EC-Council Certified Ethical Hacker (CEH) v12 practice questions
212 free questions with answers and explanations.
- 101.A security team is analyzing a recent data breach where an attacker exploited a misconfigured Identity and Access Management (IAM) policy in a cloud environment. The attacker gained unauthorized access to sensitive S3 buckets by leveraging overly permissive roles assigned to a compute instance. Which cloud computing threat category does this scenario primarily fall under?Cloud Computing
- 102.A cloud architect is designing a highly available application that needs to withstand the failure of an entire data center. The application will be deployed across multiple independent physical locations within a single cloud region. Which architectural concept is being applied here?Cloud Computing
- 103.A security auditor is reviewing a serverless application deployed on a cloud platform. The application consists of multiple functions triggered by API Gateway events. The auditor discovers that one function has an overly permissive IAM role allowing it to read and write to all S3 buckets in the account, even though it only needs access to a single, specific bucket. This configuration introduces a significant security risk. Which principle of cloud security is being violated?Cloud Computing
- 104.A penetration tester is evaluating a cloud-native application that uses a serverless function to process data uploaded to an S3 bucket. During the assessment, the tester discovers that the serverless function's code contains hardcoded API keys for a third-party service. Which cloud security best practice is violated by this practice?Cloud Computing
- 105.A cloud security engineer needs to implement a solution that allows multiple tenants (different organizations) to share the same underlying cloud infrastructure while ensuring strict logical isolation and data segregation between them. Each tenant must perceive they have their own dedicated resources, even though they are running on shared hardware. Which architectural concept is being described?Cloud Computing
- 106.A penetration tester is attempting to exploit a vulnerable web application hosted on a public cloud provider. During reconnaissance, they discover that the application's underlying compute instances are configured with an Instance Metadata Service (IMS) that is accessible without authentication from within the instance. The tester successfully retrieves temporary security credentials by making a request to 'http://169.254.169.254/latest/meta-data/iam/security-credentials/'. What type of attack is being performed?Cloud Computing
- 107.A company is migrating its on-premises applications to a cloud environment. They require significant control over the operating system, runtime, and deployed applications, but want to offload the management of the underlying network, storage, and virtualization. Which cloud service model best fits these requirements?Cloud Computing
- 108.A cybersecurity analyst is evaluating a cloud deployment model where the cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). The infrastructure may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises. Which cloud deployment model is being described?Cloud Computing
- 109.A cybersecurity team is implementing comprehensive social engineering countermeasures within their organization. They have focused on technical controls, such as advanced spam filters and email authentication protocols. However, they observe that employees are still falling victim to sophisticated phishing attacks, particularly those involving urgent requests from seemingly legitimate internal departments. Which countermeasure is most likely to be missing or insufficient in their current strategy, leading to these continued successful attacks?Social Engineering
- 110.A cybercriminal group is planning a highly targeted attack against a senior financial executive of a major corporation. They spend months collecting personal information about the executive, including their family members, hobbies, recent travel, and professional relationships, through open-source intelligence (OSINT) and social media reconnaissance. Their goal is to craft a highly believable and emotionally manipulative email to trick the executive into approving a fraudulent wire transfer. Which specific type of social engineering attack are they preparing?Social Engineering
- 111.A disgruntled former employee, seeking revenge against their previous company, creates a fake social media profile impersonating a senior executive. They then use this profile to send malicious links and gather sensitive information from current employees, leveraging the trust associated with the executive's position. Which social engineering technique is primarily being employed here?Social Engineering
- 112.An organization is adopting a cloud-first strategy and is concerned about the potential for 'vendor lock-in' if they heavily rely on a single cloud provider's proprietary services. They want to ensure they can easily migrate their applications and data to another cloud provider or back to on-premises if needed. Which cloud computing countermeasure directly addresses this concern?Cloud Computing
- 113.An attacker is attempting to gain access to a company's internal network. They notice that employees frequently leave the main entrance open for a brief period after swiping their access cards. The attacker then waits for an employee to swipe in and quickly follows them through the door before it closes, without swiping their own card. Which social engineering technique is the attacker utilizing?Social Engineering
- 114.A cloud security team is tasked with ensuring the confidentiality and integrity of data stored in a cloud object storage service. They decide to implement client-side encryption, where data is encrypted before being sent to the cloud provider and decrypted after retrieval. What is a key advantage of this approach compared to server-side encryption managed by the cloud provider?Cloud Computing
- 115.A company is implementing end-to-end encryption for its internal messaging system. They need a cryptographic algorithm that uses the same key for both encryption and decryption, offering high speed for large volumes of data. Which type of algorithm would best suit these requirements?Cryptography
- 116.A cryptocurrency exchange is developing a new system to generate transaction IDs. They need a cryptographic primitive that produces a fixed-size output, is computationally infeasible to reverse, and ensures that even a tiny change in the input results in a drastically different output. Which primitive should they use?Cryptography
- 117.A forensic investigator is analyzing encrypted files recovered from a suspect's hard drive. The suspect is known to have used VeraCrypt with a very strong passphrase. The investigator has obtained a memory dump of the suspect's computer from before it was powered off. What is the most promising technique to recover the encryption keys for the VeraCrypt volumes from this memory dump?Cryptography
- 118.During a security audit, an organization discovers that its legacy system uses SSLv3 for securing internal communications. Given the current threat landscape, what is the most significant cryptographic vulnerability associated with SSLv3 that necessitates immediate remediation?Cryptography
- 119.A security architect is designing a system for a highly sensitive government agency that transmits classified data over an untrusted network. They require a cryptographic solution that not only provides confidentiality but also guarantees data integrity and authenticity through a single, efficient cryptographic primitive. Which of the following best fits this requirement?Cryptography
- 120.An ethical hacker is performing a cryptographic analysis on an embedded system that uses a custom stream cipher. They discover that the cipher reuses the same key stream for multiple messages encrypted with the same key. What is the most significant cryptographic attack that this vulnerability enables?Cryptography
- 121.A penetration tester is attempting to circumvent a web application's authentication mechanism. They discover that the application uses a custom hashing algorithm for passwords without any salting or key stretching. The tester has obtained a database dump of these hashes. Which attack method would be most effective for quickly cracking a significant number of these passwords?Cryptography
- 122.A developer is designing a system for digital currency transactions. They need to ensure that transactions are verifiable as originating from the sender and that the sender cannot later deny having sent the transaction. Which cryptographic primitive is essential for achieving both authenticity and non-repudiation in this context?Cryptography
- 123.A security analyst is investigating a suspected man-in-the-middle (MITM) attack where an attacker intercepted and modified encrypted communications between two parties. The analyst found that while the data integrity was compromised, the confidentiality of the original messages was largely maintained due to strong symmetric encryption keys. Which cryptographic goal was primarily violated in this scenario?Cryptography
- 124.A system administrator needs to securely store user passwords in a database. To protect against rainbow table attacks and ensure that identical passwords result in different stored hashes, which cryptographic technique should be employed in conjunction with a strong hashing algorithm?Cryptography
- 125.A security researcher discovers a vulnerability in a custom cryptographic protocol. The protocol uses a hash function for message integrity, but instead of using a keyed hash (like HMAC), it concatenates the secret key with the message and then hashes the result (e.g., H(key || message)). Which cryptographic attack is this construction primarily vulnerable to?Cryptography
- 126.An attacker has successfully exfiltrated a database containing encrypted credit card numbers. The encryption method used was AES-256 in Electronic Codebook (ECB) mode. What is the primary vulnerability introduced by using ECB mode for this type of data, even with a strong algorithm like AES-256?Cryptography
- 127.An advanced persistent threat (APT) group has successfully breached a defense contractor's network. After gaining initial access, they spend several months moving laterally across the network, escalating privileges, and exfiltrating highly sensitive intellectual property, all while meticulously avoiding detection. Which characteristic of an APT is best demonstrated by this behavior?Information Security and Ethical Hacking Overview
- 128.During a security audit, an organization is found to be storing customer credit card numbers in plain text within an unencrypted database. This practice directly violates which core principle of the Payment Card Industry Data Security Standard (PCI DSS)?Information Security and Ethical Hacking Overview
- 129.A security researcher discovers a flaw in a popular web browser that allows an attacker to execute arbitrary code on a user's machine simply by visiting a malicious website. The researcher responsibly discloses this vulnerability to the browser vendor, giving them time to develop and release a patch before publicly revealing the details. This type of vulnerability, unknown to the vendor and public, is commonly referred to as a:Information Security and Ethical Hacking Overview
- 130.A new zero-day exploit is discovered targeting a widely used operating system. Before patches are available, security teams are advised to implement intrusion detection systems (IDS) with updated signatures, apply host-based firewalls, and restrict network access to affected services. Which principle of information security is primarily being addressed by these temporary measures?Information Security and Ethical Hacking Overview
- 131.An ethical hacker is performing a reconnaissance phase against a target organization. They decide to use public search engines, social media, and publicly available financial reports to gather information about the company's structure, employees, and technologies. What ethical hacking methodology step are they currently performing?Information Security and Ethical Hacking Overview
- 132.An organization is developing a new cloud-based application that will process sensitive customer data. To comply with various industry regulations and data protection laws, the development team is integrating security measures from the initial design phase through deployment. This approach, which aims to reduce vulnerabilities and ensure security by default, is best described as:Information Security and Ethical Hacking Overview
- 133.A security analyst is reviewing logs from a perimeter firewall and notices a high volume of SYN packets originating from various external IP addresses targeting multiple internal servers, but no corresponding SYN-ACK packets are observed from the internal servers. This activity occurs over a short period and significantly impacts network performance. Which type of attack is most likely occurring?Information Security and Ethical Hacking Overview
- 134.A penetration tester is hired to evaluate the security posture of a financial institution. The scope of engagement explicitly states that the tester must not perform any denial-of-service attacks or modify production data. The tester is given a dedicated network segment with simulated production systems and accounts. What type of ethical hacking engagement is being conducted?Information Security and Ethical Hacking Overview
- 135.A software development company mandates that all code changes must undergo a peer review process, followed by automated static code analysis, and then dynamic application security testing (DAST) before deployment. This multi-faceted approach aims to catch vulnerabilities at different stages of the development and testing lifecycle. Which type of information security control is being most effectively implemented here?Information Security and Ethical Hacking Overview
- 136.A company has implemented a robust security policy that mandates frequent password changes, multi-factor authentication for all critical systems, and regular security awareness training for employees. Despite these measures, a recent internal audit revealed several instances of unauthorized access to sensitive data, primarily due to employees sharing credentials or writing them down. Which security control category is most directly failing in this scenario?Information Security and Ethical Hacking Overview
- 137.A global technology company is expanding its operations into the European Union. To ensure compliance with strict data protection regulations, the company must appoint a Data Protection Officer (DPO), conduct Data Protection Impact Assessments (DPIAs), and implement robust mechanisms for data subject rights, such as the 'right to be forgotten'. Which regulation is driving these specific requirements?Information Security and Ethical Hacking Overview
- 138.A cybercriminal group launches an attack against a critical national infrastructure provider, aiming to disrupt power grids across several states. Their primary motivation is to destabilize the economy and cause widespread panic, rather than financial gain. This type of threat actor is best categorized as a:Information Security and Ethical Hacking Overview
- 139.An organization is implementing a new security policy to prevent malware infections. Which of the following countermeasures is specifically designed to protect against malware that attempts to exploit unpatched software vulnerabilities by executing malicious code directly in memory?Malware Threats
- 140.A security analyst is investigating a compromised workstation that exhibits unusual network traffic patterns, including frequent connections to a remote IP address on an uncommon port. The workstation's CPU usage is also consistently high, even when idle. Further investigation reveals a hidden process running in the background. Which type of malware is most likely responsible for these observations?Malware Threats
- 141.During a malware incident response, an analyst observes that infected systems are communicating with external IP addresses on TCP port 6667 and 6697, which are commonly associated with IRC (Internet Relay Chat). Which malware characteristic is most likely being utilized for command and control (C2) in this scenario?Malware Threats
- 142.A security analyst is performing incident response after a critical database server was found to be infected with malware. During the forensic analysis, the analyst discovers that the malware has modified the system's kernel to redirect system calls and hide its processes and files from standard operating system utilities. This sophisticated technique makes it very difficult for administrators to detect and remove the malicious software. Which type of malware is most likely responsible for this compromise?Malware Threats
- 143.A security incident response team is analyzing a memory dump from a compromised server. They discover a hidden process that is not visible through standard operating system tools and has injected malicious code into a legitimate system process. Which malware attack tool or technique is the team most likely observing?Malware Threats
- 144.A cybersecurity analyst is investigating an incident where a smart thermostat in a manufacturing plant was remotely manipulated, causing a critical temperature fluctuation that disrupted production. The thermostat communicates wirelessly within a segmented network. Which of the following attack vectors was most likely exploited in this scenario?Mobile Platform, IoT, and OT Hacking
- 145.A security analyst is investigating a suspected malware infection on a corporate workstation. During the investigation, the analyst uses a debugger to step through the malware's code. However, the malware detects the debugger and terminates its execution, preventing further analysis. This behavior is a clear indication that the malware is employing which specific anti-analysis technique?Malware Threats
- 146.A security researcher is analyzing a new variant of malware that is designed to steal banking credentials. The malware employs techniques to detect if it is running inside a virtual machine or a sandbox environment, and if so, it terminates its execution. Which malware evasion technique is this malware utilizing?Malware Threats
- 147.A penetration tester is evaluating the security of an IoT device, specifically a smart camera, which uses MQTT for communication. During their assessment, they discover that the camera publishes its live video feed to an MQTT topic without any form of authentication or encryption. Which of the following attack vectors is MOST directly exemplified by this vulnerability?Mobile Platform, IoT, and OT Hacking
- 148.A threat intelligence analyst is researching a new malware family that targets specific industrial control systems. The analysis reveals that the malware is designed to be highly modular, with different components for reconnaissance, command and control, and payload delivery. Each component can be updated independently by the attackers, allowing for flexible and evolving attack capabilities. This modular design is a characteristic feature of which type of advanced malware?Malware Threats
- 149.A cybersecurity researcher is analyzing a new malware sample. The malware attempts to establish communication with a Command and Control (C2) server by sending DNS queries for seemingly legitimate, but non-existent, domain names. The C2 server then responds with encoded instructions within the DNS response. Which technique is this malware employing to evade detection?Malware Threats
- 150.An unauthenticated attacker discovers a smart light bulb in a publicly accessible area that responds to commands sent via a proprietary wireless protocol. By reverse engineering the protocol, the attacker can send commands to change the light's color and brightness. However, they are unable to cause any permanent damage or gain access to other networked devices. Which of the following attack vectors is the attacker primarily exploiting?Mobile Platform, IoT, and OT Hacking