CEH-001 Exam Details

  • Exam Code
    :CEH-001
  • Exam Name
    :Certified Ethical Hacker (CEH)
  • Certification
    :GAQM Certifications
  • Vendor
    :GAQM
  • Total Questions
    :878 Q&As
  • Last Updated
    :May 30, 2026

GAQM CEH-001 Online Questions & Answers

  • Question 101:

    What happens when one experiences a ping of death?

    A. This is when an IP datagram is received with the "protocol" field in the IP header set to 1 (ICMP) and the "type" field in the ICMP header is set to 18 (Address Mask Reply).
    B. This is when an IP datagram is received with the "protocol" field in the IP header set to 1 (ICMP), the Last Fragment bit is set, and (IP offset ` 8) + (IP data length) >65535. In other words, the IP offset (which represents the starting position of this fragment in the original packet, and which is in 8-byte units) plus the rest of the packet is greater than the maximum size for an IP packet.
    C. This is when an IP datagram is received with the "protocol" field in the IP header set to 1 (ICMP) and the source equal to destination address.
    D. This is when an the IP header is set to 1 (ICMP) and the "type" field in the ICMP header is set to 5 (Redirect).

  • Question 102:

    What statement is true regarding LM hashes?

    A. LM hashes consist in 48 hexadecimal characters.
    B. LM hashes are based on AES128 cryptographic standard.
    C. Uppercase characters in the password are converted to lowercase.
    D. LM hashes are not generated when the password length exceeds 15 characters.

  • Question 103:

    While performing ping scans into a target network you get a frantic call from the organization's security team. They report that they are under a denial of service attack. When you stop your scan, the smurf attack event stops showing up on the organization's IDS monitor. How can you modify your scan to prevent triggering this event in the IDS?

    A. Scan more slowly.
    B. Do not scan the broadcast IP.
    C. Spoof the source IP address.
    D. Only scan the Windows systems.

  • Question 104:

    Which types of detection methods are employed by Network Intrusion Detection Systems (NIDS)? (Choose two.)

    A. Signature
    B. Anomaly
    C. Passive
    D. Reactive

  • Question 105:

    Which type of Nmap scan is the most reliable, but also the most visible, and likely to be picked up by and IDS?

    A. SYN scan
    B. ACK scan
    C. RST scan
    D. Connect scan
    E. FIN scan

  • Question 106:

    Which of the following types of firewall inspects only header information in network traffic?

    A. Packet filter
    B. Stateful inspection
    C. Circuit-level gateway
    D. Application-level gateway

  • Question 107:

    You just purchased the latest DELL computer, which comes pre-installed with Windows 7, McAfee antivirus software and a host of other applications. You want to connect Ethernet wire to your cable modem and start using the computer immediately. Windows is dangerously insecure when unpacked from the box, and there are a few things that you must do before you use it.

    A. New installation of Windows should be patched by installing the latest service packs and hotfixes
    B. Key applications such as Adobe Acrobat, Macromedia Flash, Java, Winzip etc., must have the latest security patches installed
    C. Install a personal firewall and lock down unused ports from connecting to your computer
    D. Install the latest signatures for Antivirus software
    E. Configure "Windows Update" to automatic
    F. Create a non-admin user with a complex password and logon to this account
    G. You can start using your computer as vendors such as DELL, HP and IBM would have already installed the latest service packs.

  • Question 108:

    What port scanning method involves sending spoofed packets to a target system and then looking for adjustments to the IPID on a zombie system?

    A. Blind Port Scanning
    B. Idle Scanning
    C. Bounce Scanning
    D. Stealth Scanning
    E. UDP Scanning

  • Question 109:

    Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?

    A. Cross-site scripting
    B. SQL injection
    C. Missing patches
    D. CRLF injection

  • Question 110:

    What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?

    A. Passive
    B. Reflective
    C. Active
    D. Distributive

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only GAQM exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CEH-001 exam preparations and GAQM certification application, do not hesitate to visit our Vcedump.com to find your solutions here.