Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the ECCouncil CEH v13 312-50v13 Questions and answers with CertsForce

Viewing page 4 out of 16 pages
Viewing questions 46-60 out of questions
Questions # 46:

A company hires a hacker to test its network security by simulating real-world attacks. The hacker has permission and operates within legal boundaries. What is this type of hacker called?

Options:

A.

Script Kiddie


B.

Black Hat Hacker


C.

Grey Hat Hacker


D.

White Hat Hacker


Expert Solution
Questions # 47:

During a penetration test at Pinnacle Bank in Chicago, ethical hacker Sarah injects crafted TCP packets into an active communication between a customer ' s browser and the online banking server. The victim ' s connection becomes unstable, allowing Sarah ' s system to maintain communication with the server in place of the legitimate client. She later demonstrates to the IT team how attackers could forcibly take control of live sessions through this approach.

Which type of session hijacking is Sarah performing in this scenario?

Options:

A.

Passive Session Hijacking


B.

Blind Hijacking


C.

Man-in-the-Browser Attack


D.

Active Session Hijacking


Expert Solution
Questions # 48:

While evaluating a smart card implementation, a security analyst observes that an attacker is measuring fluctuations in power consumption and timing variations during encryption operations on the chip. The attacker uses this information to infer secret keys used within the device. What type of exploitation is being carried out?

Options:

A.

Disrupt control flow to modify instructions


B.

Observe hardware signals to deduce secrets


C.

Crack hashes using statistical collisions


D.

Force session resets through input flooding


Expert Solution
Questions # 49:

Which vulnerability exploits memory corruption?

Options:

A.

XSS


B.

Buffer overflow


C.

CSRF


D.

SQLi


Expert Solution
Questions # 50:

A web server was compromised through DNS hijacking. What would most effectively prevent this in the future?

Options:

A.

Changing IP addresses


B.

Regular patching


C.

Implementing DNSSEC


D.

Using LAMP architecture


Expert Solution
Questions # 51:

An ethical hacker needs to enumerate user accounts and shared resources within a company ' s internal network without raising any security alerts. The network consists of Windows servers running default configurations. Which method should the hacker use to gather this information covertly?

Options:

A.

Deploy a packet sniffer to capture and analyze network traffic


B.

Perform a DNS zone transfer to obtain internal domain details


C.

Exploit null sessions to connect anonymously to the IPC$ share


D.

Utilize SNMP queries to extract user information from network devices


Expert Solution
Questions # 52:

During a physical penetration test at Sterling Electronics in Cleveland, ethical hacker Priya waits near the employee entrance during a shift change. When a group of staff enters the building using their access cards, Priya closely follows behind without swiping her own badge. None of the employees confront her, assuming she belongs there. Once inside, Priya proceeds to the break area where she documents the success of the exercise.

Which social engineering technique is Priya demonstrating?

Options:

A.

Shoulder Surfing


B.

Dumpster Diving


C.

Tailgating


D.

Piggybacking


Expert Solution
Questions # 53:

A threat intelligence review at a manufacturing firm in Pittsburgh, Pennsylvania, revealed repeated external queries targeting the organization’s public name servers. Although no intrusion occurred, analysts observed that the queries appeared designed to systematically map internal naming conventions and infrastructure patterns.

The security team determined that the issue was not excessive traffic volume but rather the exposure of internal namespace details through responses handled by the same server used for both internal and external resolution. To reduce the risk of disclosing sensitive structural information to outside systems, the team redesigned their DNS deployment.

Which countermeasure best addresses the risk described in this scenario?

Options:

A.

Randomizing DNS Source Ports and Query Identifiers


B.

Implementing a Split DNS Architecture


C.

Implementing Rate Limiting on DNS Servers


D.

Enabling DNS Logging and Anomaly Detection


Expert Solution
Questions # 54:

During LDAP-based enumeration, you observe that some critical information cannot be retrieved. What is the most likely reason?

Options:

A.

LDAP directory data is protected by Access Control Lists (ACLs)


B.

LDAP is running on a non-standard port


C.

Hosts are in a different subnet


D.

Network congestion is causing dropped requests


Expert Solution
Questions # 55:

A penetration tester suspects that a web application ' s user profile page is vulnerable to SQL injection, as it uses the userID parameter in SQL queries without proper sanitization. Which technique should the tester use to confirm the vulnerability?

Options:

A.

Use the userID parameter to perform a brute-force attack on the admin login page


B.

Modify the userID parameter in the URL to ' OR ' 1 ' = ' 1 and check if it returns multiple profiles


C.

Inject HTML code into the userID parameter to test for Cross-Site Scripting (XSS)


D.

Attempt a directory traversal attack using the userID parameter


Expert Solution
Questions # 56:

A multinational organization is implementing a security upgrade for its corporate wireless infrastructure. The current WPA2-Personal configuration relies on a shared passphrase, which the IT team finds difficult to rotate and manage securely across hundreds of employee devices. To enhance security and scalability, the organization decides to migrate to WPA2-Enterprise. The new setup must allow for centralized control of user authentication, support certificate-based identity verification, and ensure that each authenticated client is assigned a unique session encryption key to prevent key reuse and limit the blast radius of potential breaches.

Which component is essential for enabling this centralized, certificate-based authentication with unique key generation per session in a WPA2-Enterprise environment?

Options:

A.

Opportunistic Wireless Encryption (OWE)


B.

Pre-Shared Key (PSK)


C.

Temporal Key Integrity Protocol (TKIP)


D.

RADIUS with Extensible Authentication Protocol (EAP)


Expert Solution
Questions # 57:

Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some measures and implemented the necessary controls. After that, another security risk assessment was performed showing that risk has decreased to 10%. The risk threshold for the application is 20%. Which of the following risk decisions will be the best for the project in terms of its successful continuation with the most business profit?

Options:

A.

Introduce more controls to bring risk to 0%


B.

Avoid the risk


C.

Mitigate the risk


D.

Accept the risk


Expert Solution
Questions # 58:

A financial institution in Chicago deploys an internal HTTPS-based customer portal that uses response compression to optimize bandwidth. During an authorized security assessment, a tester gains a vantage point along the communication path between internal clients and the gateway device.

By repeatedly initiating controlled requests and analyzing subtle differences in encrypted response sizes, the tester correlates variations in compressed output with specific input patterns. Over time, this analysis enables extraction of portions of a protected authentication value transmitted within the secure channel.

Which session hijacking technique best describes this activity?

Options:

A.

Forbidden Attack


B.

CRIME Attack


C.

Man-in-the-Browser (MITB) Attack


D.

Man-in-the-Middle (MITM) Attack


Expert Solution
Questions # 59:

During a penetration test at Cascade Biotech in Portland, Oregon, ethical hacker Olivia Harper installs a monitoring agent on a single test workstation inside the research subnet. The system records local events such as file access, configuration changes, and unauthorized process execution. Olivia explains to the security team that attackers often attempt to disable or evade this type of monitoring to avoid being detected at the host level.

Which security system is Olivia most likely demonstrating?

Options:

A.

Network-Based Firewall


B.

Host-Based Firewall


C.

Network-Based Intrusion Detection System


D.

Host-Based Intrusion Detection System


Expert Solution
Questions # 60:

You are Noah Kim, an ethical hacker at Quantum Cyber Solutions, hired to test the mobile device security of TechTrend Innovations, a tech firm in Austin, Texas. During a covert assessment, your objective is to simulate an attacker attempting to gain privileged access to an iPhone 12 running iOS 14.5 used for proprietary app development. You apply a jailbreaking technique that allows the device to fully restart without requiring a computer, maintaining a patched kernel and enabling access to sensitive app data in the file system. Based on this method, which iOS jailbreaking technique are you using?

Options:

A.

Semi-tethered jailbreaking


B.

Untethered jailbreaking


C.

Semi-untethered jailbreaking


D.

Tethered jailbreaking


Expert Solution
Viewing page 4 out of 16 pages
Viewing questions 46-60 out of questions