wrong because blackholing all traffic to the target IP (via BGP null routing) drops all traffic, including legitimate traffic, effectively causing a denial of service for valid users and not mitigating the attack but rather accepting defeat. Option B is wrong because anycast network distribution primarily helps distribute traffic across multiple geographic locations to absorb some attack volume, but it does not filter malicious traffic; it only spreads the load, and if the attack is large enough, it can still overwhelm all anycast nodes. Option C is wrong because rate limiting on the firewall is a reactive, per-connection or per-IP threshold mechanism that is ineffective against volumetric floods that originate from many distributed sources (e.g., botnets) and can be bypassed by varying source IPs; it also risks dropping legitimate traffic if thresholds are set too low.

168
MCQhard

An organization's security team observes a surge in outgoing DNS queries to external servers from a single internal host, with each query returning unusually large responses (e.g., 4000 bytes). The host is not configured as a DNS resolver. Which attack is MOST likely occurring?

A.DNS cache poisoning
B.DNS zone transfer
C.DNS amplification DDoS attack
D.DNS tunneling
AnswerD

DNS tunneling is a technique used to encapsulate data of other protocols within DNS queries and responses, often for covert communication or data exfiltration. While it involves using DNS traffic to bypass firewalls or security controls, its primary goal is to establish a hidden communication channel, not to generate an enormous volume of large, legitimate-looking DNS responses for denial-of-service. The data volume is typically limited by the tunneling payload, not designed for massive amplification.

Why this answer

The scenario describes a single internal host initiating a surge of outgoing DNS queries to external servers and receiving unusually large responses (e.g., 4000 bytes). This behavior, particularly from a host not configured as a DNS resolver, is a strong indicator of DNS tunneling. In DNS tunneling, a compromised host establishes a covert communication channel by encapsulating data within DNS queries and responses, often for data exfiltration or command and control.

Large DNS responses, frequently utilizing record types like TXT, are commonly employed to transfer significant amounts of data back to the compromised host. DNS amplification DDoS attacks, in contrast, involve an attacker spoofing a victim's IP address to send small queries to open resolvers, causing the victim to be overwhelmed by large, unsolicited responses; the victim does not actively send the initial queries in this scenario.

Exam trap

The CEH exam often tests the distinction between DNS tunneling and DNS amplification. Candidates might mistakenly choose DNS amplification DDoS attack (C) by focusing solely on 'large responses' and misinterpreting the internal host as the *victim* of an amplification attack. However, the critical detail is that the internal host is *sending* the outgoing queries and *receiving* the large responses, which is characteristic of DNS tunneling (D) where data is exfiltrated or commanded.

In a DNS amplification attack, the victim *receives* large responses without initiating the queries themselves (their IP is spoofed).

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning involves corrupting a resolver's cache with forged DNS records to redirect traffic, not generating large response volumes from a single host. Option B is wrong because DNS zone transfer is a legitimate mechanism for replicating DNS zone data between authoritative servers, typically using TCP port 53, and does not involve sending large responses to a single host from external servers. Option D is wrong because DNS tunneling encodes non-DNS data (e.g., SSH, HTTP) within DNS queries and responses for covert communication, but it does not produce the massive response sizes (4000 bytes) characteristic of amplification; tunneling typically uses small, consistent packet sizes to avoid detection.

169
MCQeasy

Which of the following is a type of malware that replicates itself by attaching to executable files and requires human action to spread, such as opening an infected attachment?

A.Worm
B.Ransomware
C.File virus
D.Trojan
AnswerC

A file virus is a classic form of malware that replicates by attaching its malicious code to legitimate executable files or scripts on a host system. When an infected program is executed, the virus code runs first, often infecting other uninfected files on the same system or accessible network drives. This direct modification and execution-based propagation mechanism is a fundamental characteristic of file viruses, making them a clear example of replicating malware.

Why this answer

A file virus (also known as a file infector) is a type of malware that replicates by inserting its code into executable files (e.g., .exe, .com, .dll). It requires human action to spread, such as opening an infected email attachment or running an infected program, because the virus code is only activated when the host executable is executed.

Exam trap

The trap here is that candidates often confuse a file virus with a worm because both can spread via email attachments, but the key differentiator is that a worm self-replicates without human interaction, while a file virus requires the user to execute the infected file.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads automatically over networks without requiring human action, exploiting vulnerabilities like open ports or weak credentials. Option B is wrong because ransomware is a type of malware that encrypts files or locks systems to demand a ransom, and it does not primarily replicate by attaching to executables; its spread often relies on other vectors like phishing or exploits. Option D is wrong because a Trojan is malware disguised as legitimate software that does not self-replicate; it relies on social engineering to trick users into installing it, but it does not attach to executable files to propagate.

170
Multi-Selecthard

A security analyst is investigating a malware incident. The analyst observes that the malware creates a scheduled task to run a script every time the system starts, and it also modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to execute a payload. Which two persistence techniques is the malware using? (Choose two.)

Select 2 answers
A.Bootkit
B.Registry Run key
C.Service creation
D.DLL hijacking
E.Scheduled task
AnswersB, E

The scenario explicitly mentions modification of the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, which is a classic registry Run key persistence method. This key causes the specified program to execute automatically when the user logs on. Therefore, this is one of the correct answers.

Why this answer

The malware uses two persistence techniques: creating a scheduled task to run at startup and modifying the registry Run key to execute a payload on user logon. Both are explicitly described in the scenario. The other options are different persistence methods not mentioned.

Exam trap

The trap here is assuming that any mention of 'startup' implies a service or bootkit, but the specific artifacts named—scheduled task and HKCU Run key—are the definitive indicators.

171
Multi-Selectmedium

Which TWO of the following are characteristics of a polymorphic virus?

Select 2 answers
A.It uses a decryption routine that varies
B.It uses a constant signature across all infections
C.It changes its code signature each time it replicates
D.It can only infect boot sectors
E.It always remains in memory
AnswersA, C

A polymorphic virus employs a sophisticated mutation engine that generates a unique decryption routine for each new infection instance. This varying decryption stub is prepended to the encrypted virus body, ensuring that the overall code signature changes every time the virus replicates. This constant alteration of the decryption mechanism is crucial for evading static signature-based antivirus detection, as the virus's executable form never presents the same byte pattern.

Why this answer

A polymorphic virus uses a decryption routine that varies with each infection, preventing signature-based detection. Option C is also correct because the changing decryption routine causes the virus's code signature to change each time it replicates, further evading signature matching.

Exam trap

The trap here is that candidates confuse 'polymorphic' with 'metamorphic' — polymorphic changes the decryption routine but keeps the payload constant, whereas metamorphic rewrites the entire code body, and the exam often tests this distinction by listing 'constant signature' as a distractor.

172
MCQeasy

An attacker sends an email that appears to come from the CEO of the company, requesting an urgent wire transfer to a specific account. This is an example of which social engineering attack?

A.Whaling
B.Spear phishing
C.Phishing
D.Pretexting
AnswerA

Whaling is a highly specialized form of spear phishing that specifically targets high-profile individuals within an organization, such as CEOs, CFOs, or other senior executives. The attacker crafts extremely convincing emails, often spoofing the identity of a trusted internal or external party, to trick these 'big fish' into divulging sensitive information or authorizing fraudulent transactions. The objective is typically significant financial gain or access to critical corporate data, leveraging the executive's authority and perceived urgency.

Why this answer

Whaling is a targeted social engineering attack that specifically goes after high-profile individuals like the CEO or CFO. In this scenario, the attacker impersonates the CEO to trick an employee into authorizing a fraudulent wire transfer, which is the classic hallmark of whaling rather than generic phishing.

Exam trap

The trap here is that candidates confuse whaling with spear phishing because both are targeted, but whaling is specifically reserved for attacks against senior executives or high-value targets, not just any individual.

How to eliminate wrong answers

Option B (Spear phishing) is wrong because spear phishing targets a specific individual or group but does not necessarily focus on senior executives; the attack here is explicitly against the CEO's identity. Option C (Phishing) is wrong because phishing is a broad, untargeted attack sent to many users, not a personalized email impersonating a specific executive. Option D (Pretexting) is wrong because pretexting involves creating a fabricated scenario or pretext to obtain information, not directly requesting an action like a wire transfer via email impersonation.

173
MCQmedium

A security analyst discovers a user downloaded a file that, when executed, creates a hidden process that connects to a remote server and allows full remote control of the system. Which type of malware BEST describes this behavior?

A.Worm
B.Ransomware
C.Remote Access Trojan (RAT)
D.Polymorphic virus
AnswerC

A Remote Access Trojan (RAT) is a sophisticated form of malware specifically engineered to grant an attacker comprehensive, covert administrative control over an infected system. It establishes a persistent backdoor, enabling remote execution of commands, file manipulation, keystroke logging, screen capture, and even webcam/microphone activation. This direct, interactive control makes a RAT the definitive tool for remote system manipulation and surveillance.

Why this answer

The behavior described—downloading a file that, when executed, creates a hidden process that connects to a remote server and provides full remote control—is the classic definition of a Remote Access Trojan (RAT). A RAT is a type of malware that allows an attacker to remotely control the victim's system, often using a command-and-control (C2) channel over protocols like TCP or HTTP. The hidden process and outbound connection to a remote server are key indicators of a RAT, distinguishing it from other malware types that do not provide interactive remote control.

Exam trap

The trap here is that candidates often confuse a RAT with a worm or virus because they focus on the 'remote control' aspect, but fail to recognize that a RAT specifically provides interactive remote access, whereas worms and viruses have different primary behaviors like self-replication or code mutation.

How to eliminate wrong answers

Option A is wrong because a worm is a self-replicating malware that spreads across networks without requiring user interaction to execute a downloaded file, and it does not typically provide full remote control of a single system. Option B is wrong because ransomware encrypts files or locks the system to demand a ransom, and it does not create a hidden process for remote control or connect to a remote server for interactive access. Option D is wrong because a polymorphic virus changes its code signature to evade detection but does not inherently create a hidden process or establish a remote control channel; its primary behavior is infection and mutation, not remote access.

174
MCQmedium

A network administrator notices an unusually high number of half-open TCP connections to the company's web server. The source IPs are spoofed. Which type of attack is MOST likely occurring?

A.Smurf attack
B.UDP flood
C.SYN flood
D.ICMP flood
AnswerC

A SYN flood is a classic denial-of-service attack that exploits the TCP three-way handshake. The attacker sends a large volume of TCP SYN (synchronize) requests to a target server but never completes the handshake by sending the final ACK (acknowledgment). This leaves numerous "half-open" connections in the server's memory, exhausting its connection table and preventing legitimate clients from establishing new connections, thus denying service.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IPs to the target server. The server responds with SYN-ACK packets and allocates resources for each half-open connection, exhausting its connection queue and preventing legitimate connections. The description of half-open TCP connections with spoofed source IPs is the classic signature of a SYN flood.

Exam trap

The trap here is that candidates confuse a SYN flood with a Smurf attack because both use spoofed IPs, but Smurf attacks rely on ICMP broadcast amplification, not TCP half-open connections.

How to eliminate wrong answers

Option A is wrong because a Smurf attack uses ICMP echo requests sent to a network's broadcast address with a spoofed victim IP, causing all hosts to reply to the victim, not half-open TCP connections. Option B is wrong because a UDP flood sends large numbers of UDP packets to random ports, overwhelming the target's bandwidth or processing, but does not involve TCP handshake states or half-open connections. Option D is wrong because an ICMP flood overwhelms the target with ICMP packets (e.g., ping floods), consuming bandwidth or CPU, but does not create half-open TCP connections.

175
MCQeasy

Which tool is specifically designed to create fake login pages for phishing campaigns and can be integrated with Metasploit?

A.Social Engineering Toolkit (SET)
B.Nmap
C.Wireshark
D.Ettercap
AnswerA

The Social Engineering Toolkit (SET) is explicitly designed for various social engineering attacks, including the creation of convincing fake login pages. Its "Web Attack Vectors" module, specifically the "Credential Harvester Attack," allows an attacker to clone legitimate websites, including their login forms. This cloned page then captures any credentials entered by unsuspecting victims, forwarding them to the attacker while often redirecting the user to the actual legitimate site to avoid suspicion.

Why this answer

The Social Engineering Toolkit (SET) is specifically designed to automate social engineering attacks, including the creation of fake login pages (credential harvesting) for phishing campaigns. It includes a built-in 'Website Attack Vectors' module that can clone legitimate sites and capture submitted credentials, and it offers direct integration with Metasploit to deliver payloads or establish reverse shells upon credential submission.

Exam trap

The CEH exam often tests the distinction between general-purpose tools (like Nmap or Wireshark) and specialized social engineering frameworks, leading candidates to confuse a network attack tool (Ettercap) with a phishing-specific tool like SET.

How to eliminate wrong answers

Option B is wrong because Nmap is a network scanning and reconnaissance tool used for port discovery and service enumeration, not for creating phishing pages or social engineering attacks. Option C is wrong because Wireshark is a network protocol analyzer used for packet capture and traffic inspection, not for generating fake login pages or integrating with Metasploit for phishing. Option D is wrong because Ettercap is a man-in-the-middle attack tool focused on ARP poisoning and packet sniffing on local networks, not for crafting phishing pages or credential harvesting via fake login forms.

176
MCQhard

During a forensic investigation, an analyst retrieves a suspicious executable. Running 'strings' reveals no readable text, and VirusTotal shows zero detections. However, when executed in a sandbox, the binary connects to a remote IP and injects code into 'explorer.exe'. Which conclusion is MOST accurate?

A.The file is a worm because it connects to a remote IP
B.The file is likely a packed trojan that evades signature-based detection
C.The file is benign because static analysis found no indicators
D.The file is a false positive and the sandbox environment is compromised
AnswerB

The absence of discernible strings during static analysis and zero detections by antivirus engines strongly suggest the file is packed or heavily obfuscated to evade signature-based detection. Subsequent dynamic analysis in a sandbox environment, revealing malicious behaviors such as network connections to suspicious IPs or process injection, confirms its true malicious intent. These combined indicators are highly characteristic of a packed trojan designed to bypass initial security checks and execute its payload.

Why this answer

The absence of readable strings and zero VirusTotal detections strongly suggest the executable is packed or obfuscated, a common evasion technique used by trojans. The sandbox behavior—connecting to a remote IP and injecting code into explorer.exe—confirms malicious intent, specifically trojan-like remote access and process injection. This combination of static stealth and dynamic malicious activity indicates a packed trojan designed to bypass signature-based antivirus.

Exam trap

The trap here is that candidates assume 'no static indicators' means the file is benign, ignoring that packing is a deliberate evasion technique, and that dynamic analysis (sandbox execution) is essential to uncover hidden malicious behavior.

How to eliminate wrong answers

Option A is wrong because connecting to a remote IP alone does not define a worm; worms self-replicate and spread autonomously, whereas this file exhibits trojan behavior (remote access and code injection). Option C is wrong because static analysis (e.g., 'strings') is insufficient to declare a file benign; packed malware intentionally hides indicators, and dynamic analysis revealed malicious activity. Option D is wrong because the sandbox environment is not compromised; the binary's outbound connection and injection are consistent with malware behavior, not a false positive from a compromised sandbox.

177
MCQmedium

Which of the following tools is specifically designed to perform MAC flooding to force a switch into fail-open mode, allowing packet sniffing?

A.Ettercap
B.Wireshark
C.Nmap
D.macof
AnswerD

macof, a tool within the dsniff suite, is specifically engineered to execute MAC flooding attacks against network switches. It operates by rapidly generating and transmitting a massive number of Ethernet frames, each containing a unique, randomly generated source MAC address. This malicious activity aims to exhaust the switch's Content Addressable Memory (CAM) table, forcing the switch to enter a "fail-open" or "hub mode" state. In this state, the switch broadcasts all incoming traffic to every connected port, thereby allowing an attacker to passively sniff all network communications.

Why this answer

The macof tool (part of the dsniff suite) is specifically designed to perform MAC flooding attacks. It floods a switch with thousands of random MAC addresses, exhausting the Content Addressable Memory (CAM) table. When the CAM table is full, the switch enters fail-open mode and begins flooding all frames out all ports, effectively turning it into a hub and allowing an attacker to sniff traffic that was not originally destined for their port.

Exam trap

The trap here is that candidates often confuse MAC flooding with ARP poisoning, and mistakenly choose Ettercap (which is famous for ARP spoofing) instead of recognizing that macof is the dedicated tool for CAM table overflow attacks.

How to eliminate wrong answers

Option A is wrong because Ettercap is a comprehensive man-in-the-middle (MITM) attack toolkit that supports ARP poisoning, DNS spoofing, and other interception techniques, but it does not perform MAC flooding as its primary or designed function. Option B is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets; it has no capability to generate traffic or perform MAC flooding. Option C is wrong because Nmap is a network scanning and reconnaissance tool used for port scanning, service detection, and OS fingerprinting; it is not designed to flood a switch's CAM table.

178
Multi-Selecthard

During a forensic investigation, you find a file named 'svch0st.exe' in the startup folder. The file has a suspicious icon and was downloaded from an untrusted source. Analysis shows it opens a backdoor on port 4444 and sends system information to a remote server. Which THREE best describe this malware and its characteristics?

Select 3 answers
A.It functions as a remote access Trojan (RAT)
B.It is classified as a Trojan horse
C.It is a polymorphic virus that changes its signature each time it runs
D.It is a worm that replicates across the network automatically
E.It is capable of exfiltrating data to a remote server
AnswersA, B, E

A Remote Access Trojan (RAT) like 'svch' establishes a covert communication channel, often a backdoor, allowing an attacker to remotely control the compromised system. It facilitates unauthorized access to files, execution of commands, and monitoring of user activity, effectively turning the victim's machine into a remote puppet. This capability to open a backdoor and send information is a hallmark of RAT functionality, enabling persistent and stealthy control.

Why this answer

Option A is correct because a program that covertly opens a backdoor on port 4444 and accepts remote commands is functioning as a remote access Trojan (RAT), giving an attacker interactive control of the host. Option B is correct because the file masquerades as a legitimate executable (svch0st.exe mimicking svchost.exe), was downloaded from an untrusted source, and hides malicious functionality, which is the defining behavior of a Trojan horse. Option E is correct because the malware sends system information to a remote server, which is data exfiltration over the network to an attacker-controlled endpoint.

Option C is not correct because nothing in the scenario indicates self-mutating code or signature changes on each execution, which would be required for a polymorphic virus. Option D is not correct because there is no evidence of self-replication or automatic propagation across the network, which is the defining trait of a worm.

Exam trap

The trap here is that candidates may confuse a RAT with a worm or virus, but the key differentiator is that a RAT provides remote access without self-replication, while worms spread automatically and viruses require a host file to replicate.

179
Multi-Selectmedium

Which TWO of the following are examples of application layer (Layer 7) DDoS attacks? (Select 2)

Select 2 answers
A.HTTP flood
B.Smurf attack
C.SYN flood
D.UDP flood
E.Slowloris
AnswersA, E

An HTTP flood is a Layer 7 (Application Layer) Distributed Denial of Service (DDoS) attack that overwhelms a web server by sending a massive volume of legitimate-looking HTTP GET or POST requests. These requests consume the server's CPU, memory, and bandwidth resources, making it unable to respond to legitimate user traffic. Unlike lower-layer attacks, it targets the specific application protocol, mimicking normal user behavior to evade simple network-level defenses.

Why this answer

HTTP flood is a Layer 7 DDoS attack because it targets the application layer by sending seemingly legitimate HTTP GET or POST requests to overwhelm a web server's resources. Unlike network-layer attacks, HTTP flood exploits the server's ability to process requests, often mimicking normal user behavior to bypass basic rate limiting. Slowloris is also a Layer 7 attack that works by opening multiple HTTP connections and keeping them open with partial requests, exhausting the server's connection pool without completing the handshake.

Exam trap

The trap here is that candidates often confuse SYN flood (Layer 4) with application-layer attacks because both involve flooding, but SYN flood targets the TCP handshake at the transport layer, not the HTTP protocol at Layer 7.

180
MCQmedium

Which tool is commonly used to perform DNS spoofing on a local network by intercepting DNS requests and replying with forged responses?

A.Ettercap
B.Wireshark
C.Nmap
D.tcpdump
AnswerA

Ettercap performs ARP poisoning to place itself between hosts and the DNS server, then intercepts DNS queries and returns forged replies, satisfying the local-network DNS spoofing requirement. Its integrated sniffing and filtering plugins make this man-in-the-middle attack practical without additional tooling.

Why this answer

Ettercap is a comprehensive suite for man-in-the-middle attacks on a local network. It can perform DNS spoofing by intercepting DNS requests (typically over UDP port 53) and replying with forged responses before the legitimate DNS server can respond, redirecting victims to malicious IP addresses.

Exam trap

EC-Council often tests the distinction between passive monitoring tools (Wireshark, tcpdump) and active attack tools (Ettercap), leading candidates to confuse packet capture capabilities with the ability to inject forged traffic.

How to eliminate wrong answers

Option B (Wireshark) is wrong because it is a network protocol analyzer used for capturing and inspecting packets, not for injecting or modifying traffic to perform DNS spoofing. Option C (Nmap) is wrong because it is a network discovery and security scanning tool used for port scanning and service enumeration, not for intercepting and forging DNS responses. Option D (tcpdump) is wrong because it is a command-line packet capture utility used for network traffic analysis, lacking the capability to actively manipulate or spoof DNS replies.

181
MCQmedium

An attacker uses the Social Engineering Toolkit (SET) to clone a legitimate website and send a malicious link to employees. When an employee clicks the link, they are prompted to enter their credentials. Which attack is this?

A.SMiShing
B.Spear phishing
C.Vishing
D.Phishing
AnswerD

Cloning a legitimate site and harvesting credentials via a sent link is credential phishing. The Social Engineering Toolkit automates the fake login page, but the attack category remains phishing, defined by deceptive messaging that induces victims to surrender sensitive information.

Why this answer

The Social Engineering Toolkit (SET) is used to clone a legitimate website and capture credentials via a malicious link. This is a classic phishing attack because it involves sending a fraudulent communication (the link) that mimics a trusted entity to trick victims into revealing sensitive information. The attack does not rely on SMS (SMiShing), voice calls (Vishing), or targeted personalization (Spear phishing) beyond the generic employee group.

Exam trap

The CEH exam often tests the distinction between generic phishing and spear phishing, where the trap is assuming any targeted employee list automatically qualifies as spear phishing, even without personalized content.

How to eliminate wrong answers

Option A is wrong because SMiShing (SMS phishing) uses text messages as the delivery vector, not a cloned website link sent via email or other channels. Option B is wrong because spear phishing involves highly targeted, personalized messages to specific individuals or roles, whereas this scenario describes a generic link sent to employees without customization. Option C is wrong because vishing (voice phishing) uses phone calls or voice messages to trick victims, not a cloned website link.

182
MCQmedium

A company wants to protect its network from MAC flooding attacks. Which of the following countermeasures is MOST effective?

A.Use Wireshark to monitor for floods
B.Disable CAM table learning
C.Enable port security on switches
D.Implement ARP spoofing detection
AnswerC

Enabling port security on switches is the most effective defense against MAC flooding attacks. This feature allows administrators to configure a maximum number of MAC addresses permitted to be learned on a specific switch port. When the configured limit is exceeded, the switch can be configured to take action, such as shutting down the port, restricting further MAC address learning, or generating an alert, thereby preventing the attacker from overflowing the CAM table.

Why this answer

Enabling port security on switches directly limits the number of MAC addresses that can be learned on a switch port, preventing an attacker from flooding the CAM table with fake MAC addresses. When the configured limit is exceeded, the switch can either drop traffic, shut down the port, or send an alert, effectively stopping the MAC flooding attack at the access layer.

Exam trap

The CEH exam often tests the distinction between passive monitoring tools (like Wireshark) and active security controls (like port security), and the trap here is that candidates confuse detection with prevention, or confuse MAC flooding with ARP spoofing attacks.

How to eliminate wrong answers

Option A is wrong because Wireshark is a passive packet analyzer that can detect a MAC flooding attack in progress but cannot prevent or stop it; it provides no active countermeasure. Option B is wrong because disabling CAM table learning would break normal switch operation, as the switch would be unable to build its forwarding table and would flood all frames out all ports, effectively turning the switch into a hub and causing network disruption. Option D is wrong because ARP spoofing detection addresses ARP cache poisoning attacks, not MAC flooding attacks; MAC flooding targets the switch's CAM table by exhausting its memory with fake MAC addresses, while ARP spoofing manipulates IP-to-MAC mappings on hosts.

183
MCQhard

During a forensic investigation, an analyst finds a suspicious file that changes its code signature each time it replicates. The file uses encryption and polymorphism to evade signature-based detection. Which type of virus is this?

A.Macro virus
B.File infector virus
C.Boot sector virus
D.Polymorphic virus
AnswerD

Polymorphic viruses are a sophisticated type of malware designed to evade signature-based detection by constantly changing their executable code while retaining their original functionality. They achieve this through a 'mutation engine' that encrypts the virus body with a different key and decryption routine for each new infection. This process ensures that every new instance of the virus has a unique signature, making it extremely challenging for traditional antivirus software to identify based on static patterns.

Why this answer

D is correct because a polymorphic virus is specifically designed to change its code signature each time it replicates, using encryption and mutation engines to evade signature-based detection. The description of altering the signature with each replication while maintaining the same core functionality is the defining characteristic of a polymorphic virus.

Exam trap

CEH often tests the distinction between a polymorphic virus and a metamorphic virus; the trap here is that candidates may confuse 'polymorphic' (which changes the decryption routine but keeps the body encrypted) with 'metamorphic' (which rewrites its entire code without encryption), but the question explicitly mentions encryption, confirming polymorphism.

How to eliminate wrong answers

Option A is wrong because a macro virus infects documents or spreadsheets by embedding malicious macros in scripting languages like VBA, and while it can replicate, it does not inherently change its code signature through encryption and polymorphism. Option B is wrong because a file infector virus attaches itself to executable files and activates when the host program runs, but it typically does not alter its signature with each replication unless it incorporates polymorphic techniques, which is not its defining feature. Option C is wrong because a boot sector virus infects the master boot record or boot sector of a storage device, loading before the OS, and it does not routinely change its code signature via encryption and polymorphism as a primary evasion method.

184
Multi-Selectmedium

Which TWO of the following are characteristics of a DNS amplification attack? (Select 2)

Select 2 answers
A.It targets the victim's MAC address
B.It uses spoofed source IP addresses
C.It exploits open DNS resolvers
D.It requires the attacker to be on the same subnet as the victim
E.It uses ICMP echo requests
AnswersB, C

This is a critical characteristic of DNS amplification. The attacker sends small DNS queries to numerous open DNS resolvers, but crafts these queries to appear as if they originated from the victim's IP address. This IP spoofing ensures that when the resolvers send their much larger responses, they are directed to the legitimate victim's network, effectively overwhelming their bandwidth and causing a denial of service. Without spoofing, the responses would return to the attacker, nullifying the amplification effect.

Why this answer

DNS amplification attacks rely on sending DNS queries with a spoofed source IP address that matches the victim's IP. The attacker sends small queries to open DNS resolvers, which then send large responses to the victim, overwhelming their bandwidth. This spoofing ensures the amplified traffic is directed at the victim, not the attacker.

Exam trap

The trap here is that candidates often confuse DNS amplification with other reflection attacks like Smurf (which uses ICMP) or think the attacker must be local, but the key differentiator is the use of spoofed source IPs and open DNS resolvers over UDP.

185
MCQeasy

Which type of malware is characterized by self-replication and spreading across networks without needing a host file?

A.Trojan
B.Worm
C.Ransomware
D.Virus
AnswerB

A worm is a standalone malicious program designed to self-replicate and propagate across computer networks without requiring a host program or user intervention. Worms exploit vulnerabilities in operating systems or applications to spread autonomously, often scanning for vulnerable systems and then infecting them to continue their replication cycle. This independent self-replication and network-based propagation are their defining characteristics, allowing them to consume network bandwidth and system resources rapidly.

Why this answer

A worm is a standalone malware program that replicates itself to spread to other computers over a network, exploiting vulnerabilities or using social engineering, without requiring a host file or user intervention. Unlike viruses, worms do not need to attach to an existing program; they operate independently, often using network protocols like SMB, HTTP, or email to propagate.

Exam trap

EC-CEH often tests the distinction between a virus and a worm by emphasizing that a virus requires a host file to attach to, while a worm is self-contained and spreads independently over networks, leading candidates to mistakenly choose 'Virus' when they see 'self-replication' without noting the 'no host file' condition.

How to eliminate wrong answers

Option A is wrong because a Trojan disguises itself as legitimate software but does not self-replicate; it relies on user execution and lacks autonomous network propagation. Option C is wrong because ransomware encrypts files or locks systems for ransom but does not self-replicate or spread across networks without user action; its primary behavior is extortion, not autonomous replication. Option D is wrong because a virus requires a host file (e.g., an executable or document) to attach to and replicate, and it typically spreads via file sharing or removable media, not autonomously across networks without a host.

186
MCQmedium

A network administrator notices a large number of SYN packets from various spoofed source IP addresses targeting a web server. The server's connection table is full, and legitimate users cannot connect. Which type of attack is this?

A.Ping flood
B.Smurf attack
C.UDP flood
D.SYN flood
AnswerD

A SYN flood is a type of DoS attack where an attacker sends a succession of SYN requests with spoofed source IPs to a target. The server allocates resources for each half-open connection, eventually exhausting its connection table and denying service to legitimate users. This matches the scenario perfectly.

Why this answer

The attack uses spoofed SYN packets to exhaust the server's connection table, preventing legitimate connections. This is a SYN flood, a common TCP-based denial-of-service attack. The other options describe different flood attacks using ICMP or UDP.

Exam trap

The trap here is confusing SYN flood with other flood attacks; the key is the use of SYN packets and the exhaustion of the connection table, which is specific to TCP SYN floods.

187
MCQhard

A security team suspects a session hijacking attack. The analyst examines network traffic and sees packets with sequence numbers that increment by predictable values. Which attack is MOST likely occurring?

A.TCP sequence prediction
B.ARP poisoning
C.DNS spoofing
D.MAC flooding
AnswerA

TCP sequence prediction involves an attacker guessing the next valid sequence number in a TCP connection. If the sequence numbers are predictable, the attacker can inject crafted packets into an established session, effectively hijacking it. By successfully predicting and sending packets with the correct sequence and acknowledgment numbers, the attacker can impersonate one of the legitimate communication parties, taking control of the session without needing to intercept initial authentication. This allows for unauthorized command execution or data manipulation within the active session.

Why this answer

TCP sequence prediction attacks exploit the ability to guess the next sequence number in a TCP connection, allowing an attacker to inject forged packets and hijack the session. The analyst observed packets with sequence numbers incrementing by predictable values, which is the hallmark of weak or static sequence number generation in older TCP implementations.

Exam trap

The trap here is that candidates confuse session hijacking with ARP poisoning or DNS spoofing, but the key clue is 'predictable sequence numbers,' which directly points to TCP sequence prediction, not Layer 2 or DNS manipulation.

How to eliminate wrong answers

Option B (ARP poisoning) is wrong because it involves manipulating ARP tables to intercept traffic at Layer 2, not predicting TCP sequence numbers. Option C (DNS spoofing) is wrong because it corrupts DNS responses to redirect traffic, not targeting TCP sequence numbers. Option D (MAC flooding) is wrong because it overwhelms a switch's CAM table to force it into hub mode, enabling packet sniffing, not sequence number prediction.

188
MCQmedium

During a social engineering assessment, an attacker calls a help desk impersonating a new employee and requests a password reset due to a 'locked account'. The help desk complies. Which social engineering technique is being used?

A.Phishing
B.Vishing
C.Pretexting
D.Quid pro quo
AnswerC

Pretexting is a sophisticated form of social engineering where an attacker invents a believable, fabricated scenario (a "pretext") to manipulate a target into divulging information or performing an action. This often involves extensive research to create a credible backstory, a false identity, and a plausible reason for the interaction, making the target believe they are interacting with someone authorized or legitimate. The scenario's description of an attacker calling and using a fabricated scenario directly aligns with the definition of pretexting.

Why this answer

Pretexting is the correct answer because the attacker fabricates a scenario (the pretext of being a new employee with a locked account) to manipulate the help desk into performing a password reset. This technique relies on a crafted story to gain trust and bypass security procedures, rather than using technical exploits or direct requests for information.

Exam trap

The trap here is that candidates confuse the medium (phone call) with the technique, incorrectly selecting vishing (Option B) instead of recognizing that the core deception is the fabricated pretext, not the voice channel itself.

How to eliminate wrong answers

Option A is wrong because phishing typically involves sending fraudulent emails or messages that mimic legitimate entities to trick victims into revealing sensitive information or clicking malicious links, not a direct phone call impersonation. Option B is wrong because vishing (voice phishing) uses phone calls to extract sensitive data like credit card numbers or credentials, but the core technique here is the fabricated identity and story, not the medium alone. Option D is wrong because quid pro quo involves offering a service or benefit in exchange for information or access (e.g., 'I'll fix your computer if you give me your password'), whereas this scenario uses a false identity to request a routine action without any reciprocal offer.

189
MCQhard

A security engineer is configuring DDoS protection for a web server. The goal is to mitigate a Slowloris attack. Which mitigation technique is MOST effective?

A.Use anycast routing
B.Implement rate limiting and connection timeout
C.Increase the maximum number of simultaneous connections
D.Enable SYN cookies
AnswerB

Slowloris attacks aim to exhaust server resources by maintaining numerous open, incomplete HTTP connections. Implementing a strict connection timeout for idle or slow-sending connections will effectively terminate these malicious sessions before they can consume all available server sockets indefinitely. Additionally, rate limiting the number of new connections or requests from a single source IP can prevent an attacker from establishing a sufficient volume of connections to overwhelm the server's capacity, thus mitigating the attack.

Why this answer

Slowloris works by opening many HTTP connections and keeping them alive by sending partial requests, never completing them, which exhausts the server's connection pool. Rate limiting restricts the number of connections from a single IP, and connection timeouts force idle connections to close, directly countering Slowloris's behavior. This combination prevents the attacker from holding connections open indefinitely.

Exam trap

The trap here is that candidates confuse Slowloris with a SYN flood and choose SYN cookies (Option D), but Slowloris operates at the application layer after the TCP handshake completes, so SYN cookies are ineffective.

How to eliminate wrong answers

Option A is wrong because anycast routing distributes traffic across multiple data centers, which helps with volumetric DDoS attacks but does not prevent a single low-bandwidth connection from exhausting server resources, as Slowloris does. Option C is wrong because increasing the maximum number of simultaneous connections only gives the attacker more room to open additional connections, making the attack worse. Option D is wrong because SYN cookies protect against SYN flood attacks by deferring resource allocation until the handshake completes, but Slowloris completes the TCP handshake and then sends partial HTTP requests, so SYN cookies do not mitigate it.

190
MCQmedium

A network switch starts behaving like a hub, broadcasting all traffic to all ports. The security team suspects an attack that floods the switch with fake MAC addresses. Which attack is this?

A.MAC flooding
B.ARP poisoning
C.STP attack
D.DNS spoofing
AnswerA

MAC flooding involves overwhelming a switch's Content Addressable Memory (CAM) table (also known as MAC address table) with a multitude of forged source MAC addresses. When the CAM table becomes full, the switch can no longer store new legitimate MAC-to-port mappings. Consequently, for any new incoming frames destined for an unknown MAC address, the switch resorts to broadcasting the frames out of all ports, effectively degrading its functionality to that of a network hub. This allows an attacker to capture traffic intended for other hosts on the segment.

Why this answer

MAC flooding exploits the limited size of a switch's Content Addressable Memory (CAM) table. By sending thousands of packets with unique, fake source MAC addresses, the attacker fills the CAM table, forcing the switch to fail open and broadcast all incoming frames to every port, effectively behaving like a hub. This allows the attacker to capture traffic not originally destined for their port.

Exam trap

EC-Council often tests the distinction between MAC flooding (layer 2 CAM table exhaustion) and ARP poisoning (layer 2/3 cache manipulation), so candidates mistakenly choose ARP poisoning because both involve MAC addresses, but only MAC flooding causes the switch to broadcast traffic like a hub.

How to eliminate wrong answers

Option B (ARP poisoning) is wrong because it manipulates the ARP cache of hosts to associate the attacker's MAC address with the IP address of a legitimate device, enabling man-in-the-middle attacks; it does not flood the switch's CAM table. Option C (STP attack) is wrong because it targets the Spanning Tree Protocol by sending forged Bridge Protocol Data Units (BPDUs) to cause topology changes or denial of service, not by exhausting CAM table entries. Option D (DNS spoofing) is wrong because it corrupts DNS resolver caches to redirect domain name lookups to malicious IP addresses, which is a layer-7 attack unrelated to switch MAC address tables.

191
MCQeasy

A security analyst receives an email from what appears to be the company's CEO requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ce0@company.com instead of ceo@company.com). Which type of social engineering attack is this?

A.Vishing
B.Phishing
C.Whaling
D.Spear phishing
AnswerD

Spear phishing is a highly targeted form of email-based social engineering where attackers craft personalized messages for a specific individual, such as a security analyst. These emails often leverage specific knowledge about the target, their role, or their organization, making the lure appear highly credible and increasing the likelihood of the recipient falling victim. The goal is typically to trick the individual into revealing sensitive information, clicking a malicious link, or downloading an infected attachment, directly aligning with the scenario described.

Why this answer

Spear phishing is a targeted phishing attack aimed at a specific individual or group. In this scenario, the attacker sends an email impersonating the CEO to a specific security analyst, making it a spear phishing attempt. The target is the analyst, not the CEO, so it is not whaling, which targets senior executives directly.

Exam trap

The trap is confusing whaling with spear phishing. Whaling targets senior executives; this attack targets a security analyst by impersonating the CEO, so it is spear phishing.

How to eliminate wrong answers

Option A is wrong because vishing (voice phishing) uses phone calls or voice messages, not email. Option B is wrong because phishing is a broad term for mass, untargeted attacks, whereas this scenario targets a specific high-level executive. Option D is wrong because spear phishing targets a specific individual or group but does not necessarily focus on senior executives; whaling is a subset of spear phishing aimed at 'big fish' like the CEO.

192
MCQhard

After a security incident, an analyst retrieves a suspicious file. To determine if it is malicious without executing it, the analyst runs the 'strings' command and uploads the file to VirusTotal. Which type of malware analysis is being performed?

A.Static analysis
B.Behavioral analysis
C.Code analysis
D.Dynamic analysis
AnswerA

Static analysis involves examining a file's properties and contents without executing it. Running the `strings` command extracts printable character sequences, providing clues about embedded text, URLs, or file paths. Uploading to VirusTotal leverages a multitude of static analysis engines and reputation databases to identify known malware signatures and indicators of compromise, all performed on the file at rest.

Why this answer

The analyst is performing static analysis because they are examining the file without executing it. Running the 'strings' command extracts readable text from the binary, and uploading to VirusTotal checks the file's hash against known malware signatures — both are non-behavioral, non-runtime techniques. Static analysis focuses on file properties, code structure, and metadata without triggering the malware's execution.

Exam trap

Common confusion: Static analysis does not execute the file, while dynamic analysis runs it in a sandbox. Uploading to VirusTotal is a form of static analysis based on signatures.

How to eliminate wrong answers

Option B is wrong because behavioral analysis requires executing the malware in a controlled environment (e.g., sandbox) to observe runtime actions like registry changes or network connections, which did not occur here. Option C is wrong because code analysis typically involves disassembly or decompilation (e.g., using IDA Pro or Ghidra) to examine the actual instructions, not just running 'strings' or checking hashes. Option D is wrong because dynamic analysis involves running the file and monitoring its behavior in real time, which was explicitly avoided by the analyst.

193
MCQhard

An ethical hacker is analyzing a suspicious file using static analysis. Which of the following actions is part of static malware analysis?

A.Running the file in a sandboxed environment and monitoring its behavior
B.Uploading the file to VirusTotal for scanning
C.Examining the file's strings and metadata without executing it
D.Using Wireshark to capture packets sent by the file
AnswerC

Static analysis inspects the file's bytes, embedded strings, headers and metadata without running it, so malicious behaviour cannot trigger on the analyst's host. This contrasts with dynamic analysis, which executes the sample in a sandbox and observes its runtime actions.

Why this answer

Static malware analysis involves examining the file without executing it. Option C is correct because analyzing strings and metadata (e.g., file headers, embedded URLs, IP addresses, or suspicious function calls) is a core static analysis technique, often performed using tools like `strings`, `binwalk`, or `PEview`. This approach avoids the risks of execution and helps identify indicators of compromise (IOCs) before dynamic analysis.

Exam trap

The trap here is that candidates confuse 'static analysis' with 'dynamic analysis' or 'online scanning,' leading them to select options that involve execution (A, D) or third-party aggregation (B) instead of direct file inspection without execution.

How to eliminate wrong answers

Option A is wrong because running the file in a sandboxed environment and monitoring its behavior is dynamic analysis, not static analysis. Option B is wrong because uploading to VirusTotal is a form of automated online scanning that may involve both static and dynamic checks, but it is not a pure static analysis action performed by the analyst directly on the file. Option D is wrong because using Wireshark to capture packets sent by the file requires execution of the file, which falls under dynamic or network-based analysis, not static analysis.

194
MCQmedium

A security analyst is investigating a suspicious file and wants to quickly determine whether it is known malware without executing it. Which approach should the analyst use FIRST?

A.Disassemble the file with IDA Pro
B.Check for strings in the binary
C.Run the file in a sandbox environment
D.Submit the file to VirusTotal for hash lookup
AnswerD

VirusTotal's hash lookup matches the file's cryptographic fingerprint against aggregated antivirus signatures, confirming known malware without execution. This satisfies the stem's constraint of identifying known threats safely and immediately, since a hash match requires no sandbox detonation or runtime analysis. Unknown files return no match, prompting deeper investigation.

Why this answer

Submitting the file's hash to VirusTotal is the fastest and safest first step to determine if the file is known malware. VirusTotal aggregates results from over 70 antivirus engines and threat intelligence feeds, allowing the analyst to check the file's reputation without any risk of execution or analysis overhead. This approach leverages existing threat intelligence to instantly identify known malicious samples, which is the most efficient initial triage step.

Exam trap

EC-CEH often tests the misconception that dynamic analysis (sandboxing) is the fastest initial step, but the trap here is that a hash lookup is both safer and quicker for known malware, while sandboxing is reserved for unknown or suspicious files after a hash check fails.

How to eliminate wrong answers

Option A is wrong because disassembling with IDA Pro is a deep static analysis technique that is time-consuming and unnecessary for a quick reputation check; it should be performed only after simpler methods fail. Option B is wrong because checking for strings in the binary can reveal suspicious indicators but is not definitive for identifying known malware, as strings can be obfuscated or benign, and this method does not leverage community threat intelligence. Option C is wrong because running the file in a sandbox environment, while useful for dynamic analysis, introduces execution risk and is slower than a hash lookup; it is not the first step when a simple hash check can immediately confirm known malware.

← PreviousPage 3 of 3 · 194 questions total

Ready to test yourself?

Try a timed practice session using only Ceh Malware Social Network questions.