Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 9 pages
Exam (elaborations)

CEH Exam Practice Questions Module 1 with Answers.

Document preview thumbnail
Preview 2 out of 9 pages

CEHExamPracticeQuestionsModule1with Answers. A security team is implementing various security controls across the organization. After several configurations and applications, a final agreed-on set of security controls are put into place; However, not all risks are mitigated by the controls. of the following, which is the next best step?: Continue applying controls until all risk is eliminated, Ignore any remaining risk as "best effort controlled," Ensure that any remaining risk is residual or low and accept the risk. Remove all controls. - Correct Answer Ensure that any remaining risk is residual or low and accept the risk. A Certified Ethical Hacker (CEH) follows a specific methodology for testing a system. Which step comes after footprinting in the CEH methodology? Scanning, Enumeration, Reconnaissance, Application attack. - Correct Answer Reconnaissance Which of the following best describes a newly discovered flaw in a software application? - Correct Answer Zero-d

Content preview

CEH Exam Practice Questions Module 1 with
Answers.
A security team is implementing various security controls across the organization. After
several configurations and applications, a final agreed-on set of security controls are put
into place; However, not all risks are mitigated by the controls. of the following, which is
the next best step?: Continue applying controls until all risk is eliminated, Ignore any
remaining risk as "best effort controlled," Ensure that any remaining risk is residual or low
and accept the risk. Remove all controls. - Correct Answer Ensure that any remaining risk
is residual or low and accept the risk.


A Certified Ethical Hacker (CEH) follows a specific methodology for testing a system.
Which step comes after footprinting in the CEH methodology? Scanning, Enumeration,
Reconnaissance, Application attack. - Correct Answer Reconnaissance


Which of the following best describes a newly discovered flaw in a software application? -
Correct Answer Zero-day


Which type of security control is met by encryption? - Correct Answer Preventative


You've been hired as part of pen test team. During the brief, you learn the client wants the
pen test attack to simulate a normal user who finds ways to elevate privileges and create
attacks. Which test type does the client want? - Correct Answer A gray Box


Which of the following is defined as ensuring the enforcement of organizational security
policy does not rely on voluntary user compliance by assigning sensitivity labels on
information and comparing this to the level of security a user is operating at? - Correct
Answer Mandatory Access Control


You begin your first pen test assignment by checking out IP address ranges owned by the
target as well as details of their domain name registration. Additionally, you visit job
boards and financial websites to gather any technical information online. What activity
are you performing? - Correct Answer Passive footprinting


Of the following choices, which best defines a formal written document defining what
employees are allowed to use organization systems for, what is not allowed, and what the
repercussions are for breaking the rules? - Correct Answer Information security policy
(ISP)

, An ethical hacker is given no prior knowledge of the network and has a specific
framework in which to work. The agreement specifies boundaries, nondisclosure
agreements, and a completion date definition. Which of the following is true? - Correct
Answer A white hat is attempting a black-box test


Which of the following is a detective control? - Correct Answer Audit trail


As part of a pen test on a U.S. government system, you discover files containing Social
Security numbers and other sensitive personally identifiable information (PII) information.
You are asked about controls placed on the dissemination of this information. Which of
the following acts should you check? - Correct Answer Privacy Act


Joe is performing an audit to validate the effectiveness of the organization's security
policies. During his tests, he discovers that a user has a dial-out modem installed on a
PC. Which security policy should be checked to see whether modems are allowed? -
Correct Answer Remote access policy


A hacker is attempting to gain access to target inside a business. After trying several
methods, he gets frustrated and starts a denial-of-service attack against a server
attached to the target. Which security control is the hacker affecting? - Correct Answer
Availability


In which phase of the ethical hacking methodology would a hacker discover available
targets on a network? - Correct Answer Scanning and Enumeration


Which of the following are potential drawbacks to a black-box test? - Correct Answer The
client does not get a focused picture of an internal attacker dedicated on their systems.
This test takes the longest amount of time to complete.


Which of the following best defines a logical or technical control? - Correct Answer
Security Tokens


Which of the following would not be considered passive reconnaissance? - Correct
Answer Ping Sweeping a range of IP addresses found through a DNS lookup.


As part of the preparation phase for a pen test you are participating in, the client relays
their intent to discover security flaws and possible remediation. They seem particularly
concerned about external threats and do not mention internal threats at all. When

Document information

Uploaded on
November 15, 2024
Number of pages
9
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Josejosy
5.0
(2)
Sold
9
Followers
1
Items
1857
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions