CEH-001 Exam Details

  • Exam Code
    :CEH-001
  • Exam Name
    :Certified Ethical Hacker (CEH)
  • Certification
    :GAQM Certifications
  • Vendor
    :GAQM
  • Total Questions
    :878 Q&As
  • Last Updated
    :May 30, 2026

GAQM CEH-001 Online Questions & Answers

  • Question 131:

    You want to capture Facebook website traffic in Wireshark. What display filter should you use that shows all TCP packets that contain the word 'facebook'?

    A. display==facebook
    B. traffic.content==facebook
    C. tcp contains facebook
    D. list.display.facebook

  • Question 132:

    The programmers on your team are analyzing the free, open source software being used to run FTP services on a server. They notice that there is an excessive number of fgets() and gets() on the source code. These C++ functions do not check bounds.

    What kind of attack is this program susceptible to?

    A. Buffer of Overflow
    B. Denial of Service
    C. Shatter Attack
    D. Password Attack

  • Question 133:

    What will the following command produce on a website's login page if executed successfully? SELECT email, passwd, login_id, full_name FROM members WHERE email = '[email protected]'; DROP TABLE members; --'

    A. This code will insert the [email protected] email address into the members table.
    B. This command will delete the entire members table.
    C. It retrieves the password for the first user in the members table.
    D. This command will not produce anything since the syntax is incorrect.

  • Question 134:

    Say that "abigcompany.com" had a security vulnerability in the javascript on their website in the past. They recently fixed the security vulnerability, but it had been there for many months. Is there some way to 4go back and see the code for that error?

    Select the best answer.

    A. archive.org
    B. There is no way to get the changed webpage unless you contact someone at the company
    C. Usenet
    D. Javascript would not be in their html so a service like usenet or archive wouldn't help you

  • Question 135:

    Which of the following LM hashes represent a password of less than 8 characters? (Select 2)

    A. BA810DBA98995F1817306D272A9441BB
    B. 44EFCE164AB921CQAAD3B435B51404EE
    C. 0182BD0BD4444BF836077A718CCDF409
    D. CEC52EB9C8E3455DC2265B23734E0DAC
    E. B757BF5C0D87772FAAD3B435B51404EE
    F. E52CAC67419A9A224A3B108F3FA6CB6D

  • Question 136:

    Simon is security analyst writing signatures for a Snort node he placed internally that captures all mirrored traffic from his border firewall. From the following signature, what will Snort look for in the payload of the suspected packets? alert tcp $EXTERNAL_NET any -> $HOME_NET 27374 (msG. "BACKDOOR SIG - SubSseven 22";flags: A+; content: "|0d0a5b52504c5d3030320d0a|"; reference:arachnids, 485;) alert

    A. The payload of 485 is what this Snort signature will look for.
    B. Snort will look for 0d0a5b52504c5d3030320d0a in the payload.
    C. Packets that contain the payload of BACKDOOR SIG - SubSseven 22 will be flagged.
    D. From this snort signature, packets with HOME_NET 27374 in the payload will be flagged.

  • Question 137:

    While testing web applications, you attempt to insert the following test script into the search area on the company's web site:

    Later, when you press the search button, a pop up box appears on your screen with the text "Testing Testing Testing". What vulnerability is detected in the web application here?

    A. Cross Site Scripting
    B. Password attacks
    C. A Buffer Overflow
    D. A hybrid attack

  • Question 138:

    What is the key advantage of Session Hijacking?

    A. It can be easily done and does not require sophisticated skills.
    B. You can take advantage of an authenticated connection.
    C. You can successfully predict the sequence number generation.
    D. You cannot be traced in case the hijack is detected.

  • Question 139:

    An attacker uses a communication channel within an operating system that is neither designed nor intended to transfer information. What is the name of the communications channel?

    A. Classified
    B. Overt
    C. Encrypted
    D. Covert

  • Question 140:

    Which one of the following network attacks takes advantages of weaknesses in the fragment reassembly functionality of the TCP/IP protocol stack?

    A. Teardrop
    B. Smurf
    C. Ping of Death
    D. SYN flood
    E. SNMP Attack

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only GAQM exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CEH-001 exam preparations and GAQM certification application, do not hesitate to visit our Vcedump.com to find your solutions here.