EC-Council Certified Ethical Hacker (CEH) v12 practice questions
212 free questions with answers and explanations.
- 51.A penetration tester is performing reconnaissance on an organization's public-facing web servers. They use the 'dirb' tool with a wordlist to discover hidden directories and files that are not linked from the main website. What enumeration technique is being employed here?Reconnaissance Techniques
- 52.An ethical hacker is performing an internal penetration test and has gained access to a workstation. They want to identify other active hosts on the local network segment without sending any packets that would leave the local subnet and trigger network-based intrusion detection systems (NIDS). Which of the following Nmap host discovery techniques would be most suitable for this scenario?Reconnaissance Techniques
- 53.An ethical hacker is performing a black-box penetration test on a web application. They discover that the application uses a JavaScript library to validate user input on the client side before submission. The hacker bypasses this client-side validation by intercepting the HTTP request with a proxy tool and modifying the input values before they reach the server. Which of the following is the most significant security implication of relying solely on client-side validation?Web Application Hacking
- 54.A penetration tester is performing a network scan on a target's perimeter network. They perform an Nmap scan and receive responses from both TCP and UDP ports. To ensure the accuracy of the UDP scan results, which often suffer from false positives or timeouts, what is the most reliable method to confirm if a UDP port is truly open?Reconnaissance Techniques
- 55.A security auditor is reviewing a web application's configuration. They discover that the application allows HTTP TRACE requests, and sensitive information, such as HTTPOnly cookies and authentication headers, is reflected back in the TRACE response. Which of the following attack types is facilitated by this misconfiguration?Web Application Hacking
- 56.A penetration tester is tasked with identifying the operating systems running on a target's internal network hosts. They have already performed a basic port scan and identified several open ports. To accurately determine the OS, which Nmap scan type would be most appropriate and effective without being overly intrusive?Reconnaissance Techniques
- 57.A security analyst is reviewing network traffic to a web server and observes several HTTP GET requests for non-existent files with repeated patterns like `../../../../etc/passwd`. The server responds with 404 Not Found errors for these requests. Which attack technique is the analyst most likely observing?Web Application Hacking
- 58.A cybersecurity consultant is advising a small business on hardening their public-facing web server to prevent information leakage. The previous penetration test identified that the server's HTTP response headers (e.g., 'Server', 'X-Powered-By') were revealing specific software versions and technologies. Which of the following is the most effective countermeasure to address this specific issue?Reconnaissance Techniques
- 59.A security analyst is investigating a potential phishing campaign targeting their organization. They want to identify if any internal email addresses are publicly exposed on various websites or forums. Which footprinting tool or technique would be most effective for gathering this type of information without directly interacting with the target's network?Reconnaissance Techniques
- 60.A newly hired cybersecurity analyst is reviewing the organization's current footprinting countermeasures. They notice that public-facing web servers are still configured with verbose error messages that reveal database connection strings, internal file paths, and application versions. What is the primary risk associated with these verbose error messages, and what countermeasure should be immediately implemented?Reconnaissance Techniques
- 61.A penetration tester is performing a black-box assessment against a client's web application. They need to identify all subdomains associated with `example.com` to expand their attack surface. Which of the following methods would be most comprehensive for discovering subdomains without relying solely on DNS brute-forcing?Reconnaissance Techniques
- 62.A security consultant is performing an internal penetration test and has gained a foothold on a Windows workstation. To identify other active hosts on the local subnet for lateral movement, without relying on tools that might be flagged by antivirus, which native Windows command-line utility could be used for basic host discovery?Reconnaissance Techniques
- 63.A security consultant is performing an external penetration test. They need to identify all subdomains associated with the target's primary domain (example.com) to expand the attack surface. They decide to use a technique that queries various public DNS records and search engines. Which enumeration method is being employed?Reconnaissance Techniques
- 64.A penetration tester is performing a black-box assessment and needs to identify live hosts within a target network segment. They want to avoid sending any packets that would generate logs on the target's operating system or application layers, aiming for a very low-noise approach. Which Nmap host discovery technique, while less reliable on some systems, primarily aims to elicit responses only from the network stack without engaging higher-level services?Reconnaissance Techniques
- 65.A penetration tester is evaluating a web application that allows users to submit feedback through a form. The form includes a text area for comments and a hidden field for a 'category' value. The tester intercepts the request and modifies the hidden 'category' field from 'General' to 'Admin'. Upon submission, the feedback is processed with administrative privileges, allowing the tester to view sensitive internal system logs. Which type of vulnerability has been exploited?Web Application Hacking
- 66.A web application developer is designing a new API endpoint that accepts JSON payloads containing user data. To prevent malicious data from being processed, the developer wants to ensure that all incoming JSON data strictly conforms to a predefined schema, rejecting any requests with extra fields or incorrect data types. Which web application security concept is the developer implementing?Web Application Hacking
- 67.A security team is implementing a defense-in-depth strategy for a critical web application. They have decided to place a reverse proxy in front of the web server. This reverse proxy will be configured to inspect incoming HTTP requests for malicious patterns, filter out known attack signatures, and block suspicious IP addresses before requests even reach the backend application. Which type of web application security component is this reverse proxy primarily acting as?Web Application Hacking
- 68.A security analyst is investigating suspicious network activity originating from an unknown IP address. They want to identify the country and the Internet Service Provider (ISP) associated with this IP address to gather initial intelligence. Which of the following tools or techniques would be most effective for this purpose?Reconnaissance Techniques
- 69.A security analyst is conducting reconnaissance on a target organization. They are attempting to gather information about the organization's network infrastructure, including IP address ranges, domain names, and contact information, without directly interacting with the target's systems. Which of the following techniques is being employed?Reconnaissance Techniques
- 70.A penetration tester is performing a black-box assessment against a client's web application. They discover that the web server is configured to display detailed server error messages, including software versions and internal file paths, when an invalid request is made. Which of the following enumeration countermeasures would best mitigate this information leakage?Reconnaissance Techniques
- 71.A web developer is building a RESTful API that handles sensitive user data. To ensure data privacy during transmission, they decide to implement HTTPS. Which of the following components is primarily responsible for establishing the encrypted communication channel in HTTPS?Web Application Hacking
- 72.A penetration tester is evaluating the security posture of an organization's internal network. They want to identify active hosts on the local subnet without generating significant network traffic that could trigger intrusion detection systems. Which Nmap scan type is best suited for this objective?Reconnaissance Techniques
- 73.A penetration tester is evaluating the robustness of a client's perimeter network. They need to identify all open TCP ports on a range of external IP addresses. The client has a strict policy against any scanning techniques that could cause service disruption or be easily detectable by common firewalls and IDS/IPS. Which Nmap scan type is generally considered the most stealthy and least disruptive for identifying open TCP ports, while still being effective?Reconnaissance Techniques
- 74.A security analyst is performing an external penetration test against a client's public-facing web server. They are attempting to identify the web server software and its version without directly connecting to the server. Which of the following reconnaissance techniques would be most effective for this passive information gathering?Reconnaissance Techniques
- 75.A security analyst is investigating a potential data breach and needs to determine if any sensitive files from their internal network have been indexed by public search engines. Which of the following advanced search engine operators would be most effective for identifying specific file types (e.g., .pdf, .docx, .xlsx) within a particular domain?Reconnaissance Techniques
- 76.A web administrator is configuring a new e-commerce application. To enhance security, they want to prevent attackers from manipulating price parameters in HTTP requests before they reach the server. Which of the following countermeasures would be most effective in addressing this specific concern?Web Application Hacking
- 77.A security consultant is performing an external penetration test against a client's organization. They discovered that the client's public-facing DNS server allows recursive queries from external IP addresses. Which of the following enumeration techniques could an attacker leverage due to this misconfiguration?Reconnaissance Techniques
- 78.A web application allows users to upload images for their profile. During a security audit, it was discovered that the application checks the file extension on the client side (JavaScript) and then again on the server side by simply checking the MIME type provided in the HTTP request header. An attacker uploads a file named `profile.php.jpg` with a valid JPEG MIME type. Upon successful upload, the attacker can execute arbitrary PHP code by requesting `profile.php.jpg` directly. Which specific type of vulnerability has been exploited?Web Application Hacking
- 79.An ethical hacker is conducting initial reconnaissance for a penetration test. The client has provided a list of publicly accessible company websites. The hacker wants to gather as much information as possible about the organization's network infrastructure, domain registration details, and employee contacts without directly interacting with the target systems. Which of the following techniques would be most effective for this objective?Reconnaissance Techniques
- 80.A penetration tester has identified an open SMB (Server Message Block) port (TCP 445) on a Windows server during the scanning phase. To gather more specific information about the shared folders, users, and groups on this server, which enumeration tool would be most effective and appropriate?Reconnaissance Techniques
- 81.A penetration tester is evaluating the security of a client's web application. They notice that when they input invalid data into a form field, the application returns verbose error messages that include internal file paths, database query syntax, and even parts of the source code. What countermeasure should the client prioritize to mitigate this information disclosure vulnerability?Reconnaissance Techniques
- 82.A security auditor is performing an external penetration test against a large corporation. They have identified a public-facing DNS server. To gather as much information as possible about the corporation's internal network structure, the auditor attempts to perform a DNS zone transfer. Which DNS record type, if allowed to be queried by unauthorized sources, would enable a successful zone transfer?Reconnaissance Techniques
- 83.A penetration tester needs to perform a comprehensive port scan on a target network, but the client has strict requirements to minimize the chances of detection by network monitoring tools. The tester decides to use a scan that is known for its ability to bypass some firewalls and IDS by setting specific TCP flags. Which Nmap scan type fits this description and typically involves FIN, PSH, and URG flags?Reconnaissance Techniques
- 84.A penetration tester is performing reconnaissance against a large target organization. They want to identify publicly accessible resources, including IoT devices, industrial control systems (ICS), and webcams that might be inadvertently exposed to the internet. Which specialized search engine or platform is best suited for this task?Reconnaissance Techniques
- 85.A security team is reviewing their organization's external footprinting countermeasures. They are particularly concerned about preventing unauthorized parties from mapping their internal network structure by querying their DNS servers. Which of the following is the most critical countermeasure to implement to prevent DNS zone transfers?Reconnaissance Techniques
- 86.A security analyst is investigating a web application that allows users to create custom reports based on SQL queries. The application concatenates user-provided input directly into the SQL query string without proper sanitization. An attacker successfully injected `'; DROP TABLE users; --` into a report query field, leading to data loss. Which type of web application attack does this scenario describe?Web Application Hacking
- 87.A company is concerned about potential enumeration of their internal network services by attackers who might gain a foothold on an internal machine. Specifically, they want to prevent an attacker from easily determining which services are running on non-standard ports or identifying detailed version information. Which countermeasure would be most effective in making service enumeration more difficult?Reconnaissance Techniques
- 88.A security auditor is performing an internal network scan. They are concerned about potential misconfigurations in network devices that might allow unauthorized access. Specifically, they want to identify devices that respond to SNMP (Simple Network Management Protocol) requests and determine their community strings. Which port and associated tool would be most effective for this task?Reconnaissance Techniques
- 89.A penetration tester is attempting to map the network topology of a target organization. They are using traceroute to determine the path packets take to reach various hosts. However, some routers along the path are configured to drop ICMP Time Exceeded messages, which are crucial for traceroute's operation. Which of the following Nmap options could the tester use to perform a similar route tracing function by sending TCP SYN or ACK packets instead of ICMP?Reconnaissance Techniques
- 90.A web application is vulnerable to Cross-Site Scripting (XSS). An attacker injects a malicious script into a user's comment, which, when viewed by other users, executes in their browser and sends their session cookies to the attacker's server. Which type of XSS attack is this?Web Application Hacking
- 91.An ethical hacker is performing a penetration test against an organization's wireless network. Before attempting to crack wireless passwords, they need to identify all active wireless networks (SSIDs), their MAC addresses (BSSIDs), and the channels they are operating on within range. Which of the following tools is specifically designed for this type of wireless network reconnaissance?Reconnaissance Techniques
- 92.An ethical hacker is performing a penetration test on a web application that processes user-uploaded images. They discover that the application checks the file extension on the client-side (e.g., `.jpg`, `.png`) but does not perform any server-side validation of the file's actual content type. The hacker successfully uploads a web shell disguised as an image. Which vulnerability did the ethical hacker exploit?Web Application Hacking
- 93.A penetration tester is evaluating the security posture of an organization's network. They want to identify active hosts on the network segments without generating significant network traffic or triggering easily detectable alerts. The network administrators have configured firewalls to drop ICMP echo requests. Which Nmap host discovery technique would be most effective and stealthy in this scenario?Reconnaissance Techniques
- 94.A penetration tester is performing reconnaissance against a target organization's web applications and notices that many of them are hosted on cloud platforms like Amazon Web Services (AWS) and Azure. The tester wants to identify potential misconfigurations or exposed services associated with these cloud instances. Which specialized search engine would be most effective for discovering internet-connected devices, databases, and services, including those hosted in the cloud?Reconnaissance Techniques
- 95.A web administrator is configuring a new web server and wants to ensure that all communications between the client and server are encrypted and authenticated. They provision a digital certificate and configure the web server to listen on port 443. Which protocol is being implemented to achieve this secure communication?Web Application Hacking
- 96.A security auditor is examining a web server that hosts multiple virtual hosts. The auditor discovers that one of the virtual hosts is configured with weak ciphers and an outdated TLS protocol version (TLS 1.0). An attacker could potentially exploit this misconfiguration to downgrade the encryption and intercept sensitive data. Which common web server attack category does this scenario fall under?Web Application Hacking
- 97.A web developer is implementing a feature that allows users to embed content from other websites (e.g., YouTube videos, social media feeds) into their personal profiles. To mitigate the risk of Cross-Site Scripting (XSS) and other content injection attacks from potentially untrusted external sources, which HTML5 security attribute should be primarily utilized in the `<iframe>` tag?Web Application Hacking
- 98.A security analyst is conducting an external penetration test against a target organization. They discover that the organization's public-facing web server is running Apache 2.4.41 and PHP 7.3.11. This information was obtained without directly interacting with the web server, instead by examining publicly available search engine caches and archived web pages. What type of footprinting technique was primarily utilized in this scenario?Reconnaissance Techniques
- 99.A cloud administrator is configuring network security for a new application deployed in a Virtual Private Cloud (VPC). The application's web servers are in a public subnet and need to receive inbound traffic from the internet on port 443. The database servers are in a private subnet and should only allow inbound traffic from the web servers on port 3306. Which cloud network security control should be used to enforce these rules at the instance level, acting as a virtual firewall for each instance?Cloud Computing
- 100.A cloud security engineer is investigating a series of unauthorized data exfiltration attempts from an organization's cloud storage buckets. The logs indicate that the access attempts originated from a compromised EC2 instance within the same Virtual Private Cloud (VPC), but the instance itself was not directly exposed to the internet. The attacker leveraged a vulnerable web application on the EC2 instance to execute commands and then used the instance's IAM role to access the S3 buckets. What is the most effective countermeasure to prevent this specific type of lateral movement and data exfiltration?Cloud Computing