Certified Ethical Hacker (CEH) (312-50) - EC Council Actual Exam Questions
Last updated on May 13, 2026
Morris, a professional hacker, performed a vulnerability scan on a target organization by sniffing the traffic on the network lo identify the active systems, network services, applications, and vulnerabilities. He also obtained the list of the users who are currently accessing the network. What is the type of vulnerability assessment that Morris performed on the target organization?
internal assessment
Passive assessment
External assessment
Credentialed assessment
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
During an attempt to perform an SQL injection attack, a certified ethical hacker is focusing on the identification of database engine type by generating an ODBC error. The ethical hacker, after injecting various payloads, finds that the web application returns a standard, generic error message that does not reveal any detailed database information. Which of the following techniques would the hacker consider next to obtain useful information about the underlying database?
Use the UNION operator to combine the result sets of two or more SELECT statements
Attempt to compromise the system through OS-level command shell execution
Try to insert a string value where a number is expected in the input field
Utilize a blind injection technique that uses time delays or error signatures to extract information
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
You went to great lengths to install all the necessary technologies to prevent hacking attacks, such as expensive firewalls, antivirus software, anti-spam systems and intrusion detection/prevention tools in your company's network. You have configured the most secure policies and tightened every device on your network. You are confident that hackers will never be able to gain access to your network with complex security system in place. Your peer, Peter Smith who works at the same department disagrees with you. He says even the best network security technologies cannot prevent hackers gaining access to the network because of presence of "weakest link" in the security chain. What is Peter Smith talking about?
Untrained staff or ignorant computer users who inadvertently become the weakest link in your security chain
"zero-day" exploits are the weakest link in the security chain since the IDS will not be able to detect these attacks
"Polymorphic viruses" are the weakest link in the security chain since the Anti-Virus scanners will not be able to detect these attacks
Continuous Spam e-mails cannot be blocked by your security system since spammers use different techniques to bypass the filters in your gateway
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
jane invites her friends Alice and John over for a LAN party. Alice and John access Jane's wireless network without a password. However. Jane has a long, complex password on her router. What attack has likely occurred?
Wireless sniffing
Piggybacking
Evil twin
Wardriving
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Which among the following is the best example of the hacking concept called "clearing tracks"?
After a system is breached, a hacker creates a backdoor to allow re-entry into a system.
During a cyberattack, a hacker injects a rootkit into a server.
An attacker gains access to a server through an exploitable vulnerability.
During a cyberattack, a hacker corrupts the event logs on all machines.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.