CPEH-001 Exam Questions
1,043 real CPEH-001 exam questions with expert-verified answers and explanations. Page 2 of 21.
- Question #51
An attacker, using a rogue wireless AP, performed an MITM attack and injected an HTML code to embed a malicious applet in all HTTP connections. When users accessed any page, the ap...
- Question #52
You are monitoring the network of your organizations. You notice that: There are huge outbound connections from your Internal Network to External IPs On further investigation, you...
- Question #53
Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like Computer Securit...
- Question #54
Which of the following antennas is commonly used in communications for a frequency band of 10 MHz to VHF and UHF?
- Question #55
Why should the security analyst disable/remove unnecessary ISAPI filters?
- Question #56
Which of the following security policies defines the use of VPN for gaining access to an internal corporate network?
- Question #57
To determine if a software program properly handles a wide range of invalid input, a form of automated testing can be used to randomly generate invalid input in an attempt to crash...
- Question #58
If you want only to scan fewer ports than the default scan using Nmap tool, which option would you use?
- Question #59
In Risk Management, how is the term "likelihood" related to the concept of "threat?"
- Question #60
Which of the following statements is TRUE?
- Question #61
What is the least important information when you analyze a public IP address in a security alert?
- Question #62
You are the Network Admin, and you get a compliant that some of the websites are no longer accessible. You try to ping the servers and find them to be reachable. Then you type the...
- Question #63
Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides different functionality. Collective IPSec does everything except.
- Question #64
On performing a risk assessment, you need to determine the potential impacts when some of the critical business process of the company interrupt its service. What is the name of th...
- Question #65
Assume a business-crucial web-site of some company that is used to sell handsets to the customers worldwide. All the developed components are reviewed by the security team on a mon...
- Question #67
Bob finished a C programming course and created a small C application to monitor the network traffic and produce alerts when any origin sends "many" IP packets, based on the averag...
- Question #68
Which of the following is a low-tech way of gaining unauthorized access to systems?
- Question #69
When tuning security alerts, what is the best approach?
- Question #70
In an internal security audit, the white hat hacker gains control over a user account and attempts to acquire access to another account's confidential files and information. How ca...
- Question #71
Which regulation defines security and privacy controls for Federal information systems and organizations?
- Question #72
Your company performs penetration tests and security assessments for small and medium-sized business in the local area. During a routine security assessment, you discover informati...
- Question #73
You are a security officer of a company. You had an alert from IDS that indicates that one PC on your Intranet is connected to a blacklisted IP address (C2 Server) on the Internet....
- Question #74
Identify the UDP port that Network Time Protocol (NTP) uses as its primary means of communication?
- Question #75
It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse...
- Question #76
Which of the following cryptography attack is an understatement for the extraction of cryptographic secrets (e.g. the password to an encrypted file) from a person by a coercion or...
- Question #77
In cryptanalysis and computer security, 'pass the hash' is a hacking technique that allows an attacker to authenticate to a remote server/service by using the underlying NTLM and/o...
- Question #78
You are looking for SQL injection vulnerability by sending a special character to web applications. Which of the following is the most useful for quick validation?
- Question #79
A virus that attempts to install itself inside the file it is infecting is called?
- Question #82
While examining audit logs, you discover that people are able to telnet into the SMTP server on port 25. You would like to block this, though you do not see any evidence of an atta...
- Question #83
Windows LAN Manager (LM) hashes are known to be weak. Which of the following are known weaknesses of LM? (Choose three)
- Question #84
Fingerprinting an Operating System helps a cracker because:
- Question #85
In the context of Windows Security, what is a 'null' user?
- Question #86
What does the following command in netcat do? nc -l -u -p55555 < /etc/passwd
- Question #87
What hacking attack is challenge/response authentication used to prevent?
- Question #88
In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then sca...
- Question #89
Bob is going to perform an active session hijack against Brownies Inc. He has found a target that allows session oriented connections (Telnet) and performs the sequence prediction...
- Question #90
This TCP flag instructs the sending system to transmit all buffered data immediately.
- Question #91
The network administrator at Spears Technology, Inc has configured the default gateway Cisco router's access-list as below: You are hired to conduct security testing on their netwo...
- Question #92
You work for Acme Corporation as Sales Manager. The company has tight network security restrictions. You are trying to steal data from the company's Sales database (Sales.xls) and...
- Question #93
Study the snort rule given below and interpret the rule. alert tcp any any --> 192.168.1.0/24 111 (content:"|00 01 86 a5|"; msG. "mountd access";)
- Question #94
What port number is used by LDAP protocol?
- Question #95
Fred is the network administrator for his company. Fred is testing an internal switch. From an external IP address, Fred wants to try and trick this switch into thinking it already...
- Question #96
Within the context of Computer Security, which of the following statements describes Social Engineering best?
- Question #97
What is a NULL scan?
- Question #98
What is the proper response for a NULL scan if the port is open?
- Question #99
Which of the following statements about a zone transfer correct? (Choose three.)
- Question #100
An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of breach has the individual just performed?
- Question #101
Which of the following is the best countermeasure to encrypting ransomwares?
- Question #102
If an attacker uses the command SELECT*FROM user WHERE name = `x' AND userid IS NULL; --`; which type of SQL injection attack is the attacker performing?
- Question #103
Sophia travels a lot and worries that her laptop containing confidential documents might be stolen. What is the best protection that will work for her?