CPEH-001 Exam Questions
1,043 real CPEH-001 exam questions with expert-verified answers and explanations. Page 12 of 21.
- Question #554
Which of the following is a strong post designed to stop a car?
- Question #555
A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID car...
- Question #556
A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, r...
- Question #557
An NMAP scan of a server shows port 69 is open. What risk could this pose?
- Question #558
What information should an IT system analysis provide to the risk assessor?
- Question #559
Which of the following is a preventive control?
- Question #560Introduction to Ethical Hacking and Information Security
An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet...
protocol analyzerIDSPCAPpacket analysis - Question #561Web Server and Web Application Hacking
An attacker gains access to a Web server's database and displays the contents of the table that holds all of the names, passwords, and other user information. The attacker did this...
input validationSQL injectionweb application securitydatabase attack - Question #562Introduction to Ethical Hacking and Information Security
Which of the following is a protocol specifically designed for transporting event messages?
SYSLOGevent loggingnetwork protocolslog management - Question #563Footprinting and Reconnaissance
Which of the following security operations is used for determining the attack surface of an organization?
attack surfacenetwork scanningDMZreconnaissance - Question #564Introduction to Ethical Hacking and Information Security
The security concept of "separation of duties" is most similar to the operation of which type of security device?
separation of dutiesfirewallsecurity conceptsaccess control - Question #565Introduction to Ethical Hacking and Information Security
The "black box testing" methodology enforces which kind of restriction?
black box testingpenetration testing methodologytesting types - Question #566Introduction to Ethical Hacking and Information Security
The "gray box testing" methodology enforces what kind of restriction?
gray box testingpenetration testing methodologytesting types - Question #567
Which of the following lists are valid data-gathering activities associated with a risk assessment?
- Question #568
A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior...
- Question #569
Which of the following is a detective control?
- Question #570
Which of the following is a component of a risk assessment?
- Question #571Introduction to Ethical Hacking and Information Security
Risks = Threats x Vulnerabilities is referred to as the:
risk equationrisk managementthreatvulnerability - Question #572Introduction to Ethical Hacking and Information Security
Which of the following is designed to identify malicious attempts to penetrate systems?
IDSintrusion detectionnetwork securitymalicious detection - Question #573Web Server and Web Application Hacking
Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?
Niktoweb server scanningCGI testingvulnerability scanner - Question #574Sniffing and Session Hijacking
Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?
tcptracepacket capture analysistcpdumpWireshark - Question #575Wireless Network Hacking
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?
Kismetwireless detection802.11WLAN scanning - Question #576
Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?
- Question #577
While conducting a penetration test, the tester determines that there is a firewall between the tester's machine and the target machine. The firewall is only monitoring TCP handsha...
- Question #578
A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set: Untrust (Inter...
- Question #579
A circuit level gateway works at which of the following layers of the OSI Model?
- Question #580
Which of the following is a symmetric cryptographic standard?
- Question #581
Which property ensures that a hash function will not produce the same hashed value for two different messages?
- Question #582
How can telnet be used to fingerprint a web server?
- Question #583
Low humidity in a data center can cause which of the following problems?
- Question #584
A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company`s building dressed lik...
- Question #585
While performing data validation of web content, a security technician is required to restrict malicious input. Which of the following processes is an efficient way of restricting...
- Question #586
A covert channel is a channel that
- Question #587
Least privilege is a security concept that requires that a user is
- Question #588
If the final set of security controls does not eliminate all risk in a system, what could be done next?
- Question #589
What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on?
- Question #590
Which of the following examples best represents a logical or technical control?
- Question #591Introduction to Ethical Hacking and Information Security
It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of t...
threat definitionsecurity terminologyrisk managementinformation security - Question #592Web Server and Web Application Hacking
Initiating an attack against targeted businesses and organizations, threat actors compromise a carefully selected website by inserting an exploit resulting in malware infection. Th...
watering hole attackzero-day exploittargeted attackdrive-by download - Question #593Enumeration and Vulnerability Analysis
You have successfully gained access to your client's internal network and successfully comprised a Linux server which is part of the internal IP network. You want to know which Mic...
port 445SMBWindows file sharingenumeration - Question #594Wireless Network Hacking
It is a short-range wireless communication technology intended to replace the cables connecting portable of fixed devices while maintaining high levels of security. It allows mobil...
Bluetoothshort-range wirelesswireless communicationcable replacement - Question #595System Hacking and Malware
You have compromised a server and successfully gained a root access. You want to pivot and pass traffic undetected over the network and evade any possible Intrusion Detection Syste...
CryptcatIDS evasionpivotingencrypted tunneling - Question #596System Hacking and Malware
It is a kind of malware (malicious software) that criminals install on your computer so they can lock it from a remote location. This malware generates a pop-up window, webpage, or...
ransomwaremalwareextortionmalicious software - Question #597Scanning Networks
Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection?
NmapTCP scanICMP bypassOS fingerprinting - Question #598
While checking the settings on the internet browser, a technician finds that the proxy server settings have been checked and a computer is trying to use itself as a proxy server. W...
- Question #599
A company has five different subnets: 192.168.1.0, 192.168.2.0, 192.168.3.0, 192.168.4.0 and 192.168.5.0. How can NMAP be used to scan these adjacent Class C networks?
- Question #600
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the test...
- Question #601
A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use?
- Question #602
ICMP ping and ping sweeps are used to check for active systems and to check
- Question #603
Which command line switch would be used in NMAP to perform operating system detection?