PM
CEH V2 EXAM QUESTIONS AND ANSWERS WITH COMPLETE
SOLUTIONS VERIFIED LATEST UPDATE 2025/2026 GRADED
A+ VERIFIED!!
Which regulation defines A
security and privacy controls
for Federal information
systems and
organizations?
A. NIST-800-53
B. PCI-DSS
C. EU Safe Harbor
D. HIPAA
You've just been hired to B
perform a pen test on an
organization that has
been
subjected to a large-scale
attack. The CIO is
concerned with mitigating
threats and
vulnerabilities
to totally
eliminate
risk.
What is one of the first
things you should do when
given the job?
1/33
,6/28/25, 2:05
PM
A. Interview all employees in
the company to rule out
possible insider threats.
B. Explain to the CIO that you
cannot
eliminate all risk, but you will
be able to reduce risk to
acceptable levels.
C. Establish attribution
to suspected
attackers.
D. Start the wireshark
application to start
sniffing network traffic.
While performing online C
banking using a Web
browser, a user receives an
email that contains a
link to an interesting Web
site. When the user clicks
on the link, another Web
browser session
starts and displays a video of
cats playing a piano. The
next business day, the user
receives what looks like an
email from his bank,
indicating that his bank
account has been accessed
from a foreign country. The
email asks the user to call
his bank and verify the
authorization of a funds
2/33
,6/28/25, 2:05
PM
transfer
that took place.
What Web browser-based
security
vulnerability was exploited
to compromise the user?
A. Cross-Site Scripting
B. Clickjacking
C. Cross-Site Request Forgery
D. Web form input validation
During a recent security D
assessment, you discover
the organization has one
Domain Name Server (DNS)
in a Demilitarized Zone
(DMZ) and a second DNS
server on the
internal network.
What is this type of DNS
configuration commonly
called?
A. DNSSEC
B. DynDNS
C. DNS Scheme
D. Split DNS
During a blackbox pen test A
3/33
, 6/28/25, 2:05
PM
you attempt to pass IRC
traffic over port 80/TCP
from a
compromised
web enabled host. The traffic
gets blocked; however,
outbound HTTP traffic is
unimpeded.
What type of firewall is
inspecting outbound
traffic?
A. Application
B. Circuit
C. Stateful
D. Packet Filtering
You just set up a security B
system in your network. In
what kind of system would
you find the
following string of
characters used as a rule
within its configuration?
alert tcp any any ->
192.168.100.0/24 21 (msg: "FTP
on the network!";)
A. A firewall IPTable
4/33