CPEH-001 Exam Questions
1,043 real CPEH-001 exam questions with expert-verified answers and explanations. Page 8 of 21.
- Question #354
Which of the following is optimized for confidential communications, such as bidirectional voice and video?
- Question #355
Advanced encryption standard is an algorithm used for which of the following?
- Question #356
The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses which of the following?
- Question #357
An attacker sniffs encrypted traffic from the network and is subsequently able to decrypt it. The attacker can now use which cryptanalytic technique to attempt to discover the encr...
- Question #358
What is the primary drawback to using advanced encryption standard (AES) algorithm with a 256 bit key to share sensitive data?
- Question #359
A Certificate Authority (CA) generates a key pair that will be used for encryption and decryption of email. The integrity of the encrypted email is dependent on the security of whi...
- Question #360
When setting up a wireless network, an administrator enters a pre-shared key for security. Which of the following is true?
- Question #361
An attacker has captured a target file that is encrypted with public key cryptography. Which of the attacks below is likely to be used to crack the target file?
- Question #362
Which of the following processes of PKI (Public Key Infrastructure) ensures that a trust relationship exists and that a certificate is still valid for specific operations?
- Question #363
Which of the following describes a component of Public Key Infrastructure (PKI) where a copy of a private key is stored to provide third-party access and to facilitate recovery ope...
- Question #364
To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settin...
- Question #365
Which of the following is a common Service Oriented Architecture (SOA) vulnerability?
- Question #366
The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, an...
- Question #367
An IT security engineer notices that the company's web server is currently being hacked. What should the engineer do next?
- Question #368
Which of the following is a primary service of the U.S. Computer Security Incident Response Team (CSIRT)?
- Question #369
Which of the following items is unique to the N-tier architecture method of designing software applications?
- Question #370
Which of the following descriptions is true about a static NAT?
- Question #371
Which of the following network attacks takes advantage of weaknesses in the fragment reassembly functionality of the TCP/IP protocol stack?
- Question #372
Employees in a company are no longer able to access Internet web sites on their computers. The network administrator is able to successfully ping IP address of web servers on the I...
- Question #373
While testing the company's web applications, a tester attempts to insert the following test script into the search area on the company's web site: <script>alert(" Testing Testing...
- Question #374
Which of the following is an advantage of utilizing security testing methodologies to conduct a security audit?
- Question #375
The Open Web Application Security Project (OWASP) testing methodology addresses the need to secure web applications by providing which one of the following services?
- Question #376
In the OSI model, where does PPTP encryption take place?
- Question #377
Which of the following is an example of IP spoofing?
- Question #378
For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using...
- Question #379
Some passwords are stored using specialized encryption algorithms known as hashes. Why is this an appropriate method?
- Question #380
Company A and Company B have just merged and each has its own Public Key Infrastructure (PKI). What must the Certificate Authorities (CAs) establish so that the private PKIs for Co...
- Question #381
Which of the following defines the role of a root Certificate Authority (CA) in a Public Key Infrastructure (PKI)?
- Question #382
A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate web site from their workstations. Which of the following is the...
- Question #383
Which of the following levels of algorithms does Public Key Infrastructure (PKI) use?
- Question #384
Which of the following is a characteristic of Public Key Infrastructure (PKI)?
- Question #385
Which security strategy requires using several, varying methods to protect IT systems against attacks?
- Question #386
SOAP services use which technology to format information?
- Question #387
Which of the following can take an arbitrary length of input and produce a message digest output of 160 bit?
- Question #388
Which element of Public Key Infrastructure (PKI) verifies the applicant?
- Question #389
Which vital role does the U.S. Computer Security Incident Response Team (CSIRT) provide?
- Question #390
How do employers protect assets with security policies pertaining to employee surveillance activities?
- Question #391
Which of the following ensures that updates to policies, procedures, and configurations are made in a controlled and documented fashion?
- Question #392
Which of the following tools would be the best choice for achieving compliance with PCI Requirement 11?
- Question #393
Which United States legislation mandates that the Chief Executive Officer (CEO) and the Chief Financial Officer (CFO) must sign statements verifying the completeness and accuracy o...
- Question #394
How can a policy help improve an employee's security awareness?
- Question #395
Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design,...
- Question #396
Which of the following guidelines or standards is associated with the credit card industry?
- Question #397
International Organization for Standardization (ISO) standard 27002 provides guidance for compliance by outlining
- Question #398
Which type of security document is written with specific step-by-step details?
- Question #399
An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker...
- Question #400
A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from f...
- Question #401
Which initial procedure should an ethical hacker perform after being brought into an organization?
- Question #402
A consultant has been hired by the V.P. of a large financial organization to assess the company's security posture. During the security testing, the consultant comes across child p...
- Question #403
A computer technician is using a new version of a word processing software package when it is discovered that a special sequence of characters causes the entire computer to crash....