CEH-001 Exam Details

  • Exam Code
    :CEH-001
  • Exam Name
    :Certified Ethical Hacker (CEH)
  • Certification
    :GAQM Certifications
  • Vendor
    :GAQM
  • Total Questions
    :878 Q&As
  • Last Updated
    :May 30, 2026

GAQM CEH-001 Online Questions & Answers

  • Question 641:

    Which of the following is one of the key features found in a worm but not seen in a virus?

    A. The payload is very small, usually below 800 bytes.
    B. It is self replicating without need for user intervention.
    C. It does not have the ability to propagate on its own.
    D. All of them cannot be detected by virus scanners.

  • Question 642:

    How would you describe an attack where an attacker attempts to deliver the payload over multiple packets over long periods of time with the purpose of defeating simple pattern matching in IDS systems without session reconstruction? A characteristic of this attack would be a continuous stream of small packets.

    A. Session Hijacking
    B. Session Stealing
    C. Session Splicing
    D. Session Fragmentation

  • Question 643:

    Which of the following represent weak password? (Select 2 answers)

    A. Passwords that contain letters, special characters, and numbers ExamplE. ap1$%##f@52
    B. Passwords that contain only numbers ExamplE. 23698217
    C. Passwords that contain only special characters ExamplE. and*#@!(%)
    D. Passwords that contain letters and numbers ExamplE. meerdfget123
    E. Passwords that contain only letters ExamplE. QWERTYKLRTY
    F. Passwords that contain only special characters and numbers ExamplE. 123@$45
    G. Passwords that contain only letters and special characters ExamplE. bob@andba
    H. Passwords that contain Uppercase/Lowercase from a dictionary list ExamplE. OrAnGe

  • Question 644:

    ARP poisoning is achieved in _____ steps

    A. 1
    B. 2
    C. 3
    D. 4

  • Question 645:

    You receive an e-mail with the following text message.

    "Microsoft and HP today warned all customers that a new, highly dangerous virus has been discovered which will erase all your files at midnight. If there's a file called hidserv.exe on your computer, you have been infected and your computer is now running a hidden server that allows hackers to access your computer. Delete the file immediately. Please also pass this message to all your friends and colleagues as soon as possible." You launch your antivirus software and scan the suspicious looking file hidserv.exe located in c:\windows directory and the AV comes out clean meaning the file is not infected. You view the file signature and confirm that it is a legitimate Windows system file "Human Interface Device Service".

    What category of virus is this?

    A. Virus hoax
    B. Spooky Virus
    C. Stealth Virus
    D. Polymorphic Virus

  • Question 646:

    In what stage of Virus life does a stealth virus gets activated with the user performing certain actions such as running an infected program?

    A. Design
    B. Elimination
    C. Incorporation
    D. Replication
    E. Launch
    F. Detection

  • Question 647:

    Attacking well-known system defaults is one of the most common hacker attacks. Most software is shipped with a default configuration that makes it easy to install and setup the application. You should change the default settings to secure the system.

    Which of the following is NOT an example of default installation?

    A. Many systems come with default user accounts with well-known passwords that administrators forget to change
    B. Often, the default location of installation files can be exploited which allows a hacker to retrieve a file from the system
    C. Many software packages come with "samples" that can be exploited, such as the sample programs on IIS web services
    D. Enabling firewall and anti-virus software on the local system

  • Question 648:

    What port number is used by Kerberos protocol?

    A. 88
    B. 44
    C. 487
    D. 419

  • Question 649:

    Assuring two systems that are using IPSec to protect traffic over the internet, what type of general attack could compromise the data?

    A. Spoof Attack
    B. Smurf Attack
    C. Man inthe Middle Attack
    D. Trojan Horse Attack
    E. Back Orifice Attack

  • Question 650:

    Which statement is TRUE regarding network firewalls preventing Web Application attacks?

    A. Network firewalls can prevent attacks because they can detect malicious HTTP traffic.
    B. Network firewalls cannot prevent attacks because ports 80 and 443 must be opened.
    C. Network firewalls can prevent attacks if they are properly configured.
    D. Network firewalls cannot prevent attacks because they are too complex to configure.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only GAQM exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CEH-001 exam preparations and GAQM certification application, do not hesitate to visit our Vcedump.com to find your solutions here.