EC-Council Certified Ethical Hacker (CEH) v12 practice questions
212 free questions with answers and explanations.
- 201.During a penetration test, an ethical hacker successfully exploits a buffer overflow vulnerability on a target system. After gaining initial access, the hacker discovers that the current user context has very limited privileges. To achieve their objective of full system compromise, what is the IMMEDIATE next step the hacker should attempt?System Hacking Phases and Attack Techniques
- 202.A penetration tester is evaluating a web application that handles sensitive customer data. They identify an input field that is vulnerable to SQL injection, allowing them to extract database schema information. However, the web application firewall (WAF) blocks direct attempts to use SQL keywords like 'UNION SELECT'. To bypass this WAF, the tester encodes the SQL injection payload using URL encoding and character obfuscation. This technique is an example of which aspect of vulnerability analysis and exploitation?System Hacking Phases and Attack Techniques
- 203.A red team operator has successfully exploited a vulnerable service on a Windows server and obtained a low-privileged shell. To elevate their privileges to 'SYSTEM', they attempt to exploit a known kernel vulnerability. Which system hacking technique are they primarily employing?System Hacking Phases and Attack Techniques
- 204.A blue team analyst is investigating a Windows server after a successful phishing attack led to initial compromise. They discover that a legitimate system utility, `svchost.exe`, is running from an unusual directory (`C:\Temp\` instead of `C:\Windows\System32\`) and is making suspicious outbound connections. What type of attack technique is this most indicative of?System Hacking Phases and Attack Techniques
- 205.A blue team analyst is investigating a suspected breach and discovers that an attacker has modified the system's `utmp`, `wtmp`, and `btmp` files on a Linux server. What is the primary purpose of modifying these specific files?System Hacking Phases and Attack Techniques
- 206.A security auditor is performing a black-box assessment on a new web application. They use an automated tool to scan for common vulnerabilities. The tool reports a 'SQL Injection' vulnerability on a login page, indicating that input validation is insufficient. Which category of vulnerability analysis does this tool primarily fall under?System Hacking Phases and Attack Techniques
- 207.A security analyst is investigating a suspected intrusion on a Linux server. They need to determine if any unauthorized modifications have been made to critical system files. Which of the following tools is BEST suited for this purpose by comparing current file states against a known good baseline?System Hacking Phases and Attack Techniques
- 208.A system administrator is reviewing network traffic logs and observes unusual inbound connections on port 3389 (RDP) from external IP addresses that are not part of the organization's VPN range. Upon further investigation, it is discovered that a user's credentials were compromised, and the attacker is attempting to log in directly. Which phase of the system hacking process does this activity represent?System Hacking Phases and Attack Techniques
- 209.A penetration tester has successfully exploited a vulnerable web application and gained initial access to a Linux server as a low-privileged user. They now need to elevate their privileges to 'root'. They discover that a cron job is configured to run a script, '/opt/cleanup.sh', every 5 minutes with root privileges. The permissions on '/opt/cleanup.sh' are 'rwxrwxrwx' (777). Which of the following is the most direct and effective method for privilege escalation in this scenario?System Hacking Phases and Attack Techniques
- 210.A red team operator has successfully gained initial access to a client's internal network via a phishing campaign. They now need to enumerate internal systems and identify potential targets for further exploitation. Which of the following techniques is most appropriate for discovering active hosts and open ports within the newly accessed internal network segment, without generating excessive noise?System Hacking Phases and Attack Techniques
- 211.A penetration tester is performing an internal assessment. They notice that a critical web application is running on an outdated version of Apache Tomcat. They consult public vulnerability databases and find several known high-severity vulnerabilities (e.g., CVEs) associated with this specific version. Which step in the vulnerability analysis process is the tester currently performing?System Hacking Phases and Attack Techniques
- 212.A penetration tester is conducting a black-box assessment against a client's web application. They discover that the application uses an outdated version of a common JavaScript library. Which of the following phases of system hacking does this finding primarily relate to?System Hacking Phases and Attack Techniques