Official Bank 0/125

Certified Ethical Hacker (CEH) v9 (312-50V9) - EC Council Actual Exam Questions

Last updated on May 13, 2026

97% Exam Compliance
125 Total Questions
1
Question

Port scanning can be used as part of a technical assessment to determine network vulnerabilities. The TCP XMAS scan is used to identify listening port on the targeted system. If a scanned port is open, what happens?

Options
A

The port will ignore the packets.

B

The port will send an RST.

C

The port will send an ACK.

D

The port will send a SYN.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

While performing online banking using a web browser, a user receives an email that contains a link to an interesting Web site. When the user clicks on the link, another web browser session starts and displays a video of cats playing a piano. The next business day, the user receives what looks like an email from his bank, indicating that his bank account has been accessed from a foreign country. The email asks the user to call his bank and verify the authorization of a funds transfer that took place. What web browser-based security vulnerability was exploited to compromise the user?

Options
A

Cross-Site Request Forgery

B

Cross-Site Scripting

C

Web form input validation

D

Clickjacking

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

The Open Web Application Security Project (OWASP) is the worldwide not-for-profit charitable organization focused on improving the security of software. What item is the primary concern on OWASP’s Top Ten Project most Critical Web application Security Rules?

Options
A

Injection

B

Cross site Scripting

C

Cross site Request Forgery

D

Path Disclosure

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

As a Certified Ethical hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specified of the testing, the associated violations, and essentially protects both the organization’s interest and your li abilities as a tester?

Options
A

Term of Engagement

B

Non-Disclosure Agreement

C

Project Scope

D

Service Level Agreement

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

The “white box testing” methodology enforces what kind of restriction?

Options
A

The internal operation of a system is completely known to the tester.

B

Only the internal operation of a system is known to the tester.

C

Only the external operation of a system is accessible to the tester.

D

The internal operation of a system is only partly accessible to the tester.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.