Browse all practice questions for the EC-Council Certified Ethical Hacker (CEH) v13 (312-50v13) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

EC-Council Certified Ethical Hacker (CEH) v13 (312-50v13) Practice Exam 2026 – Your All-in-One Guide to Certification Success! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is the definition of inherent risk?
  • Which statement best describes XSS Reflection vulnerability?
  • What is the difference between a stateful and stateless firewall?
  • Which description best characterizes a demilitarized zone (DMZ) in a network?
  • What does DNSSEC add to the original DNS design?
  • What does PKI stand for in the context of cryptography?
  • What is the function of the web server in the recommended architecture?
  • Which approach helps ensure the integrity of financial statements before sending to the accountant?
  • Which of the following describes a data security concept related to Bluetooth vulnerabilities?
  • Which statement best describes zone transfers?
  • What are the consequences of not deleting HTTP cookies?
  • Which tools are used for enumeration?
  • What is the significance of enabling audit features in sensitive systems?
  • Which DNS configuration uses separate internal and external views?
  • Which statement is true about IPsec?
  • Which command is used by SMTP to transmit email over TLS?
  • What is a potential flaw of MAC address filtering?
  • Which statement correctly describes the -T flag's effect on scanning?
  • On a compromised web-enabled host with outbound HTTP traffic unimpeded, what happens to IRC traffic?
  • If a command demonstrates that the guest account has NOT been disabled, what does this indicate?
  • A successful clickjacking attack may result in which of the following?
  • What is a potential drawback of white-box testing?
  • What is the main purpose of split-horizon operation for DNS servers?
  • Which statement about digital signatures is true?
  • What type of attack is most likely when a token and a 4-digit PIN are used for access and the token performs offline checking?
  • What does the term 'false positive' mean in the context of IDS alerts?
  • Which OSI layer is primarily responsible for translating data formats to be understood by the receiving application?
  • Which type of virus infects both the system boot sector and executable files?
  • How do host-based application firewalls operate?
  • Which statement best describes a protocol analyzer's role in network security?
  • What does the use of a hash assure?
  • In risk management, which concept represents the monetary loss expected from a single incident?
  • What is the significance of the 'nc' file in the context of the notes?
  • What is the first step a bank should take regarding auditing sensitive information?
  • If an attacker wants to redirect users from 'www.MyPersonalBank.com' to a phishing site, which file should they modify?
  • Which definition best describes a covert channel?
  • Which approach would most effectively improve the uptake of computer security certification or accreditation?
  • What does Dynamic ARP Inspection (DAI) protect against?
  • What is the function of a digital signature?
  • What is the role of the OSI Presentation Layer?
  • Which security property does IPsec provide to prevent replay attacks?
  • Why is it important to monitor computer systems and networks?
  • Which DNS record designates the mail server for a domain?
  • What is the most likely reason a user cannot capture logons using L0phtcrack on a Windows 2000 network?
  • How is Annual Loss Expectancy (ALE) calculated?
  • If zone transfers are not restricted, which risk increases?
  • What type of attacks can ISAPI filters potentially expose a webserver to?
  • In the context of wireless security, what is the typical effect of MAC filtering?
  • Which description best characterizes Netcat?
  • The primary purpose of hardening network elements in a data center is to
  • What is the primary function of a security policy in an organization?
  • Which statement correctly describes nslookup's role in DNS zone transfers?
  • Which statement best describes NAT’s primary function in a network?
  • What is the purpose of an application firewall?
  • In wireless networking, what does the SSID identify?
  • What kind of email did the attacker send to the receptionist in the social engineering example?
  • Which statement aligns with protecting cardholder data under PCI compliance?
  • If an event occurs every three years, what is the Annual Rate of Occurrence (ARO)?
  • In cybersecurity, what does IDS stand for?
  • What does privilege escalation entail in system security?
  • Which of the following is a stated consequence of unauthorized changes to the CEHv13 product?
  • Which of the following describes a hash-based birthday attack?
  • Which statement best describes residual risk after risk controls are deployed?
  • What does Gray-box testing restrict in terms of system access?
  • In risk management, which term describes how often an event is expected to occur in a year?
  • Why might an IRC server be running on port 80?
  • Which DNS record contains administrative information such as serial number and refresh rates for a zone?
  • If '/bin/sh' is found in the ASCII output of a network IDS entry, what does this imply?
  • In the context of network security, what does STP manipulation primarily enable?
  • What does email spoofing aim to achieve?
  • Why is restricting Zone transfers important in DNS security?
  • Time synchronization in logs supports legal investigations by ensuring what?
  • Which term quantifies the financial impact of a single occurrence of a risk event?
  • In a network security context, what should be regularly monitored and tested?
  • What is a common characteristic of a private network?
  • Who should be covered by an organization's information security policy?
  • Which DNS record is primarily used to map hostnames to IP addresses?
  • Which DNS record defines the primary name server for the domain and the duration of DNS caching?
  • Which statement accurately describes the relationship between a private key and a digital signature?
  • DNS poisoning is best described as which type of attack?
  • What is the purpose of the CEHv13 practice exam?
  • What is the difference between NIDS and HIDS?
  • Why might you send an email to a non-existent address during a penetration test?
  • DNS stands for?
  • In the recovery scenario, how many hours are allocated to database recovery?
  • Which of the following is a consequence of ARP spoofing?
  • What does ALE stand for in risk management?
  • Which of the following best describes the function of a vulnerability scanner?
  • Which statement best describes risk acceptance?
  • What is the function of Finger in a network environment?
  • What issue might occur if a computer can transfer files locally but cannot connect to the Internet?
  • Which exploit is commonly associated with the MS Blaster worm?
  • Before enabling audit logging, what is an important consideration for administrators?
  • Clickjacking is best described as which of the following?
  • What does Kismet do?
  • What best describes the distinction between network-based application firewalls and traditional packet-filtering firewalls?
  • What is a macro virus?
  • What does a wireless client need to authenticate with a router?
  • Which organization provides guidelines for implementing security standards and guidelines for federal agencies (as referenced by FISMA)?
  • What does the command prompt indicate in Eve's actions?
  • Which practice best prevents unauthorized DNS zone transfers?
  • What is the cost of a new hard drive in the given scenario?
  • What does the term 'server publishing' refer to in networking?
  • What tool should be used to perform a Blackjacking attack?
  • Which statement best describes the main function of an application firewall?
  • What is the role of the database server in the recommended architecture?
  • What does a firewall inspect to decide whether to allow packets into an organization?
  • Which statement correctly describes the purpose of DNS zone transfers?
  • In data center security, what is a primary function of firewall and intrusion prevention systems?
  • What is the first step followed by Vulnerability Scanners when scanning a network?
  • What is Tess King attempting with the nslookup command?
  • What does the term 'null session' refer to in networking?
  • In DNS, a Resource Record serves what purpose?
  • What class of hacker operates both offensively and defensively?
  • Which tool provides a graphical front-end and integrated sorting and filtering options?
  • Which of the following represents recommended DNS security practices?
  • What happens when a client's MAC address does not match the router's whitelist?
  • What is the significance of using a password-protected Excel file for sensitive data?
  • Which method is explicitly listed for providing feedback about the CEHv13 exam product?
  • Which statement correctly contrasts tcpdump and Wireshark?
  • What is a likely cause for mismatched event logs during a security breach investigation?
  • What is the role of a network security officer?
  • Which port is commonly used by zone transfers when TCP is required?
  • Which tool is used to detect wireless LANs using the 802.11 standards on a Linux platform?
  • What is the proper response for a NULL scan if the port is closed?
  • If you want to speed up an Nmap scan by reducing the number of ports scanned, which option would you use?
  • What is the default port for IRC according to IANA?
  • A SYN scan is used to determine which of the following about a target?
  • Which technology can provide secure access to users?
  • What can you do with a tool that captures information about Bluetooth devices?
  • If a wireless client can see a network but cannot connect, what is a plausible cause?
  • If one user sees a defaced website while another does not, what is the most likely cause?
  • What is the purpose of using a packet sniffer in network troubleshooting?
  • What does OpenVAS stand for?
  • What term describes the process of gathering information about a target company to enhance the trust level of a phishing message?
  • What happens if port 53 for DNS is blocked?
  • What detection technique in antivirus software collects data from multiple systems instead of analyzing files locally?
  • What is the primary consequence of Heartbleed?
  • What is the effect of the -F flag on Nmap's scan speed?
  • What does the term 'enumeration' refer to in hacking processes?
  • Which approach results in accepting some risk while implementing actions to cap exposure, rather than eliminating it entirely?
  • Which option corresponds to the password retrieval means that includes hardware, software, and sniffing?
  • What does the term 'DoS' refer to in penetration testing?
  • What risk is associated with misconfiguring DNS zone transfers?
  • What is the main function of a router in a wireless network?
  • In the context of IDS entries, the 0x90 value is typically associated with which of the following?
  • Routing table injection refers to what type of attack?
  • Which remote access protocol is considered secure and preferred over Telnet?
  • What is the best way to defend against network sniffing?
  • In computer security, PKI stands for which of the following?
  • Which HTTP method is used to modify a resource on the server?
  • What is the correct count of ports scanned by default in Nmap?
  • DNSSEC helps mitigate which type of attacks?
  • What is the first step in a DNS lookup?
  • What is the primary tactic used in social engineering attacks?
  • Which statement correctly characterizes the relationship between encryption and data protection in transit?
  • Which server component typically interfaces directly with external clients on the internet?
  • What was the outcome of the social engineering attack described in the notes?
  • What is a common feature of many host-based application firewalls?
  • What is the primary purpose of security audits in a network environment?
  • How is residual risk calculated?
  • What is the purpose of Network Address Translation (NAT) in a local network?
  • Which statement best describes the main characteristic of asymmetric cryptography?
  • What type of attack occurs when an attacker sits between two communicating parties and can intercept and alter traffic without either party knowing?
  • The purpose of reconnaissance in cyber operations is to gather information about the target to facilitate the attack.
  • What is the purpose of performing service and OS discovery during vulnerability scanning?
  • What Wireshark filter will show connections from a Snort machine to a Kiwi Syslog machine?
  • What is the main benefit of DHCP snooping on a network?
  • Which statement best describes the purpose of a zone transfer in DNS?
  • In the OSI model, which layer is the application layer?
  • Which tool is commonly used to enumerate open ports and services on a host during security testing?
  • Which practice best prevents unauthorized access to DNS data?
  • What type of attack does Cross Site Scripting (XSS) represent?
  • Which tool analyzes packet-capture files such as tcpdump and Wireshark?
  • Which statement best describes enumeration in security testing?
  • Which statement about the capabilities of application-layer filtering is true?
  • What does Single Loss Expectancy (SLE) quantify in risk assessment?
  • What is the risk of using higher timing values (-T) in Nmap scans?
  • What is the significance of running Tripwire on a web server?
  • What is the term for the amount of risk that remains after vulnerabilities are classified and countermeasures are deployed?
  • What is the significance of the hash in digital signatures?
  • What is the impact of variable network latency on NTP?
  • When was the Heartbleed bug discovered?
  • What is the primary purpose of hiring more computer security monitoring personnel?
  • What happens if an attacker successfully manipulates STP?
  • What is the primary reason for using public-key cryptography during TLS handshake?
  • What is the primary function of a network sniffer in security assessments?
  • In a packet capture, what does the expression tcp.srcport == 514 indicate?
  • In a DNS resolution sequence, what is the first server the recursive resolver queries after receiving a domain name?
  • What is the main advantage of using symmetric encryption in SSL/TLS?
  • Which Nmap command quickly enumerates all machines in the 10.10.0.0/24 network?
  • What is the primary duty of a network security officer in an organization?
  • What does SLE stand for in risk management?
  • If IRC traffic is blocked on port 80/TCP, which firewall type is likely inspecting outbound traffic?
  • Host-based application firewalls are commonly used together with what security mechanism?
  • What is the implication of receiving a suspicious message from a Yahoo Bank representative?
  • When does a DMZ make sense?
  • What is the formula for calculating Single Loss Expectancy (SLE)?
  • What is the primary function of an Intrusion Detection System (IDS)?
  • Biometric authentication provides what type of identifier?
  • Which statement describes how application layer filtering decisions can be made?
  • What can result from unsynchronized clocks on network devices?
  • What is the importance of using encrypted protocols for file transfers?
  • What does the term Exposure Factor (EF) refer to in risk management?
  • Which statement describes a False Positive in IDS alerts?
  • What is the main purpose of a vulnerability scanner?
  • Which security concept is described by an attacker intercepting communications between two parties without their awareness?
  • In a scenario where a DNS server is vulnerable, which mitigation helps reduce DNS spoofing risk?
  • Which statement best describes gray-box testing?
  • Which vulnerability involves modifying URL parameters to reflect changes on the web page?
  • What type of security policy does a company implement regarding HTTP cookies?
  • Which security device actively blocks threats based on detection, rather than just alerting?
  • What does the term 'privilege escalation' refer to?
  • In the context of disaster recovery planning, which activity would be classified under risk transference?
  • What is the expected outcome when a wireless client is configured correctly?
  • If ARO is 0.33 and SLE is $900, what is ALE?
  • Which device typically assigns IP addresses automatically in a local network?
  • Exposure Factor (EF) in risk management represents:
  • Which IPsec feature ensures that data cannot be altered in transit?
  • In the context of DNS, what does the lower numerical preference value for MX records indicate?
  • Which of the following tools can be used for SNMP enumeration?
  • In IPsec, which mode encrypts the payload to protect data while the packet is transmitted within a LAN?
  • In DNS, what does SOA stand for?
  • Which term describes modifying cookies to gain unauthorized access or manipulate user sessions?
  • What does the term 'covert channel' imply in cybersecurity?
  • What is the significance of Bob in cybersecurity?
  • What does DNS primarily use to serve requests?
  • What is the purpose of the SOA record in DNS?
  • What happens to IP packets originating from or addressed to a private IP address?
  • What is the definition of a zone transfer in DNS?
  • What type of vulnerabilities can Nikto identify on web servers?
  • What does the acronym SOA stand for in networking?
  • What is the effect of the -F option on port scanning in Nmap?
  • What does Netcat primarily provide?
  • Which policy practice directly reduces the risk of credential theft through cookies?
  • What is the TTL value in the Rutgers.edu SOA record?
  • Which vulnerability allows injecting malicious scripts into web pages viewed by others?
  • What is a brute-force attack?
  • What is the purpose of a hash in information security?
  • What is the definition of a false positive in IDS alerts?
  • What is the primary purpose of installing a firewall in an environment subject to PCI compliance?
  • What is the primary purpose of email spoofing in practice statements?
  • Which statement best defines a brute-force attack?
  • Which risk mitigation strategy combines aspects of risk acceptance and risk avoidance?
  • How does an application firewall differ from traditional security appliances?
  • Nessus is best described as which of the following?
  • What does the root server respond with during a DNS lookup?
  • What should Bob do after receiving a suspicious text message from someone claiming to be from Yahoo Bank?
  • Which tool can be used to perform session splicing attacks?
  • Which statement correctly compares Exam Pool A and Exam Pool B in terms of question count?
  • Which statement best describes the primary purpose of a security policy?
  • What is the purpose of using Secure Shell (SSH)?
  • Which phishing tactic helps attackers appear legitimate?
  • Open-source intelligence is best described as which of the following?
  • What does Steve's technological solution for identifying people based on walking patterns implement?
  • What is the best security policy for a data center housing network elements?
  • If Asset Value is $550 and Exposure Factor is 0.5, what is SLE?
  • Which authentication approach is described by Steve's walking-pattern system paired with RFID badges?
  • What is the last step in the DNS lookup process?
  • What does sniffing refer to in network security?
  • DNS spoofing can lead to which outcome?
  • Which file is typically targeted to obtain password hashes during credential dumping?
  • In host-based firewalls, what does granularity refer to?
  • What is the purpose of the Dsniff tool mentioned by Eric?
  • Which item is an example of 'Something you are'?
  • Which firewall type is described as inspecting outbound traffic and blocking nonstandard application traffic such as IRC on port 80?
  • To prevent NetBIOS traffic, which firewall ports should be blocked?
  • What is the main function of firewalls?
  • Reconnaissance in cyber operations is the process of collecting information about a target before an attack.
  • Which of the following is a PCI compliance requirement?
  • Why is Double DES considered insecure?
  • What was the main issue Joseph faced when accessing the Mason Insurance website?
  • Which scenario would indicate vulnerability to meet-in-the-middle attacks?
  • What is the purpose of sending an email to an invalid address in a penetration test?
  • Which type of virus is usually targeted at Microsoft Office products?
  • Which statement best describes public key cryptography?
  • Which organization policy should address information security for employees and contractors?
  • What might be the problem if websites are accessible via IP but not URL?
  • Which component is primarily responsible for translating a domain name to an IP address during a DNS lookup?
  • What tool can be used to determine if packets captured by an IDS are genuinely malicious?
  • Which statement best describes the significance of the Federal Information Security Modernization Act of 2014 (FISMA)?
  • Which statement describes Solarwinds IP Network Browser?
  • Which of the following best describes Nikto's vulnerability assessment scope?
  • What is the function of prompts in host-based application firewalls?
  • Which input types does fuzzing focus on testing for robustness?
  • What is the purpose of filtering ports 137 and 139?
  • Which regulation defines security and privacy controls for Federal information systems?
  • Which DNS record stores administrative information about a zone and marks authority for the zone?
  • Which element is essential to Kerberos authentication?
  • What is the primary challenge of using test automation in security testing?
  • Which of the following is a social engineering tactic?
  • Which of the following is a key feature of IPsec?
  • What is the main motivation behind using bluedriving?
  • TTL in DNS records indicates what?
  • Which Linux command resolves a domain name into an IP address?
  • Which statement best describes a true positive in IDS alerts?
  • Which of the following describes the purpose of assigning a unique ID to each person with computer access in PCI compliance?
  • Which information is primarily enumerated by the http-methods NSE script in Nmap?
  • Which Linux-based tool can change any user's password on a Windows 2008 R2 server?
  • What role do urgency or fear play in social engineering?
  • What is the main advantage of network-based application firewalls over traditional firewalls?
  • What is the main function of the nslookup command?
  • What does the Federal Information Security Modernization Act of 2014 (FISMA) stand for?
  • Which practice best describes the proper handling and documentation of evidence to maintain its integrity?
  • What is the purpose of restricting physical access to cardholder data?
  • Which statement best describes the client-server model in NTP?
  • Which tool would you deploy to watch for unusual ARP traffic as part of security monitoring?
  • Which of the following describes the primary purpose of a digital signature?
  • What is the main function of an application firewall?
  • What does IPsec protect against?
  • What is the role of transport layer port numbers in firewall checks?
  • Which statement describes Nikto's scanning focus?
  • What is the main focus of NIST publications?
  • What is the function of the 802.1x protocol in network security?
  • Which of the following address ranges is reserved for private networks according to IANA?
  • Which of the following statements best describes a password retrieval method listed in the material?
  • What is the role of Nessus in vulnerability assessment?
  • What should be done to protect against the large sniffing attack surface?
  • ISAPI filters can potentially expose a webserver to what kind of attacks?
  • What is white-box testing?
  • What is the primary goal of a buffer overflow attack?
  • Which statement about biometric authentication is true?
  • If the asset value is $500,000 and the exposure factor is 0.3, what is the SLE?
  • What is the role of an Intrusion Detection System (IDS) in network security?
  • Which of the following is listed as a means Bob can adopt to retrieve passwords from client hosts and servers?
  • Which option best describes a key focus of administrative safeguards in risk management?
  • Which statement best describes password-protected Excel files for sensitive data?
  • What are the reserved IPv4 address ranges for private networks according to IANA?
  • Which tool did the hacker probably use to inject HTML code in the MITM attack?
  • How does Tcpdump function?
  • Which tool is commonly used to monitor ARP activity for spoofing detection?
  • What is the primary function of a Wireless Access Point (WAP)?
  • What is the primary function of a DNS Anti-spoofing installation?
  • What is the role of a honeypot in network security?
  • During a vulnerability scan, which activity is typically not performed?
  • What is the primary risk associated with improperly set file system permissions?
  • What is a potential issue with the solution regarding authentication?
  • Which protocol is commonly used to negotiate keys securely in a TLS handshake?
  • What is the hourly wage of the recovery person in the scenario?
  • Which term describes when an IDS fails to alert on a real attack?
  • In a MITM scenario, injecting HTML code generally aims to achieve which outcome?
  • Tracking and monitoring access to network resources helps ensure the security of what?
  • Which of the following is a mitigation for DNS spoofing when a DNS server is vulnerable?
  • Which phase of the incident handling process is responsible for defining rules and creating a backup plan?
  • Which statement describes the effect of using higher timing templates in Nmap, such as -T4?
  • What are the three steps performed by Vulnerability Scanners?
  • What is the known plaintext attack against DES that suggests using two keys is no more secure than one?
  • What is an advantage of using both symmetric and asymmetric cryptography in SSL/TLS?
  • What is another evasion technique used to confuse packet reassemblers?
  • Which tool would help perform SNMP inquiries over the network?
  • Which technology maps private IP addresses to public addresses to enable Internet access for internal hosts?
  • What are the two primary categories of application firewalls?
  • What is the role of DHCP in a wireless network?
  • Which statement best describes SPAN-related traffic behavior in the context of network analysis?
  • Which action best protects against parameter tampering?
  • When unknown files are found in the root directory of a Linux FTP server, what is the most appropriate initial action for a network administrator?
  • Two-factor authentication using a smart card and PIN satisfies which factors?
  • Which scenario best demonstrates the value of audit trails in security?
  • What is a component of a risk assessment?
  • What is the significance of disabling unused ports on switches?
  • What will the Google search query 'site:target.com - site:Marketing.target.com accounting' return?
  • Which Windows service is commonly exploited by null sessions to access shared resources on a network?
  • If the true administrator is Joe, what does this indicate?
  • Using the name of a company CEO in a phishing message raises the trust level of the phishing message by mimicking internal communications.
  • Tripwire is primarily used to detect unauthorized changes to what?
  • What does Static Network Address Translation allow?
  • Email spoofing can lead to which type of attacks as noted in the material?
  • Which of the following can cause errors in NTP synchronization?
  • What is the primary purpose of Network Time Protocol (NTP)?
  • Which tool is command-line based for capturing packets?
  • How long will secondary servers attempt to contact the primary server before considering the zone dead?
  • What does the term 'chain of custody' refer to in the context of log collection?
  • Which system provides publicly available databases containing domain name registration contact information?
  • How many hours are needed to restore the database from the last backup?
  • What does social engineering involve in the context of unauthorized access?
  • A wireless client cannot connect to an 802.11 network even though the network is visible. Which is a plausible reason?
  • Which address translation scheme allows a single public IP address to correspond to a single machine on an internal network?
  • What type of attack can occur after STP manipulation?
  • What is the implication of the phrase 'best option' in the context of EC-Council exams?
  • Which statement best describes the difference between a spoofing attack and a man-in-the-middle attack?
  • What is the purpose of a DMZ in network security?
  • How many percentage points did the risk drop after implementing controls?
  • What is indicated by the value 0x90 in a network IDS entry?
  • What is the purpose of splitting an attack payload into multiple small packets?
  • What is Solarwinds IP Network Browser used for?
  • What happens if a packet is not received within a reasonable period during session splicing?
  • Which of the following best describes risk avoidance?
  • Which statement best describes a DNS zone transfer?
  • What is the function of the tool 'Burp' in security testing?
  • Which statement correctly describes a DMZ's access control?
  • What message was displayed on the defaced Mason Insurance website?
  • Why is a penetration test considered more thorough than a vulnerability scan?
  • What was the risk percentage for the main company application after implementing necessary controls?
  • If SLE is $2,000 and ARO is 0.25, what is ALE?
  • What testing method involves manipulating individuals into revealing sensitive information?
  • What should you do if you discover information suggesting human trafficking during a security assessment?
  • How many questions are in Exam Pool B?
  • What does decision coverage ensure in white-box testing?
  • What is the significance of the IP address 192.168.0.99 in the context of the notes?
  • What is the limitation of sending financial statements via email and USB for comparison?
  • What does a vulnerability scan help identify in a system?
  • Which statement describes a major vulnerability of SMTP?
  • What does the netstat command reveal about the 'nc' process?
  • Which statement is true about Nmap's default port coverage?
  • What is the best risk decision for the project if the risk is at 10% and the threshold is 20%?
  • What is the recommended server architecture for a new web-based software package requiring three servers?
  • Which statement correctly describes how backbone routers handle private IP addresses?
  • A tool that captures information about Bluetooth devices can do which of the following?
  • What is the formula for calculating ALE?
  • Why is it important to encrypt the transmission of cardholder data across public networks?
  • What does risk acceptance entail?
  • What was the result of the social engineering attack described in the notes?
  • Finding '/bin/sh' in command output captured by an IDS most likely suggests which of the following?
  • Which is an example of risk limitation?
  • What is the main limitation of host-based application firewalls?
  • Which physical security component protects against vehicle intrusion at a building entrance?
  • What is the most effective method to bridge the knowledge gap between 'black' hats and 'white' hats?
  • Where are network-based and host-based application firewalls deployed?
  • Encryption is typically done at which OSI layer, and decryption is also handled there?
  • How many steps are there in a DNS lookup when no information is cached?
  • In an STP manipulation scenario, what is the purpose of creating a SPAN entry on the spoofed root bridge?
  • Why is risk avoidance usually the most expensive risk mitigation option?
  • Which protocol family does NTP primarily utilize for time data transmission?
  • What is the purpose of the DNS system?
  • Which of the following is not a Bluetooth attack?
  • What does the acronym CVE stand for in the context of vulnerabilities?
  • Which statement about DNS caching TTL is true?
  • What type of attack involves a rogue wireless access point to inject malicious HTML code?
  • In the TCP three-way handshake, which event initiates the connection from the client side?
  • Nmap's default port scanning covers how many ports?
  • What is the significance of the encryption code for each order?
  • Blocking inbound TCP port 53 connections serves to prevent unauthorized zone transfers.
  • Which tool can crack Windows SMB passwords by listening to network traffic?
  • Which practice best supports the principle of least privilege in access control?
  • What is a NULL scan?
  • DNS zone transfers, if not restricted, can lead to what risk?
  • In the recovery scenario, how many hours are allocated to OS/software recovery?
  • Deleting HTTP cookies upon termination mitigates which security risk?
  • What is the importance of not using vendor-supplied defaults for system passwords?
  • What does a router do when it receives a connection request from a device with an unrecognized MAC address?
  • In DNS, what is the primary role of MX records?
  • Which TCP flag sequence is used by the client to initiate a connection?
  • Which technique allows an attacker to determine which ports are open behind a firewall by analyzing packet responses?
  • During a DNS lookup, which component returns the IP address to the client after resolution?
  • Which tool is recommended for performing session splicing attacks according to the EC-Council exam?
  • What is the role of a Honeypot in security?
  • What is the role of a Wireless Access Point (WAP) in a network?
  • Which term describes the act of transferring risk to a willing third party, such as outsourcing operations?
  • Which statement best describes the 'sniffing attack surface'?
  • What is the purpose of NIST Special Publication 800-53?
  • Under what condition does a secondary name server request a zone transfer from a primary name server?
  • In a DNS setup, when a secondary DNS server cannot reach the primary, which describes its behavior after a timeout?
  • What is the primary purpose of DHCP in a network?
  • How is SLE calculated?
  • What type of software is Wireshark?
  • What type of session does a null session represent?
  • What does an IDS alerting to a malicious sequence of packets indicate?
  • Which option is listed as a password retrieval method?
  • Dynamic ARP Inspection validates ARP packets against entries in which database?
  • In Wireshark, what does the filter 'tcp.port != 21' accomplish?
  • Which act does SP 800-53 support in federal information security?
  • Which statement best identifies a Smurf attack?
  • Which statement describes Finger?
  • What is the main function of a firewall?
  • What should you provide when contacting support for the CEHv13 exam?
  • What does IDS stand for in network security?
  • Which protocol is used to transmit email across the Internet?
  • What is the role of anti-virus software in maintaining a Vulnerability Management Program?
  • Which of the following is a well-known macro virus?
  • What is the purpose of a tunneling protocol?
  • What happens to Nmap scanning speed when using the -F flag?
  • In Nmap usage, what does the -T flag adjust?
  • What is a low-tech method for gaining unauthorized access to systems?
  • How does MAC filtering improve network security?
  • Which term describes a network segment exposed to the internet that isolates critical internal resources?
  • What is the primary use of NMap?
  • Which statement is NOT a PCI compliance recommendation?
  • Which of the following is a well-known macro virus?
  • Which option best describes CAPTCHA?
  • What is the proper response for a NULL scan if the port is open?
  • Which intrusion detection system is best for large environments with critical assets?
  • At which layer does IPsec primarily operate?
  • What does statement coverage measure in white-box testing?
  • What technologies allow intranet machines to connect to the Internet?
  • What is IPsec?
  • Which type of cryptography are PGP, SSL, and IKE examples of?
  • What is the impact of not having auditing enabled on a sensitive information system?
  • Which option correctly identifies the exam pool with the most questions?
  • How many hours are required to restore the OS and software to a new hard disk?
  • What best describes a counter-based authentication system?
  • What is the significance of the USER and NICK commands in IRC?
  • What does a stateless firewall do?
  • ARP spoofing refers to what?
  • In IPsec, which statement best describes host-to-host versus network-to-network?
  • What is the consequence of an IDS stopping reassembly during a session splicing attack?
  • What is the main characteristic of a polymorphic virus?
  • What is the primary goal of social engineering attacks?
  • How does a host-based application firewall define rules for processes?
  • In the context of ARP spoofing, what is the attacker primarily attempting to achieve?
  • Which statement best describes a digital signature?
  • If the expected frequency of a hard drive failure is once every three years, what is the ARO?
  • Which statement best describes a hacker who operates both offensively and defensively?
  • Which server type is primarily used to enable communication between different networks or protocols?
  • Which of the following is a white-box test design technique?
  • In the cost formula example, what are the two components combined to determine the total cost?
  • Which evasion technique complicates packet reassembly for an IDS by pausing between sending parts of an attack to hope the IDS times out before the target computer responds?
  • What is the role of an Intrusion Prevention System (IPS) in a security architecture?
  • What is the correct formula to calculate the cost of a hard drive replacement and recovery operation?
  • What is the impact of subnet diversity between DNS servers?
  • What is a common consequence of not observing proper chain of custody?
  • Why are encrypted transfer protocols used for file transfers?
  • What is the purpose of implementing a strong password policy?
  • What does True Negative indicate in IDS alerts?
  • Which statement best describes enumeration as used in security testing?
  • What is the primary goal of an attacker using web parameter tampering?
  • What is the main goal of fuzzing in software testing?
  • What is the total cost of recovery if the recovery person earns $10/hour?
  • Which of the following is NOT a white-box test design technique?
  • What command shows that the 'nc' file is running as a process?
  • What is the priority behavior of MX records?
  • What is the purpose of using tools like Kismet in network security?
  • Which type of algorithm guarantees the integrity of messages being sent, in transit, or stored?
  • What are the three possible authentication factors in two-factor authentication?
  • What alert indicated malware activities in the network?
  • Which statement best describes the primary function of a firewall?
  • Why is time synchronization important in network security?
  • Which statement best defines MAC filtering in wireless networks?
  • What is the role of TCP in network communication?
  • What does a man-in-the-middle attack involve?
  • A common feature of phishing emails hackers use is that they model the message to look similar to legitimate internal communications.
  • Which legislation requires federal agencies to secure information and information systems, with guidelines provided by NIST?
  • How does MAC filtering contribute to network efficiency?
  • Which statements about a zone transfer are correct?
  • In DNS, zone transfers are typically conducted between which types of servers?
  • Which mode of IPsec provides security and confidentiality of data transmitted within a local area network?
  • Phishing emails often rely on mimicking internal communications to foster trust. Which statement best reflects this tactic?
  • What is the primary purpose of a DMZ in a network?
  • Which ports must be filtered to check for null sessions on a network?
  • Which HTTP method is typically used to retrieve a resource representation from a server?
  • What is a potential security risk of using the same machines for DNS and other applications?
  • What property of a hashing algorithm makes it useful for verifying data integrity?
  • What does TTL stand for in DNS?
  • Which item is an example of 'Something you have'?
  • What is the role of the application server in the recommended architecture?
  • What primary function does a packet sniffer serve in network troubleshooting?
  • How does Wireshark differ from tcpdump?
  • What is the role of Kerberos in network security?
  • In TLS, which function is primarily performed by the private key?
  • Which UDP port is used by the Network Time Protocol (NTP) for communication?
  • What are the two authentication factors implemented in the solution?
  • Who first presented the meet-in-the-middle attack for cryptanalysis?
  • Which statement describes Dig's DNS capabilities?
  • In Nmap, what is the purpose of the -T flag?
  • What does a higher primary SOA indicate in a DNS setup?
  • What does the Annual Loss Expectancy (ALE) represent?
  • What type of measures are required to protect against sniffing attacks?
  • In the scenario with financial documents, which action helps verify integrity of the document after approval?
  • What does a closed port respond with during a NULL scan?
  • The -T flag in Nmap affects which aspects of a scan?
  • tcptraceroute is used for what?
  • What happens after the recursive resolver receives the IP address from the domain's nameserver?
  • What is the minimum number of network connections in a multihomed firewall?
  • Which of the following is NOT a secure protocol?
  • What did Joseph do to troubleshoot the website vandalism?
  • SMTP's lack of encryption primarily affects which aspect of email security?
  • What is the primary purpose of a counter-based authentication system?
  • Which description best defines a birthday attack in cryptography?
  • What is the primary role of the Dig tool in DNS operations?
  • In DNS, what is the purpose of a zone transfer?
  • Diffie and Hellman are associated with which cryptographic concept?
  • How do 2FA and MFA differ?
  • What two conditions must a digital signature meet?
  • If insecure protocols must be used, what should be done?
  • In a three-tier architecture, which component hosts the business logic and application code?
  • Which white-box test design technique focuses on the life cycle of data as it moves through the program to identify unused or uninitialized variables?
  • How many questions are in the CEH v13 exam's question pool?
  • Heartbleed affects which component?
  • Which statement best describes a covert channel as used in cybersecurity?
  • What is a common consequence of DNS spoofing attacks?
  • What skills are utilized in white-box testing?
  • What should a bank do before enabling the audit feature on their system?
  • What is bluedriving?
  • In an Nmap scan, what is the effect of the -oX option?
  • Which statement best defines risk avoidance?
  • What is the contact method for feedback regarding the CEHv13 exam product?
  • What does the TLD server respond with in a DNS lookup?
  • What security feature prevents vehicles from crashing through building doors?
  • In network security, what does DMZ stand for?
  • What is the closest approximate cost of the replacement and recovery operation per year?
  • What is the purpose of placing a network sniffer during a security assessment?
  • What vulnerability does the Shellshock exploit attempt to achieve on a Linux host?
  • What is the role of backbone routers in relation to private IP addresses?
  • Which statement best describes the Annual Rate of Occurrence (ARO)?
  • Which algorithm does NTP use to select accurate time servers?
  • DNSSEC helps protect against which threats?
  • Which virus type infects both the boot sector and executable files?
  • What is tcpdump used for?
  • What does the command 'net use \\targetipc$ "" /u:""' accomplish?
  • Which action would most effectively prevent unauthorized zone transfers?
  • Which credential is typically required for wireless access in networks using MAC filtering, as per common practice?
  • In risk management, which focus best describes risk mitigation?
  • What does Nikto scan for on web servers?
  • What is the significance of encryption in data protection?
  • In Windows networking, a null session is established by which method?
  • In an STP manipulation attack, what action might an attacker perform to capture traffic?
  • Which statement accurately describes the main advantage of test automation in security testing?
  • Which statement correctly describes the purpose of a CVE?
  • What does the acronym DHCP stand for?
  • In DNS, what does SOA stand for?
  • What are the initial two commands an IRC client sends to join an IRC network?
  • What is the role of test automation in security testing?
  • What is the main advantage of using a Linux LiveCD for password recovery?
  • What is a common method for protecting a network's internal resources?
  • What is the significance of the number of characters in a digital signature?
  • Which activity supports ongoing security for network elements in a data center?
  • Which of the following best describes MAC filtering's access control?
  • If insecure protocols must be used, what is the recommended approach to data protection?
  • Why is it important to regularly test security systems and processes?
  • Which statement about NTP synchronization accuracy is true?
  • What term describes automated testing that generates invalid input to attempt to crash a program?
  • Which statement about blocking NetBIOS traffic on a firewall is true?
  • What is the key length of Triple DES?
  • Which of the following statements about unknown files found in a critical directory is most accurate?
  • What is the main advantage of test automation in security testing?
  • Which technology enables devices with private IP addresses to communicate with public Internet resources by translating addresses?
  • In a counter-based OTP system, what is the role of the secret key?
  • Which type of IDS monitors activity on individual hosts and is useful for protecting specific machines?
  • A cryptographic hash function should be deterministic and produce fixed-length output.
  • What does Static Network Address Translation enable?
  • What is the primary function of a DMZ?
  • In SSL/TLS, what is the main advantage of using symmetric encryption for the data payload?
  • To reduce sniffing risk, which practice should organizations avoid?
  • In which year was the Heartbleed vulnerability publicly disclosed?
  • Which Nmap NSE script helps detect HTTP methods available on a web server?
  • Which DNS record indicates the Start of Authority and contains zone administrative information?
  • What is a 'rubber-hose' attack in cryptanalysis?
  • Which statement best describes a limitation of MAC filtering?
  • Which password cracking method takes the most time and effort?
  • What does IDS stand for?
  • Which metric is used to estimate the expected annual monetary loss due to risk?
  • The primary objective of hardening network elements includes securing them with strong authentication and performing regular security tests.
  • Which layer 3 protocol allows for end-to-end encryption of FTP connections?
  • What is the role of the DNS resolver in the lookup process?
  • How does the probability of an event occurring relate to the Annual Rate of Occurrence (ARO)?
  • What is the main function of a Resource record in DNS?
  • What should Bob do to prevent unauthorized student access to the wired network?
  • What is the primary function of a cryptographic hash function in cybersecurity?
  • What is the role of a Proxy server in a network?
  • In IDS evaluation, which statement describes a True Negative?
  • Which set of protocols should be preferred over insecure alternatives?
  • What is the function of a mediation server in networking?
  • What best defines a meet-in-the-middle attack (MITM)?
  • What does the term 'social engineering' refer to in cybersecurity?
  • Which port does IRC typically operate on?
  • In a DNS lookup, what is the significance of the IP address?
  • How does IPsec differ from TLS and SSH?
  • What is the primary function of network-based application firewalls?
  • Why should unnecessary ISAPI filters be disabled or removed?
  • What is the purpose of using a hash algorithm on financial statements?
  • Monitoring computer systems and networks primarily aims to achieve what outcome?
  • SQL injection is?
  • What does ARO stand for in risk management?
  • What is the primary communication method for NTP?
  • If a device's MAC address is on the whitelist, what happens when it tries to connect?
  • If SLE is $275 and ARO is 0.2, what is ALE?
  • Which statement best describes DNSSEC?
  • Which of the following items is typically required when requesting assistance for the CEHv13 exam?
  • Which statement correctly describes Secure Shell (SSH) usage?
  • What types of checks does Nikto perform on web servers?
  • If a secondary server cannot contact the primary server, what typically happens?
  • What is the definition of a false negative in IDS alerts?
  • A DMZ is typically used to host which type of resources?
  • Which DNS server provides the address of the domain's nameserver?
  • What is the primary purpose of training reservists in computer security?
  • What type of attack is described when an attacker intercepts communications between two entities without their knowledge?
  • What is a typical use of a Linux LiveCD in password recovery?
  • Which tool performs comprehensive tests against web servers for vulnerabilities?
  • What is the role of cryptographic security services in IPsec?
  • What can be a consequence of email spoofing?
  • Fuzzing primarily helps identify which type of software weakness?
  • Which cryptographic function is used to verify data integrity by producing a fixed-size representation of input data?
  • What is the main purpose of enabling auditing on a system that processes sensitive information?
  • Which term describes the initial information-gathering phase conducted by attackers to map an organization before intrusion?
  • What is the DNS configuration called when one DNS server is in the DMZ and another is on the internal network?
  • Which tool is used to detect and analyze wireless network traffic?
  • Which account typically has broad privileges on a system?
  • What is the consequence of unauthorized changes to the CEHv13 product?
  • In incident handling, which phase should define rules and backup planning?
  • What type of vulnerability allows a binary to be replaced with a malicious one due to improper permissions?
  • What is 'session splicing' in the context of packet crafting?
  • Which pair correctly lists the counts of questions in Exam Pool A and Exam Pool B?
  • What is the purpose of caching in DNS lookups?
  • Heartbleed vulnerability leaves exposed which type of key?
  • Why do phishing messages often include logos and formatting that mimic legitimate brands?
  • Which statement about the Hosts file is true?
  • Which statement about a hash and document integrity is correct?
  • What hacking process is characterized by gathering information about a target company?
  • Which Windows command would you use to query DNS records for troubleshooting name resolution?
  • Which mode allows a network interface controller to pass all traffic to the CPU?
  • In a DMZ, public-facing systems are typically placed?
  • In asymmetric cryptography, which elements constitute the key pair used for encryption and decryption?
  • OpenVAS is best described as which of the following?
  • Which statement describes a collision attack in cryptography?
  • What is the risk threshold for the application mentioned in the notes?
  • Which DNS record indicates the version of the zone file?
  • Which DNS security practice prevents zone data leakage?
  • What was the initial risk percentage for the main company application after the security risk assessment?
  • Which DNS resource record indicates how long DNS poisoning could last?
  • What type of attack involves tricking a user into clicking on a hidden or disguised webpage element?
  • What is the role of nslookup in relation to zone transfers?
  • What is risk mitigation?
  • Which term describes exploiting human psychology to obtain confidential information?
  • Nessus is best described as?
  • Which port is commonly used for unencrypted FTP transfers?
  • What is the significance of using static ARP entries in a small network?
  • Which statement best describes a man-in-the-middle attack?
  • What is the main advantage of a 'rubber-hose' attack?
  • What is the impact of residual risk in risk management?
  • What is a common reason for running an IRC server on a high-number port?
  • Which user account has System Administrator privileges from the SIDs list extracted by Peter?
  • In the recovery scenario, what is the total time required for recovery?
  • What is the primary function of the ENUM tool used by Eve?
  • Which tool can be used to monitor strange ARP activity?
  • What factor makes preventing social engineering attacks particularly challenging?
  • Which DNS record indicates the Start of Authority for a zone?
  • Which DNS record identifies the authoritative name server for a zone and governs caching parameters?
  • Which term describes the collection of publicly available information that can be used for actionable intelligence?
  • Which command-line tool serves as a packet analyzer similar to Wireshark?
  • Which Resource Records are included in a zone file?
  • Which tool is identified for conducting a Blackjacking-type attack?
  • What is the purpose of a Snort rule in network security?
  • What is a common characteristic of phishing scams claiming to be from financial institutions?
  • What does a zone transfer in DNS allow?
  • What is the role of a DNS recursive resolver in name resolution?
  • At which OSI layer does the encryption and decryption of a message using PKI occur?
  • If a wireless client is configured correctly, what should happen when it connects to the network?
  • What is the primary goal of white-box testing?
  • Which security feature on switches uses the DHCP snooping database to prevent man-in-the-middle attacks?
  • How does DAI validate ARP packets?
  • Which measure is most effective as a proactive safeguard against ARP spoofing on a switched network?
  • What is the recommended approach for discovering vulnerabilities on a Windows-based computer?
  • Which statement describes the use of tcptraceroute?
  • Heartbleed affects which TLS library's implementation?
  • Which technology is free and open-source used for network troubleshooting, analysis, software and communications protocol development, and education?
  • What is the function of CAPTCHA in online security?
  • What is session splicing in the context of IDS evasion techniques?
  • At which OSI layer do application firewalls primarily operate?
  • What is Eve trying to do when she uses the ENUM tool on Alice's machine?
  • Which organization officially assigns ports for network protocols?
  • What is the significance of the SOA record version in DNS?
  • What does MAC filtering help prevent in an enterprise wireless network?
  • What does an attacker typically need to perform a meet-in-the-middle attack?
  • What is the main function of a perimeter email gateway?
  • What does the term 'false positives' refer to in authentication systems?
  • In cybersecurity, enumeration refers to which activity?
  • In network security, what does a Snort rule primarily do?
  • What is the purpose of STARTTLS in SMTP?
  • Which exam topic has the highest number of questions in CEH v13?
  • What is risk transference?
  • What is the version in the SOA record for Rutgers.edu?
  • How many questions are in Exam Pool A?
  • What alternative can a tester use if ICMP is disabled when pinging a target?
  • At what levels can white-box testing be applied?
  • What is the purpose of the CEHv13 exam?
  • Which type of malware actively alters service call interruptions to hide from anti-virus programs?
  • What is the goal of restricting access to cardholder data?
  • What is the importance of tracking vulnerable packets in network security?
  • What is a common use of L0phtcrack?
  • What is the main goal of email spoofing in cybersecurity?
  • By default, how many ports does Nmap scan?
  • What type of attack is identified by a Unicode Directory Traversal Attack?
  • Macros are typically embedded in which type of documents?
  • Which description best characterizes a DMZ in a network?
  • SNMP enumeration tools such as SNMPUtil, SNScan, and Solarwinds IP Network Browser are used to perform what on a network?
  • What is the purpose of a demilitarized zone (DMZ) on a network?
  • A Unicode Directory Traversal Attack primarily relies on which tactic?
  • Which statement describes NMap?
  • Which operating system was not directly affected by the Shellshock vulnerability?
  • Which of the following is a secure file transfer protocol?
  • DNSSEC helps mitigate which type of vulnerability?
  • Why is monitoring ARP activity important for network security?
  • What is risk limitation?
  • Which of the following does a SYN scan typically check for?
  • In data center security, which statement best describes the role of perimeter defense mechanisms such as firewalls and IPS?
  • In what kind of system would you find a rule like 'alert tcp any any -> 192.168.100.0/24 21'?
  • DNS poisoning can accomplish which outcome?
  • A sniffing attack is best described as which of the following?
  • What is the goal of training more National Guard and reservists in computer security?
  • What is the main goal of a phishing attack?
  • Which command can be used in Wireshark to filter for unencrypted file transfers on port 21?
  • If the guest account has been disabled, what does this indicate?
  • In white-box testing, what does control flow testing primarily verify?
  • Which statement best describes Kismet's function?
  • What does the -F flag in Nmap do?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy