CEH-001 Exam Details

  • Exam Code
    :CEH-001
  • Exam Name
    :Certified Ethical Hacker (CEH)
  • Certification
    :GAQM Certifications
  • Vendor
    :GAQM
  • Total Questions
    :878 Q&As
  • Last Updated
    :May 30, 2026

GAQM CEH-001 Online Questions & Answers

  • Question 431:

    A specific site received 91 ICMP_ECHO packets within 90 minutes from 47 different sites. 77 of the ICMP_ECHO packets had an ICMP ID:39612 and Seq:57072. 13 of the ICMP_ECHO packets had an ICMP ID:0 and Seq:0. What can you infer from this information?

    A. The packets were sent by a worm spoofing the IP addresses of 47 infected sites
    B. ICMP ID and Seq numbers were most likely set by a tool and not by the operating system
    C. All 77 packets came from the same LAN segment and hence had the same ICMP ID and Seq number
    D. 13 packets were from an external network and probably behind a NAT, as they had an ICMP ID 0 and Seq 0

  • Question 432:

    You work as security technician at XYZ.com. While doing web application testing, you might be required to look through multiple web pages online which can take a long time. Which of the processes listed below would be a more efficient way of doing this type of validation?

    A. Use mget to download all pages locally for further inspection.
    B. Use wget to download all pages locally for further inspection.
    C. Use get* to download all pages locally for further inspection.
    D. Use get() to download all pages locally for further inspection.

  • Question 433:

    Jim is having no luck performing a penetration test in XYZ's network. He is running the tests from home and has downloaded every security scanner that he could lay his hands on. Despite knowing the IP range of all the systems, and the exact network configuration, Jim is unable to get any useful results.

    Why is Jim having these problems?

    A. Security scanners are not designed to do testing through a firewall.
    B. Security scanners cannot perform vulnerability linkage.
    C. Security scanners are only as smart as their database and cannot find unpublished vulnerabilities.
    D. All of the above.

  • Question 434:

    All the web servers in the DMZ respond to ACK scan on port 80. Why is this happening ?

    A. They are all Windows based webserver
    B. They are all Unix based webserver
    C. The company is not using IDS
    D. The company is not using a stateful firewall

  • Question 435:

    Jack Hacker wants to break into Brown Co.'s computers and obtain their secret double fudge cookie recipe. Jack calls Jane, an accountant at Brown Co., pretending to be an administrator from Brown Co. Jack tells Jane that there has been a

    problem with some accounts and asks her to verify her password with him ''just to double check our records.'' Jane does not suspect anything amiss, and parts with her password. Jack can now access Brown Co.'s computers with a valid user

    name and password, to steal the cookie recipe.

    What kind of attack is being illustrated here?

    A. Reverse Psychology
    B. Reverse Engineering
    C. Social Engineering
    D. Spoofing Identity
    E. Faking Identity

  • Question 436:

    A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use?

    A. -sO
    B. -sP
    C. -sS
    D. -sU

  • Question 437:

    You want to perform advanced SQL Injection attack against a vulnerable website. You are unable to perform command shell hacks on this server. What must be enabled in SQL Server to launch these attacks?

    A. System services
    B. EXEC master access
    C. xp_cmdshell
    D. RDC

  • Question 438:

    Leesa is the senior security analyst for a publicly traded company. The IT department recently rolled out an intranet for company use only with information ranging from training, to holiday schedules, to human resources data. Leesa wants to make sure the site is not accessible from outside and she also wants to ensure the site is Sarbanes-Oxley (SOX) compliant. Leesa goes to a public library as she wants to do some Google searching to verify whether the company's intranet is accessible from outside and has been indexed by Google. Leesa wants to search for a website title of "intranet" with part of the URL containing the word "intranet" and the words "human resources" somewhere in the webpage.

    What Google search will accomplish this?

    A. related:intranet allinurl:intranet:"human resources"
    B. cache:"human resources" inurl:intranet(SharePoint)
    C. intitle:intranet inurl:intranet+intext:"human resources"
    D. site:"human resources"+intext:intranet intitle:intranet

  • Question 439:

    Windump is the windows port of the famous TCPDump packet sniffer available on a variety of platforms. In order to use this tool on the Windows platform you must install a packet capture library. What is the name of this library?

    A. NTPCAP
    B. LibPCAP
    C. WinPCAP
    D. PCAP

  • Question 440:

    In Linux, the three most common commands that hackers usually attempt to Trojan are:

    A. car, xterm, grep
    B. netstat, ps, top
    C. vmware, sed, less
    D. xterm, ps, nc

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only GAQM exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CEH-001 exam preparations and GAQM certification application, do not hesitate to visit our Vcedump.com to find your solutions here.