CEH v11
INDEX
- Set 1 (Q1 to Q30)
- Set 2 (Q31 to Q60)
- Set 3 (Q61 to Q90)
- Set 4 (Q91 to Q120)
- Set 5 (Q121 to Q150)
- Set 6 (Q151 to Q180)
- Set 7 (Q181 to Q210)
- Set 8 (Q211 to Q240)
- Set 9 (Q241 to Q270)
- Set 10 (Q271 to Q300)
- Set 11 (Q301 to Q330)
- Set 12 (Q331 to Q360)
- Set 13 (Q361 to Q390)
- Set 14 (Q391 to Q420)
- Set 15 (Q421 to Q450)
- Set 16 (Q451 to Q480)
- Set 17 (Q481 to Q510)
- Set 18 (Q511 to Q540)
- Set 19 (Q541 to Q570)
- Set 20 (Q571 to Q600)
- Set 21 (Q601 to Q630)
- Set 22 (Q631 to Q660)
- Set 23 (Q661 to Q690)
- Set 24 (Q691 to Q720)
Q601 - Tess King is using the nslookup command to craft queries to list all DNS information (such asName Servers, host names, MX records, CNAME records, glue records (delegation for child Domains),zone serial number, TimeToLive (TTL) records, etc) for a Domain.What do you think Tess King is trying to accomplish? Select the best answer.
- A zone harvesting
- A zone transfer
- A zone update
- A zone estimate
Answer: B
Q602 - Which of the following is a protocol specifically designed for transporting event messages?
- SYSLOG
- SMS
- SNMP
- ICMP
Answer: A
Q603 - Alice encrypts her data using her public key PK and stores the encrypted data in the cloud. Which of the following attack scenarios will compromise the privacy of her data?
- None of these scenarios compromise the privacy of Alice's data
- Agent Andrew subpoenas Alice, forcing her to reveal her private key. However, the cloud server successfully resists Andrew's attempt to access the stored data
- Hacker Harry breaks into the cloud server and steals the encrypted data
- Alice also stores her private key in the cloud, and Harry breaks into the cloud server as before
Answer: D
Q604 - The network administrator at Spears Technology, Inc has configured the default gateway Cisco router's access-list as below: You are hired to conduct security testing on their network. You successfully brute-force the SNMP community string using a SNMP crack tool. The access-list configured at the router prevents you from establishing a successful connection. You want to retrieve the Cisco configuration from the router. How would you proceed?
- Use the Cisco's TFTP default password to connect and download the configuration file
- Run a network sniffer and capture the returned traffic with the configuration file from the router
- Run Generic Routing Encapsulation (GRE) tunneling protocol from your computer to the router masking your IP address
- Send a customized SNMP set request with a spoofed source IP address in the range -192.168.1.0
Answer: B & D
Q605 - In order to prevent particular ports and applications from getting packets into an organization, what does a firewall check?
- Network layer headers and the session layer port numbers
- Presentation layer headers and the session layer port numbers
- Application layer port numbers and the transport layer headers
- Transport layer port numbers and application layer headers
Answer: D
Q606 - You have successfully gained access to your client's internal network and successfully comprised a Linux server which is part of the internal IP network. You want to know which Microsoft Windows workstations have file sharing enabled. Which port would you see listening on these Windows machines in the network?
- 445
- 3389
- 161
- 1433
Answer: A
Q607 - The following are types of Bluetooth attack EXCEPT_____?
- Bluejacking
- Bluesmaking
- Bluesnarfing
- Bluedriving
Answer: D
Q608 - Destination unreachable administratively prohibited messages can inform the hacker to what?
- That a circuit level proxy has been installed and is filtering traffic
- That his/her scans are being blocked by a honeypot or jail
- That the packets are being malformed by the scanning software
- That a router or other packet-filtering device is blocking traffic
- That the network is functioning normally
Answer: D
Q609 - A possibly malicious sequence of packets that were sent to a web server has been captured by an Intrusion Detection System (IDS) and was saved to a PCAP file. As a network administrator, you need to determine whether this packets are indeed malicious. What tool are you going to use?
- Intrusion Prevention System (IPS)
- Vulnerability scanner
- Protocol analyzer
- Network sniffer
Answer: C
Q610 - A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version installed. Considering the NMAP result below, which of the following is likely to be installed on the target machine by the OS?
- The host is likely a Windows machine.
- The host is likely a Linux machine.
- The host is likely a router.
- The host is likely a printer.
Answer: D
Q611 - Which results will be returned with the following Google search query?site:target.com -site:Marketing.target.com accounting
- Results matching all words in the query
- Results matching "accounting" in domain target.com but not on the site Marketing.target.com
- Results from matches on the site marketing.target.com that are in the domain target.com but do not include the word accounting
- Results for matches on target.com and Marketing.target.com that include the word "accounting"
Answer: B
Q612 - What is the most common method to exploit the "Bash Bug" or "ShellShock" vulnerability?
- Through Web servers utilizing CGI (Common Gateway Interface) to send a malformed environment variable to a vulnerable Web server
- Manipulate format strings in text fields
- SSH
- SYN Flood
Answer: A
Q613 - It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of the following terms best matches the definition?
- Threat
- Attack
- Vulnerability
- Risk
Answer: A
Q614 - Which of the following cryptography attack methods is usually performed without the useof a computer?
- Ciphertext-only attack
- Chosen key attack
- Rubber hose attack
- Rainbow table attack
Answer: C
Q615 - Which statement best describes a server type under an N-tier architecture?
- A group of servers at a specific layer
- A single server with a specific role
- A group of servers with a unique role
- A single server at a specific layer
Answer: C
Q616 - When utilizing technical assessment methods to assess the security posture of a network, which of the following techniques would be most effective in determining whether end-user security training would be beneficial?
- Vulnerability scanning
- Social engineering
- Application security testing
- Network sniffing
Answer: B
Q617 - Which statement is TRUE regarding network firewalls preventing Web Application attacks?
- Network firewalls can prevent attacks because they can detect malicious HTTP traffic.
- Network firewalls cannot prevent attacks because ports 80 and 443 must be opened.
- Network firewalls can prevent attacks if they are properly configured.
- Network firewalls cannot prevent attacks because they are too complex to configure.
Answer: B
Q618 - You work as a Security Analyst for a retail organization. In securing the company's network, you set up a firewall and an IDS. However, hackers are able to attack the network. After investigating, you discover that your IDS is not configured properly and therefore is unable to trigger alarms when needed. What type of alert is the IDS giving?
- False Negative
- False Positive
- True Negative
- True Positive
Answer: A
Q619 - The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, and DNS servers. What should the security team do to determine which alerts to check first?
- Investigate based on the maintenance schedule of the affected systems.
- Investigate based on the service level agreements of the systems.
- Investigate based on the potential effect of the incident.
- Investigate based on the order that the alerts arrived in.
Answer: C
Q620 - What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?
- Passive
- Reflective
- Active
- Distributive
Answer: C
Q621 - During a penetration test, a tester finds a target that is running MS SQL 2000 with default credentials. The tester assumes that the service is running with Local System account. How can this weakness be exploited to access the system?
- Using the Metasploit psexec module setting the SA / Admin credential
- Invoking the stored procedure xp_shell to spawn a Windows command shell
- Invoking the stored procedure cmd_shell to spawn a Windows command shell
- Invoking the stored procedure xp_cmdshell to spawn a Windows command shell
Answer: D
Q622 - What is the primary drawback to using advanced encryption standard (AES) algorithm with a 256 bit key to share sensitive data?
- Due to the key size, the time it will take to encrypt and decrypt the message hinders efficient communication.
- To get messaging programs to function with this algorithm requires complex configurations.
- It has been proven to be a weak cipher; therefore, should not be trusted to protect sensitive data.
- It is a symmetric key algorithm, meaning each recipient must receive the key through a different channel than the message.
Answer: D
Q623 - Nathan is testing some of his network devices. Nathan is using Macof to try and flood theARP cache of these switches.If these switches' ARP cache is successfully flooded, what will be the result?
- The switches will drop into hub mode if the ARP cache is successfully flooded.
- If the ARP cache is flooded, the switches will drop into pix mode making it less susceptible to attacks.
- Depending on the switch manufacturer, the device will either delete every entry in its ARP cache or reroute packets to the nearest switch.
- The switches will route all traffic to the broadcast address created collisions.
Answer: A
Q624 - This is an attack that takes advantage of a web site vulnerability in which the site displays content that includes un-sanitized user-provided data.
What is this attack?
- Cross-site-scripting attack
- SQL Injection
- URL Traversal attack
- Buffer Overflow attack
Answer: A
Q625 - When setting up a wireless network, an administrator enters a pre-shared key for security. Which of the following is true?
- The key entered is a symmetric key used to encrypt the wireless data.
- The key entered is a hash that is used to prove the integrity of the wireless data.
- The key entered is based on the Diffie-Hellman method.
- The key is an RSA key used to encrypt the wireless data
Answer: A
Q626 - For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using a digital signature, the message digest is encrypted with which key?
- Sender's public key
- Receiver's private key
- Receiver's public key
- Sender's private key
Answer: D
Q627 - One advantage of an application-level firewall is the ability to
- filter packets at the network level.
- filter specific commands, such as http:post.
- retain state information for each packet.
- monitor tcp handshaking.
Answer: B
Q628 - Jesse receives an email with an attachment labeled "Court_Notice_21206.zip". Inside the zipfile is a file named "Court_Notice_21206.docx.exe" disguised as a word document. Upon execution, awindow appears stating, "This word document is corrupt." In the background, the file copies itself to Jesse APPDATA\local directory and begins to beacon to a C2 server to download additional malicious binaries.What type of malware has Jesse encountered?
- Trojan
- Worm
- Macro Virus
- Key-Logger
Answer: A
Q629 - Rebecca commonly sees an error on her Windows system that states that a Data Execution Prevention (DEP) error has taken place. Which of the following is most likely taking place?
- A race condition is being exploited, and the operating system is containing the malicious process.
- A page fault is occurring, which forces the operating system to write data from the hard drive.
- Malware is executing in either ROM or a cache memory area.
- Malicious code is attempting to execute instruction in a non-executable memory region.
Answer: D
Q630 - Insecure direct object reference is a type of vulnerability where the application does notverify if the user is authorized to access the internal object via its name or key. Suppose a malicious user Rob tries to get access to the account of a benign user Ned. Which of the following requests best illustrates an attempt to exploit an insecure direct object reference vulnerability?
- "GET/restricted/goldtransfer?to=Rob&from=1 or 1=1' HTTP/1.1Host: westbank.com"
- "GET/restricted/accounts/?name=Ned HTTP/1.1 Host: westbank.com"
- "GET/restricted/bank.getaccount('Ned') HTTP/1.1 Host: westbank.com"
- "GET/restricted/\r\n\%00account%00Ned%00access HTTP/1.1 Host: westbank.com"
Answer: B