Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Certified Ethical Hacker Exam (CEHv13) Question and Answers

Certified Ethical Hacker Exam (CEHv13)

Last Update Jul 26, 2026
Total Questions : 797

We are offering FREE 312-50v13 ECCouncil exam questions. All you do is to just go and sign up. Give your details, prepare 312-50v13 free exam questions and then go for complete pool of Certified Ethical Hacker Exam (CEHv13) test questions that will help you more.

312-50v13 pdf

312-50v13 PDF

$36.75  $104.99
312-50v13 Engine

312-50v13 Testing Engine

$43.75  $124.99
312-50v13 PDF + Engine

312-50v13 PDF + Testing Engine

$57.75  $164.99
Questions 1

A regional law firm authorizes a wireless resilience evaluation after employees report intermittent connectivity disruptions in conference rooms. An ethical hacker assigned to the assessment analyses client behaviour while transmitting carefully crafted 802.11 management frames toward the organization ' s primary access point. Each transmission immediately causes several connected laptops to lose association with the network, requiring users to reconnect manually. Connectivity interruptions occur only when the crafted frames are sent. Identify the wireless attack illustrated by this activity.

Options:

A.  

Eavesdropping Attack

B.  

Jamming Attack

C.  

Evil Twin Attack

D.  

Deauthentication Attack

Discussion 0
Questions 2

Bob received this text message on his mobile phone: “Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: scottsmelby@yahoo.com”. Which statement below is true?

Options:

A.  

This is a scam because Bob does not know Scott.

B.  

This is probably a legitimate message as it comes from a respectable organization.

C.  

Bob should write to scottsmelby@yahoo.com to verify the identity of Scott.

D.  

This is a scam as everybody can get a @yahoo address, not the Yahoo customer service employees.

Discussion 0
Questions 3

Which indicator most strongly confirms a MAC flooding attack?

Options:

A.  

Multiple IPs to one MAC

B.  

Multiple MACs to one IP

C.  

Numerous MAC addresses on a single switch port

D.  

Increased ARP requests

Discussion 0
Questions 4

During a security assessment of a metropolitan public transportation terminal, a penetration tester examines a network-connected IoT surveillance camera system used for 24/7 video monitoring. The camera uses outdated SSLv2 encryption to transmit video data. The tester intercepts and decrypts video streams due to the weak encryption and absence of authentication mechanisms. What IoT vulnerability is most likely being exploited in this scenario?

Options:

A.  

Insecure data transfer and storage

B.  

Jamming attack on RF communication

C.  

Credential theft via web application

D.  

Replay attack on wireless signals

Discussion 0
Questions 5

What is a “Collision attack” in cryptography?

Options:

A.  

Collision attacks try to find two inputs producing the same hash

B.  

Collision attacks try to get the public key

C.  

Collision attacks try to break the hash into three parts to get the plaintext value

D.  

Collision attacks try to break the hash into two parts, with the same bytes in each part to get the private key

Discussion 0
Questions 6

During a cryptographic audit of a legacy system, a security analyst observes that an outdated block cipher is leaking key-related information when analyzing large sets of plaintext–ciphertext pairs. What approach might an attacker exploit here?

Options:

A.  

Launch a key replay through IV duplication

B.  

Use linear approximations to infer secret bits

C.  

Modify the padding to obtain plaintext

D.  

Attack the hash algorithm for collisions

Discussion 0
Questions 7

During a red team exercise for a global insurance provider in Chicago, ethical hacker Maria tests the effectiveness of the company ' s endpoint defenses. She launches an attack by injecting malicious PowerShell commands into a trusted process without dropping any executables to disk. The code executes entirely in memory, generating abnormal spikes in resource usage. After a reboot, Maria notes that the system returns to normal and traditional antivirus logs show no evidence of infection.

Which type of malware technique did Maria most likely use in this test?

Options:

A.  

Rootkit

B.  

Trojan

C.  

Fileless Malware

D.  

Ransomware

Discussion 0
Questions 8

A university authorizes a wireless protocol resilience assessment on its WPA2-secured network. An ethical hacker positions a testing device within range of an access point and observes the key negotiation exchange between the client and the access point.

By selectively retransmitting a previously captured handshake message at a precise moment in the exchange, the tester causes the client device to reinstall an already negotiated encryption key. Subsequent traffic patterns reveal that certain protections expected from unique session parameters are no longer consistently enforced.

What kind of wireless attack technique is being illustrated in this scenario?

Options:

A.  

Key Reinstallation Attack (KRACK)

B.  

Replay Attack

C.  

Man-in-the-Middle Attack

D.  

WPA2 PSK Offline Cracking

Discussion 0
Questions 9

A cybersecurity consultant suspects attackers are attempting to evade an Intrusion Detection System (IDS). Which technique is most likely being used?

Options:

A.  

Deploying self-replicating malware

B.  

Fragmenting malicious packets into smaller segments

C.  

Flooding the IDS with ICMP packets

D.  

Sending phishing emails

Discussion 0
Questions 10

At a smart retail outlet in San Diego, California, ethical hacker Sophia Bennett assesses IoT-based inventory sensors that synchronize with a cloud dashboard. She discovers that sensitive business records are sent across the network without encryption and are also stored in a retrievable format on the provider ' s cloud platform.

Which IoT attack surface area is most directly demonstrated in this finding?

Options:

A.  

Insecure ecosystem interfaces

B.  

Insecure data transfer and storage

C.  

Insecure network services

D.  

Insecure default settings

Discussion 0
Questions 11

A financial institution in San Francisco suffers a breach where attackers install malware that captures customer account credentials. The stolen data is then sold on underground forums for profit. No political or social statements are made, and the attackers remain anonymous while continuing to target similar organizations for financial gain. Based on this activity, what category of hacker is most likely responsible?

Options:

A.  

Black Hat hackers

B.  

Hacktivists

C.  

Script Kiddies

D.  

White Hat hackers

Discussion 0
Questions 12

“ShadowFlee” is fileless malware using PowerShell and legitimate tools. Which strategy offers the most focused countermeasure?

Options:

A.  

Restrict and monitor script and system tool execution

B.  

Isolate systems and inspect traffic

C.  

Schedule frequent reboots

D.  

Clean temporary folders

Discussion 0
Questions 13

A healthcare analytics firm in Denver, Colorado hosts several internal applications on an IIS web server. During an authorized security assessment, a tester evaluates a lesser-used endpoint designed for administrative operations. By sending crafted HTTP requests directly to this endpoint, the tester is able to invoke server-side management functions without interacting with the standard login workflow presented by the primary user interface.

Further review indicates that certain restricted operations can be executed when accessed through alternate request paths, suggesting inconsistent enforcement of access controls within the application.

Which IIS vulnerability is most accurately demonstrated in this scenario?

Options:

A.  

File and Directory Permissions Vulnerability

B.  

CRLF Cross-Site Scripting Vulnerability

C.  

Trust Boundary Violation Vulnerability

D.  

Authentication Bypass Vulnerability

Discussion 0
Questions 14

While simulating a reconnaissance phase against a cloud-hosted retail application, your team attempts to gather DNS records to map the infrastructure. You avoid brute-forcing subdomains and instead aim to collect specific details such as the domain’s mail server, authoritative name servers, and potential administrative information like serial number and refresh interval.

Given these goals, which DNS record type should you query to extract both administrative and technical metadata about the target zone?

Options:

A.  

MX

B.  

SOA

C.  

TXT

D.  

NS

Discussion 0
Questions 15

A penetration tester is conducting a security assessment for a client and needs to capture sensitive information transmitted across multiple VLANs without being detected by the organization ' s security monitoring systems. The network employs strict VLAN segmentation and port security measures. Which advanced sniffing technique should the tester use to discreetly intercept and analyze traffic across all VLANs?

Options:

A.  

Deploy a rogue DHCP server to redirect network traffic

B.  

Exploit a VLAN hopping vulnerability to access multiple VLANs

C.  

Implement switch port mirroring on all VLANs

D.  

Use ARP poisoning to perform a man-in-the-middle attack

Discussion 0
Questions 16

At a biomedical analytics firm in Raleigh, North Carolina, security consultant Marcus Ellison was reviewing exposed services on a legacy Linux host located in a screened subnet. While mapping available services, he observed that the machine was responding to time synchronization queries from multiple internal systems.

Curious whether the service might reveal additional intelligence, Marcus issued targeted queries against the time service and received responses that exposed internal client addresses and system identifiers interacting with it. The information provided unexpected visibility into internal network structure without requiring authentication.

From the available options, what enumeration technique is illustrated in this scenario?

Options:

A.  

NFS Enumeration

B.  

NetBIOS Enumeration

C.  

SNMP Enumeration

D.  

NTP Enumeration

Discussion 0
Questions 17

You are Evelyn, an ethical hacker at LoneStar Health in Austin, Texas, engaged to investigate a recent compromise of archived patient records. During the investigation you recover a large set of encrypted records from a compromised backup and, separately, obtain several original template records (standard headers and form fields) that correspond to some entries in the encrypted set. You plan to use these paired examples (the original templates and their encrypted counterparts) to attempt to recover keys or deduce other plaintext values. Which cryptanalytic approach is most appropriate for this situation?

Options:

A.  

Chosen-ciphertext attack

B.  

Known-plaintext attack

C.  

Chosen-plaintext attack

D.  

Ciphertext-only attack

Discussion 0
Questions 18

After a breach, investigators discover attackers used modified legitimate system utilities and a Windows service to persist undetected and harvest credentials. What key step would best protect against similar future attacks?

Options:

A.  

Disable unused ports and restrict outbound firewall traffic

B.  

Perform weekly backups and store them off-site

C.  

Ensure antivirus and firewall software are up to date

D.  

Monitor file hashes of critical executables for unauthorized changes

Discussion 0
Questions 19

During a penetration testing engagement at First Union Bank in Chicago, ethical hacker Rachel Morgan is assigned to assess the internal network for potential sniffing activity that could compromise sensitive customer data. While inspecting traffic in the loan processing department, Rachel observes that a workstation is receiving packets not addressed to it, raising suspicion of a sniffing tool operating in promiscuous mode. To validate her hypothesis, she prepares to conduct an active verification using a classic detection approach.

Which detection technique should Rachel use to confirm the presence of a sniffer in this case?

Options:

A.  

Sniffer detection using an NSE script to check for promiscuous mode

B.  

DNS method by monitoring reverse DNS lookup traffic

C.  

ARP method by sending non-broadcast ARP requests

D.  

Ping method by sending packets with an incorrect MAC address

Discussion 0
Questions 20

What is CVSS used for?

Options:

A.  

Auditing

B.  

Encryption

C.  

Severity scoring

D.  

Exploitation

Discussion 0
Questions 21

You are conducting a security audit at a government agency. During your walkthrough, you observe a temporary contractor sitting in the staff lounge using their smartphone to discretely record employees as they enter passwords into their systems. Upon further investigation, you find discarded documents in a nearby trash bin containing sensitive project information. What type of attack is most likely being performed?

Options:

A.  

Cisco-in attack

B.  

Insider attack

C.  

Distribution attack

D.  

Passive attack

Discussion 0
Questions 22

A smart building management company in Seattle, Washington deploys wireless door sensors and badge-based access systems throughout its corporate headquarters. During a security assessment, an analyst captures legitimate radio transmissions between employee access badges and the entry control units.

Later that evening, without modifying or decrypting the original communication, the analyst retransmits the previously captured signal toward a secured entrance. The access control system accepts the transmission as valid and unlocks the door, even though the legitimate badge is not present.

Determine the attack technique demonstrated in this assessment.

Options:

A.  

BlueBorne Attack

B.  

Replay Attack

C.  

Rolling Code Attack

D.  

Sybil Attack

Discussion 0
Questions 23

A mid-sized insurance provider in Hartford, Connecticut authorizes a controlled red team engagement to evaluate its public-facing customer portal. Before progressing to active exploitation, the assessment team concentrates on understanding how the site is organized and how its content is interconnected.

Using automated tooling, they systematically retrieve publicly accessible pages along with associated resources such as scripts, media files, and referenced directories. The collected material allows the team to analyze navigation paths, hidden references, and structural relationships without repeatedly interacting with the live production system.

This preparatory effort is intended to build a detailed structural understanding of the application before later testing phases begin.

Within the web server attack methodology, which stage is most accurately demonstrated in this scenario?

Options:

A.  

Website Mirroring

B.  

Information Gathering

C.  

Web Server Footprinting

D.  

Vulnerability Scanning

Discussion 0
Questions 24

In an ethical hacking methodology and framework, which of the following step is known for “active and passive information gathering”?

Options:

A.  

Obfuscation

B.  

Exploitation

C.  

Reconnaissance

D.  

Denial of service

Discussion 0
Questions 25

During a UDP service enumeration scan, the tester sees that some ports respond with ICMP Type 3 Code 3 (Port Unreachable), while most remain silent. No firewall or IDS is interfering. What can the tester conclude about the non-responsive ports?

Options:

A.  

The ports are likely closed because no ICMP response was received.

B.  

The system blocked all probes after rate-limiting was detected.

C.  

They may be open or filtered, requiring retransmission.

D.  

They may correspond to some services requiring three-way handshakes.

Discussion 0
Questions 26

A REST API uses user-provided object IDs without authorization checks. What flaw is this?

Options:

A.  

Mass assignment

B.  

XSS

C.  

SQLi

D.  

BOLA

Discussion 0
Questions 27

An AWS security operations team receives an alert regarding abnormal outbound traffic from an EC2 instance. The instance begins transmitting encrypted data packets to an external domain that resolves to a Dropbox account not associated with the organization. Further analysis reveals that a malicious executable silently modified the Dropbox sync configuration to use the attacker ' s access token, allowing automatic synchronization of internal files to the attacker’s cloud storage. What type of attack has likely occurred?

Options:

A.  

Cloud Snooper attack leveraging port masquerading

B.  

Man-in-the-Cloud (MITC) attack

C.  

Side-channel attack exploiting CPU cache

D.  

Cryptojacking using Coin Hive scripts

Discussion 0
Questions 28

Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network?

Options:

A.  

139 and 443

B.  

137 and 139

C.  

137 and 443

D.  

139 and 445

Discussion 0
Questions 29

At a federal research agency, cybersecurity officer Nikhil is drafting a vulnerability assessment report. In this section, he documents the scanning methodology used, the information about the targets, the type and scope of scans performed, and the tools involved. He does not yet include specific vulnerabilities or affected assets, as this portion of the report is meant to provide context for how the assessment was conducted.

Which section of the vulnerability assessment report is Nikhil working on?

Options:

A.  

Supporting Information

B.  

Risk Assessment

C.  

Assessment Overview

D.  

Findings

Discussion 0
Questions 30

In the heart of Silicon Valley, ethical hacker Sophia Nguyen is hired by InnoVate Solutions, a San Francisco-based startup, to secure their cloud-based task management platform. On March 15, 2025, Sophia begins testing a feature that allows users to upload custom workflow templates to streamline project assignments. By carefully crafting a template file, she manipulates the platform’s data processing, triggering unexpected behavior that grants her administrative access to restricted project dashboards. The issue arises from the platform’s handling of user-supplied data during object reconstruction, not from database queries, client-side code execution, or session manipulation. Sophia documents her findings to help InnoVate’s developers strengthen their application.

Which web application vulnerability is Sophia most likely exploiting in InnoVate Solutions’ task management platform?

Options:

A.  

Session Hijacking

B.  

Local File Inclusion

C.  

Verbose Error Messages

D.  

Insecure Deserialization

Discussion 0
Questions 31

A senior executive receives a personalized email with the subject line “Annual Performance Review 2024.” The email contains a downloadable PDF that installs a backdoor when opened. The email appears to come from the CEO and includes company branding. Which phishing method does this best illustrate?

Options:

A.  

Broad phishing sent to all employees

B.  

Pharming using DNS poisoning

C.  

Whaling attack aimed at high-ranking personnel

D.  

Email clone attack with altered attachments

Discussion 0
Questions 32

During a penetration test at a healthcare facility in Baltimore, Maryland, an ethical hacker demonstrates how attackers are mapping active hosts and open ports using ICMP-based techniques. To reduce the organization’s exposure, the security team decides to implement a countermeasure that specifically disrupts ICMP discovery traffic by preventing error messages from being returned. Which action should they take?

Options:

A.  

Use a custom rule set to lock down the network, block unwanted ports at the firewall, and filter specific ports

B.  

Configure firewall and IDS rules to detect and block probes

C.  

Block unwanted services running on the ports and update the service versions

D.  

Block inbound ICMP message types and all outbound ICMP type 3 (Destination Unreachable) messages

Discussion 0
Questions 33

A penetration tester is attempting to gain access to a wireless network that is secured with WPA2 encryption. The tester successfully captures the WPA2 handshake but now needs to crack the pre-shared key. What is the most effective method to proceed?

Options:

A.  

Perform a brute-force attack using common passwords against the captured handshake

B.  

Use a dictionary attack against the captured WPA2 handshake to crack the key

C.  

Execute a SQL injection attack on the router ' s login page

D.  

Conduct a de-authentication attack to disconnect all clients from the network

Discussion 0
Questions 34

A penetration tester observes that traceroutes to various internal devices always show 10.10.10.1 as the second-to-last hop, regardless of the destination subnet. What does this pattern most likely indicate?

Options:

A.  

DNS poisoning at the local resolver used by the compromised host

B.  

Loopback misconfiguration at the destination endpoints

C.  

A core router facilitating communication across multiple internal subnets

D.  

Presence of a transparent proxy device acting as a forwarder

Discussion 0
Questions 35

A financial technology firm in Atlanta, Georgia launches an internal investigation after multiple employees report that a popular messaging application on their Android devices has begun displaying excessive advertisements and behaving unpredictably. Security analysts discover that users had installed a utility application from a third-party marketplace weeks earlier. Further examination shows that this application silently replaced certain legitimate apps already present on the device. The compromised applications were then used to generate large volumes of advertisements and collect user data for external transmission. Based on the observed behavior, what malware is most consistent with this incident?

Options:

A.  

Mamo

B.  

Pegasus

C.  

Agent Smith

D.  

GoldPickaxe

Discussion 0
Questions 36

A web server was compromised through DNS hijacking. What would most effectively prevent this in the future?

Options:

A.  

Changing IP addresses

B.  

Regular patching

C.  

Implementing DNSSEC

D.  

Using LAMP architecture

Discussion 0
Questions 37

During a security review, you have discovered that there are no documented security policies for the area you are assessing. Which of the following would be the most appropriate course of action?

Options:

A.  

Create policies while testing

B.  

Stop the audit

C.  

Identify and evaluate current practices

D.  

Increase the level of testing

Discussion 0
Questions 38

At a Los Angeles-based online gaming company, penetration tester John investigates a recent cloud breach that caused downtime and delayed alerts. He finds that the root issue was management ' s lack of defined responsibilities for monitoring, auditing, and securing serverless services, which left critical functions unmanaged. Which cloud computing threat does this scenario best illustrate?

Options:

A.  

Insufficient logging and monitoring

B.  

Loss of governance

C.  

Privilege escalation

D.  

Side-channel attacks

Discussion 0
Questions 39

At Liberty Mutual ' s cybersecurity operations center in Boston, network engineer Marcus is troubleshooting a critical issue during peak transaction hours. Multiple VLANs are experiencing intermittent access delays, and several endpoints including those on isolated VLANs are receiving network traffic not intended for them, raising concerns about data exposure. Marcus notices that the issue began after a newly imaged workstation used by an intern named Lisa was connected to a trunk port in the server room. Switch logs indicate abnormal traffic patterns overwhelming the network.

Which sniffing technique is Lisa ' s workstation most likely using to cause this behavior?

Options:

A.  

DNS Cache Poisoning

B.  

ARP Poisoning

C.  

MAC Flooding

D.  

Switch Port Stealing

Discussion 0
Questions 40

Lily, a network security analyst at a regional healthcare provider, is preparing defenses ahead of a scheduled external vulnerability assessment. During internal simulation drills, she observes that scanners are successfully identifying open ports and service banners across critical systems. Tasked with reducing exposure to such reconnaissance efforts, Lily is instructed to apply measures that specifically hinder port scanning activity without disrupting legitimate traffic.

Which of the following actions should Lily implement?

Options:

Discussion 0
Questions 41

Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?

Options:

A.  

OpenVAS

B.  

Nessus

C.  

tcptraceroute

D.  

tcptrace

Discussion 0
Questions 42

During an internal penetration test within a large corporate environment, the red team gains access to an unrestricted network port in a public-facing meeting room. The tester deploys an automated tool that sends thousands of DHCPDISCOVER requests using randomized spoofed MAC addresses. The DHCP server’s lease pool becomes fully depleted, preventing legitimate users from obtaining IP addresses. What type of attack did the penetration tester perform?

Options:

A.  

DHCP starvation

B.  

Rogue DHCP relay injection

C.  

DNS cache poisoning

D.  

ARP spoofing

Discussion 0
Questions 43

During a red team assessment at Apex Technologies in Austin, ethical hacker Ryan tests whether employees can be tricked into disclosing sensitive data over the phone. He poses as a vendor requesting payment details and reaches out to several staff members. To evaluate defenses, the security team emphasizes that beyond general training, there is a practical step employees must apply in every interaction to avoid being deceived by such calls.

Which countermeasure should Apex Technologies prioritize to directly prevent this type of social engineering attempt?

Options:

A.  

Conduct security awareness programs

B.  

Employees must verify the identity of individuals requesting information

C.  

Establish policies and procedures

D.  

Use two-factor authentication

Discussion 0
Questions 44

An internal review at a financial analytics firm in Minneapolis, Minnesota, uncovered unusual query patterns directed at the company’s directory services infrastructure. Security engineer Olivia Grant examined the logs and discovered that a user account had been issuing structured directory queries to retrieve lists of user objects, group memberships, and organizational units.

Further inspection revealed that the account was able to access information about privileged groups containing the word “Admin” in their titles. The activity did not involve password guessing or authentication bypass, but rather systematic directory lookups to map internal user and group relationships.

What type of enumeration is illustrated in this scenario?

Options:

A.  

VoIP Enumeration

B.  

LDAP Enumeration

C.  

SMTP Enumeration

D.  

DNS Enumeration

Discussion 0
Questions 45

An attacker abuses PowerShell heavily. Which log helps most?

Options:

A.  

DNS logs

B.  

Firewall logs

C.  

Syslog

D.  

PowerShell script block logs

Discussion 0
Questions 46

Why is using Google Hacking justified during passive footprinting?

Options:

A.  

Identifying weaknesses in website source code

B.  

Locating phishing sites mimicking the organization

C.  

Mapping internal network structures

D.  

Discovering hidden organizational data indexed by search engines

Discussion 0
Questions 47

During a compliance review at a law firm in Chicago, an ethical hacker tests the firm’s secure email gateway. She observes that sensitive legal documents are being transmitted in clear text over the Internet, allowing anyone intercepting the traffic to read the contents. The firm is concerned about unauthorized individuals being able to view these communications. Which principle of information security is being violated?

Options:

A.  

Confidentiality

B.  

Integrity

C.  

Non-Repudiation

D.  

Availability

Discussion 0
Questions 48

A cybersecurity team identifies suspicious outbound network traffic. Investigation reveals malware utilizing the Background Intelligent Transfer Service (BITS) to evade firewall detection. Why would attackers use this service to conceal malicious activities?

Options:

A.  

Because BITS packets appear identical to normal Windows Update traffic.

B.  

Because BITS operates exclusively through HTTP tunneling.

C.  

Because BITS utilizes IP fragmentation to evade intrusion detection systems.

D.  

Because BITS traffic uses encrypted DNS packets.

Discussion 0
Questions 49

Abnormal DNS resolution behavior is detected on an internal network. Users are redirected to altered login pages. DNS replies come from an unauthorized internal IP and are faster than legitimate responses. ARP spoofing alerts are also detected. What sniffing-based attack is most likely occurring?

Options:

A.  

Internet DNS spoofing

B.  

Intranet DNS poisoning via local spoofed responses

C.  

Proxy-based DNS redirection

D.  

Upstream DNS cache poisoning

Discussion 0
Questions 50

During a penetration test at a telecom provider in Denver, Colorado, Maria, a senior ethical hacker, notices that her scans are immediately flagged by intrusion detection systems. She modifies her technique, and as a result, the IDS devices are unable to reassemble the packets correctly, allowing her probes to slip through without detection. Which scanning evasion technique is Maria applying in this case?

Options:

A.  

Packet Fragmentation

B.  

Source Routing

C.  

Decoy Scanning

D.  

IP Spoofing

Discussion 0
Questions 51

Which tool dumps Windows hashes?

Options:

A.  

Mimikatz

B.  

John

C.  

Hydra

D.  

Aircrack-ng

Discussion 0
Questions 52

A university ' s online registration system is disrupted by a combined DNS reflection and HTTP Slowloris DDoS attack. Standard firewalls cannot mitigate the attack without blocking legitimate users. What is the best mitigation strategy?

Options:

A.  

Increase server bandwidth and implement basic rate limiting

B.  

Deploy an Intrusion Prevention System (IPS) with deep packet inspection

C.  

Configure the firewall to block all incoming DNS and HTTP requests

D.  

Utilize a hybrid DDoS mitigation service that offers both on-premises and cloud-based protection

Discussion 0
Questions 53

During enumeration, a tool sends requests to UDP port 161 and retrieves a large list of installed software due to a publicly known community string. What enabled this technique to work so effectively?

Options:

A.  

Unencrypted FTP services storing software data

B.  

The SNMP agent allowed anonymous bulk data queries due to default settings

C.  

Remote access to encrypted Windows registry keys

D.  

SNMP trap messages logged in plain text

Discussion 0
Questions 54

An ethical hacker conducts testing with full knowledge and permission. What type of hacking is this?

Options:

A.  

Blue Hat

B.  

Grey Hat

C.  

White Hat

D.  

Black Hat

Discussion 0
Questions 55

You suspect a Man-in-the-Middle (MitM) attack inside the network. Which network activity would help confirm this?

Options:

A.  

Sudden increase in traffic

B.  

Multiple login attempts from one IP

C.  

IP addresses resolving to multiple MAC addresses

D.  

Abnormal DNS request volumes

Discussion 0
Questions 56

In Atlanta, Georgia, ethical hacker James Patel is hired by Southern Retail, a major e-commerce chain, to test the security of their online shopping platform. During his penetration test, James aims to simulate a session hijacking attack by setting up a proxy to intercept HTTP traffic between customers and the platform, log the requests, and perform advanced searches on the captured data to identify session tokens. He needs a lightweight tool specifically designed for security research that can handle these tasks in a controlled environment to demonstrate vulnerabilities to the company ' s security team.

Which tool should James use to perform this session hijacking simulation?

Options:

A.  

Caido

B.  

Hetty

C.  

Bettercap

D.  

Wireshark

Discussion 0
Questions 57

The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?

Options:

A.  

RST

B.  

ACK

C.  

SYN-ACK

D.  

SYN

Discussion 0
Questions 58

During a security evaluation of a smart agriculture setup, an analyst investigates a cloud-managed irrigation controller. The device is found to transmit operational commands and receive firmware updates over unencrypted HTTP. Additionally, it lacks mechanisms to verify the integrity or authenticity of those updates. This vulnerability could allow an adversary to intercept communications or inject malicious firmware, leading to unauthorized control over the device ' s behavior or denial of essential functionality. Which IoT threat category does this situation best illustrate?

Options:

A.  

Insecure default settings

B.  

Insecure ecosystem interfaces

C.  

Insufficient privacy protection

D.  

Insecure network services

Discussion 0
Questions 59

During a large-scale network assessment of a telecom provider in Dallas, Texas, a cybersecurity consultant uses Recon-ng and Nmap to enumerate legacy and infrastructure-level services across multiple nodes. The tools uncover open Telnet ports, FTP directories with anonymous login enabled, active TFTP services, and exposed SMB shares. The consultant also detects a service that responds to VRFY, EXPN, and RCPT commands, allowing the enumeration of user identities and delivery addresses due to weak input validation. IPv6 tunneling protocols are also detected. Concerned about information leakage, the consultant flags these services for immediate remediation.

Which classification best describes this set of enumeration activities?

Options:

A.  

LDAP Enumeration

B.  

VoIP Enumeration

C.  

SMTP Enumeration

D.  

DNS Enumeration

Discussion 0
Questions 60

During a red team operation on a segmented enterprise network, the testers discover that the organization’s perimeter devices deeply inspect only connection-initiation packets (such as TCP SYN and HTTP requests). Response packets and ACK packets within established sessions, however, are minimally inspected. The red team needs to covertly transmit payloads to an internal compromised host by blending into normal session traffic. Which approach should they take to bypass these defensive mechanisms?

Options:

A.  

Port knocking

B.  

SYN scanning

C.  

ICMP flooding

D.  

ACK tunneling

Discussion 0
Questions 61

At a digital marketing firm in Atlanta, Georgia, employees began reporting that access to a widely used cloud collaboration portal was intermittently redirecting them to a counterfeit interface hosted on an unfamiliar IP address. Security engineers observed that when multiple users across different departments attempted to access the legitimate domain, they consistently received the same incorrect IP resolution. The anomalous behavior persisted across sessions and affected numerous internal clients until the organization ' s name resolution service was restarted, after which normal resolution resumed. What DNS manipulation technique best explains this scenario?

Options:

A.  

Performing Intranet DNS Spoofing within the local network

B.  

Injecting malicious records through DNS Cache Poisoning

C.  

Executing Proxy Server DNS Poisoning to alter resolution paths

D.  

Conducting Internet DNS Spoofing from a remote network

Discussion 0
Questions 62

During a black-box penetration test, an attacker runs the following command:

nmap -p25 --script smtp-enum-users --script-args EXPN,RCPT < target IP >

The script successfully returns multiple valid usernames. Which server misconfiguration is being exploited?

Options:

A.  

The SMTP server allows authentication without credentials

B.  

The SMTP server has disabled STARTTLS, allowing plaintext enumeration

C.  

SMTP user verification commands are exposed without restrictions

D.  

DNS MX records point to an internal mail relay

Discussion 0
Questions 63

In a vertical privilege escalation scenario, the attacker attempts to gain access to a user account with higher privileges than their current level. Which of the following examples describes vertical privilege escalation?

Options:

A.  

An attacker exploits weak access controls to access and steal sensitive information from another user ' s account with alike privileges.

B.  

An attacker leverages a lack of session management controls to switch accounts and access resources assigned to another user with the same permissions.

C.  

An attacker uses an unquoted service path vulnerability to gain unauthorized access to another user ' s data with equivalent privileges.

D.  

An attacker escalates from a regular user to an administrator by exploiting administrative functions.

Discussion 0
Questions 64

In Pittsburgh, Pennsylvania, a major steel manufacturer operates a production plant with numerous automated loops that regulate temperature, pressure, and conveyor speed. During an audit, ethical hacker Marcus Reed observes that these loops are coordinated by a centralized supervisory network that links multiple controllers across the facility. Based on this design, which OT system concept is being applied?

Options:

A.  

Manual loop

B.  

Distributed Control System (DCS)

C.  

Open loop

D.  

Closed loop

Discussion 0
Questions 65

In Miami, Florida, cybersecurity analyst Laura Bennett is investigating unauthorized access incidents affecting Sunshine Credit Union’s online banking platform. Audit logs reveal that compromised accounts consistently involve users who accessed the portal through specially crafted links sent via email.

The links direct victims to the legitimate website, where they proceed to authenticate successfully. Shortly afterward, unauthorized access to the same accounts is observed without any additional credential guessing or brute-force activity.

Further examination shows that a value associated with the user’s interaction with the application remains unchanged throughout the authentication process and can be introduced before the user completes sign-in.

Which countermeasure should Laura implement to prevent this type of account takeover?

Options:

A.  

Use restrictive cache directives such as Cache-Control: no-cache

B.  

Implement SSL to encrypt all information in transit via the network

C.  

Regenerate the session ID after a successful login

D.  

Do not create sessions for unauthenticated users

Discussion 0
Questions 66

At HarborGrid Utilities in Oregon, a security assessment team is reviewing how the organization’s network monitoring platform evaluates inbound traffic targeting its SCADA management interface. During testing, the red team introduces carefully crafted packets that adhere to known protocol standards but contain payload sequences previously identified in documented exploit repositories.

The monitoring system immediately flags the activity because it matches patterns stored in its internal threat database. However, when the team slightly modifies the exploit sequence while preserving its overall malicious intent, the alerts are no longer triggered.

Based on this behavior, which intrusion detection method is most likely deployed in this environment?

Options:

A.  

Protocol Anomaly Detection

B.  

Anomaly Detection

C.  

Stateful Protocol Analysis

D.  

Signature Recognition

Discussion 0
Questions 67

A private equity firm in Minneapolis, Minnesota allows employees to access internal reporting tools from their personally owned smartphones under its BYOD program. During a routine security assessment, a consultant observes that when an employee leaves their unlocked phone unattended, a colleague can immediately open the firm’s financial application and review client investment records without any additional verification step inside the application.

The operating system itself requires a passcode to unlock the device, but once unlocked, corporate applications open directly to sensitive dashboards.

Identify the BYOD security guideline that would directly mitigate this exposure.

Options:

A.  

Use Encryption Mechanism to Store Data

B.  

Set a Strong Passcode on the Device and Change It Relatively Often

C.  

Maintain a Clear Separation between Business and Personal Data

D.  

Set Passwords for Apps to Restrict Others from Accessing Them

Discussion 0
Questions 68

A malware analyst is tasked with evaluating a suspicious PDF file suspected of launching attacks through embedded JavaScript. Initial scans using pdfid show the presence of /JavaScript and /OpenAction keywords. What should the analyst do next to understand the potential impact?

Options:

A.  

Upload the file to VirusTotal and rely on engine consensus

B.  

Disassemble the PDF using PE Explorer

C.  

Extract and analyze stream objects using PDFStreamDumper

D.  

Compute file hashes using HashMyFiles for signature matching

Discussion 0
Questions 69

During a targeted intrusion against a cloud infrastructure company in Salt Lake City, Utah, an attacker distributes a modified installation package of a legitimate network diagnostic utility widely used by employees. Before distributing the package, the attacker binds a malicious remote-access payload with the original executable so that both components are installed together.

When users launch the diagnostic tool, it performs its normal troubleshooting functions, while the hidden payload simultaneously executes in the background and establishes communication with a remote command server.

From a malware deployment perspective, what technique best describes this approach?

Options:

A.  

Wrapper

B.  

Downloader

C.  

Packer

D.  

Dropper

Discussion 0
Questions 70

By using a smart card and pin, you are using a two-factor authentication that satisfies

Options:

A.  

Something you know and something you are

B.  

Something you have and something you know

C.  

Something you have and something you are

D.  

Something you are and something you remember

Discussion 0
Questions 71

A penetration tester identifies that a web application ' s login form is not using secure password hashing mechanisms, allowing attackers to steal passwords if the database is compromised. What is the best approach to exploit this vulnerability?

Options:

A.  

Perform a dictionary attack using a list of commonly used passwords against the stolen hash values

B.  

Input a SQL query to check for SQL injection vulnerabilities in the login form

C.  

Conduct a brute-force attack on the login form to guess weak passwords

D.  

Capture the login request using a proxy tool and attempt to decrypt the passwords

Discussion 0
Questions 72

During a red team exercise at a financial institution in New York, penetration tester Bob investigates irregularities in time synchronization across critical servers. While probing one server, he decides to use a diagnostic command that allows him to directly interact with the NTP daemon and query its internal state. This command enables him to perform monitoring and retrieve statistics, but it is primarily focused on controlling and checking the operation of the NTP service rather than listing peers with delay, offset, and jitter values.

Which command should Bob use to accomplish this?

Options:

A.  

ntpq -p [host]

B.  

ntptrace [-m maxhosts] [servername/IP_address]

C.  

ntpdc [-ilnps] [-c command] [host]

D.  

ntpq [-inp] [-c command] [host]...

Discussion 0
Questions 73

Which payload is most effective for testing time-based blind SQL injection?

Options:

A.  

AND 1=0 UNION ALL SELECT ' admin ' , ' admin

B.  

UNION SELECT NULL, NULL, NULL --

C.  

OR ' 1 ' = ' 1 ' ;

D.  

AND BENCHMARK(5000000,ENCODE( ' test ' , ' test ' ))

Discussion 0
Questions 74

During testing against a network protected by a signature-based IDS, the tester notices that standard scans are blocked. To evade detection, the tester sends TCP headers split into multiple small IP fragments so the IDS cannot reassemble or interpret them, but the destination host can. What technique is being used?

Options:

A.  

IP decoying with randomized address positions

B.  

SYN scan with spoofed MAC address

C.  

Packet crafting with randomized window size

D.  

Packet fragmentation to bypass filtering logic

Discussion 0
Questions 75

During a physical penetration test at Sterling Electronics in Cleveland, ethical hacker Priya waits near the employee entrance during a shift change. When a group of staff enters the building using their access cards, Priya closely follows behind without swiping her own badge. None of the employees confront her, assuming she belongs there. Once inside, Priya proceeds to the break area where she documents the success of the exercise.

Which social engineering technique is Priya demonstrating?

Options:

A.  

Shoulder Surfing

B.  

Dumpster Diving

C.  

Tailgating

D.  

Piggybacking

Discussion 0
Questions 76

What does TTL manipulation help evade?

Options:

A.  

Encryption

B.  

Firewall

C.  

IDS

D.  

Router

Discussion 0
Questions 77

A multinational corporation deploys a major internal tool built on a PowerShell-based automation framework. Shortly after a scheduled rollout, the IT team notices intermittent system slowdowns and unexplained bandwidth spikes. Despite running updated endpoint protection and restrictive firewall rules, traditional scanning tools report no malicious files on disk. However, internal telemetry flags a trusted process repeatedly executing obfuscated PowerShell commands in memory. The anomalous activity vanishes upon reboot and appears to leave no footprint behind on the system.

Which type of malware is most likely responsible for this behavior?

Options:

A.  

Worm

B.  

Trojan

C.  

Rootkit

D.  

Fileless Malware

Discussion 0
Questions 78

Which patch management strategy is most effective?

Options:

A.  

External-only patches

B.  

Automated patch management with monitoring

C.  

Manual patching on live servers

D.  

Applying all patches regardless of source

Discussion 0
Questions 79

Malware uses Background Intelligent Transfer Service (BITS) to evade detection. Why is BITS attractive to attackers?

Options:

A.  

It uses IP fragmentation

B.  

It encrypts DNS packets

C.  

It looks like normal Windows Update traffic

D.  

It works only through HTTP tunneling

Discussion 0
Questions 80

As an IT security analyst, you perform network scanning using ICMP Echo Requests. During the scan, several IP addresses do not return Echo Replies, yet other network services remain operational. How should this situation be interpreted?

Options:

A.  

The non-responsive IP addresses indicate severe network congestion.

B.  

A firewall or security control is likely blocking ICMP Echo Requests.

C.  

The lack of Echo Replies indicates an active security breach.

D.  

The IP addresses are unused and available for reassignment.

Discussion 0
Questions 81

In downtown Chicago, Illinois, security analyst Mia Torres investigates a breach at Windy City Enterprises, a logistics firm running an Apache HTTP Server. The attacker exploited a known vulnerability in an outdated version, gaining unauthorized access to customer shipment data. Mia’s analysis reveals the server lacked recent security updates, leaving it susceptible to remote code execution. Determined to prevent future incidents, Mia recommends a strategy to the IT team to address this exposure.

Which approach should Mia recommend to secure Windy City Enterprises ' Apache HTTP Server against such vulnerabilities?

Options:

A.  

Eliminate unnecessary files within the jar files

B.  

Block all unnecessary ports, ICMP traffic, and unnecessary protocols such as NetBIOS and SMB

C.  

Use a dedicated machine as a web server

D.  

Conduct an extensive risk assessment to determine which segments of the network are most vulnerable or at high risk that need to be patched first

Discussion 0
Questions 82

A security consultant is conducting an authorized assessment for a healthcare billing provider in Phoenix, Arizona. While monitoring internal traffic, he observes an authenticated employee interacting with a sensitive web-based management portal over TCP.

During the session, the consultant carefully crafts and injects packets into the ongoing communication stream. Shortly afterward, the legitimate user experiences irregular responses from the application, and the server begins processing commands originating from the consultant’s injected traffic as though they were part of the established session.

The technique does not involve credential guessing or forcing the user to reauthenticate. Instead, it targets the communication channel already in progress.

From a network-level perspective, what type of session hijacking technique is being demonstrated?

Options:

A.  

UDP Hijacking

B.  

RST Hijacking

C.  

Blind Hijacking

D.  

TCP/IP Hijacking

Discussion 0
Questions 83

An attacker uses many plaintext–ciphertext pairs and applies statistical analysis to XOR combinations of specific bits. Which technique is being used?

Options:

A.  

Brute-force attack

B.  

Differential cryptanalysis

C.  

Linear cryptanalysis

D.  

Side-channel attack

Discussion 0
Questions 84

Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?

Options:

A.  

John the Ripper

B.  

Dsniff

C.  

Snort

D.  

Nikto

Discussion 0
Questions 85

During a red team assessment at New England Insurance in Boston, ethical hacker Daniel sends a series of spoofed TCP packets carrying the reset flag to a server hosting client applications. As a result, several active sessions between employees and the server are abruptly terminated, causing temporary disruption of legitimate work. Daniel uses this demonstration to highlight how attackers can forcibly tear down sessions without completing a full hijack.

Which type of network-level session hijacking technique is Daniel simulating?

Options:

A.  

UDP Hijacking

B.  

RST Hijacking

C.  

Blind Hijacking

D.  

TCP/IP Hijacking

Discussion 0
Questions 86

As a Certified Ethical Hacker assessing session management vulnerabilities in a secure web application using MFA, encrypted cookies, and a WAF, which technique would most effectively exploit a session management weakness while bypassing these defenses?

Options:

A.  

Utilizing Session Fixation to force a victim to use a known session ID

B.  

Executing a Cross-Site Request Forgery (CSRF) attack

C.  

Exploiting insecure deserialization vulnerabilities for code execution

D.  

Conducting Session Sidejacking using captured session tokens

Discussion 0
Questions 87

A penetration tester gains access to a target system through a vulnerability in a third-party software application. What is the most effective next step to take to gain full control over the system?

Options:

A.  

Conduct a denial-of-service (DoS) attack to disrupt the system’s services

B.  

Execute a Cross-Site Request Forgery (CSRF) attack to steal session data

C.  

Perform a brute-force attack on the system ' s root password

D.  

Use a privilege escalation exploit to gain administrative privileges on the system

Discussion 0
Questions 88

During a controlled red team engagement at a financial institution in New Jersey, ethical hacker Ryan tests the bank ' s resilience against stealth-based malware. He plants a custom malicious program on an employee workstation. After execution, he observes that the infected files continue to function normally, but his malware conceals its modifications by intercepting operating system calls. Antivirus scans repeatedly return “no threats detected,” even though the malicious code remains active and hidden on the system.

Which type of virus did Ryan most likely deploy in this assessment?

Options:

A.  

Cavity Virus

B.  

Stealth Virus

C.  

Polymorphic Virus

D.  

Macro Virus

Discussion 0
Questions 89

You are Sofia Patel, an ethical hacker at Nexus Security Labs, hired to test the mobile device security of Bayview University in San Francisco, California. During your assessment, you are given an Android 11-based Samsung Galaxy Tab S6 with USB debugging disabled and OEM unlock restrictions in place. To simulate an attacker attempting to gain privileged access, you install a mobile application that exploits a system vulnerability to gain root access directly on the device without requiring a PC. This allows you to bypass OS restrictions and retrieve sensitive research data. Based on this method, which Android rooting tool are you using?

Options:

A.  

Magisk Manager

B.  

One Click Root

C.  

KingoRoot

D.  

RootMaster

Discussion 0
Questions 90

What is MAC spoofing used for?

Options:

A.  

Encryption

B.  

IDS

C.  

Bypass filters

D.  

Logging

Discussion 0
Questions 91

Which wireless attack captures handshake?

Options:

A.  

Deauth

B.  

Jamming

C.  

Spoofing

D.  

Replay

Discussion 0
Questions 92

A Windows endpoint generates alerts for credential dumping tools. What asset is targeted?

Options:

A.  

Network

B.  

Logs

C.  

Availability

D.  

Credentials

Discussion 0
Questions 93

A multinational company plans to deploy an IoT-based environmental control system across global manufacturing units. The security team must identify the most likely attack vector an Advanced Persistent Threat (APT) group would use to compromise the system. What is the most plausible method?

Options:

A.  

Launching a DDoS attack to overload IoT devices

B.  

Compromising the system using stolen user credentials

C.  

Exploiting zero-day vulnerabilities in IoT device firmware

D.  

Performing an encryption-based Man-in-the-Middle attack

Discussion 0
Questions 94

A multinational corporation recently survived a severe Distributed Denial-of-Service (DDoS) attack and has implemented enhanced security measures. During an audit, you discover that the organization uses both hardware- and cloud-based solutions to distribute incoming traffic in order to absorb and mitigate DDoS attacks while ensuring legitimate traffic remains available. What type of DDoS mitigation strategy is the company utilizing?

Options:

A.  

Black Hole Routing

B.  

Load Balancing

C.  

Rate Limiting

D.  

Sinkholing

Discussion 0
Questions 95

During a forensic log review at a satellite communications provider in Denver, Colorado, cybersecurity analyst Kevin Morales identified subtle timestamp irregularities in archived telemetry records. Although the discrepancies were minor, regulatory reporting standards required confirmation that the system clock was synchronizing correctly with its configured time sources.

Kevin needed to interact directly with the host’s running time service to review its current associations and operational state. He was not attempting to reset the clock or trace the hierarchy of upstream time authorities, but rather to query the active service for detailed status information from the target machine.

Identify the command Kevin should execute to obtain this information.

Options:

A.  

ntptrace [-n] [-m maxhosts] [servername/IP address]

B.  

ntpq [-inp] [-c command] [host] [...]

C.  

ntpdc [-ilnps] [-c command] [host] [...]

D.  

ntpq -p [host]

Discussion 0
Questions 96

During a penetration test at Horizon Tech in Austin, ethical hacker Michael sets up a man-in-the-middle attack to intercept traffic between employees and the company ' s internal web applications. He uses a lightweight tool capable of performing ARP spoofing, DNS manipulation, and packet injection while providing an interactive interface for real-time monitoring. This allows him to capture and manipulate session tokens in transit, which he later presents to the security team as proof of risk.

Which tool is Michael most likely using in this exercise?

Options:

A.  

Wireshark

B.  

Hetty

C.  

Caido

D.  

Bettercap

Discussion 0
Questions 97

You perform a SYN (half-open) scan and receive a SYN/ACK packet in response. How should this result be interpreted?

Options:

A.  

The target IP is not reachable

B.  

The scanned port is open

C.  

The scanned port is filtered

D.  

The scanned port is closed

Discussion 0
Questions 98

A WPA2-PSK wireless network is tested. Which method would allow identification of a key vulnerability?

Options:

A.  

De-authentication attack to capture the four-way handshake

B.  

MITM to steal the PSK directly

C.  

Jamming to force PSK disclosure

D.  

Rogue AP revealing PSK

Discussion 0
Questions 99

During a penetration test at Cascade Financial in Seattle, ethical hacker Elena Vasquez probes the input handling of the company ' s web server. She discovers that a single crafted request is processed as two separate ones, allowing her to inject malicious data into the server ' s communication. This type of attack falls into the same category of input validation flaws as cross-site scripting (XSS), cross-site request forgery (CSRF), and SQL injection. Which type of web server attack is Elena most likely demonstrating?

Options:

A.  

Password Cracking Attack

B.  

HTTP Response Splitting Attack

C.  

Directory Traversal Attack

D.  

Web Cache Poisoning Attack

Discussion 0
Questions 100

A cybersecurity company wants to prevent attackers from gaining information about its encrypted traffic patterns. Which of the following cryptographic algorithms should they utilize?

Options:

A.  

HMAC

B.  

RSA

C.  

DES

D.  

AES

Discussion 0
Questions 101

During an authorized cloud security assessment for an e-commerce company based in Seattle, Washington, a certified ethical hacker gains temporary programmatic access to the organization’s cloud account. The tester focuses on identifying permission boundaries by querying the account to determine which identity entities are associated with attached policies and what level of access those identities possess across cloud resources. The objective is to understand privilege relationships before attempting any further controlled actions.

Which cloud reconnaissance activity best aligns with this effort?

Options:

A.  

Enumerating IAM Roles

B.  

Enumerating S3 Buckets

C.  

Enumerating EC2 Instances

D.  

Enumerating Serverless Resources

Discussion 0
Questions 102

At a private aerospace research facility in Mesa, Arizona, an executive raises concerns after sensitive discussion points from speakerphone meetings begin surfacing externally. The device shows no indicators of active audio recording, and application permission history does not reflect recent camera or microphone authorization changes.

A forensic mobile analysis identifies that an installed application has been continuously reading motion sensor output while the phone’s loudspeaker is active. The collected sensor data was later transmitted to a remote server, where acoustic characteristics were reconstructed from the recorded measurements.

Identify the attack technique responsible for this compromise.

Options:

A.  

Camfecting

B.  

StormBreaker Abuse

C.  

Android Camera Hijack Attack

D.  

Spearphone Attack

Discussion 0
Questions 103

Targeted, logic-based credential guessing using prior intel best describes which technique?

Options:

A.  

Strategic pattern-based input using known logic

B.  

Exhaustive brute-force testing

C.  

Shoulder surfing

D.  

Rule-less hybrid attack

Discussion 0
Questions 104

During security awareness training, which scenario best describes a tailgating social engineering attack?

Options:

A.  

An attacker impersonates a customer to recover account credentials

B.  

An attacker leaves a malicious USB labeled “Employee Bonus List”

C.  

A person gains access to a secure building by following an authorized employee through a locked door

D.  

An email urges employees to enter credentials for an urgent system update

Discussion 0
Questions 105

A network administrator reviews logs and observes that an attacker sends packets requesting the target system’s internal clock value. The response includes timing information that can be used to calculate round-trip delay and analyze host characteristics.

What host discovery technique is being used in this scenario?

Options:

A.  

UDP Ping Scan

B.  

ICMP Echo Ping Sweep

C.  

IP Protocol Scan

D.  

ICMP Timestamp Ping Scan

Discussion 0
Questions 106

A cloud storage provider discovers that an unauthorized party obtained a complete backup of encrypted database files containing archived client communications. The attacker did not compromise the encryption keys, nor is there evidence that any original plaintext records were exposed. A forensic cryptography specialist reviewing the breach considers the possibility that the adversary is attempting to analyze the encrypted data in isolation, searching for statistical irregularities or structural repetition within the encrypted output to infer meaningful information. To properly assess the organization ' s exposure, the specialist must determine which cryptanalytic approach best matches an attack conducted using only the intercepted encrypted data.

Options:

A.  

Ciphertext-only attack

B.  

Known-plaintext attack

C.  

Chosen-plaintext attack

D.  

Chosen-ciphertext attack

Discussion 0
Questions 107

An internal audit at a pharmaceutical research company in San Diego, California, revealed that a directory server was reachable from a restricted testing subnet. Security analyst Daniel Harper initiated a basic directory query using simple authentication to validate connectivity. The query succeeded, confirming that the server was responding to unauthenticated search requests.

To understand the structural layout of the directory before performing deeper queries, Daniel needed to retrieve the base-level naming context entries exposed by the server. His objective was to identify the root domain components and configuration partitions before constructing targeted search filters.

Which command should Daniel execute to obtain the directory naming context information?

Options:

A.  

ldapsearch -x -h < host > -b " DC=htb,DC=local " objectclass= " * "

B.  

ldapsearch -h < host > -x

C.  

ldapsearch -h < host > -x -b " DC=htb,DC=local "

D.  

ldapsearch -h < host > -x -s base namingContexts

Discussion 0
Questions 108

A hacker is analyzing a system that uses two rounds of symmetric encryption with different keys. To speed up key recovery, the attacker encrypts the known plaintext with all possible values of the first key and stores the intermediate ciphertexts. Then, they decrypt the final ciphertext using all possible values of the second key and compare the results to the stored values. Which cryptanalytic method does this approach represent?

Options:

A.  

Flood memory with brute-forced credentials

B.  

Scrape electromagnetic leakage for bits

C.  

Use midpoint collision to identify key pair

D.  

Reverse permutations to bypass encryption

Discussion 0
Questions 109

Amid the vibrant buzz of Miami’s digital scene, ethical hacker Sofia Alvarez embarks on a mission to fortify the web server of Sunshine Media’s streaming platform. Diving into her security assessment, Sofia sends a meticulously crafted GET / HTTP/1.0 request to the server, scrutinizing its response. The server obligingly returns headers exposing its software version and operating system, a revelation that could empower malicious actors to tailor their attacks. Committed to bolstering the platform’s defenses, Sofia documents her findings to urge the security team to address this exposure.

What approach is Sofia using to expose the vulnerability in Sunshine Media’s web server?

Options:

A.  

Information Gathering from Robots.txt File

B.  

Vulnerability Scanning

C.  

Directory Brute Forcing

D.  

Web Server Footprinting Banner Grabbing

Discussion 0
Questions 110

Cyber experts conducting covert missions exclusively for national interests are best classified as:

Options:

A.  

State-sponsored hackers

B.  

Organized hackers

C.  

Gray hat hackers

D.  

Hacktivists

Discussion 0
Questions 111

During a simulated attack against a university ' s IT network in California, ethical hacker Sophia deploys custom malicious code onto one lab workstation. Without requiring further user interaction, she observes the malware automatically copying itself into shared folders and spreading through weak admin credentials. Within a short time, dozens of computers across multiple departments are infected with the same payload, even though only one machine was initially targeted.

Which type of malware is Sophia most likely demonstrating?

Options:

A.  

Logic Bomb

B.  

Worm

C.  

Backdoor

D.  

Fileless Malware

Discussion 0
Questions 112

A penetration tester is evaluating a web application that does not properly validate the authenticity of HTTP requests. The tester suspects the application is vulnerable to Cross-Site Request Forgery (CSRF). Which approach should the tester use to exploit this vulnerability?

Options:

A.  

Execute a directory traversal attack to access restricted server files

B.  

Create a malicious website that sends a crafted request on behalf of the user when visited

C.  

Perform a brute-force attack on the application’s login page to guess weak credentials

D.  

Inject a SQL query into the input fields to perform SQL injection

Discussion 0
Questions 113

A U.S.-based online securities trading firm in New York is reviewing its transaction authentication process. The security team confirms that each transaction is processed by first generating a hash of the transaction data. The hash value is then signed using the sender’s private key.

During verification, the recipient uses the corresponding public key to validate the signature before approving the transaction. The system documentation specifies that the same algorithm supports encryption, digital signatures, and key exchange mechanisms within the organization’s secure communications infrastructure.

Which encryption algorithm is being used in this implementation?

Options:

A.  

DSA

B.  

ElGamal

C.  

RSA

D.  

Diffie-Hellman

Discussion 0
Questions 114

Which advanced session hijacking technique is hardest to detect and mitigate in a remote-access environment?

Options:

A.  

Session sidejacking over public Wi-Fi

B.  

ARP spoofing on local networks

C.  

Brute-force session guessing

D.  

Cookie poisoning

Discussion 0
Questions 115

After responding to an alert involving unauthorized access to payroll data, forensic analyst Jason Miller traces the breach to a Windows workstation previously used by a temporary staff member in Chicago. While analyzing the event timeline, Jason identifies a non-elevated process that launched a signed Microsoft binary — one of several auto-elevate executables such as fodhelper.exe, eventvwr.exe, or sdclt.exe — which resulted in execution of unauthorized code without prompting the user. Registry analysis reveals manipulation of shell-related keys under the current user hive, redirecting the trusted binary to invoke a malicious payload.

Which technique most likely enabled the privilege escalation?

Options:

A.  

Kernel Exploitation

B.  

Scheduled Task

C.  

UAC Bypass

D.  

DLL Hijacking

Discussion 0
Questions 116

A red team operator wants to obtain credentials from a Windows machine without touching LSASS memory due to security controls and Credential Guard. They use SSPI to generate NetNTLM responses in the logged-in user context and collect those responses for offline cracking. Which attack technique is being used?

Options:

A.  

Internal Monologue attack technique executed through OS authentication protocol manipulations

B.  

Replay attack attempt by reusing captured authentication traffic sequences

C.  

Hash injection approach using credential hashes for authentication purposes

D.  

Pass-the-ticket attack method involving forged tickets for network access

Discussion 0
Questions 117

A national e-commerce retailer experiences a sustained distributed attack that saturates its edge connectivity with high-volume traffic originating from thousands of globally dispersed hosts. Internal mitigation attempts such as ACL tuning and rate limiting fail to restore service stability.

After escalating the issue, the organization coordinates with its upstream connectivity provider, which begins rerouting inbound traffic through a large-scale filtering infrastructure capable of absorbing and scrubbing malicious traffic before forwarding legitimate requests back to the retailer’s network.

What defensive approach is being applied in this scenario?

Options:

A.  

Implementing RFC 3704 Filtering at the Network Edge

B.  

Enabling Cisco IPS Source IP Reputation Filtering

C.  

Leveraging DDoS Prevention Offerings from an ISP or DDoS Mitigation Service

D.  

Deploying Black Hole Filtering at the Routing Layer

Discussion 0
Questions 118

You are Maya, a security engineer at HarborPoint Cloud Services in Chicago, Illinois, performing a post-incident hardening review after an internal audit flagged multiple services that rely on legacy public-key algorithms. The engineering team must prioritize actions company-wide to reduce long-term risk from future quantum-capable adversaries while development continues on a large refactor of several services. Which proactive control should Maya recommend as the highest-priority change to embed into the organization ' s development lifecycle to improve future resistance to quantum-based attacks?

Options:

A.  

Include quantum-resistance checks in SDLC and code review processes

B.  

Encrypt stored data with quantum-resistant algorithms

C.  

Use quantum-specific firewalls to protect quantum communication channels

D.  

Break data into fragments and distribute it across multiple locations

Discussion 0
Questions 119

A web application returns generic error messages. The analyst submits AND 1=1 and AND 1=2 and observes different responses. What type of injection is being tested?

Options:

A.  

UNION-based SQL injection

B.  

Error-based SQL injection

C.  

Boolean-based blind SQL injection

D.  

Time-based blind SQL injection

Discussion 0
Questions 120

In a high-stakes cybersecurity exercise in Boston, Emily, an ethical hacker, is tasked with tracing a mock phishing email sent to a healthcare provider’s staff. Using the email header, she identifies a series of IP addresses and server details, including multiple timestamps and server names. Her objective is to pinpoint the exact moment the email was processed by the sender’s system.

As part of her reconnaissance, what specific detail from the email header should Emily examine to determine this information?

Options:

A.  

Sender’s mail server

B.  

Date and time of message sent

C.  

Authentication system used by sender’s mail server

D.  

Date and time received by the originator’s email servers

Discussion 0
Questions 121

During a penetration test at a shipping company in Miami, ethical hacker Daniel delivers a disguised email attachment containing a hidden payload. Once executed by employees, the compromised workstations begin to silently communicate with a remote server under Daniel’s control. Over the following week, he confirms that multiple infected endpoints can receive synchronized commands and perform background tasks simultaneously, including sending bursts of outbound traffic on demand.

Which type of malicious component is Daniel most likely simulating in this assessment?

Options:

A.  

Spyware

B.  

Botnet Agents

C.  

Scareware

D.  

Potentially Unwanted Applications (PUAs)

Discussion 0
Questions 122

Granite Ridge Technologies in New Jersey is preparing to formalize its information security governance model. Executive leadership requires adoption of an internationally recognized framework that ensures confidentiality, integrity, and availability of information while enabling the organization to systematically identify, assess, and manage information security risks. The framework must also support compliance with regulatory and contractual obligations and demonstrate commitment to stakeholders.

Which standard best fulfills these requirements?

Options:

A.  

ISO/IEC 27001:2022

B.  

ISO/IEC 27005:2022

C.  

ISO/IEC 27701:2019

D.  

ISO/IEC 27002:2022

Discussion 0
Questions 123

A regional healthcare provider in Portland, Oregon, recently migrated its patient scheduling portal to a new cloud platform. Within days, multiple patients reported that when searching online for the clinic’s appointment system, they were directed to a website that looked identical to the official portal.

The fraudulent page appeared prominently in search engine results and prompted users to log in using their patient credentials. The URL closely resembled the legitimate domain name, and no internal DNS servers had been altered within the organization’s infrastructure.

Security analysts later determined that the attacker had created a convincing replica of the portal and manipulated search visibility so that unsuspecting users would voluntarily navigate to the malicious site.

Which type of social engineering technique best explains this attack?

Options:

A.  

Whaling

B.  

Pharming

C.  

Spear Phishing

D.  

Spimming

Discussion 0
Questions 124

As a Certified Ethical Hacker, you are assessing a corporation’s serverless cloud architecture. The organization experienced an attack where a user manipulated a function-as-a-service (FaaS) component to execute malicious commands. The root cause was traced to an insecure third-party API used within a serverless function. What is the most effective countermeasure to strengthen the security posture?

Options:

A.  

Regularly updating serverless functions to reduce vulnerabilities.

B.  

Using a Cloud Access Security Broker (CASB) to enforce third-party policies.

C.  

Deploying a Cloud-Native Security Platform (CNSP) for full cloud protection.

D.  

Implementing function-level permissions and enforcing the principle of least privilege.

Discussion 0
Questions 125

Which sophisticated DoS technique is hardest to detect and mitigate?

Options:

A.  

Distributed SQL injection DoS

B.  

Coordinated UDP flood on DNS servers

C.  

Zero-day exploit causing service crash

D.  

Smurf attack using ICMP floods

Discussion 0
Questions 126

During an ethical hacking exercise, a security analyst is testing a web application that manages confidential information and suspects it may be vulnerable to SQL injection. Which payload would most likely reveal whether the application is vulnerable to time-based blind SQL injection?

Options:

A.  

UNION SELECT NULL, NULL, NULL--

B.  

' OR ' 1 ' = ' 1 ' --

C.  

' OR IF(1=1,SLEEP(5),0)--

D.  

AND UNION ALL SELECT ' admin ' , ' admin ' --

Discussion 0
Questions 127

A penetration tester is assessing the security of a corporate wireless network that uses WPA2-Enterprise encryption with RADIUS authentication. The tester wants to perform a man-in-the-middle attack by tricking wireless clients into connecting to a rogue access point. What is the most effective method to achieve this?

Options:

A.  

Set up a fake access point with the same SSID and use a de-authentication attack

B.  

Use a brute-force attack to crack the WPA2 encryption directly

C.  

Perform a dictionary attack on the RADIUS server to retrieve credentials

D.  

Execute a Cross-Site Scripting (XSS) attack on the wireless controller ' s login page

Discussion 0
Questions 128

During an internal assessment, a penetration tester gains access to a hash dump containing NTLM password hashes from a compromised Windows system. To crack the passwords efficiently, the tester uses a high-performance CPU setup with Hashcat, attempting millions of password combinations per second. Which technique is being optimized in this scenario?

Options:

A.  

Spoof NetBIOS to impersonate a file server

B.  

Leverage hardware acceleration for cracking speed

C.  

Dump SAM contents for offline password retrieval

D.  

Exploit dictionary rules with appended symbols

Discussion 0
Questions 129

Michael, an ethical hacker at a New York-based e-commerce company, is evaluating the security of their online payment system after a recent incident where fraudulent transactions went undetected. His investigation reveals that the system uses an asymmetric encryption algorithm to ensure the authenticity of payment confirmations. He finds that the algorithm employs a public-key cryptosystem, where the sender signs the transaction with a private key, and the recipient verifies it using a corresponding public key located in a directory. During his test, Michael intercepts a signed message and notices that the algorithm supports modular exponentiation for generating digital signatures, a process critical to verifying the identity of the signatory. He aims to assess if the algorithm ' s configuration could be vulnerable to a meet-in-the-middle attack due to its key structure. Which asymmetric encryption algorithm should Michael identify as the one used by the payment system?

Options:

A.  

Diffie-Hellman

B.  

DSA

C.  

RSA

D.  

ElGamal

Discussion 0
Questions 130

In the crisp mountain air of Denver, Colorado, ethical hacker Lila Chen investigates the security framework of MedVault, a US-based healthcare platform used by regional clinics to manage patient data. During her assessment, Lila manipulates session parameters while navigating the patient portal’s dashboard. Her tests reveal a critical flaw: the system allows users to access sensitive medical records not associated with their own account, enabling unauthorized changes to private health data. Upon deeper inspection, Lila determines that the issue stems from the application allowing users to perform actions beyond their assigned roles rather than failures in encryption, unsafe object handling, or server configuration.

Which OWASP Top 10 2021 vulnerability is Lila most likely exploiting in MedVault’s web application?

Options:

A.  

Security Misconfiguration

B.  

Insecure Deserialization

C.  

Cryptographic Failures

D.  

Broken Access Control

Discussion 0
Questions 131

You are an ethical hacker at SilverRock Security, engaged by BayState Credit Union in Boston, Massachusetts, to evaluate their online loan application portal. While testing the customer dashboard, you inject crafted input into a numeric parameter. Instead of returning only the expected loan details, the response also displays sensitive employee information from another table, merged into the same page results. This behavior indicates that the attacker’s input successfully combined multiple datasets into a single output.

Based on the observed behavior, which type of SQL injection attack are you exploiting?

Options:

A.  

Error-Based SQL Injection

B.  

Blind SQL Injection

C.  

Second-Order SQL Injection

D.  

UNION SQL Injection

Discussion 0
Questions 132

A penetration tester is assessing a web application that uses dynamic SQL queries for searching users in the database. The tester suspects the search input field is vulnerable to SQL injection. What is the best approach to confirm this vulnerability?

Options:

A.  

Input DROP TABLE users; -- into the search field to test if the database query can be altered

B.  

Inject JavaScript into the search field to test for Cross-Site Scripting (XSS)

C.  

Use a directory traversal attack to access server configuration files

D.  

Perform a brute-force attack on the user login page to guess weak passwords

Discussion 0
Questions 133

During a red team engagement at a healthcare provider in Miami, ethical hacker Rachel suspects that a compromised workstation is running a sniffer in promiscuous mode. To confirm her suspicion, she sends specially crafted ICMP packets with a mismatched MAC address but a correct IP destination. Minutes later, the suspected machine responds to the probe even though ordinary systems would ignore it.

Which detection technique is Rachel most likely using to validate the presence of a sniffer?

Options:

A.  

Ping Method

B.  

ARP Method

C.  

DNS Method

D.  

Nmap sniffer-detect (NSE)

Discussion 0
Questions 134

Which WPA vulnerability allowed packet injection and decryption attacks?

Options:

A.  

Lack of AES encryption

B.  

Predictable GTK

C.  

Weak Initialization Vectors (IVs)

D.  

Weak passwords

Discussion 0
Questions 135

Which algorithm best protects encrypted traffic patterns?

Options:

A.  

PSA

B.  

AES

C.  

DES

D.  

HMAC

Discussion 0
Questions 136

In the rainy streets of Portland, Oregon, ethical hacker Ethan Brooks delves into the security layers of ShopSwift, a US-based e-commerce platform reeling from a recent data breach. Tasked with uncovering the method behind unauthorized account takeovers, Ethan examines login patterns across the platform ' s user base. His investigation reveals a surge of automated login activity across multiple accounts, with a suspiciously high success rate. Determined to trace the root cause, Ethan compiles a detailed log to assist ShopSwift ' s security team in restoring trust.

Which attack method is Ethan most likely uncovering in ShopSwift’s authentication system?

Options:

A.  

Password Spraying

B.  

Brute Force Attack

C.  

Credential Stuffing

D.  

Phishing Attacks

Discussion 0
Questions 137

During a red team exercise at a financial services firm in Phoenix, Arizona, an ethical hacker sends a phishing email with a disguised attachment to employees. The purpose is to transmit the payload into the environment so later attack steps can proceed. In the cyber kill chain model, which phase does this represent?

Options:

A.  

Reconnaissance

B.  

Exploitation

C.  

Delivery

D.  

Weaponization

Discussion 0
Questions 138

You are a security analyst at Sentinel Cyber Group, monitoring the web portal of Aspen Valley Bank in Salt Lake City, Utah. During log review, you notice repeated attempts by attackers to inject malicious strings into the login fields. However, despite these attempts, the application executes queries safely without altering their logic, since user inputs are kept separate from the SQL statements and bound as fixed values before execution.

Based on the observed defense mechanism, which SQL injection countermeasure is the application employing?

Options:

A.  

Perform user input validation

B.  

Restrict database access

C.  

Encoding the single quote

D.  

Use parameterized queries or prepared statements

Discussion 0
Questions 139

In Boston, Massachusetts, network administrator Daniel Carter is monitoring the IT infrastructure of New England Insurance, a prominent firm, after receiving alerts about sluggish system performance. While reviewing traffic patterns, Daniel observes an unusual volume of concurrent requests overwhelming critical servers. To validate his suspicion of a session hijacking attempt, he begins capturing and reviewing live network traffic to identify unauthorized session behaviors before escalating to the security team.

What detection method should Daniel use to confirm the session hijacking attack in this scenario?

Options:

A.  

Use an intrusion detection system (IDS)

B.  

Check for predictable session tokens

C.  

Monitor for ACK storms

D.  

Perform manual packet analysis using packet sniffing tools

Discussion 0
Questions 140

In sunny San Diego, California, security consultant Maya Ortiz is engaged by PacificGrid, a regional utilities provider, to analyze suspicious access patterns on their employee portal. While reviewing authentication logs, Maya notices many accounts each receive only a few login attempts before the attacker moves on to other targets; the attempts reuse a very small set of likely credentials across a large number of accounts and are spread out over several days and IP ranges to avoid triggering automated lockouts. Several low-privilege accounts were successfully accessed before the pattern was detected. Maya prepares a forensic timeline to help PacificGrid contain the incident.

Which attack technique is being used?

Options:

A.  

Session Hijacking

B.  

Password Spraying

C.  

Cross-Site Request Forgery (CSRF)

D.  

Brute Force Attack

Discussion 0
Questions 141

Which of the following best describes an attack that altered the contents of two critical files?

Options:

A.  

Availability

B.  

Authentication

C.  

Confidentially

D.  

Integrity

Discussion 0
Questions 142

A Nessus scan reveals a critical SSH vulnerability (CVSS 9.0) allowing potential remote code execution on a Linux server. What action should be immediately prioritized?

Options:

A.  

Redirect SSH traffic to another server

B.  

Treat the finding as a possible false positive

C.  

Immediately apply vendor patches and reboot during scheduled downtime

D.  

Temporarily isolate the affected server, conduct a forensic audit, and then patch

Discussion 0
Questions 143

During a security penetration test at ABC Financial Services in Miami, Florida, on July 9, 2025, ethical hacker Javier Morales targets the company’s online banking portal to assess its resilience. Over several hours, the portal’s web server begins to falter, with legitimate users reporting inability to log in or complete transactions. The IT team notices the server is struggling to accept new connections, as its maximum connection limit is nearly reached, despite no significant spike in overall network traffic. Javier’s controlled test, run from a secure system, logs interactions to simulate a real attack, aiming to evaluate the IT team’s ability to identify the threat.

What DoS or DDoS attack technique is Javier’s exercise primarily simulating?

Options:

A.  

Slowloris Attack

B.  

UDP Flood Attack

C.  

Peer-to-Peer Attack

D.  

SYN Flood Attack

Discussion 0
Questions 144

Steve, an attacker, created a fake profile on a social media website and sent a request to Stella. Stella was enthralled by Steve ' s profile picture and the description given for his profile, and she initiated a conversation with him soon after accepting the request. After a few days, Steve started asking about her company details and eventually gathered all the essential information regarding her company. What is the social engineering technique Steve employed in the above scenario?

Options:

A.  

Honey trap

B.  

Diversion theft

C.  

Piggybacking

D.  

Baiting

Discussion 0
Questions 145

On July 25, 2025, during a security assessment at Apex Technologies in Boston, Massachusetts, ethical hacker Sophia Patel conducts a penetration test to evaluate the company’s defenses against a simulated DDoS attack targeting their e-commerce platform. The simulated attack floods the platform with traffic from multiple sources, attempting to overwhelm server resources. The IT team activates a specific tool that successfully mitigates this attack by distributing traffic across multiple servers and filtering malicious requests. Sophia’s test aims to verify the effectiveness of this tool in maintaining service availability.

Which DoS DDoS protection tool is most likely being utilized by the IT team in this scenario?

Options:

A.  

Web Application Firewall WAF

B.  

Load Balancer

C.  

Intrusion Prevention System IPS

D.  

Firewall

Discussion 0
Questions 146

Which advanced session-hijacking technique is hardest to detect and mitigate?

Options:

A.  

Covert XSS attack

B.  

Man-in-the-Browser (MitB) attack

C.  

Passive sniffing on Wi-Fi

D.  

Session fixation

Discussion 0
Questions 147

An IDS generates alerts during normal user activity. What is the most likely cause?

Options:

A.  

Firewall failure

B.  

IDS outdated

C.  

Excessive IDS sensitivity causing false positives

D.  

Users triggering protocols

Discussion 0
Questions 148

A security consultant is performing an authorized assessment of a regional healthcare provider’s patient portal in Portland, Oregon. During testing, he observes that authenticated users are assigned session identifiers embedded within URL parameters after login.

To evaluate the robustness of the session management implementation, he initiates multiple authentication requests in rapid succession using controlled test accounts. He then compares the issued identifiers and notices that although parts of the value remain constant, certain segments change in a predictable progression over time.

By analyzing the incremental pattern across a controlled batch of issued identifiers generated within the same time window, he is able to anticipate future valid identifiers without capturing traffic from other users.

Which token prediction mechanism best explains the weakness identified in this scenario?

Options:

A.  

Small Token Space

B.  

Timestamp-based Tokens

C.  

Sequential Tokens

D.  

Weak Random Number Generator (PRNG)

Discussion 0
Questions 149

A regional hospital network is conducting incident containment after discovering that an internal file server was accessed by unauthorized actors. While forensic analysis is ongoing, a security engineer must immediately protect sensitive medical records stored on a mounted partition without shutting down the system.

The solution must support strong encryption, including 256-bit AES, allow creation of encrypted containers within existing storage volumes, and provide the capability to conceal protected data inside standard-looking volumes to reduce visibility during continued investigation.

Select the disk encryption tool that best satisfies these operational and security requirements.

Options:

A.  

FileVault

B.  

Rohos Disk Encryption

C.  

VeraCrypt

D.  

BitLocker Drive Encryption

Discussion 0
Questions 150

As part of a penetration test for a financial firm’s smart headquarters in Denver, Colorado, ethical hacker Jordan Lee begins evaluating the IoT infrastructure responsible for lighting, HVAC, and badge-controlled access. Jordan documents details such as device models, manufacturer names, firmware versions, and supported protocols like Zigbee and BLE. This information is used to understand the device ecosystem. Which step of the IoT hacking methodology is being carried out in this phase?

Options:

A.  

Information gathering

B.  

Launch attacks

C.  

Vulnerability scanning

D.  

Gain remote access

Discussion 0
Questions 151

John, a penetration tester at a Los Angeles-based online gaming company, is analyzing the company ' s cloud infrastructure after a recent security breach caused unexpected downtime and delayed alerts. His investigation reveals that the attackers remained undetected, due to the absence of mechanisms that track function-level activity and capture anomalous events. The backend architecture for matchmaking and in-game purchases is serverless, increasing the importance of robust security measures.

So, which cloud computing threat should John prioritize to prevent similar breaches?

Options:

A.  

Insufficient logging and monitoring

B.  

Privilege escalation

C.  

Loss of governance

D.  

Side-channel attacks

Discussion 0
Questions 152

During an investigation, an ethical hacker discovers that a web application’s API has been compromised, leading to unauthorized access and data manipulation. The attacker is using webhooks and a webshell. To prevent further exploitation, which of the following actions should be taken?

Options:

A.  

Implement a Web Application Firewall (WAF) with rules to block webshell traffic and increase the logging verbosity of webhooks.

B.  

Perform regular code reviews for the webhooks and modify the API to block connections from unknown IP addresses.

C.  

Harden the web server security, add multi-factor authentication for API users, and restrict the execution of scripts server-side.

D.  

Implement input validation on all API endpoints, review webhook payloads, and schedule regular scanning for webshells.

Discussion 0
Questions 153

You are an ethical hacker at Nexus Cybersecurity, contracted to perform a penetration test for BlueRidge Retail, a US-based e-commerce company in Atlanta, Georgia. While testing their online store’s product search page, you attempt to inject a malicious query into the URL to extract customer data. The application is protected by a web application firewall WAF that blocks standard SQL injection attempts. To bypass this, you modify your input to split the query into multiple parts, ensuring the malicious instructions are not detected as a single signature. For example, you craft the URL as products.php?id=1+UNION+SE+LECT+1,2, which successfully retrieves unauthorized data. Based on the observed behavior, which SQL injection evasion technique are you employing?

Options:

A.  

Hex Encoding

B.  

String Concatenation

C.  

In-line Comment

D.  

Null Byte

Discussion 0
Questions 154

During a cloud security assessment, it was discovered that a former employee still had access to critical resources months after leaving the organization. Which practice would have most effectively prevented this issue?

Options:

A.  

Using multi-cloud deployment models

B.  

Implementing real-time traffic analysis

C.  

Conducting regular penetration tests

D.  

Enforcing timely user de-provisioning

Discussion 0
Questions 155

At TechTrend Innovations in Silicon Valley, network administrator Jake Henderson reviews the configuration of their web infrastructure. While inspecting the web server setup, he identifies the directory that stores the publicly accessible website content such as HTML files, images, and client-side scripts. Jake highlights this area as a frequent target for attackers, since improper permissions could expose sensitive files to unauthorized users.

Which web server component is Jake analyzing in this scenario?

Options:

A.  

Application Server

B.  

Document Root

C.  

HTTP Server (Core)

D.  

Virtual Document Tree

Discussion 0
Questions 156

An ethical hacker needs to enumerate user accounts and shared resources within a company ' s internal network without raising any security alerts. The network consists of Windows servers running default configurations. Which method should the hacker use to gather this information covertly?

Options:

A.  

Deploy a packet sniffer to capture and analyze network traffic

B.  

Perform a DNS zone transfer to obtain internal domain details

C.  

Exploit null sessions to connect anonymously to the IPC$ share

D.  

Utilize SNMP queries to extract user information from network devices

Discussion 0
Questions 157

On a busy Monday morning at Horizon Financial Services in Chicago, accounts assistant Clara Nguyen receives an email that appears to come from the company ' s IT department. The email, addressed specifically to Clara and mentioning her role in the accounts team, warns of a critical system vulnerability requiring immediate action. It includes a link to a login page resembling the company ' s internal portal, urging her to update her credentials to prevent account suspension. The email ' s sender address looks legitimate, but Clara notices a slight misspelling in the domain name.

What social engineering technique is being attempted against Clara?

Options:

A.  

Spear Phishing

B.  

Impersonation

C.  

Quid Pro Quo

D.  

Vishing

Discussion 0
Questions 158

Scenario: Joe turns on his home computer to access personal online banking. When he enters the URL www.bank.com, the website is displayed, but it prompts him to re-enter his credentials as if he has never visited the site before. When he examines the website URL closer, he finds that the site is not secure and the web address appears different. What type of attack is he experiencing?

Options:

A.  

DNS hijacking

B.  

ARP cache poisoning

C.  

DHCP spoofing

D.  

DoS attack

Discussion 0
Questions 159

A penetration tester performs a vulnerability scan on a company’s web server and identifies several medium-risk vulnerabilities related to misconfigured settings. What should the tester do to verify the vulnerabilities?

Options:

A.  

Use publicly available tools to exploit the vulnerabilities and confirm their impact

B.  

Ignore the vulnerabilities since they are medium-risk

C.  

Perform a brute-force attack on the web server ' s login page

D.  

Conduct a denial-of-service (DoS) attack to test the server ' s resilience

Discussion 0
Questions 160

A system’s audit logs are not centralized. Which attack phase is hardest to detect?

Options:

A.  

Initial access

B.  

Lateral movement

C.  

Delivery

D.  

Recon

Discussion 0
Questions 161

You are Michael Rivera, a cybersecurity consultant at FortiSec Solutions, hired to strengthen the wireless network of DesertTech Innovations, a startup in Phoenix, Arizona. After a recent penetration test revealed vulnerabilities, the IT manager, Lisa Nguyen, asks you to recommend a defense mechanism to prevent unauthorized devices from connecting to the corporate Wi-Fi. You suggest a method that requires each connecting device to authenticate through a centralized server using a unique username and password. Based on the described approach, which wireless security countermeasure should DesertTech implement?

Options:

A.  

Use 802.1X Authentication

B.  

Disable TKIP

C.  

MAC Address Filtering

D.  

Upgrade to WPA3

Discussion 0
Questions 162

Which of the following is one primary difference between a malicious hacker and an ethical hacker?

Options:

A.  

Malicious hackers use different tools and techniques than ethical hackers use.

B.  

Ethical hackers obtain permission before bringing down servers or stealing credit card databases.

C.  

Malicious hackers are more advanced than ethical hackers because they can use any technique to attack a system or network.

D.  

Ethical hackers use the same methods but strive to do no harm.

Discussion 0
Questions 163

During a red team exercise at Horizon Financial Services in Chicago, ethical hacker Clara crafts an email designed to trick the company’s CEO. The message, disguised as an urgent memo from the legal department, warns of a pending lawsuit and includes a link to a fake internal portal requesting the executive’s credentials. Unlike generic phishing, this attack is tailored specifically toward a high-ranking individual with decision-making authority.

Options:

A.  

Whaling

B.  

Spear Phishing

C.  

Clone Phishing

D.  

Consent Phishing

Discussion 0
Questions 164

A regional logistics provider in Charlotte, North Carolina operates its shipment tracking and partner API services on an Apache web platform configured to support a modern multiplexed communication protocol to improve efficiency under concurrent load. During a controlled stress assessment, testers simulate sustained client activity that repeatedly initiates and completes numerous lightweight exchanges over persistent connections.

Over time, system monitoring reveals that memory utilization steadily increases despite stable request volume and no proportional rise in active sessions. Even after the simulated clients disconnect normally, resource usage does not return to baseline levels. After several cycles, the service becomes sluggish and must be restarted to restore normal responsiveness. No unusual disk activity or database errors are observed during the test window.

The behavior is only present when the multiplexed protocol mode is enabled; reverting to legacy handling eliminates the issue.

Which Apache vulnerability best explains this behavior?

Options:

A.  

DoS in HTTP/2 with Initial Window Size 0

B.  

HTTP/2 Stream Memory Not Reclaimed on RST

C.  

Insecure Default Configuration

D.  

mod_macro Buffer Over-read

Discussion 0
Questions 165

You are an ethical hacker at RedOak Cyber Solutions, contracted to perform a penetration test for MetroHealth Hospital in Cleveland, Ohio. While assessing the hospital ' s appointment booking portal, you craft and submit multiple malicious inputs into the patient search field. One of your payloads successfully manipulates the backend query, returning additional appointment data that was not intended to be displayed.

Based on the observed behavior, which step of the SQL injection methodology are you performing?

Options:

A.  

Identifying Data Entry Paths

B.  

Launching SQL Injection Attacks

C.  

Database Enumeration

D.  

Information Gathering and Vulnerability Detection

Discussion 0
Questions 166

During an executive-level incident review at HarborTech Industries in Baltimore, Maryland, analysts categorize key elements of a recent intrusion. They identify the organization that orchestrated the attack, document the malicious infrastructure used to reach internal systems, outline the technical approach employed to exploit weaknesses, and specify which internal business unit was affected.

Within the Diamond Model of Intrusion Analysis, which element represents the technical approach used to carry out the attack?

Options:

A.  

Adversary

B.  

Infrastructure

C.  

Capability

D.  

Victim

Discussion 0
Questions 167

You are a cybersecurity analyst at a global banking corporation and suspect a backdoor attack due to abnormal outbound traffic during non-working hours, unexplained reboots, and modified system files. Which combination of measures would be most effective to accurately identify and neutralize the backdoor while ensuring system integrity?

Options:

A.  

Review firewall logs, analyze traffic, and immediately reboot systems

B.  

Monitor system and file activity, apply anomaly detection, and use advanced anti-malware tools

C.  

Enforce strong passwords, MFA, and regular vulnerability assessments

D.  

Apply ACLs, patch systems, and audit user privileges

Discussion 0
Questions 168

During a stealth penetration test at a defense research facility, ethical hacker Daniel installs a payload that survives even after multiple operating system reinstalls. The implant resides deep inside the system hardware and executes before the OS is loaded, ensuring that forensic scans and antivirus tools at the OS level cannot detect or remove it. Administrators notice unusual activity on network cards and storage devices, but repeated scans show no malware traces within the file system.

Which type of rootkit most likely enabled this level of persistence?

Options:

A.  

Boot-Loader-Level Rootkit

B.  

Hypervisor-Level Rootkit

C.  

Kernel-Level Rootkit

D.  

Hardware/Firmware Rootkit

Discussion 0
Questions 169

A media streaming company in Los Angeles, California engages a certified ethical hacker to evaluate the resilience of its cloud-hosted infrastructure. After initial access is obtained through an exposed credential in a development repository, the tester systematically modifies logging configurations, establishes alternate access keys for persistence, and documents privilege relationships between services within the tenant.

The tester’s actions are focused on maintaining continued access and mapping the internal structure of the environment after initial compromise has occurred.

Within the cloud attack lifecycle, which phase best represents this stage of activity?

Options:

A.  

Exploitation

B.  

Information Gathering

C.  

Vulnerability Assessment

D.  

Post-Exploitation

Discussion 0
Questions 170

An energy infrastructure company in Tulsa, Oklahoma initiated a controlled phishing simulation targeting multiple operational departments.

The test email claimed to originate from the corporate compliance office and instructed employees to “complete a mandatory regulatory update within the next 30 minutes to avoid account suspension.” The message used a broad salutation instead of employee names and lacked the standard corporate signature footer normally appended to official communications.

Additionally, security analysts observed that the embedded hyperlink displayed the organization’s domain in the message body; however, when examined more closely, the actual destination resolved to a shortened external URL redirecting to an unrelated host.

From a defensive analysis standpoint, which indicator provides the strongest technical validation that the message is malicious?

Options:

Discussion 0
Questions 171

A web application allows users to upload files and later include them in pages dynamically. Attackers exploit this to execute code. Which vulnerability exists?

Options:

A.  

LFI

B.  

RFI

C.  

CSRF

D.  

XSS

Discussion 0
Questions 172

A financial institution ' s online banking platform is experiencing intermittent downtime caused by a sophisticated DDoS attack that combines SYN floods and HTTP GET floods from a distributed botnet. Standard firewalls and load balancers cannot mitigate the attack without affecting legitimate users. To protect their infrastructure and maintain service availability, which advanced mitigation strategy should the institution implement?

Options:

A.  

Configure firewalls to block all incoming SYN and HTTP requests from external IPs

B.  

Increase server bandwidth and apply basic rate limiting on incoming traffic

C.  

Deploy an Intrusion Prevention System (IPS) with deep packet inspection capabilities

D.  

Utilize a cloud-based DDoS protection service that offers multi-layer traffic scrubbing and auto-scaling

Discussion 0
Questions 173

During a security assessment in San Francisco, an ethical hacker is tasked with evaluating a network ' s resilience against stealthy reconnaissance attempts. The hacker needs to employ a scanning technique that leverages TCP flags to evade detection by intrusion detection systems, relying on the target ' s response behavior to infer port states without completing a full connection. Which approach best aligns with this strategy, ensuring minimal visibility during the assessment?

Options:

A.  

TCP Connect Scan

B.  

Network Scanning

C.  

FIN Scan

D.  

NULL Scan

Discussion 0
Questions 174

A sophisticated injection attack bypassed validation using obfuscation. What is the best future defense?

Options:

A.  

Continuous code review and penetration testing

B.  

Deploy WAF with evasion detection

C.  

SIEM monitoring

D.  

Enforce 2FA

Discussion 0
Questions 175

A cybersecurity team at a regional healthcare provider is conducting an internal red team exercise to assess their exposure to service enumeration attacks. Amanda, a senior penetration tester, is assigned to probe the internal network for services that may reveal usernames, group information, or system details without requiring prior authentication. She decides to target common services running on specific ports that are often misconfigured or loosely monitored. During her reconnaissance, Amanda identifies several open ports across various hosts and must now prioritize which ones to probe first for maximum information gain related to enumeration. Which of the following services should Amanda target as a priority to enumerate usernames and group information without authentication?

Options:

A.  

TCP 139 and UDP 137, 138

B.  

TCP 21 and UDP 137, 138

C.  

TCP 23 and UDP 137, 138

D.  

TCP 25 and UDP 133

Discussion 0
Questions 176

The company ABC recently contracts a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. Which of the following options can be useful to ensure the integrity of the data?

Options:

A.  

The document can be sent to the accountant using an exclusive USB for that document

B.  

The CFO can use an excel file with a password

C.  

The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document

D.  

The CFO can use a hash algorithm in the document once he approved the financial statements

Discussion 0
Questions 177

After the completion of the pen test, you have provided the client with a list of controls to implement to reduce the identified risk. What term best describes the risk that remains after the controls have been implemented?

Options:

A.  

Inherent risk

B.  

Residual risk

C.  

Gap analysis

D.  

Total risk

Discussion 0
Questions 178

You discover an unpatched Android permission-handling vulnerability on a device with fully updated antivirus software. What is the most effective exploitation approach that avoids antivirus detection?

Options:

A.  

Develop a custom exploit using obfuscation techniques

B.  

Use Metasploit to deploy a known payload

C.  

Install a rootkit to manipulate the device

D.  

Use SMS phishing to trick the user

Discussion 0
Questions 179

An ethical hacker is conducting a penetration test on a company’s network with full knowledge and permission from the organization. What is this type of hacking called?

Options:

A.  

Blue Hat Hacking

B.  

Grey Hat Hacking

C.  

Black Hat Hacking

D.  

White Hat Hacking

Discussion 0
Questions 180

During a quarterly vulnerability management review at RedCore Motors, Priya finalizes the deployment of Nessus Essentials across the company ' s IT infrastructure. The solution is selected for its ability to support diverse technologies including operating systems, databases, web servers, and virtual environments. While preparing a training session for junior analysts, Priya asks them to identify a capability that Nessus Essentials is specifically designed to provide as part of its scanning process.

Which capability is Nessus Essentials specifically designed to provide?

Options:

A.  

Patch management for operating systems and third-party applications

B.  

High-speed asset discovery

C.  

Checks for outdated versions across a wide range of server and service technologies

D.  

Agent-based detection

Discussion 0
Questions 181

Ethical hacker Ryan Brooks, a skilled penetration tester from Austin, Texas, was hired by Skyline Aeronautics, a leading aerospace firm in Denver, to conduct a security assessment. One stormy morning, Ryan noticed an unexpected lag in the routine system update process while running his tests, sparking his curiosity. During a late-night session, he observed a junior analyst, Chris Miller, cautiously modifying a legacy server’s configuration, including a scheduled task set to a specific date. The lead developer, Jessica Hayes, casually mentioned receiving an odd email from an unfamiliar source, which she ignored as clutter. As Ryan probed deeper, he detected a faint increase in network activity only after the scheduled date passed, and a systems admin, Mark Thompson, quickly pointed out some unusual code traces on a dormant workstation.

Which type of threat best characterizes this attack?

Options:

A.  

Logic Bomb

B.  

Fileless Malware

C.  

Advanced Persistent Threat APT

D.  

Ransomware

Discussion 0
Questions 182

A penetration tester suspects that a web application ' s product search feature is vulnerable to SQL injection. The tester needs to confirm this by manipulating the SQL query. What is the best technique to test for SQL injection?

Options:

A.  

Inject a malicious script into the search field to test for Cross-Site Scripting (XSS)

B.  

Use directory traversal syntax in the search field to access server files

C.  

Input 1 OR 1=1 in the search field to retrieve all products from the database

D.  

Insert admin ' — in the search field to attempt bypassing authentication

Discussion 0
Questions 183

What is GINA?

Options:

A.  

GUI Installed Network Application CLASS

B.  

Gateway Interface Network Application

C.  

Graphical Identification and Authentication DLL

D.  

Global Internet National Authority (G-USA)

Discussion 0
Questions 184

During a penetration test at a logistics company in Atlanta, Georgia, you examine the configuration of network devices and discover that they rely on legacy communication mechanisms lacking encryption and integrity checks. These mechanisms allow neighboring systems to exchange operational data without verification, exposing the infrastructure to potential manipulation. What type of vulnerability is most clearly present?

Options:

A.  

Firewall vulnerabilities

B.  

Lack of password protection

C.  

Lack of authentication

D.  

Insecure routing protocols

Discussion 0
Questions 185

A multinational payment processor conducts a long-term risk assessment to evaluate the durability of its encrypted archives against future computational advances. Internal analysts warn that if large-scale quantum computers become operational, currently deployed public-key schemes protecting stored customer data may become vulnerable to rapid key recovery.

To maintain long-term confidentiality of archived financial records, the security architecture team must implement a defensive strategy that directly addresses cryptographic resilience rather than relying solely on network segmentation or development policy controls.

Determine the most appropriate mitigation to protect stored data against quantum-enabled decryption capabilities.

Options:

A.  

Use quantum-specific firewalls to protect quantum communication channels

B.  

Break data into fragments and distribute it across multiple locations

C.  

Encrypt stored data with quantum-resistant algorithms

D.  

Include quantum-resistance checks in SDLC and code review processes

Discussion 0
Questions 186

Arjun Mehta, a red team specialist at Sentinel Dynamics, is conducting a controlled reconnaissance assessment against the company’s perimeter network. During testing, the security operations team observes that the firewall logs display several different originating systems associated with the same scanning activity. Arjun’s objective is to ensure that his actual testing machine cannot be easily distinguished from other recorded entries.

What technique is Arjun using in this scenario?

Options:

A.  

Source Routing

B.  

IP Address Decoy

C.  

Source Port Manipulation

D.  

IP Address Spoofing

Discussion 0
Questions 187

A penetration tester is tasked with assessing the security of a smart home IoT device that communicates with a mobile app over an unencrypted connection. The tester wants to intercept the communication and extract sensitive information. What is the most effective approach to exploit this vulnerability?

Options:

A.  

Perform a brute-force attack on the device ' s Wi-Fi credentials

B.  

Use a man-in-the-middle (MitM) attack to intercept and analyze the unencrypted traffic

C.  

Execute a SQL injection attack on the IoT device’s cloud management portal

D.  

Use a dictionary attack to guess the admin login credentials of the device

Discussion 0
Questions 188

A penetration tester is tasked with mapping an organization ' s network while avoiding detection by sophisticated intrusion detection systems (IDS). The organization employs advanced IDS capable of recognizing common scanning patterns. Which scanning technique should the tester use to effectively discover live hosts and open ports without triggering the IDS?

Options:

A.  

Execute a FIN scan by sending TCP packets with the FIN flag set

B.  

Use an Idle scan leveraging a third-party zombie host

C.  

Conduct a TCP Connect scan using randomized port sequences

D.  

Perform an ICMP Echo scan to ping all network devices

Discussion 0
Questions 189

What indicates advanced persistent threat behavior?

Options:

A.  

Long dwell time

B.  

Malware spam

C.  

One-time exploit

D.  

Brute force

Discussion 0
Questions 190

A penetration tester is investigating a web server that allows unrestricted file uploads without validating file types. Which technique should be used to exploit this vulnerability and potentially gain control of the server?

Options:

A.  

Perform a SQL injection attack to extract sensitive database information

B.  

Upload a shell script disguised as an image file to execute commands on the server

C.  

Conduct a brute-force attack on the server ' s FTP service to gain access

D.  

Use a Cross-Site Scripting (XSS) attack to steal user session cookies

Discussion 0
Questions 191

You are performing a security audit for a regional hospital in Dallas, Texas. While monitoring the network, you discover that an unknown actor has been silently capturing clear-text credentials and analyzing unencrypted traffic flowing across the internal Wi-Fi network. No modifications have been made to the data, and the attack remained undetected until your assessment. Based on this activity, what type of attack is most likely being conducted?

Options:

A.  

Passive attack

B.  

Distribution attack

C.  

Close-in attack

D.  

Insider attack

Discussion 0
Questions 192

Working as an Information Security Analyst at a technology firm, you are designing training material for employees about the dangers of session hijacking. As part of the training, you want to explain how attackers could use sidejacking to compromise user accounts. Which of the following scenarios most accurately describes a sidejacking attack?

Options:

A.  

An attacker exploits a vulnerability in the company’s network firewall to gain unauthorized access to internal systems.

B.  

An attacker intercepts network traffic, captures unencrypted session cookies, and uses them to impersonate the user.

C.  

An attacker uses social engineering techniques to trick an employee into revealing their password.

D.  

An attacker convinces an employee to visit a malicious website that injects a harmful script into their browser.

Discussion 0
Questions 193

In a security assessment conducted in New York, Sarah, an ethical hacker, is evaluating a corporate network to enhance its protection against potential threats. She aims to gather essential data about available access points to guide her analysis. Which scanning technique should Sarah apply to meet this objective while adhering to the organization ' s ethical guidelines?

Options:

A.  

Vulnerability Scanning

B.  

Port Scanning

C.  

Topology Mapping

D.  

Network Scanning

Discussion 0
Questions 194

In Seattle, Washington, ethical hacker Mia Chen is tasked with testing the network defenses of Pacific Shipping Co., a major logistics firm. During her penetration test, Mia targets the company ' s external-facing web server, which handles customer tracking requests. She observes that the security system filtering traffic to this server analyzes incoming SSH and DNS requests to block unauthorized access attempts. Mia plans to craft specific payloads to bypass this system to expose vulnerabilities to the IT department.

Which security system is Mia attempting to bypass during her penetration test of Pacific Shipping Co. ' s web server?

Options:

A.  

Stateful Multilayer Inspection Firewall

B.  

Application-Level Firewall

C.  

Packet Filtering Firewall

D.  

Circuit-Level Gateway Firewall

Discussion 0
Questions 195

During a scheduled red team engagement at a regional investment firm in Phoenix, Arizona, security consultants were permitted limited after-hours access to employee workstations. As part of the evaluation, a small intermediary device was placed inline between a keyboard and its connected desktop system.

Over time, the device began forwarding captured keystroke activity through the company’s established wireless environment, allowing the assessment team to collect periodic log data without interacting further with the workstation.

What type of keylogger does this scenario describe?

Options:

A.  

Hardware Keylogger

B.  

Acoustic/CAM Keylogger

C.  

Wi-Fi Keylogger

D.  

Bluetooth Keylogger

Discussion 0
Questions 196

In the bustling tech hub of Silicon Valley, cybersecurity investigator Elena Martinez found herself deep into a late-night investigation at Horizon Tech Solutions on July 7, 2025. The company had reported sporadic network disruptions affecting their research team ' s access to critical project files. Elena, working under the cover of a maintenance window from midnight to 3 AM PDT, began monitoring the internal network, focusing on a subnet reserved for the R & D department. She noticed a pattern of failed connection attempts logged just before each disruption, with multiple hosts reporting temporary IP address conflicts. Suspecting foul play, Elena deployed a discreet test to simulate an internal threat scenario. Shortly afterward, several workstations began showing unfamiliar gateway settings and redirected users to misleading login portals during routine access attempts. Despite these anomalies, no security alerts were triggered.

What type of attack technique did Elena most likely simulate?

Options:

A.  

DHCP Starvation Attack

B.  

Packet Sniffing

C.  

MAC Flooding

D.  

Rogue DHCP Server Attack

Discussion 0
Questions 197

A penetration tester is evaluating the security of a mobile application and discovers that it lacks proper input validation. The tester suspects that the application is vulnerable to a malicious code injection attack. What is the most effective way to confirm and exploit this vulnerability?

Options:

A.  

Perform a brute-force attack on the application ' s login page to guess weak credentials

B.  

Inject a malicious JavaScript code into the input fields and observe the application ' s behavior

C.  

Use directory traversal to access sensitive files stored in the application ' s internal storage

D.  

Execute a dictionary attack on the mobile app ' s encryption algorithm

Discussion 0
Questions 198

On July 9, 2025, during a security penetration test at MedSecure Health in Phoenix, Arizona, the ethical hacking team evaluates the resilience of the company ' s patient portal system. Ethical hacker Aisha Khan initiates a controlled test that generates sustained traffic pressure against the web application servers. As system responsiveness declines, the IT operations team reallocates backend resources, suspending lower-priority modules such as system alerts and notification services, allowing high-priority functions like prescription refills and patient check-ins to remain accessible. Aisha’s controlled simulation is designed to assess the IT team’s ability to maintain critical functionality under partial resource exhaustion.

What DoS DDoS countermeasure strategies is Aisha’s exercise primarily simulating?

Options:

Discussion 0
Questions 199

While evaluating a smart card implementation, a security analyst observes that an attacker is measuring fluctuations in power consumption and timing variations during encryption operations on the chip. The attacker uses this information to infer secret keys used within the device. What type of exploitation is being carried out?

Options:

A.  

Disrupt control flow to modify instructions

B.  

Observe hardware signals to deduce secrets

C.  

Crack hashes using statistical collisions

D.  

Force session resets through input flooding

Discussion 0
Questions 200

Which strategy best mitigates session hijacking?

Options:

A.  

IPsec VPN encryption

B.  

Physical security

C.  

Network IPS

D.  

Security awareness training

Discussion 0
Questions 201

A telecommunications provider in Toronto operates a monitoring platform that analyzes inbound traffic streams during suspected denial-of-service conditions. The system converts traffic measurements into signal components and evaluates their energy across multiple frequency ranges to distinguish abnormal traffic bursts from background network noise.

Rather than focusing on traffic baselines or identifying the exact statistical breakpoint where behavior changes, the platform identifies anomalies by decomposing traffic signals into spectral components for analysis.

Which DDoS detection technique is being used in this scenario?

Options:

A.  

Traffic Pattern Analysis

B.  

Sequential Change-Point Detection

C.  

Activity Profiling

D.  

Wavelet-Based Signal Analysis

Discussion 0
Questions 202

A Nessus scan reports a CVSS 9.0 SSH vulnerability allowing remote code execution. What should be immediately prioritized?

Options:

A.  

Apply the vendor patch and reboot during maintenance

B.  

Dismiss it as a false positive if unverified

C.  

Reroute SSH traffic to another server

D.  

Isolate the server, audit it, and apply patches

Discussion 0
Questions 203

During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?

Options:

A.  

DNS Scheme

B.  

DNSSEC

C.  

DynDNS

D.  

Split DNS

Discussion 0
Questions 204

A penetration tester is hired to legally assess the security of a company ' s network by identifying vulnerabilities and attempting to exploit them. What type of hacker is this?

Options:

A.  

Black Hat

B.  

Grey Hat

C.  

Script Kiddie

D.  

White Hat

Discussion 0
Questions 205

An attacker accesses a server using reused NTLM hashes without cracking passwords. What attack is this?

Options:

A.  

Brute force

B.  

Replay

C.  

Kerberoasting

D.  

Pass-the-hash

Discussion 0
Questions 206

While analyzing suspicious network activity, you observe a slow, stealthy scanning technique that is difficult to trace back to the attacker. Which scenario best describes the scanning technique being used?

Options:

A.  

The attacker sends FIN packets to infer port states based on responses

B.  

The attacker uses a “zombie” machine to perform scans, hiding their true identity

C.  

The attacker performs full TCP connect scans on all ports

D.  

The attacker sends packets with all TCP flags set

Discussion 0
Questions 207

Michael, an ethical hacker at a New York-based e-commerce company, is evaluating the security of their online payment system after a recent incident where fraudulent transactions went undetected. His investigation reveals that the system uses an asymmetric encryption algorithm to ensure the authenticity of payment confirmations. He finds that the algorithm employs a public-key cryptosystem, where the sender signs the transaction with a private key, and the recipient verifies it using a corresponding public key located in a directory. During his test, Michael intercepts a signed message and notices that the algorithm supports modular exponentiation for generating digital signatures, a process critical for verifying the identity of the signatory. He aims to assess if the algorithm’s configuration could be vulnerable to a man-in-the-middle attack due to its key structure.

Which asymmetric encryption algorithm should Michael identify as the one used by the payment system?

Options:

A.  

Diffie-Hellman

B.  

RSA

C.  

ElGamal

D.  

DSA

Discussion 0
Questions 208

As a cybersecurity professional at XYZ Corporation, you are tasked with investigating anomalies in system logs that suggest potential unauthorized activity. System administrators have detected repeated failed login attempts on a critical server, followed by a sudden surge in outbound data traffic. These indicators suggest a possible compromise. Given the sensitive nature of the system and the sophistication of the threat, what should be your initial course of action?

Options:

A.  

Conduct real-time monitoring of the server, analyze logs for abnormal patterns, and identify the nature of the activity to formulate immediate countermeasures.

B.  

Conduct a comprehensive audit of all outbound traffic and analyze destination IP addresses to map the attacker’s network.

C.  

Immediately reset all server credentials and instruct all users to change their passwords.

D.  

Immediately disconnect the affected server from the network to prevent further data exfiltration.

Discussion 0
Questions 209

Which of the following program infects the system boot sector and the executable files at the same time?

Options:

A.  

Stealth virus

B.  

Polymorphic virus

C.  

Macro virus

D.  

Multipartite Virus

Discussion 0
Questions 210

During a red team test, a web application dynamically builds SQL queries using a numeric URL parameter. The tester sends the following request:

http://vulnerableapp.local/view.php?id=1; DROP TABLE users;

The application throws errors and the users table is deleted. Which SQL injection technique was used?

Options:

A.  

UNION-based SQL injection

B.  

Stacked (Piggybacked) queries

C.  

Boolean-based SQL injection

D.  

Error-based SQL injection

Discussion 0
Questions 211

A penetration tester is assessing an IoT thermostat used in a smart home system. The device communicates with a cloud server for updates and commands. The tester discovers that communication between the device and the cloud server is not encrypted. What is the most effective way to exploit this vulnerability?

Options:

A.  

Conduct a Cross-Site Scripting (XSS) attack on the thermostat’s web interface

B.  

Perform a brute-force attack on the thermostat’s local admin login

C.  

Execute a SQL injection attack on the cloud server ' s login page

D.  

Use a man-in-the-middle (MitM) attack to intercept and manipulate unencrypted communication

Discussion 0
Questions 212

During a penetration test at Triangle FinTech in Raleigh, North Carolina, ethical hacker Ethan attempts to bypass the company ' s perimeter firewall. Instead of sending obvious malicious payloads, he encapsulates his traffic inside standard web requests on port 80, blending in with normal browsing activity. This method allows his packets to slip past perimeter defenses that are not performing deep application inspection.

Which firewall evasion technique is Ethan most likely using?

Options:

A.  

HTTP Tunneling

B.  

Source Routing

C.  

Tiny Fragments

D.  

DNS Tunneling

Discussion 0
Questions 213

Which action would most effectively increase the security of a virtual-hosted web server?

Options:

A.  

Implement LAMP architecture

B.  

Change IP addresses regularly

C.  

Regularly update and patch server software

D.  

Move document root to another disk

Discussion 0
Questions 214

A penetration tester alters the " file " parameter in a web application (e.g., view?file=report.txt) to ../../../../etc/passwd and successfully accesses restricted system files. What attack method does this scenario illustrate?

Options:

A.  

Conduct a brute-force attack to obtain administrative credentials

B.  

Use directory traversal sequences in URL parameters to retrieve unauthorized system content

C.  

Inject malicious scripts into web pages to manipulate content via XSS vulnerabilities

D.  

Exploit buffer overflow issues by injecting oversized data in HTTP request headers

Discussion 0
Questions 215

You are a security analyst conducting a footprinting exercise for a new client to gather information without direct interaction. After using search engines and public databases, you consider using Google Hacking (Google Dorking) techniques to uncover further vulnerabilities. Which option best justifies this decision?

Options:

A.  

Google Hacking can help locate phishing websites that mimic the client’s website.

B.  

Google Hacking can help discover hidden organizational data from the Deep Web.

C.  

Google Hacking can help identify weaknesses in the client’s website code.

D.  

Google Hacking can assist in mapping the client’s internal network structure.

Discussion 0
Questions 216

In a tense red team exercise at a mid-sized university in Austin, Texas, an ethical hacker named Jake targeted a legacy Linux server in the engineering department. Late one afternoon, he discovered TCP port 2049 was open during his first sweep, suggesting hidden file-sharing capabilities. Intrigued, Jake used a standard utility to request a list of remote file systems shared across the network, aiming to map accessible resources. Meanwhile, he idly checked for Telnet access and probed a time-sync service out of routine, but both proved fruitless on this host.

Which enumeration method is actively demonstrated in this scenario?

Options:

A.  

NFS Enumeration

B.  

SNMP Enumeration

C.  

NetBIOS Enumeration

D.  

NTP Enumeration

Discussion 0
Questions 217

You are Michael, an ethical hacker at a New York–based e-commerce company performing a security review of their payment-signing service. While observing the signing process (without access to private keys), you note the service generates a fresh random value for each signature operation, the signature algorithm uses modular arithmetic in a subgroup defined by public domain parameters, and signatures are verified with a public verification key rather than by decrypting the message. Which asymmetric algorithm best matches the signing mechanism you observed?

Options:

A.  

DSA

B.  

RSA

C.  

Diffie-Hellman

D.  

ElGamal

Discussion 0
Questions 218

A large media-streaming company receives complaints that its web application is timing out or failing to load. Security analysts observe the web server is overwhelmed with a large number of open HTTP connections, transmitting data extremely slowly. These connections remain open indefinitely, exhausting server resources without consuming excessive bandwidth. The team suspects an application-layer DoS attack. Which attack is most likely responsible?

Options:

A.  

A UDP flooding attack targeting random ports.

B.  

An ICMP Echo Request flooding attack.

C.  

A Slowloris attack that keeps numerous HTTP connections open to exhaust server resources.

D.  

A fragmented packet attack with overlapping offset values.

Discussion 0
Questions 219

You’ve recently joined an international software firm as part of the cybersecurity governance team. While preparing for an internal compliance review, your supervisor asks you to identify the ISO/IEC standard that serves as a comprehensive framework for managing an organization ' s information security. You examine several standards, including those focusing on risk management, cybersecurity, and control implementation. However, you need to select the one that defines the overarching structure for managing information security programs across the organization.

Which of the following standards should you choose?

Options:

A.  

ISO/IEC 27002:2022

B.  

ISO/IEC 27005:2022

C.  

ISO/IEC 27001:2022

D.  

ISO/IEC 27701:2019

Discussion 0
Questions 220

A web app fails to restrict API request frequency. What risk exists?

Options:

A.  

Data scraping

B.  

CSRF

C.  

XSS

D.  

SQLi

Discussion 0
Questions 221

Massive outbound HTTPS traffic hides inside normal web traffic. Likely objective?

Options:

A.  

DoS

B.  

Data exfiltration

C.  

Scanning

D.  

Recon

Discussion 0
Questions 222

At Horizon Legal Services in Boston, Massachusetts, ethical hacker Daniel Price is tasked with assessing the security of the firm ' s mobile case-tracking app. During testing, he finds that confidential case notes and client records are kept locally on the device without encryption. By browsing the file system with a standard explorer tool, he can open sensitive information without any authentication. Which OWASP Top 10 Mobile Risk is most clearly present in the app?

Options:

A.  

Insecure Communication

B.  

Improper Credential Usage

C.  

Insecure Data Storage

D.  

Inadequate Privacy Controls

Discussion 0
Questions 223

An attacker abuses weak password reuse across services using leaked credentials. What attack is this?

Options:

A.  

Replay

B.  

Credential stuffing

C.  

Brute force

D.  

Dictionary attack

Discussion 0
Questions 224

During a penetration test at IntelliCore Systems in Raleigh, North Carolina, ethical hacker Javier directs a wave of repetitive web requests against the company ' s portal that overloads backend scripts which process search queries and form submissions. As a result, legitimate customers experience long delays and occasional timeouts while attempting to log in or complete transactions.

Which DoS/DDoS technique is Javier most likely demonstrating?

Options:

A.  

Slowloris

B.  

UDP Flood

C.  

Peer-to-Peer Attack

D.  

HTTP GET/POST Attack

Discussion 0
Questions 225

An ethical hacker needs to gather sensitive information about a company ' s internal network without engaging directly with the organization ' s systems to avoid detection. Which method should be employed to obtain this information discreetly?

Options:

A.  

Analyze the organization ' s job postings for technical details

B.  

Exploit a public vulnerability in the company ' s web server

C.  

Perform a WHOIS lookup on the company ' s domain registrar

D.  

Use port scanning tools to probe the company ' s firewall

Discussion 0
Questions 226

An organization lacks centralized logs. Which attack phase is hardest to detect?

Options:

A.  

Lateral movement

B.  

Recon

C.  

Delivery

D.  

Initial access

Discussion 0
Questions 227

A technology consulting firm in Portland, Oregon began experiencing repeated topology recalculations across its switching infrastructure. Shortly after a newly connected device came online in a conference room, spanning-tree convergence events were triggered across multiple distribution switches.

Engineers determined that the access-layer interface connected to that device was influencing path-selection decisions, introducing a more favorable bridge priority value into the environment and affecting the established hierarchy.

To preserve the intended switching structure and prevent unauthorized devices from altering root selection decisions, which control should be employed?

Options:

A.  

Configuring Loop Guard on non-designated ports

B.  

Enabling BPDU Guard on edge ports

C.  

Applying Root Guard on designated interfaces

D.  

Activating UDLD on uplinks

Discussion 0
Questions 228

A malware analyst finds JavaScript and /OpenAction keywords in a suspicious PDF using pdfid. What should be the next step to assess the potential impact?

Options:

A.  

Upload the file to VirusTotal

B.  

Extract and analyze stream objects using PDFStreamDumper

C.  

Compute file hashes for signature matching

Discussion 0
Questions 229

You are Noah Kim, an ethical hacker at Quantum Cyber Solutions, hired to test the mobile device security of TechTrend Innovations, a tech firm in Austin, Texas. During a covert assessment, your objective is to simulate an attacker attempting to gain privileged access to an iPhone 12 running iOS 14.5 used for proprietary app development. You apply a jailbreaking technique that allows the device to fully restart without requiring a computer, maintaining a patched kernel and enabling access to sensitive app data in the file system. Based on this method, which iOS jailbreaking technique are you using?

Options:

A.  

Semi-tethered jailbreaking

B.  

Untethered jailbreaking

C.  

Semi-untethered jailbreaking

D.  

Tethered jailbreaking

Discussion 0
Questions 230

A multinational manufacturing company in San Jose, California has deployed a perimeter firewall to protect its internal production networks. During a red team exercise, testers observe that the device monitors active TCP communications and allows traffic to continue only when packets correspond to recognized, previously established connections.

The firewall evaluates multiple header attributes across ongoing communications while operating inline at the network boundary.

From a firewall architecture perspective, what type of firewall is most likely in use at this perimeter?

Options:

A.  

Stateful Multilayer Inspection Firewall

B.  

Circuit-Level Gateway Firewall

C.  

Application-Level Firewall

D.  

Packet Filtering Firewall

Discussion 0
Questions 231

A regional investment firm in Denver, Colorado, recently migrated to a fully switched Ethernet infrastructure. During an authorized security evaluation, a consultant connected a test device to an access-layer switch and initiated a scripted network interaction.

Within minutes, administrators observed irregular switching behavior. Frames that were normally delivered directly between specific workstations began appearing across multiple switch ports. Users reported brief connectivity instability, but no configuration changes were made to the switch. After the activity subsided, forwarding operations gradually stabilized.

Based on the observed behavior, which sniffing technique was most likely performed?

Options:

A.  

Switch Port Stealing

B.  

ARP Poisoning

C.  

MAC Flooding

D.  

DNS Poisoning

Discussion 0
Questions 232

During a security assessment, an attacker identifies a flaw in a multi-user file system. The system first verifies access rights to a temporary file created by a user. However, immediately after this verification, and before the file is processed, the attacker manages to swap the original file with a malicious version. This manipulation happens in the brief interval between the system ' s access verification and the moment it handles the file, resulting in the malicious file being treated as legitimate. Which vulnerability is the attacker exploiting?

Options:

A.  

Time-of-validation/time-of-execution issue in resource management logic.

B.  

Improper certificate validation in trusted communication channels.

C.  

Integer overflow during arithmetic computations with limited memory bounds.

D.  

Null pointer dereference leading to unexpected application behavior.

Discussion 0
Questions 233

A security analyst investigates unusual east-west traffic on a corporate network. A rogue device has been physically inserted between a workstation and the switch, enabling unauthorized access while inheriting the workstation’s authenticated network state. Which evasion technique is being used?

Options:

A.  

Exploiting a wireless rogue access point to tunnel through the firewall

B.  

NAC bypass using a pre-authenticated device for network bridging

C.  

Spoofing ARP responses from a dynamic IP allocation pool

D.  

VLAN double tagging to shift between network segments

Discussion 0
Questions 234

While auditing legacy network devices at a public hospital in Miami, Jason, a penetration tester, needs to verify what SNMP traffic is leaking across the internal segment. Instead of running structured queries, he decides to capture live network traffic and manually review the protocol fields. This method allows him to see SNMP requests and responses in transit but requires manual parsing of OIDs, community strings, and variable bindings.

Which method should Jason use in this situation?

Options:

A.  

Nmap

B.  

Wireshark

C.  

SnmpWalk

D.  

SoftPerfect Network Scanner

Discussion 0
Questions 235

During an authorized engagement at IronClad Financial Services in Charlotte, the red team successfully exploits a weakness and obtains administrative access to a critical server. After achieving this objective, the team installs a backdoor mechanism to ensure continued access even if the original vulnerability is remediated. The team documents this activity as part of demonstrating long-term adversary behavior within the approved scope.

Within the CEH ethical hacking framework, which phase does this activity represent?

Options:

A.  

Reconnaissance

B.  

Vulnerability Scanning

C.  

Maintaining Access

D.  

Clearing Tracks

Discussion 0
Questions 236

You are an ethical hacker at Apex Cyber Defense contracted to audit Coastal Healthcare ' s wireless estate in Miami, Florida. During a network sweep, your logs show a previously unknown access point physically connected to the hospital ' s internal switch and issuing IP addresses to devices on the corporate VLAN - it was neither provisioned by IT nor listed in the asset inventory. The device is relaying internal traffic and providing remote connectivity back to an external host. Based on the observed behavior, which wireless threat has the attacker most likely introduced?

Options:

A.  

Misconfigured AP

B.  

Rogue AP

C.  

Honeypot AP

D.  

Evil Twin AP

Discussion 0
Questions 237

Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?

Options:

A.  

Check MITRE.org for the latest list of CVE findings

B.  

Use a scan tool like Nessus

C.  

Create a disk image of a clean Windows installation

D.  

Use the built-in Windows Update tool

Discussion 0
Questions 238

During a red team engagement at a law firm in Dallas, ethical hacker Sarah connects a compromised workstation to a core switch. Within minutes, the switch begins experiencing instability, and multiple VLANs report traffic leakage across isolated departments. Sarah observes that her machine is now receiving packets not originally destined for it, giving her visibility into multiple active sessions. Logs show the switch ' s CAM table was overwhelmed during the attack.

Which sniffing technique did Sarah most likely use?

Options:

A.  

DNS Poisoning

B.  

VLAN Hopping

C.  

ARP Poisoning

D.  

MAC Flooding

Discussion 0
Questions 239

During a red team engagement against a multinational financial services organization, an ethical hacker conducts network reconnaissance against externally accessible systems. Instead of sending scan traffic directly from the originating assessment machine, the tester routes all reconnaissance packets through an intermediary external system before they reach the target network.

When the organization’s security team reviews monitoring data, the activity appears to originate from infrastructure unrelated to the tester’s actual geographic or organizational location.

From a reconnaissance methodology perspective, what is the primary objective of using this intermediary system?

Options:

A.  

To Establish Persistent Access within the Target Network

B.  

To Bypass Authentication Controls Protecting Internal Applications

C.  

To Conceal the Origin of Reconnaissance Activity and Reduce Attribution Risk

D.  

To Spoof Packet Source Addresses at the IP Layer

Discussion 0