CPEH-001 Exam Questions
1,043 real CPEH-001 exam questions with expert-verified answers and explanations. Page 11 of 21.
- Question #504
First thing you do every office day is to check your email inbox. One morning, you received an email from your best friend and the subject line is quite strange. What should you do...
- Question #505
Defining rules, collaborating human workforce, creating a backup plan, and testing the plans are within what phase of the Incident Handling Process?
- Question #506
Which of the following BEST describes how Address Resolution Protocol (ARP) works?
- Question #507
Which of the following is a form of penetration testing that relies heavily on human interaction and often involves tricking people into breaking normal security procedures?
- Question #508
What tool and process are you going to use in order to remain undetected by an IDS while pivoting and passing traffic over a server you've compromised and gained root access to?
- Question #509
You've just gained root access to a Centos 6 server after days of trying. What tool should you use to maintain access?
- Question #510
What type of malware is it that restricts access to a computer system that it infects and demands that the user pay a certain amount of money, cryptocurrency, etc. to the operators...
- Question #511
The following are types of Bluetooth attack EXCEPT_____?
- Question #512
Which of the following is the BEST approach to prevent Cross-site Scripting (XSS) flaws?
- Question #513
A possibly malicious sequence of packets that were sent to a web server has been captured by an Intrusion Detection System (IDS) and was saved to a PCAP file. As a network administ...
- Question #514
Which of the following is the BEST way to protect Personally Identifiable Information (PII) from being exploited due to vulnerabilities of varying web applications?
- Question #515
This configuration allows NIC to pass all traffic it receives to the Central Processing Unit (CPU), instead of passing only the frames that the controller is intended to receive. S...
- Question #516
Which of the following is designed to verify and authenticate individuals taking part in a data exchange within an enterprise?
- Question #517
A software tester is randomly generating invalid inputs in an attempt to crash the program. Which of the following is a software testing technique used to determine if a software p...
- Question #518
What would you type on the Windows command line in order to launch the Computer Management Console provided that you are logged in as an admin?
- Question #519
Which of the following is a wireless network detector that is commonly found on Linux?
- Question #520
Which specific element of security testing is being assured by using hash?
- Question #521
Which of the following is a restriction being enforced in "white box testing?"
- Question #522
Which of the following is a vulnerability in GNU's bash shell (discovered in September of 2014) that gives attackers access to run remote commands on a vulnerable system?
- Question #523
When security and confidentiality of data within the same LAN is of utmost priority, which IPSec mode should you implement?
- Question #524
Jack was attempting to fingerprint all machines in the network using the following Nmap syntax: invictus@victim_server:~$ nmap -T4 -0 10.10.0.0/24 TCP/IP fingerprinting (for OS sca...
- Question #525
While performing online banking using a Web browser, Kyle receives an email that contains an image of a well-crafted art. Upon clicking the image, a new tab on the web browser open...
- Question #526
A hacker was able to easily gain access to a website. He was able to log in via the frontend user login form of the website using default or commonly used credentials. This exploit...
- Question #527
Supposed you are the Chief Network Engineer of a certain Telco. Your company is planning for a big business expansion and it requires that your network authenticate users connectin...
- Question #528
Which type of cryptography does SSL, IKE and PGP belongs to?
- Question #529
A recent security audit revealed that there were indeed several occasions that the company's network was breached. After investigating, you discover that your IDS is not configured...
- Question #530
Which of the following is a hardware requirement that either an IDS/IPS system or a proxy server must have in order to properly function?
- Question #531
Which of the following is an application that requires a host application for replication?
- Question #532
Which of the following can the administrator do to verify that a tape backup can be recovered in its entirety?
- Question #533
Which of the following describes the characteristics of a Boot Sector Virus?
- Question #534
Which statement is TRUE regarding network firewalls preventing Web Application attacks?
- Question #535
Bluetooth uses which digital modulation technique to exchange information between paired devices?
- Question #536
In order to show improvement of security over time, what must be developed?
- Question #537
Passive reconnaissance involves collecting information through which of the following?
- Question #538
The following is a sample of output from a penetration tester's machine targeting a machine with the IP address of 192.168.1.106: What is most likely taking place?
- Question #539
Which statement best describes a server type under an N-tier architecture?
- Question #540
If an e-commerce site was put into a live environment and the programmers failed to remove the secret entry point that was used during the application development, what is this sec...
- Question #541
Which of the following network attacks relies on sending an abnormally large packet size that exceeds TCP/ IP specifications?
- Question #542
Which NMAP feature can a tester implement or adjust while scanning for open ports to avoid detection by the network's IDS?
- Question #543
When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is
- Question #544
Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?
- Question #545
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
- Question #546
Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest?
- Question #547
Which cipher encrypts the plain text digit (bit or byte) one by one?
- Question #548
Which of the following types of firewall inspects only header information in network traffic?
- Question #549
During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Based on this res...
- Question #550
Firewalk has just completed the second phase (the scanning phase) and a technician receives the output shown below. What conclusions can be drawn based on these scan results? TCP p...
- Question #551
Which of the following is an example of an asymmetric encryption implementation?
- Question #552
A hacker was able to sniff packets on a company's wireless network. The following information was discovered: The Key 10110010 01001011 The Cyphertext 01100101 01011010 Using the E...
- Question #553
Which of the following cryptography attack methods is usually performed without the use of a computer?