EC-Council Certified Ethical Hacker (CEH) v12 practice questions

212 free questions with answers and explanations.

Practice test
  1. 1.A penetration tester is evaluating the security of a corporate wireless network. They have successfully captured a WPA2-Personal 4-way handshake using a tool like Airodump-ng. The target network's SSID is 'CorpNet' and its PSK is known to be a dictionary word followed by a year. Which of the following attack methods would be MOST efficient for attempting to recover the PSK in this scenario?Wireless Network Hacking
  2. 2.A network security engineer is tasked with securing a wireless network that serves a public area, offering free Wi-Fi. The primary concern is protecting user privacy and preventing unauthorized access to client data, even if the network is open. Which security measure, when implemented on the access points, would provide individual encryption for each client session without requiring a pre-shared key or 802.1X authentication?Wireless Network Hacking
  3. 3.A security analyst is conducting a wireless assessment and discovers an access point broadcasting an SSID named 'FreeWiFi' with no encryption enabled. The analyst observes numerous clients connecting to this network. Which type of attack is most readily facilitated by this configuration, allowing an attacker to intercept client communications?Wireless Network Hacking
  4. 4.A security analyst is performing a site survey for a new wireless deployment and is concerned about potential interference from non-Wi-Fi devices. Which frequency band is most susceptible to interference from common household appliances like microwave ovens and cordless phones, requiring careful channel planning to avoid performance degradation?Wireless Network Hacking
  5. 5.A security consultant is performing a wireless penetration test. They observe an access point (AP) that is configured to require clients to register their MAC addresses before being granted network access. The consultant spoofs the MAC address of an authorized client and successfully connects to the network. Which of the following wireless security mechanisms was circumvented by this action?Wireless Network Hacking
  6. 6.A wireless network is configured with WPA2-Enterprise using EAP-TLS. A penetration tester attempts to perform a Man-in-the-Middle (MitM) attack by setting up a rogue access point (Evil Twin) that mimics the legitimate network. The tester configures the rogue AP to request a username and password from connecting clients. However, legitimate clients, configured to use EAP-TLS, refuse to connect to the rogue AP and display a certificate warning. What specific security feature of EAP-TLS is preventing the success of this MitM attack?Wireless Network Hacking
  7. 7.A penetration tester is performing a wireless assessment and identifies several access points broadcasting the same SSID. They notice that clients frequently roam between these access points. To efficiently map the physical locations of these APs and their associated clients, and to understand the overall wireless network topology, which of the following tools is BEST suited for passive wireless reconnaissance and visualization?Wireless Network Hacking
  8. 8.A security auditor is performing a penetration test against a client's wireless network. They notice that the network's APs are broadcasting multiple SSIDs, some of which are hidden. During a deauthentication attack against a connected client, the client reassociates with the network, and the auditor captures the full 4-way handshake. Which of the following tools is specifically designed to perform this type of targeted deauthentication and capture the handshake for WPA/WPA2 cracking?Wireless Network Hacking
  9. 9.A security analyst is investigating a suspected wireless intrusion. They have captured a large amount of raw 802.11 traffic in a .pcap file. To identify potential rogue access points, analyze beacon frames, and detect other anomalies, which specialized wireless analysis tool is specifically designed for passive sniffing and network discovery?Wireless Network Hacking
  10. 10.A wireless network administrator is deploying a new WPA3-enabled network. They are considering the security implications of client compatibility. Which of the following WPA3 features provides protection against passive offline dictionary attacks, even if an attacker captures the initial handshake, and is a mandatory component for WPA3-Personal networks?Wireless Network Hacking
  11. 11.A penetration tester is targeting a WPA2-Enterprise network that uses 802.1X for authentication. The tester successfully captures EAPOL frames between a client and the RADIUS server. To proceed with an offline attack against the captured credentials, which specific EAP method's inner tunnel credentials must the tester attempt to extract and crack?Wireless Network Hacking
  12. 12.A cybersecurity analyst is tasked with performing a site survey for a new corporate wireless network in a multi-story building. The goal is to ensure optimal coverage and minimize interference. While using a spectrum analyzer, the analyst identifies significant interference in the 5 GHz band, specifically from devices operating on channels typically used by Wi-Fi. Which of the following is the MOST likely source of this interference?Wireless Network Hacking
  13. 13.A network architect is designing a wireless network for a critical infrastructure facility. The primary requirement is to ensure the integrity and authenticity of management frames to prevent denial-of-service attacks like deauthentication floods. Which IEEE 802.11 amendment specifically addresses this requirement by providing protection for management frames?Wireless Network Hacking
  14. 14.A security researcher discovers a new type of wireless attack where a malicious actor sends specially crafted control frames to a target access point, causing it to crash or operate erratically, disrupting service for all connected clients. This attack exploits a vulnerability in the AP's firmware handling of these specific frame types. Which category of wireless attacks does this scenario BEST describe?Wireless Network Hacking
  15. 15.A penetration tester is targeting a wireless network that utilizes WPS (Wi-Fi Protected Setup) for easy device connection. The tester uses a tool to systematically guess the WPS PIN. Which specific WPS attack exploits the design flaw where the PIN verification process can be broken into two smaller, independent halves, significantly reducing the number of attempts needed for a brute-force attack?Wireless Network Hacking
  16. 16.A penetration tester is evaluating the security of an industrial control system (ICS) wireless network that utilizes legacy 802.11b devices. The network is configured with WEP encryption. Which tool is specifically designed to exploit WEP's vulnerabilities by injecting packets and later cracking the key using statistical analysis of IVs?Wireless Network Hacking
  17. 17.A security auditor is performing a wireless penetration test on a corporate network. They successfully capture a WPA/WPA2 4-way handshake. To crack the passphrase offline, which specific cryptographic element from the handshake is essential for a dictionary or brute-force attack?Wireless Network Hacking
  18. 18.A security consultant is advising a client on securing their wireless infrastructure against denial-of-service (DoS) attacks. The client is particularly concerned about attacks that prevent legitimate users from associating with the access point or maintain existing connections. Which countermeasure directly addresses the vulnerability exploited by deauthentication and disassociation attacks?Wireless Network Hacking
  19. 19.An attacker is attempting to exploit a vulnerability in a WPA2-Personal network that uses a weak passphrase. They have captured a limited number of frames from the 4-way handshake. Instead of a full dictionary attack, they decide to use a precomputed rainbow table that maps common passphrases directly to their corresponding Pairwise Master Keys (PMKs). What is the primary limitation of using rainbow tables for cracking WPA2-Personal, especially compared to their effectiveness against other hash types?Wireless Network Hacking
  20. 20.A network administrator is designing a secure wireless network for a new office. The requirements include strong encryption, mutual authentication using certificates, and protection against common wireless vulnerabilities like key reinstallation attacks. Which combination of security protocols and authentication methods would best meet these criteria?Wireless Network Hacking
  21. 21.A penetration tester is performing a wireless assessment on a corporate network. They discover an access point that is broadcasting a hidden SSID and is configured with WPA2-Personal. The tester attempts to capture a 4-way handshake, but no active clients are connected. To force a handshake capture, the tester uses a tool to send a deauthentication packet to a client that is associated with the target AP from a distance. Which specific 802.11 frame type is the tester leveraging for this action?Wireless Network Hacking
  22. 22.A cybersecurity team is investigating a reported unauthorized access to their internal wireless network. Logs show a sudden spike in deauthentication frames targeting multiple legitimate client devices, immediately followed by connections to a rogue access point. Which wireless attack technique does this sequence of events strongly suggest?Wireless Network Hacking
  23. 23.A penetration tester is attempting to compromise a WPA2-Personal network. They have captured the 4-way handshake and are now performing an offline dictionary attack. The target network uses a passphrase of 'SecurePassword123' and the SSID is 'MyCompanyWiFi'. What is the critical mathematical operation that occurs repeatedly during the dictionary attack to generate the Pairwise Master Key (PMK) for each guessed passphrase?Wireless Network Hacking
  24. 24.A penetration tester is analyzing a wireless network that uses WPA2-Enterprise with 802.1X authentication. During the reconnaissance phase, they observe that the network requires users to input their domain credentials. Which authentication protocol is most likely being used in conjunction with 802.1X for this scenario?Wireless Network Hacking
  25. 25.A security analyst is reviewing web server logs and notices an unusually high number of GET requests to a specific static resource, `example.com/images/logo.png`, originating from a single IP address within a very short timeframe. The requests appear legitimate but are far more frequent than expected for typical user behavior. What type of web server attack is most likely occurring?Web Application Hacking
  26. 26.A web application is designed to convert user-submitted URLs into PDF documents. A security researcher attempts to submit an internal URL (e.g., `http://localhost/admin`) to the conversion service and observes that the PDF output includes content from the internal resource. Which web application attack does this scenario demonstrate?Web Application Hacking
  27. 27.A security auditor is examining a web server configuration and discovers that directory listing is enabled for several web directories. What is the primary security risk associated with enabling directory listing?Web Application Hacking
  28. 28.During a penetration test, an ethical hacker discovers that a web application is vulnerable to Cross-Site Request Forgery (CSRF). Which of the following conditions is NOT typically required for a successful CSRF attack?Web Application Hacking
  29. 29.An ethical hacker is performing reconnaissance on a web server and uses `nmap -p 80,443 --script http-enum <target_IP>`. What specific information is the hacker primarily attempting to discover with this Nmap script?Web Application Hacking
  30. 30.A web application utilizes a NoSQL database for storing user profiles. A penetration tester discovers that by injecting specific characters like `{$ne: null}` into a search query parameter, they can bypass authentication and view all user profiles without providing credentials. Which type of injection attack is this tester leveraging?Web Application Hacking
  31. 31.A web developer wants to implement a robust input validation mechanism to prevent various web application attacks. Which validation approach is generally considered the most secure and effective?Web Application Hacking
  32. 32.A web application allows users to upload profile pictures. A security engineer notices that the application checks the `Content-Type` header (e.g., `image/jpeg`) on the client-side but does not perform server-side validation of the file's actual content. An attacker could potentially bypass this control by uploading a malicious script file with a faked `Content-Type` header. Which countermeasure is most effective in preventing this type of attack?Web Application Hacking
  33. 33.An attacker is attempting to exploit a web server that is misconfigured to allow HTTP TRACE requests. What is the primary purpose of leveraging an HTTP TRACE request in an attack scenario?Web Application Hacking
  34. 34.A security researcher discovers a vulnerability in a web application where an attacker can submit a crafted XML payload to an endpoint that processes XML data. The payload includes an external entity declaration that attempts to read a local file from the server, such as `/etc/passwd`, and include its content in the XML parser's output. Which type of attack is this?Web Application Hacking
  35. 35.A penetration tester is evaluating a web application that uses URL parameters to control content display. They observe that a parameter named `page` is used to load different HTML files (e.g., `example.com/app?page=home.html`). The tester attempts to manipulate this parameter to access sensitive files outside the intended directory, such as `example.com/app?page=../../../../etc/passwd`. Which type of web application attack is being attempted?Web Application Hacking
  36. 36.A penetration tester is analyzing a web application that stores user session IDs in cookies. The tester notices that the session ID remains constant even after a user logs out and then logs back in. This behavior could indicate a vulnerability related to session management. Which specific attack could exploit this flaw?Web Application Hacking
  37. 37.A web administrator is configuring a new web server and is advised to implement a Web Application Firewall (WAF) as part of the security architecture. What is the primary function of a WAF?Web Application Hacking
  38. 38.A penetration tester is performing a network scan on a target's perimeter network. They perform an Nmap scan and receive responses from both TCP and UDP ports. To ensure the accuracy of the UDP scan results, which often suffer from false positives or timeouts, what is the most reliable method to confirm if a UDP port is truly open?Reconnaissance Techniques
  39. 39.An ethical hacker is performing an internal penetration test. They have gained access to a workstation on a subnet and want to quickly identify other active hosts on the *same local subnet* without routing through any Layer 3 devices. Which Nmap host discovery technique is most efficient for this specific scenario?Reconnaissance Techniques
  40. 40.A security team is reviewing its public-facing DNS infrastructure for potential enumeration vulnerabilities. They discover that their primary DNS server is configured to allow any external host to perform a full zone transfer. Which countermeasure should be implemented immediately to prevent unauthorized disclosure of internal network topology and host information?Reconnaissance Techniques
  41. 41.A penetration tester is evaluating a web application's login mechanism. They observe that the application uses a fixed, predictable session ID after successful authentication. If an attacker can obtain a valid session ID from a legitimate user before they log in, and then use that ID to authenticate themselves, which attack vector is the application vulnerable to?Web Application Hacking
  42. 42.A penetration tester is evaluating a web application's login form. They notice that repeated failed login attempts for a specific username do not result in any account lockout or delay mechanism. The tester then proceeds to use a tool to rapidly try thousands of common passwords against a single target username. Which type of attack is the tester performing?Web Application Hacking
  43. 43.During a penetration test, an ethical hacker discovers that a web application uses HTTP Basic Authentication over an unencrypted HTTP connection. The hacker intercepts the traffic and easily decodes the Base64-encoded credentials, gaining access to user accounts. Which web server attack countermeasure would have prevented this specific vulnerability?Web Application Hacking
  44. 44.A penetration tester is evaluating the security posture of an organization's internal network. They want to identify active hosts on the local subnet without generating significant network traffic that could trigger intrusion detection systems. Which Nmap scan type is best suited for this objective?Reconnaissance Techniques
  45. 45.A penetration tester is evaluating the robustness of a client's perimeter network. They need to identify all open TCP ports on a range of external IP addresses. The client has a strict policy against any scanning techniques that could cause service disruption or be easily detectable by common firewalls and IDS/IPS. Which Nmap scan type is generally considered the most stealthy and least disruptive for identifying open TCP ports, while still being effective?Reconnaissance Techniques
  46. 46.A security analyst is performing an external penetration test against a client's public-facing web server. They are attempting to identify the web server software and its version without directly connecting to the server. Which of the following reconnaissance techniques would be most effective for this passive information gathering?Reconnaissance Techniques
  47. 47.An ethical hacker is performing a black-box penetration test on a web application. They discover that the application uses a JavaScript library to validate user input on the client side before submission. The hacker bypasses this client-side validation by intercepting the HTTP request with a proxy tool and modifying the input values before they reach the server. Which of the following is the most significant security implication of relying solely on client-side validation?Web Application Hacking
  48. 48.A penetration tester is analyzing a web application that stores user preferences in a cookie. The cookie value is base64 encoded and contains a serialized object with user settings, including an 'isAdmin' boolean flag. The tester decodes the cookie, changes 'isAdmin' from 'false' to 'true', re-encodes it, and sends the modified cookie with the next request. The application then grants administrative privileges. This scenario describes an exploitation of which common web application vulnerability?Web Application Hacking
  49. 49.A security analyst is investigating a potential phishing campaign targeting their organization. They want to identify if any internal email addresses are publicly exposed on various websites or forums. Which footprinting tool or technique would be most effective for gathering this type of information without directly interacting with the target's network?Reconnaissance Techniques
  50. 50.A security analyst is investigating a potential data breach and needs to determine if any sensitive files from their internal network have been indexed by public search engines. Which of the following advanced search engine operators would be most effective for identifying specific file types (e.g., .pdf, .docx, .xlsx) within a particular domain?Reconnaissance Techniques