CEH
Pentest+
Security+
Network+
100

Viktor, the white hat hacker, conducts a security audit. He gains control over a user account and tries to access another account's sensitive information and files. How can he do this? 

- Port Scanning 

- Shoulder-Surfing 

- Fingerprinting 

- Privilege Escalation 

Privilege Escalation

100

During an internal engagement, you need to identify open ports and services across multiple hosts and support scripting capabilities for deeper enumeration. Which tool would best support both scanning and extensibility? 

- WHOIS 

- Netcat 

- Nmap

- tcpdump 


Nmap

100

Which mitigation technique involves the use of tools like Nagios or Splunk to continuously observe and check the operation of a system or network?

 - Patching 

- Hardening techniques 

- Monitoring 

- Segmentation

Monitoring

100

A network administrator is planning to host a company application in the cloud, making the application available for all internal and third-party users. Which of the following concepts describes this arrangement?

- Multitenancy

- VPC

- NFV

- SaaS

SaaS

200

You make a series of interactive queries, choosing subsequent plaintexts based on the information from the previous encryptions. What type of attack are you trying to perform?

- Adaptive chosen-plaintext attack  

- Ciphertext-only attack 

- Chosen-plaintext attack 

- Known-plaintext attack 

Adaptive chosen-plaintext attack  


200

During a penetration test, Adalyn has gathered several pieces of evidence, including logs and screenshots. According to best practices, what should she do with these artifacts after the test is completed? 

- Delete all artifacts securely to ensure no traces of the test remain

- Preserve the artifacts securely and hand them over to the client

- Share the artifacts publicly to demonstrate the test's success 

- Encrypt the artifacts and store them indefinitely on your systems

Preserve the artifacts securely and hand them over to the client


200

During a network investigation, Aiden, a cybersecurity analyst, identifies two key irregularities: The CEO, who tends to work late, logged in from both Paris and Tokyo within five minutes, and there's an unexpected surge in emails from the HR department outside of recruitment season. Which of the following should the analyst be MOST concerned about based on these observations? 

- A recent software update on the CEO's computer. 

- The sudden increase in emails from the HR department. 

- The absence of the CEO's usual late-night login.

- Simultaneous CEO logins from distant locations.  


Simultaneous CEO logins from distant locations.

200

A network administrator is configuring a new switch and wants to ensure that only assigned devices can connect to the switch. Which of the following should the administrator do?

- Configure ACLs.

- Implement a captive portal.

- Enable port security.

- Disable unnecessary services.

Enable port security.

300

The evil hacker Antonio is trying to attack the IoT device. He will use several fake identities to create a strong illusion of traffic congestion, affecting communication between neighboring nodes and networks. What kind of attack does Antonio perform?

- Forged Malicious Device 

- Sybil Attack 

- Side-Channel Attack 

- Exploit Kits

Sybil Attack

300

Which of the following tools provides a penetration tester with a framework to conduct technical social engineering attacks like phishing against an organization's employees? 

- SET 

- Censys 

- ProxyChains 

- Kismet

SET (Social Engineering Toolkit)

300

Which group is MOST likely to possess the funding and resources to recruit top talent, including skilled strategists, designers, coders, and hackers?

- A security researcher 

-  An open-source developer community 

- A criminal syndicate

- An independent black hat hacker

A criminal syndicate

300

A network administrator needs to change where the outside DNS records are hosted. Which of the following records should the administrator change at the registrar to accomplish this task?

- NS

- SOA

- PTR

- CNAME

NS (Name Server)

400

You conduct an investigation and find out that the browser of one of your employees sent malicious requests that the employee knew nothing about. Identify the web page vulnerability that the attacker used in the attack on your employee.

- File Inclusion Attack 

- Command Injection Attacks 

- Cross-Site Request Forgery (CSRF) 

- Hidden Field Manipulation Attack

Cross-Site Request Forgery (CSRF)

400

During a cloud infrastructure review, you need to identify exposed resources, overly permissive roles, and weak configuration settings across multiple accounts. The tool must assess posture rather than actively exploit systems. Which tool is most appropriate?

- ScoutSuite

- Netcat 

- Responder 

- Hydra

ScoutSuite

400

The executive team at a software development firm decides that any project with a potential financial impact greater than $500,000 due to a security incident will require an immediate review and intervention. This financial impact figure represents which of the following in risk management? 

- Risk tolerance 

- Risk level 

- Risk threshold

- Risk limit

Risk threshold

400

A systems administrator is investigating why users cannot reach a Linux web server with a browser but can ping the server IP. The server is online, the web server process is running, and the link to the switch is up. Which of the following commands should the administrator run on the server first?

- traceroute

- netstat

- tcpdump

- arp

netstat