ECCouncil Certified Ethical Hacker Exam (CEHv13) Sample Questions:
1. During a scheduled security review in a high-tech lab in Austin, Texas, penetration tester Lucas Bennett was assessing a state government's new payroll system hosted in a private cloud. One humid afternoon, while fuzz testing the input validation logic of the TaxCalcEngine.dll module, he triggered a buffer overflow by submitting malformed taxpayer ID strings. The crash led to unintended disclosure of payroll data due to unchecked data boundaries. Lucas traced the issue to a coding oversight in a core processing module.
Applying a structured analysis approach, which category best describes the vulnerability he discovered?
A) Poor Patch Management
B) Misconfigurations Weak Configurations
C) Design Flaws
D) Application Flaws
2. A penetration tester evaluates a company ' s susceptibility to advanced social engineering attacks targeting its executive team. Using detailed knowledge of recent financial audits and ongoing projects, the tester crafts a highly credible pretext to deceive executives into revealing their network credentials. What is the most effective social engineering technique the tester should employ to obtain the necessary credentials without raising suspicion?
A) Create a convincing fake email from the CFO asking for immediate credential verification
B) Develop a spear-phishing email that references specific financial audit details and requests login confirmation
C) Send a mass phishing email with a link to a fake financial report
D) Conduct a phone call posing as an external auditor requesting access to financial systems
3. You suspect a Man-in-the-Middle (MitM) attack inside the network. Which network activity would help confirm this?
A) Abnormal DNS request volumes
B) IP addresses resolving to multiple MAC addresses
C) Multiple login attempts from one IP
D) Sudden increase in traffic
4. During a security assessment for an e-commerce company in Boston, Massachusetts, your team conducts a reconnaissance phase to identify potential entry points into the organization ' s communication infrastructure.
You focus on gathering details about the systems responsible for handling incoming email traffic, avoiding active network probing, and relying on passive DNS data collection. Given this objective, which DNS record type should you query to extract information about the target's mail server configuration?
A) SOA
B) NS
C) MX
D) TXT
5. Which advanced session-hijacking technique is hardest to detect and mitigate?
A) Covert XSS attack
B) Passive sniffing on Wi-Fi
C) Man-in-the-Browser (MitB) attack
D) Session fixation
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: B | Question # 3 Answer: B | Question # 4 Answer: C | Question # 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Alexia

