312-50V13: Certified Ethical Hacker (CEH v13) Practice Exam
QuestionQ1
Web Application Hacking
Save question
A malware analyst must assess a suspicious PDF file believed to initiate attacks through embedded JavaScript. Initial pdfid scans show JavaScript and /OpenAction keywords.
What should the analyst do next to understand the possible impact?
ACompute file hashes using HashMyFiles for signature matching.
BExtract and analyze stream objects using PDFStreamDumper.
CDisassemble the PDF using PE Explorer.
DUpload the file to VirusTotal and rely on engine consensus.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Reconnaissance Techniques
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Reconnaissance Techniques
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Cryptography
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
System Hacking Phases and Attack Techniques
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Information Security and Ethical Hacking OverviewReconnaissance TechniquesSystem Hacking Phases and Attack TechniquesNetwork and Perimeter HackingWeb Application HackingWireless Network HackingMobile Platform, IoT, and OT HackingCloud ComputingCryptography
A financial startup in Chicago engages an ethical hacker to assess its exposure on hidden networks. The client is especially worried that confidential administrative documents may be circulating on .onion sites. To stay passive, the hacker uses advanced search filters to find files with headers indicating management-related content. Which query would best achieve this objective?
Afiletype:pdf intitle:”admin access” site:onion
Bfiletype:docx intitle:”user accounts” site:onion
Cfiletype:docx intitle:”login credentials”
Dfiletype:pdf intitle:”secure login” site:onion
Joe, a cybersecurity analyst at Norwest Freight Services, is assigned to perform a vulnerability scan across the organization’s infrastructure. He must identify weaknesses—including missing patches, unnecessary services, weak encryption, and authentication flaws—on multiple servers. The scan finds open ports and active services throughout the environment, creating a clear map of potential attacker entry points.
Which type of vulnerability scan BEST matches Joe’s assignment?
AApplication Scanning
BHost-based Scanning
CExternal Scanning
DNetwork-based Scanning
In a recent vulnerability assessment of a major corporation’s IT systems, the security team identified several potential risks. They want to use a vulnerability scoring system to quantify and prioritize these vulnerabilities. They choose to use the Common Vulnerability Scoring System (CVSS). Given the characteristics of the identified vulnerabilities, which of the following statements is most accurate about the metric types CVSS uses to measure these vulnerabilities?
ATemporal metric represents the inherent qualities of a vulnerability.
BBase metric represents the inherent qualities of a vulnerability.
CTemporal metric involves measuring vulnerabilities based on a specific environment or implementation.
DEnvironmental metric involves the features that change during the lifetime of the vulnerability.
An attacker chose to crack passwords used by industrial control systems. During this effort, the attacker used a looping strategy to recover the passwords. The attacker tested one character at a time to determine whether the first entered character was correct; if it was, the loop continued with subsequent characters. If it was not, the loop ended. In addition, the attacker measured how long the device required to complete a full password-authentication process, allowing the attacker to infer how many entered characters were correct.
What attack technique did the attacker use to crack the industrial control-system passwords?
ABuffer overflow attack
BSide-channel attack
CDenial-of-service attack
DHMI-based attack
QuestionQ6
Cryptography
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Network and Perimeter Hacking
QuestionQ8
Network and Perimeter Hacking
QuestionQ9
System Hacking Phases and Attack Techniques
QuestionQ10
Web Application Hacking
QuestionQ11
Web Application Hacking
QuestionQ12
Network and Perimeter Hacking
QuestionQ13
Mobile Platform, IoT, and OT Hacking
QuestionQ14
Reconnaissance Techniques
QuestionQ15
Web Application Hacking
QuestionQ16
Network and Perimeter Hacking
QuestionQ17
System Hacking Phases and Attack Techniques
QuestionQ18
Web Application Hacking
QuestionQ19
Reconnaissance Techniques
QuestionQ20
Reconnaissance Techniques
QuestionQ21
Cloud Computing
QuestionQ22
Network and Perimeter Hacking
QuestionQ23
Cloud Computing
QuestionQ24
Network and Perimeter Hacking
QuestionQ25
System Hacking Phases and Attack Techniques
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Tony is a penetration tester assigned to conduct a penetration test. After obtaining initial access to a target system, he discovers a list of hashed passwords.
Which of the following tools would not be useful for cracking the hashed passwords?
AHashcat
BJohn the Ripper
CTHC-Hydra
Dnetcat
Which protocol is insecure by default?
AHTTPS
BSFTP
CSSH
DTelnet
During an internal security assessment of a medium-sized enterprise network, a security analyst observes an unusual increase in ARP traffic. Closer review shows that a particular MAC address is linked to multiple IP addresses across different subnets. The ARP packets are unsolicited replies rather than requests, and several employees in different departments report intermittent connection drops, failed logins, and broken intranet sessions. The analyst suspects deliberate interference on the local network segment.
What is the most likely cause of this abnormal behavior?
AARP poisoning causing routing inconsistencies
BDHCP snooping improperly configured
CPort security restricting all outbound MAC responses
DLegitimate ARP table refresh on all clients
John, a security analyst, is examining a server suspected of compromise. The attacker used a non-admin account and has already established a foothold on the system. John finds a new Dynamic Link Library loaded in the application directory on the affected server. The DLL lacks a fully qualified path and appears malicious. Which privilege-escalation technique has the attacker most likely used to compromise the server?
ADLL Hijacking
BNamed Pipe Impersonation
CSpectre and Meltdown Vulnerabilities
DExploiting Misconfigured Services
During a targeted phishing campaign, an attacker obtains access to a trusted internal system in a corporate network secured by advanced firewalls, IDS, and email security gateways. To preserve persistence and avoid content inspection, the attacker creates a malicious HTML email attachment with obfuscated JavaScript code. When a user opens the attachment in a browser, a concealed JavaScript blob dynamically rebuilds a malware payload and initiates an automatic client-side file download. No external connections occur during this process, making the attack difficult for network security tools to detect or prevent.
Which evasion technique is used to bypass the firewall and IDS protections?
AHTTP header spoofing
BPort forwarding
CHTML smuggling
DCross-site scripting
A penetration tester believes the web application's “Order History” page may be vulnerable to SQL injection because it shows user orders from an unprotected user ID parameter in the URL.
What is the most suitable way to test this?
AInject JavaScript into the URL parameter to test for Cross-Site Scripting (XSS)
BModify the URL parameter to userlD=l OR 1=1 and observe if all orders are displayed
CPerform a directory traversal attack to access sensitive system files
DUse a brute-force attack on the login form to identify valid user credentials
This configuration enables a wired or wireless network interface controller to send all traffic it receives to the Central Processing Unit (CPU), rather than sending only the frames the controller is intended to receive.
Which of the following is described?
APromiscuous mode
BPort forwarding
CWEM
DMulti-cast mode
A critical-infrastructure facility operates an extensive network of IoT devices integrated with its OT systems. After a recent global increase in cyberattacks against similar facilities, the security team receives an anonymous email describing a possible attack on its systems. The attacker allegedly intends to compromise the IoT devices and use them as a gateway to the OT systems.
What immediate action should the security team take to mitigate this threat?
AInitiate a full-scale penetration testing exercise on IoT devices to identify and patch vulnerabilities.
BDeploy a machine-learning-based security solution to monitor and predict potential threats.
CEstablish a secure communication protocol between IoT and OT systems with proper encryption and authentication.
DEmploy an intrusion prevention system (IPS) on the network to detect and block any malicious activities.
What is the appropriate response to a NULL scan when the port is closed?
ANo response
BFIN
CRST
DSYN
EACK
FPSH
Which file is a valuable target for identifying a website's structure during web-server footprinting?
Adomain.txt
BRobots.txt
CDocument root
Dindex.html
As a newly hired network security analyst at a mid-tier company, you have been assigned to evaluate network security. As part of this work, you must ensure the company network can detect and prevent evasion techniques. You know that attackers commonly use packet fragmentation as an evasion technique.
Which of the following IDS configurations should be implemented to counter this technique?
AConfiguring the IDS to reject all fragmented packets to eliminate the risk.
BImplementing an anomaly-based IDS that can recognize the irregular traffic patterns caused by packet fragmentation.
CAdjusting the IDS to recognize the regular intervals at which fragmented packets are sent.
DEmploying a signature-based IDS that recognizes the specific signature of fragmented packets.
A system's audit logs have not been centralized.
Which attack phase is most difficult to detect?
AInitial access
BLateral movement
CDelivery
DRecon
A penetration tester is assessing a web server that permits unrestricted file uploads. The server accepts files without adequately validating or sanitizing file types.
Which technique should the tester use to exploit this weakness and potentially gain control of the server?
APerform a SQL injection attack to extract sensitive database information
BUse a Cross-Site Scripting (XSS) attack to steal user session cookies
CConduct a brute-force attack on the server’s FTP service to gain access
DUpload a shell script disguised as an image file to execute commands on the server
As a cybersecurity analyst for a multinational corporation, you are responsible for conducting routine vulnerability scans. On this occasion, you chose a different approach and used a FIN scan, a stealth-scanning technique. After completing the scan, you observe an unusual result: a significant number of ports did not respond to your FIN packets. You must now correctly interpret these findings and determine the next action.
Based on your knowledge of FIN scanning and TCP/IP protocols, how should these findings be interpreted?
AConclude that these ports are closed since they did not respond to the FIN packets.
BConsider the possibility of firewall blocking the FIN packets and investigate further.
CInterpret this as a sign of network congestion and prioritize network optimization.
DImmediately escalate this issue to management as it indicates a potential ongoing breach.
What does an ACK scan primarily identify?
AServices
BFirewall rules
CClosed ports
DOpen ports
At a Miami-based cryptocurrency exchange, investigator Jake finds that attackers exploited exposed API keys to send unauthorized cloud commands, causing resource abuse and lateral movement within the cloud environment. Which cloud-hacking technique is most directly illustrated by this incident?
ACryptojacking
BEnumerating S3 buckets
CCompromising secrets
DWrapping attack
You are a cybersecurity analyst at a financial institution. Your organization strictly prohibits all unencrypted protocols. You have observed data packets traveling over HTTP rather than HTTPS on the network. This is concerning because HTTP transmits data in plaintext. To investigate further, you choose to use a sniffing tool.
Which of the following is the most appropriate choice?
ANetcat
BWireshark
CNmap
DNessus
A security researcher is assessing a target organization’s publicly available cloud infrastructure. When inspecting the website’s HTML source, the researcher finds direct references to files hosted in Amazon S3.
What is the most effective method for finding additional publicly accessible bucket URLs used by the target?
AUse SQL injection to extract internal file paths from the database.
BExploit XSS to force the page to reveal the S3 links.
CPerform packet sniffing to intercept internal S3 bucket names.
DUse Google advanced search operators to enumerate S3 bucket URLs.
A security analyst is investigating a possible network-level session-hijacking incident. During the investigation, the analyst discovers that an attacker used a technique in which they injected an authentic-looking reset packet with a spoofed source IP address and a guessed acknowledgment number. Consequently, the victim's connection was reset. Which of the following hijacking techniques did the attacker most likely use?
ABlind hijacking
BUDP hijacking
CRST hijacking
DTCP/IP hijacking
During a stealth penetration test for a multinational shipping company, ethical hacker Daniel Reyes obtains local access to an engineering workstation and deploys a specialized payload that installs beneath the operating system. On later reboots, the payload runs before any system-level drivers or services become active, granting Daniel covert control of the machine without triggering antivirus or endpoint-detection tools. Weeks later, system administrators report suspicious network activity, yet repeated forensic scans cannot find malicious processes or user-level traces.
Which type of rootkit did Daniel most likely use to preserve this degree of stealth and persistence?
Community Discussion