A.3 Test Out Ethical Hacker Pro
Certification Practice EXAM Questions
and Answers (Verified Answers) (Latest
Update 2026) UPDATE!!
You are a cybersecurity consultant and have been asked to work with the ACME, Inc.
company to ensure their network is protected from hackers. As part of the tests, you
need to disable logging on a Windows system.
In this lab, your task is to use Windows PowerShell (as Admin) to:
View the current audit policies on the system.
Disable all audit policies.
Confirm that all the audits were disabled. -CORRECTANSWER Complete this lab as
follows:
Right-click Start and select Windows PowerShell (Admin).
Maximize the window for easier viewing.
At the command prompt, type auditpol /get /category:* and press Enter to view the
current audit policies.Notice the different settings used for each system.
Type auditpol /clear /y and press Enter to disable all audit policies.
Type auditpol /get /category:* and press Enter to confirm that the audits were
disabled.Notice that all of the polices are now set to No Auditing.
As an IT administrator, you need to know how security breaches are caused. You know
that SMAC is used for MAC spoofing, so you are going to spoof your MAC address.
,In this lab, your task is to complete the following:
On Office2 use ipconfig /all and find the IP address and MAC address.
Spoof the MAC address on ITAdmin to that of Office2 using SMAC.
Refresh your MAC and IP addresses to match the target machine. -
CORRECTANSWER Complete this lab as follows:
Find the IP address and MAC address as follows:Right-click Start and select Windows
PowerShell (Admin).At the command prompt, type ipconfig /all and press Enter.Find the
MAC address and the IP address.
Spoof the MAC address as follows:From the top navigation tabs, select Floor 1
Overview.Under IT Administration, select ITAdmin.In the search bar, type SMAC.Under
Best match, right-click SMAC and select Run as administrator.In the New Spoofed Mac
Address field, type 00:00:55:55:44:15 for the MAC address from Office2.Select Update
MAC.Select OK to restart the adapter.
Refresh your MAC and IP addresses as follows:Right-click Start and select Windows
PowerShell (Admin).At the command prompt, type ipconfig /all to confirm the MAC
address has been updated.Type ipconfig /renew to update the IP address.
You are the cypersecurity specialist for your company. You are conducting a
penetration test to see if anyone is using FTP against company policy.
In this lab, your task is to capture FTP packets as follows:
Use Wireshark to capture packets for five seconds.
Filter for FTP packets.
CORRECTANSWER the questions. -CORRECTANSWER Complete this lab as follows:
, From the Favorites bar, open Wireshark.
Under Capture, select enp2s0.
Select the blue fin to begin a Wireshark capture.
Capture packets for five seconds.
Select the red box to stop the Wireshark capture.
In the Apply a display filter field, type ftp and press Enter.
In the top right, select CORRECTANSWER Questions.
CORRECTANSWER the questions.
Select Score Lab.
You are an ethical hacker consultant working for CorpNet. They want you to discover
weaknesses in their network. From outside of the CorpNet network, you found their web
server, www.corpnet.xyz, has an IP address of 198.28.1.1. You decide to perform
several nmap scans using a few http scripts.
In this lab, your task is to run the following nmap scripts on port 80 of 198.28.1.1:
http-server-header.nse to display the HTTP server header.
http-chrono.nse to measure the time a website takes to deliver a web page.
http-headers.nse to perform a HEAD request for the root folder.
http-errors.nse to crawl through the website and return any error pages.
http-malware-host.nse to look for malware signatures of known server compromises.
http-comments-displayer.nse to display HTML and JavaScript comments. -
CORRECTANSWER Complete this lab as follows:
From the Favorites bar, open Terminal.
Certification Practice EXAM Questions
and Answers (Verified Answers) (Latest
Update 2026) UPDATE!!
You are a cybersecurity consultant and have been asked to work with the ACME, Inc.
company to ensure their network is protected from hackers. As part of the tests, you
need to disable logging on a Windows system.
In this lab, your task is to use Windows PowerShell (as Admin) to:
View the current audit policies on the system.
Disable all audit policies.
Confirm that all the audits were disabled. -CORRECTANSWER Complete this lab as
follows:
Right-click Start and select Windows PowerShell (Admin).
Maximize the window for easier viewing.
At the command prompt, type auditpol /get /category:* and press Enter to view the
current audit policies.Notice the different settings used for each system.
Type auditpol /clear /y and press Enter to disable all audit policies.
Type auditpol /get /category:* and press Enter to confirm that the audits were
disabled.Notice that all of the polices are now set to No Auditing.
As an IT administrator, you need to know how security breaches are caused. You know
that SMAC is used for MAC spoofing, so you are going to spoof your MAC address.
,In this lab, your task is to complete the following:
On Office2 use ipconfig /all and find the IP address and MAC address.
Spoof the MAC address on ITAdmin to that of Office2 using SMAC.
Refresh your MAC and IP addresses to match the target machine. -
CORRECTANSWER Complete this lab as follows:
Find the IP address and MAC address as follows:Right-click Start and select Windows
PowerShell (Admin).At the command prompt, type ipconfig /all and press Enter.Find the
MAC address and the IP address.
Spoof the MAC address as follows:From the top navigation tabs, select Floor 1
Overview.Under IT Administration, select ITAdmin.In the search bar, type SMAC.Under
Best match, right-click SMAC and select Run as administrator.In the New Spoofed Mac
Address field, type 00:00:55:55:44:15 for the MAC address from Office2.Select Update
MAC.Select OK to restart the adapter.
Refresh your MAC and IP addresses as follows:Right-click Start and select Windows
PowerShell (Admin).At the command prompt, type ipconfig /all to confirm the MAC
address has been updated.Type ipconfig /renew to update the IP address.
You are the cypersecurity specialist for your company. You are conducting a
penetration test to see if anyone is using FTP against company policy.
In this lab, your task is to capture FTP packets as follows:
Use Wireshark to capture packets for five seconds.
Filter for FTP packets.
CORRECTANSWER the questions. -CORRECTANSWER Complete this lab as follows:
, From the Favorites bar, open Wireshark.
Under Capture, select enp2s0.
Select the blue fin to begin a Wireshark capture.
Capture packets for five seconds.
Select the red box to stop the Wireshark capture.
In the Apply a display filter field, type ftp and press Enter.
In the top right, select CORRECTANSWER Questions.
CORRECTANSWER the questions.
Select Score Lab.
You are an ethical hacker consultant working for CorpNet. They want you to discover
weaknesses in their network. From outside of the CorpNet network, you found their web
server, www.corpnet.xyz, has an IP address of 198.28.1.1. You decide to perform
several nmap scans using a few http scripts.
In this lab, your task is to run the following nmap scripts on port 80 of 198.28.1.1:
http-server-header.nse to display the HTTP server header.
http-chrono.nse to measure the time a website takes to deliver a web page.
http-headers.nse to perform a HEAD request for the root folder.
http-errors.nse to crawl through the website and return any error pages.
http-malware-host.nse to look for malware signatures of known server compromises.
http-comments-displayer.nse to display HTML and JavaScript comments. -
CORRECTANSWER Complete this lab as follows:
From the Favorites bar, open Terminal.