CEH Exam practice questions module 1 -exam elaborations with 100%
verified answer/solutions- Excel & Succeed – Already Graded A+
A security team is implementing various security controls across the organization. After several
configurations and applications, a final agreed-on set of security controls are put into place; However,
not all risks are mitigated by the controls. of the following, which is the next best step?: Continue
applying controls until all risk is eliminated, Ignore any remaining risk as "best effort controlled," Ensure
that any remaining risk is residual or low and accept the risk. Remove all controls. - (ANSWER)Ensure
that any remaining risk is residual or low and accept the risk.
A Certified Ethical Hacker (CEH) follows a specific methodology for testing a system. Which step comes
after footprinting in the CEH methodology? Scanning, Enumeration, Reconnaissance, Application attack.
- (ANSWER)Reconnaissance
Which of the following best describes a newly discovered flaw in a software application? -
(ANSWER)Zero-day
Which type of security control is met by encryption? - (ANSWER)Preventative
You've been hired as part of pen test team. During the brief, you learn the client wants the pen test
attack to simulate a normal user who finds ways to elevate privileges and create attacks. Which test type
does the client want? - (ANSWER)A gray Box
Which of the following is defined as ensuring the enforcement of organizational security policy does not
rely on voluntary user compliance by assigning sensitivity labels on information and comparing this to
the level of security a user is operating at? - (ANSWER)Mandatory Access Control
You begin your first pen test assignment by checking out IP address ranges owned by the target as well
as details of their domain name registration. Additionally, you visit job boards and financial websites to
gather any technical information online. What activity are you performing? - (ANSWER)Passive
footprinting
Of the following choices, which best defines a formal written document defining what employees are
allowed to use organization systems for, what is not allowed, and what the repercussions are for
breaking the rules? - (ANSWER)Information security policy (ISP)
, CEH Exam practice questions module 1 -exam elaborations with 100%
verified answer/solutions- Excel & Succeed – Already Graded A+
An ethical hacker is given no prior knowledge of the network and has a specific framework in which to
work. The agreement specifies boundaries, nondisclosure agreements, and a completion date definition.
Which of the following is true? - (ANSWER)A white hat is attempting a black-box test
Which of the following is a detective control? - (ANSWER)Audit trail
As part of a pen test on a U.S. government system, you discover files containing Social Security numbers
and other sensitive personally identifiable information (PII) information. You are asked about controls
placed on the dissemination of this information. Which of the following acts should you check? -
(ANSWER)Privacy Act
Joe is performing an audit to validate the effectiveness of the organization's security policies. During his
tests, he discovers that a user has a dial-out modem installed on a PC. Which security policy should be
checked to see whether modems are allowed? - (ANSWER)Remote access policy
A hacker is attempting to gain access to target inside a business. After trying several methods, he gets
frustrated and starts a denial-of-service attack against a server attached to the target. Which security
control is the hacker affecting? - (ANSWER)Availability
In which phase of the ethical hacking methodology would a hacker discover available targets on a
network? - (ANSWER)Scanning and Enumeration
Which of the following are potential drawbacks to a black-box test? - (ANSWER)The client does not get a
focused picture of an internal attacker dedicated on their systems. This test takes the longest amount of
time to complete.
Which of the following best defines a logical or technical control? - (ANSWER)Security Tokens
Which of the following would not be considered passive reconnaissance? - (ANSWER)Ping Sweeping a
range of IP addresses found through a DNS lookup.
verified answer/solutions- Excel & Succeed – Already Graded A+
A security team is implementing various security controls across the organization. After several
configurations and applications, a final agreed-on set of security controls are put into place; However,
not all risks are mitigated by the controls. of the following, which is the next best step?: Continue
applying controls until all risk is eliminated, Ignore any remaining risk as "best effort controlled," Ensure
that any remaining risk is residual or low and accept the risk. Remove all controls. - (ANSWER)Ensure
that any remaining risk is residual or low and accept the risk.
A Certified Ethical Hacker (CEH) follows a specific methodology for testing a system. Which step comes
after footprinting in the CEH methodology? Scanning, Enumeration, Reconnaissance, Application attack.
- (ANSWER)Reconnaissance
Which of the following best describes a newly discovered flaw in a software application? -
(ANSWER)Zero-day
Which type of security control is met by encryption? - (ANSWER)Preventative
You've been hired as part of pen test team. During the brief, you learn the client wants the pen test
attack to simulate a normal user who finds ways to elevate privileges and create attacks. Which test type
does the client want? - (ANSWER)A gray Box
Which of the following is defined as ensuring the enforcement of organizational security policy does not
rely on voluntary user compliance by assigning sensitivity labels on information and comparing this to
the level of security a user is operating at? - (ANSWER)Mandatory Access Control
You begin your first pen test assignment by checking out IP address ranges owned by the target as well
as details of their domain name registration. Additionally, you visit job boards and financial websites to
gather any technical information online. What activity are you performing? - (ANSWER)Passive
footprinting
Of the following choices, which best defines a formal written document defining what employees are
allowed to use organization systems for, what is not allowed, and what the repercussions are for
breaking the rules? - (ANSWER)Information security policy (ISP)
, CEH Exam practice questions module 1 -exam elaborations with 100%
verified answer/solutions- Excel & Succeed – Already Graded A+
An ethical hacker is given no prior knowledge of the network and has a specific framework in which to
work. The agreement specifies boundaries, nondisclosure agreements, and a completion date definition.
Which of the following is true? - (ANSWER)A white hat is attempting a black-box test
Which of the following is a detective control? - (ANSWER)Audit trail
As part of a pen test on a U.S. government system, you discover files containing Social Security numbers
and other sensitive personally identifiable information (PII) information. You are asked about controls
placed on the dissemination of this information. Which of the following acts should you check? -
(ANSWER)Privacy Act
Joe is performing an audit to validate the effectiveness of the organization's security policies. During his
tests, he discovers that a user has a dial-out modem installed on a PC. Which security policy should be
checked to see whether modems are allowed? - (ANSWER)Remote access policy
A hacker is attempting to gain access to target inside a business. After trying several methods, he gets
frustrated and starts a denial-of-service attack against a server attached to the target. Which security
control is the hacker affecting? - (ANSWER)Availability
In which phase of the ethical hacking methodology would a hacker discover available targets on a
network? - (ANSWER)Scanning and Enumeration
Which of the following are potential drawbacks to a black-box test? - (ANSWER)The client does not get a
focused picture of an internal attacker dedicated on their systems. This test takes the longest amount of
time to complete.
Which of the following best defines a logical or technical control? - (ANSWER)Security Tokens
Which of the following would not be considered passive reconnaissance? - (ANSWER)Ping Sweeping a
range of IP addresses found through a DNS lookup.