Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CEH Exam Study Quiz 034 Questions with correct answers.

Rating
-
Sold
-
Pages
24
Grade
A+
Uploaded on
27-11-2025
Written in
2025/2026

CEH Exam Study Quiz 034 Questions with correct answers. Jimmy is standing outside a secure entrance to a facility. He is pretending to having a tense conversation on his cell phone as an authorized employee badges in. Jimmy, while still on the phone, grabs the door as it begins to close. What just happened? - Answer-Tailgating Jimmy is standing outside a secure entrance to a facility. He is pretending to having tense conversation on his cell phone as an authorized employee badges. Jimmy, while still on the phone, grabs the door as it begins to close. What just happened? - Answer-Piggybacking Matthew, a black hat, has managed to open a meterpreter session to one of the kiosk machines in Evil Corp's lobby. He checks his current SID, which is S--. What needs to happen before Matthew has full administrator access? - Answer-He must perform privilege escalation. Nation-state threat actors often discover vulnerabilities and hold on the them until they want to launch a sophisticated attack. The Sutxnet attack was an unprecedented style of attack because it used four types of vulnerability. - Answer-zero-day NMAP -sn 192.168.11.200-215 The NMAP command above performs which of the following? - Answer-A ping scan On performing a risk assessment, you need to determine the potential impacts when some of the critical business processes of the company interrupt its service. What is the name of the process by which you can determine those critical businesses? - Answer-Business Impact Analysis (BIA) PGP, SSL, and IKE are all examples of which type of cryptography? - Answer-Public Key Port scanning can be used as part of a technical assessment to determine network vulnerabilities. The TCP XMAS scan is used to identify listening ports on the targeted system. If a scanned port is open, what happens? - Answer-The port will ignore the packets. Risks = Threats x Vulnerabilities is referred to as the: - Answer-Risk equation Sam is working as a pen-tester in an organization in Houston. He performs penetration testing on IDS in order to find the different ways an attacker uses to evade the IDS. Sam sends large amount of packets to the target IDS that generate alerts which enable Sam to hide the real traffic. What type of method is Sam using to evade IDS? - Answer-False Positive Generation Scenario: 1. Victim opens the attacker's web site 2. Attacker sets of the web site which contains interesting and attractive content like "Do you want to make $1000 in a day?". 3. They can clicks to the interesting and attractive content url 4. Attacker creates a transparent 'iframe' in front of the URL which victim attempts to click, so victim thinks that he/she clicks the " do you want to make $1000 in a day?" URL but actually he/she clicks to the content or URL that exist in a transparent 'iframe' which is set up by the attacker. What is the name of the attack which is mentioned in the scenario? - Answer-ClickJacking attack Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like Computer Security Policy, Information Protection Policy, Information Security Policy, Network Security Policy, Physical Security Policy, Remote Access Policy, and User Account Policy.What is the main theme of the sub-policies for Information Technologies? - Answer-Confidentiality, Integrity, Availability Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like; Computer Security Policy, Information Protection Policy, Information Security Policy, Network Security Policy, Physical Security Policy, Remote Access Policy, User Account Policy. What is main theme of the sub-policies for Information Technologies? - Answer-Confidentiality, Integrity, Availability Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like; Computer Security Policy, Information Protection Policy, Information Security Policy, Network Security Policy, Physical Security Policy, Remote Access Policy, User Account Policy. What is main theme of the sub-policies for Information Technologies? - Answer-Confidentiality, Integrity, Availability Session splicing is an IDS evasion technique in which an attacker delivers data in multiple, small size packets to the target computer, making it very difficult for an IDS to detect the attack signatures. Which tool can be used to perform session splicing attacks? - Answer-Whisker Some clients of TPNQM SA were redirected to a malicious site when they tried to access the TPNQM main site. Bob, a system administrator at TPNQM SA, found that they were victims of DNS Cache Poisoning. What should Bob recommend to deal with such a threat? - Answer-The use of DNSSEC Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some measures and implemented the necessary controls. After that another security risk assessment was performed showing that risk has decreased to 10%.The risk threshold for the application is 20%. Which of the following risk decisions will be the best for the project in terms of its successful continuation with most business profit? - Answer-Accept the risk The "black box testing" methodology enforces which kind of restriction? - Answer-Only the external operation of a system is accessible to the tester The "gray box testing" methodology enforces what kind of restriction? - Answer-The internal operation of a system is only partly accessible to the tester The chance of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. Calculate the SLE, ARO, and ALE. Assume the EF = 1 (100%). What is the closest approximate cost of this replacement and recovery operation per year? - Answer-$146

Show more Read less
Institution
CEH
Course
CEH

Content preview

___________ Is a set of extensions to DNS that provide to DNS clients (resolvers)
origin authentication of DNS
data to reduce the threat of DNS poisoning, spoofing, and similar attacks types. -
Answer-DNSSEC

A common cryptographical tool is the use of XOR. XOR the following binary values:
10110001
00111010 - Answer-10001011

A company's security policy states that all Web browsers must automatically delete their
HTTP browser
cookies upon terminating. What sort of security breach is the policy attempting to
mitigate? - Answer-Attempts by attackers to determine the user's web browser usage
patterns, including when sites were
visited and for how long.

A company's Web development team has become aware of a certain type of security
vulnerability in their Web
software. To mitigate the possibility of this vulnerability being exploited, the team wants
to modify the software
requirements to disallow users from entering HTML as input into their Web application.
What kind of Web application vulnerability likely exists in their software? - Answer-
Cross-site scripting vulnerability

A hacker gained access to database with logins and hashed passwords. To speed up
cracking these
passwords the best method would be: - Answer-Rainbow tables

A hacker has successfully infected an internet-facing server which he will then use to
send junk mail, take part
in coordinated attacks, or host junk email content.
Which sort of trojan infects this server? - Answer-Botnet Trojan

A hacker is an intelligent individual with excellent computer skills that grant them the
ability to explore a
computer's software and hardware without the owner's permission. Their intention can
either be to simply gain
knowledge or to illegally make changes. Which of the following class of hacker refers to
individual who work
both offensively and defensively at various times? - Answer-Gray Hat

,A hacker named Jack is trying to compromise a bank's computer system. He needs to
know the operating
system of that computer to launch further attacks.
What process would help him? - Answer-Banner Grabbing

A medium-sized healthcare IT business decides to implement a risk management
strategy.
Which of the following is NOT one of the five basic responses to risk? - Answer-
Delegate

A network administrator discovers several unknown files in the root directory of his
Linux FTP server. One of
the files is a tarball, two are shell script files, and the third is a binary file is named "nc".
The FTP server's
access logs show that the anonymous user account logged into the server, uploaded
the files, and extracted
the contents of the tarball and ran the script using a function provided by the FTP
server' software. The ps
command shows that the nc file is running as process, and the netstat command shows
the nc process is
listening on a network port.
What kind of vulnerability must be present to make this remote attack possible? -
Answer-File system permissions

A new wireless client is configured to join a 802.11 network. The client uses the same
hardware and software
is many of the other clients on the network. The client can see the network, but cannot
connect. A wireless
packet sniffer shows that the wireless access point (WAP) is not responding to the
association requests being
sent by the wireless client.
What is a possible source of this problem? - Answer-The WAP does not recognize the
clients MAC address

A new wireless client is configured to join a 802.11 network. This client uses the same
hardware and software
as many of the other clients on the network. The client can see the network, but cannot
connect. A wireless
packet sniffer shows that the Wireless Access Point (WAP) is not responding to the
association requests being
sent by the wireless client.
What is possible source of the problem? - Answer-The WAP does not recognize the
client's MAC address

A penetration tester is conducting a port scan on a specific host. The tester found
several ports opened that

, were confusing in concluding the OS version installed. Considering the NMAP result
below, which of the
following is likely to be installed on the target machine by the OS? Starting NMAP 5.21
at 2011-03-15 11:06
NMAP scan report for 172.16.40.65 Host is up (1.00s latency). Not shown: 993 closed
ports PORT STATE
SERVICE 21/tcp open ftp 23/tcp open telnet 80/tcp open http 139/tcp open netbios-ssn
515/tcp open 631/tcp
open ipp 9100/tcp open MAC Address: 00:00:48:0D:EE:8 - Answer-The host is likely a
printer.

A regional bank hires your company to perform a security assessment on their network
after a recent data
breach. The attacker was able to steal financial data from the bank by compromising
only a single server. - Answer-Place a front-end web server in a demilitarized zone that
only handles external web traffic.

A tester has been hired to do a web application security test. The tester notices that the
site is dynamic and
must make use of a back end database. In order for the tester to see if SQL injection is
possible, what is the
first character that the tester should use to attempt breaking a valid SQL request? -
Answer-Single quote

A virus that attempts to install itself inside of the file it is infecting is called ? - Answer-
Cavity virus

Alice encrypts her data using her public key PK and stores the encrypted data in the
cloud. Which of the
following attack scenarios will compromise the privacy of her data? - Answer-Alice also
stores her private key in the cloud, and Harry breaks into the cloud server as before

An attacker changes the profile information of a particular user on a target website (the
victim). The attacker
uses this string to update the victim's profile to a text file and then submit the data to the
attackers database.
<iframe src="http://www.vulnweb.com/updateif.php" style='display:none"> </iframe>
What is this type of attack (that can use either HTTP GET or HTTP POST) called? -
Answer-Cross-Site Scripting

An attacker gains access to a web server's database and displays the contents of the
table that holds all of the
names, passwords, and other user information. The attacker did this by entering
information into the website's
user login page that the software's designers did not expect to be entered. This is an
example of what kind of

Written for

Institution
CEH
Course
CEH

Document information

Uploaded on
November 27, 2025
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$13.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller
Seller avatar
karimilinet45

Get to know the seller

Seller avatar
karimilinet45 EXAMS
Follow You need to be logged in order to follow users or courses
Sold
-
Member since
1 year
Number of followers
0
Documents
84
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions