Exam Details

  • Exam Code
    :CEH-001
  • Exam Name
    :Certified Ethical Hacker (CEH)
  • Certification
    :GAQM Certifications
  • Vendor
    :GAQM
  • Total Questions
    :878 Q&As
  • Last Updated
    :May 10, 2025

GAQM GAQM Certifications CEH-001 Questions & Answers

  • Question 671:

    Which of the following identifies the three modes in which Snort can be configured to run?

    A. Sniffer, Packet Logger, and Network Intrusion Detection System

    B. Sniffer, Network Intrusion Detection System, and Host Intrusion Detection System

    C. Sniffer, Host Intrusion Prevention System, and Network Intrusion Prevention System

    D. Sniffer, Packet Logger, and Host Intrusion Prevention System

  • Question 672:

    Which type of password cracking technique works like dictionary attack but adds some numbers and symbols to the words from the dictionary and tries to crack the password?

    A. Dictionary attack

    B. Brute forcing attack

    C. Hybrid attack

    D. Syllable attack

    E. Rule-based attack

  • Question 673:

    You generate MD5 128-bit hash on all files and folders on your computer to keep a baseline check for security reasons?

    What is the length of the MD5 hash?

    A. 32 character

    B. 64 byte

    C. 48 char

    D. 128 kb

  • Question 674:

    Bill is a security analyst for his company. All the switches used in the company's office are Cisco switches. Bill wants to make sure all switches are safe from ARP poisoning. How can Bill accomplish this?

    A. Bill can use the command: ip dhcp snooping.

    B. Bill can use the command: no ip snoop.

    C. Bill could use the command: ip arp no flood.

    D. He could use the command: ip arp no snoop.

  • Question 675:

    Jane wishes to forward X-Windows traffic to a remote host as well as POP3 traffic. She is worried that adversaries might be monitoring the communication link and could inspect captured traffic. She would like to tunnel the information to the remote end but does not have VPN capabilities to do so. Which of the following tools can she use to protect the link?

    A. MD5

    B. PGP

    C. RSA

    D. SSH

  • Question 676:

    NTP allows you to set the clocks on your systems very accurately, to within 100ms and sometimes-even 10ms. Knowing the exact time is extremely important for enterprise security. Various security protocols depend on an accurate source of time information in order to prevent "playback" attacks. These protocols tag their communications with the current time, to prevent attackers from replaying the same communications, e.g., a login/password interaction or even an entire communication, at a later date. One can circumvent this tagging, if the clock can be set back to the time the communication was recorded. An attacker attempts to try corrupting the clocks on devices on your network. You run Wireshark to detect the NTP traffic to see if there are any irregularities on the network. What port number you should enable in Wireshark display filter to view NTP packets?

    A. TCP Port 124

    B. UDP Port 125

    C. UDP Port 123

    D. TCP Port 126

  • Question 677:

    John runs a Web server, IDS and firewall on his network. Recently his Web server has been under constant hacking attacks. He looks up the IDS log files and sees no intrusion attempts but the Web server constantly locks up and needs rebooting due to various brute force and buffer overflow attacks but still the IDS alerts no intrusion whatsoever. John becomes suspicious and views the Firewall logs and he notices huge SSL connections constantly hitting his Web server. Hackers have been using the encrypted HTTPS protocol to send exploits to the Web server and that was the reason the IDS did not detect the intrusions. How would John protect his network from these types of attacks?

    A. Install a proxy server and terminate SSL at the proxy

    B. Enable the IDS to filter encrypted HTTPS traffic

    C. Install a hardware SSL "accelerator" and terminate SSL at this layer

    D. Enable the Firewall to filter encrypted HTTPS traffic

  • Question 678:

    To see how some of the hosts on your network react, Winston sends out SYN packets to an IP range. A number of IPs respond with a SYN/ACK response. Before the connection is established he sends RST packets to those hosts to stop the session. Winston has done this to see how his intrusion detection system will log the traffic. What type of scan is Winston attempting here?

    A. Winston is attempting to find live hosts on your company's network by using an XMAS scan.

    B. He is utilizing a SYN scan to find live hosts that are listening on your network.

    C. This type of scan he is using is called a NULL scan.

    D. He is using a half-open scan to find live hosts on your network.

  • Question 679:

    Identify SQL injection attack from the HTTP requests shown below:

    A. http://www.myserver.c0m/search.asp? lname=smith%27%3bupdate%20usertable%20set%20passwd%3d%27hAx0r%27%3b-- %00

    B. http://www.myserver.c0m/script.php?mydata=%3cscript%20src=%22

    C. http%3a%2f%2fwww.yourserver.c0m%2fbadscript.js%22%3e%3c%2fscript%3e

    D. http://www.victim.com/example accountnumber=67891andcreditamount=999999999

  • Question 680:

    What is the correct order of steps in CEH System Hacking Cycle?

    A. Option A

    B. Option B

    C. Option C

    D. Option D

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only GAQM exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CEH-001 exam preparations and GAQM certification application, do not hesitate to visit our Vcedump.com to find your solutions here.