CEH Certified Ethical Hacker

This test is useful for CEH (Certified Ethical Hacker) certification along with other type of courses like CS, GATE etc.

15 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Which of the following statements is incorrect about 'packet sniffing' method in Ethical hacking?

  1. It captures data from information packets.
  2. It can have user specific data or information.
  3. It does not require any administrator-level access to proceed.
  4. A packet sniffer can be installed on any cable modem user's computer.
  5. It causes the computer to crash and make it busy processing data that the user is unable to use.
Question 2 Multiple Choice (Single Answer)

Which of the following statements is correct about 'Strobe Scan' in Port Scanning technique?

  1. This scanning technique is performed for limited ports.
  2. In this type of scan, the hackers try to connect to all the ports of the victim.
  3. It does not establish a complete connection with the host.
  4. It is a heavyweight scan.
  5. It is based on IP routing function.
Question 3 Multiple Choice (Single Answer)

Which of the following statements is correct about Trojan horse programs?

  1. These programs capture data from information packets.
  2. These programs infect the computer with the intruders.
  3. These are used by intruders to gain remote access to the computer.
  4. These programs cause the computer to crash or make it busy in processing data.
  5. Using these programs, a malicious web developer may attach a script to something sent to a website.
Question 4 Multiple Choice (Single Answer)

Which of the following is correct about TTL Analysis in Information Security?

  1. The number of hops can be changed as per the requirement in TTL analysis.
  2. The number of hops remains constant in TTL analysis.
  3. It uses the standard called Reverse Path Forwarding (RPF).
  4. It works in case of IP spoofing.
  5. It can be applied in a transparent/bridge mode within a network for segmenting a subset of hosts.
Question 5 Multiple Choice (Single Answer)

Which of the following is false about cross-site scripting attack in Ethical hacking?

  1. This attack is spread by using the web URL.
  2. By this attack, a malicious script is transferred to the browser.
  3. This type of attack is very harmful for e-mails or other forms.
  4. It can be used by intruders to gather information.
  5. Due to this attack, the generated pages are affected where users can post text containing HTML tags.
Question 6 Multiple Choice (Single Answer)

Which of the following statements is correct about IP port spoofing in Ethical hacking?

  1. In this spoofing, the IP addresses can be specified for the ports.
  2. In this spoofing, the source port cannot be modified.
  3. The attacker cannot look into the internal traffic.
  4. It shows the binding between IP and MAC addresses.
  5. It can cause Man-in-the-Middle attack also.
Question 7 Multiple Choice (Single Answer)

Which of the following is correct about DNS spoofing attack in Ethical hacking?

  1. The forging packets can be modified in this attack.
  2. This attack is performed by a single forged packet.
  3. It causes the changes in the domain names for the respective IP addresses.
  4. No web traffic is analysed in this attack.
  5. It affects the IP configuration.
Question 8 Multiple Choice (Single Answer)

Which of the following statements is false about Buffer overflow attack?

  1. It stores the data mostly in a temporary data storage.
  2. It affects the data integrity.
  3. The corrupt data contains certain code for the specified triggering actions by the attackers.
  4. This type of attack can affect the server's configuration.
  5. The buffers are created to contain a finite amount of data.
Question 9 Multiple Choice (Single Answer)

Which of the following is false about denial-of-service (DDoS) attack?

  1. This attack can be spread in a multitude of systems.
  2. It denies service to the system to legitimate users.
  3. It can exploit a vulnerability in one computer system and makes it the DDoS master.
  4. A network-centric attack overloads a service by using up bandwidth and an application-layer attack, which overloads a service or database with application calls.
  5. It gains malicious access to resources, applications or databases.
Question 10 Multiple Choice (Single Answer)

Which of the following statements is incorrect about Man-in-the-middle attack?

  1. In this attack, the attacker makes independent connections with the victims.
  2. It is an attack on mutual authentication.
  3. It includes some form of endpoint authentication.
  4. It does not affect the transaction processing.
  5. SSL can authenticate one or both parties using a mutually trusted certification authority.
Question 11 Multiple Choice (Single Answer)

Which of the following is correct about Sidejacking in Session Hijacking?

  1. It involves sniffing data packets to steal session cookies.
  2. It has the cookies which can contain encrypted login information.
  3. The attacker can launch a man-in-the-middle attack, intercepting all data between you and the network.
  4. This involves a malicious actor using readily available software to intercept data being sent from or to the device.
  5. It involves data synchronisation.
Question 12 Multiple Choice (Single Answer)

Which of the following is false about zero-day vulnerability in Ethical security?

  1. It is a flaw in software, hardware or firmware that is exploited.
  2. It shows that there are zero days between the time the vulnerability is discovered and the first attack.
  3. It is caused due to invalid software codes.
  4. This attack can cause the website to slow down.
  5. It occurs at the same time as vulnerability.
Question 13 Multiple Choice (Single Answer)

Which of the following statements is false about zero-day exploit attack?

  1. In this attack, the vulnerability becomes generally known.
  2. There are zero days between the time the vulnerability is discovered and the first attack.
  3. Hackers can also discover the vulnerability.
  4. The vulnerability is not known in advance.
  5. It can obtain any unencrypted information.
Question 14 Multiple Choice (Single Answer)

Which of the following is incorrect about the removal of zero-day vulnerability attack?

  1. Virtual LAN/IPsec can be used to reduce this attack
  2. Deploying an intrusion detection system (IDS) helps to reduce this attack.
  3. Locking down wireless access points helps to remove this attack.
  4. Maximising protection against wireless-based attacks helps prevent this attack.
  5. Applying cryptographic techniques can reduce this attack.
Question 15 Multiple Choice (Single Answer)

Which of the following options is called Sniffing in Ethical hacking?

  1. It has the malicious actor using readily available software to intercept data.
  2. The attacker can launch a man-in-the-middle attack, intercepting all data between the user and the network.
  3. It can decrypt login information.
  4. This attack is performed by repeatedly executing invalid data.
  5. This is a form of Session Hijacking attack.