CEH final exam P4 questions well
answered graded A+
Your organization processes credit card payments and adheres to the requirements of the
Payment Card Industry Data Security Standard. Recently, you upgraded the card processing
software to a new version. When are you required by the PCI-DSS to perform external and
internal penetration testing? - correct answer ✔✔ Immediately
As part of a security audit, your team is looking for common security design issues.
In which scenario would applying the segregation of duties principle enhance security? - correct
answer ✔✔ Network administrator issues RFID cards for the server room and reviews the door
logs
Your company has completed all the appropriate steps to prepare for a potential incident. The
next day, a user informs you that the internal Web server is unavailable. When you research the
issue, you determine that a Distributed Denial of Service (DDoS) attack has been carried out
against the internal Web server. You need to follow the appropriate incident response
procedures to recover the internal Web server. What is the first step to perform when an
incident has occurred? - correct answer ✔✔ Detect and analyze
Which documentation provides an ethical hacker with the scope of targets and allowed testing
techniques and tools? - correct answer ✔✔ ROE
A hacker was recently caught trying to deface the web site of a company with which he had
serious disagreement concerning their use of certain chemicals in their products. What is this
type of hacker called? - correct answer ✔✔ Hacktivist
You are heading a committee that is responsible for creating your company's security policies.
What should you do FIRST? - correct answer ✔✔ Perform a risk assessment
, Why is someone called a suicide hacker? - correct answer ✔✔ Hope to be caught
You have been hired to perform a security assessment of the corporate network.
Which discovery requires you to contact external authorities immediately? - correct answer ✔✔
Child pornography
Which of the following statements regarding security policies is NOT true? - correct answer ✔✔
Security policies are technology specific.
Which of the following results when a consistent security policy has the support of executive
management? - correct answer ✔✔ More acceptance of the policy
You have been hired as an ethical hacker by a company. During your initial meeting, you are
given several guidelines that must be complied with by the company's security, including HIPAA.
Which type of company has MOST likely hired you? - correct answer ✔✔ Medical
You are working with another security professional to design your company's incident response
procedures. Which of the following statements is true? - correct answer ✔✔ Incident response
is part of incident handling, and incident handling is part of incident management.
Your company has decided to hire an ethical hacker to help identify issues with your company's
network. Which of the following terms can also be used to describe this position? - correct
answer ✔✔ White hat
When IDS alerts report attacks on multiple devices, on which basis should the alerts be
prioritized? - correct answer ✔✔ Potential impact of the loss for each device
Requiring an audit trail in the security policy is an example of implementing which type of
control? - correct answer ✔✔ Detective
answered graded A+
Your organization processes credit card payments and adheres to the requirements of the
Payment Card Industry Data Security Standard. Recently, you upgraded the card processing
software to a new version. When are you required by the PCI-DSS to perform external and
internal penetration testing? - correct answer ✔✔ Immediately
As part of a security audit, your team is looking for common security design issues.
In which scenario would applying the segregation of duties principle enhance security? - correct
answer ✔✔ Network administrator issues RFID cards for the server room and reviews the door
logs
Your company has completed all the appropriate steps to prepare for a potential incident. The
next day, a user informs you that the internal Web server is unavailable. When you research the
issue, you determine that a Distributed Denial of Service (DDoS) attack has been carried out
against the internal Web server. You need to follow the appropriate incident response
procedures to recover the internal Web server. What is the first step to perform when an
incident has occurred? - correct answer ✔✔ Detect and analyze
Which documentation provides an ethical hacker with the scope of targets and allowed testing
techniques and tools? - correct answer ✔✔ ROE
A hacker was recently caught trying to deface the web site of a company with which he had
serious disagreement concerning their use of certain chemicals in their products. What is this
type of hacker called? - correct answer ✔✔ Hacktivist
You are heading a committee that is responsible for creating your company's security policies.
What should you do FIRST? - correct answer ✔✔ Perform a risk assessment
, Why is someone called a suicide hacker? - correct answer ✔✔ Hope to be caught
You have been hired to perform a security assessment of the corporate network.
Which discovery requires you to contact external authorities immediately? - correct answer ✔✔
Child pornography
Which of the following statements regarding security policies is NOT true? - correct answer ✔✔
Security policies are technology specific.
Which of the following results when a consistent security policy has the support of executive
management? - correct answer ✔✔ More acceptance of the policy
You have been hired as an ethical hacker by a company. During your initial meeting, you are
given several guidelines that must be complied with by the company's security, including HIPAA.
Which type of company has MOST likely hired you? - correct answer ✔✔ Medical
You are working with another security professional to design your company's incident response
procedures. Which of the following statements is true? - correct answer ✔✔ Incident response
is part of incident handling, and incident handling is part of incident management.
Your company has decided to hire an ethical hacker to help identify issues with your company's
network. Which of the following terms can also be used to describe this position? - correct
answer ✔✔ White hat
When IDS alerts report attacks on multiple devices, on which basis should the alerts be
prioritized? - correct answer ✔✔ Potential impact of the loss for each device
Requiring an audit trail in the security policy is an example of implementing which type of
control? - correct answer ✔✔ Detective