Certified Ethical Hacker (CEH v13) Free Sample Questions

20 free sample questions320 in the full practice test Other versions: 312-50v10(321),312-50v11(124),312-50v9(613),312-50v9(803)

Try simulator

312-50v13 Sample Questions

  1. Question 1

    A penetration tester is evaluating a financial institution's internal network. They discover a legacy system running a custom application that is critical for back-office operations. The tester suspects the application is vulnerable to a buffer overflow but finds that Data Execution Prevention (DEP) is enabled on the host operating system. To bypass DEP, the tester plans to use a Return-Oriented Programming (ROP) attack. Which of the following is the primary goal of creating a ROP chain in this scenario?

    Answer and explanation

    Correct answer: B

    Return-Oriented Programming (ROP) is an advanced exploitation technique used to bypass security measures like DEP. It works by finding small pieces of executable code, called 'gadgets,' within the existing codebase of a program and its loaded libraries. Each gadget typically performs a small operation (like loading a value into a register) and ends with a ret instruction. By carefully crafting a sequence of addresses on the stack, an attacker can chain these gadgets together to perform complex operations, such as calling VirtualProtect to mark a memory region as executable, thus bypassing DEP.

  2. Question 2

    During a web application assessment, a security analyst is using Burp Suite to test for vulnerabilities. They identify a feature where user-submitted data is serialized and stored in a cookie. The application is built using Java. The analyst wants to test for insecure deserialization vulnerabilities. Which of the following tools would be most effective for creating a malicious serialized Java object to exploit this vulnerability?

    Answer and explanation

    Correct answer: B

    ysoserial is a specialized tool designed for generating payloads that exploit insecure deserialization vulnerabilities in Java applications. It contains a collection of 'gadget chains' for various common Java libraries (like Apache Commons Collections, Spring, etc.). These chains, when deserialized by a vulnerable application, can lead to arbitrary code execution. The analyst would use ysoserial to generate a payload, then use Burp Suite to insert this payload into the cookie and send it to the application.

  3. Question 3

    Multiple answers

    A red team is targeting a corporation that uses a WPA3-Enterprise protected wireless network for its employees. The team wants to gain access to the internal network by exploiting the wireless infrastructure. Which of the following attack techniques would be most relevant for targeting a WPA3-Enterprise network? (Select TWO)

    Answer and explanation

    Correct answers: B, D

  4. Question 4

    An ethical hacker is testing a smart thermostat device that communicates with a cloud-based management platform via the MQTT protocol. The hacker captures the network traffic and observes unencrypted MQTT packets containing sensitive information. To further exploit this, the hacker wants to connect their own client to the MQTT broker and subscribe to all topics to eavesdrop on all communications. Which MQTT topic subscription wildcard should be used to achieve this?

    Answer and explanation

    Correct answer: D

    In the MQTT protocol, wildcards are used to subscribe to multiple topics at once. The single-level wildcard is +, which matches a single topic level. The multi-level wildcard is #, which matches any number of topic levels. To subscribe to all topics and eavesdrop on all communications passing through the broker, the # wildcard must be used. It must be placed as the last character in the topic string.

  5. Question 5

    True or False: In a Kubernetes environment, if an attacker compromises a pod and finds a service account token mounted, they can only use this token to access the Kubernetes API server from within that same pod.

    Answer and explanation

    Correct answer: B

    This statement is false. A Kubernetes service account token is a bearer token. If an attacker exfiltrates this token from a compromised pod, they can use it from anywhere (e.g., their own machine) to authenticate to the Kubernetes API server, provided the API server is accessible. The token's permissions are determined by the Roles and ClusterRoles bound to the service account, not by the location from which it is used.

  6. Question 6

    An ethical hacker is tasked with performing reconnaissance on a target company, acmecorp.com. The hacker wants to use the new AI-powered ShellGPT tool, as covered in CEH v13, to automate the generation of a complex nmap command. The goal is to perform an aggressive scan (-A), on the most common 1000 ports, against all hosts discovered in the acmecorp.com domain, while saving the output in all available formats (-oA). Which natural language query would be most effective to provide to ShellGPT to generate the desired command?

    Answer and explanation

    Correct answer: C

    ShellGPT is designed to interpret natural language to generate commands. The most effective query is a clear, descriptive sentence that specifies the tool (nmap), the action (perform an aggressive scan), the target (acmecorp.com), and the desired output options (save the output in all formats to a file named 'acmescan'). This level of detail allows the AI to correctly map the request to the appropriate nmap flags (-A for aggressive, -oA acmescan for output in all formats). The other options are either too vague or use incorrect syntax for a natural language query tool.

  7. Question 7

    A security analyst is investigating a data exfiltration incident. The attacker used a DNS tunneling technique to bypass the corporate firewall. The analyst is reviewing packet captures and notices an unusually high volume of TXT record queries to a suspicious domain. The data appears to be encoded. Which of the following tools is specifically designed to create and manage DNS tunnels for data exfiltration or C2 communications?

    Answer and explanation

    Correct answer: B

    Iodine is a well-known tool used for tunneling IPv4 data through a DNS server. It is a popular choice for attackers to exfiltrate data or establish a command-and-control (C2) channel in highly restricted networks where only DNS traffic is allowed. It works by encapsulating data within DNS queries and responses, often using TXT or NULL record types. Dnsrecon is for DNS enumeration, Wireshark is a packet analyzer, and Netcat is a versatile networking utility but does not create DNS tunnels natively.

  8. Question 8

    A penetration tester is evaluating the security of an API endpoint that uses GraphQL. Unlike traditional REST APIs, GraphQL allows clients to request exactly the data they need. The tester wants to check for excessive data exposure vulnerabilities. Which type of GraphQL query would be most useful for discovering all possible data types and fields the API can return, potentially revealing sensitive information not intended for the public?

    Answer and explanation

    Correct answer: C

    GraphQL has a built-in feature called introspection, which allows a client to query the server for information about the API's schema, including all available types, fields, queries, and mutations. If introspection is enabled on a production server (a common misconfiguration), an attacker can send an introspection query to get a complete map of the API's capabilities. This can reveal hidden or sensitive data fields that they can then attempt to query directly.

  9. Question 9

    An incident response team is analyzing an attack on their organization. The attacker gained initial access, established persistence, and then used a 'living off the land' technique by abusing PowerShell to perform lateral movement and exfiltrate data. The activity was difficult to detect because it did not involve dropping any malicious executables onto the disk. Which of the following malware categories best describes this attack?

    Answer and explanation

    Correct answer: B

    Fileless malware is a type of malicious software that exists only as in-memory artifacts. It does not write any part of its activity to the computer's hard drive, making it very difficult for traditional signature-based antivirus solutions to detect. 'Living off the land' techniques, which abuse legitimate, pre-installed tools like PowerShell, WMI, or registry entries, are a hallmark of fileless malware attacks.

  10. Question 10

    A security auditor is reviewing the cryptographic standards for a new application. The application needs to ensure the confidentiality of data in transit. The developers have proposed a plan that involves using a symmetric cipher for bulk data encryption and an asymmetric cipher for key exchange. A primary requirement is that if the server's long-term private key is compromised, past encrypted sessions should not be decipherable. Which cryptographic property must the key exchange mechanism implement to meet this requirement?

    Answer and explanation

    Correct answer: B

    Perfect Forward Secrecy (PFS) is a property of secure communication protocols where a compromise of long-term keys does not compromise past session keys. PFS is achieved by generating a unique, ephemeral session key for each session. Key exchange protocols like Diffie-Hellman Ephemeral (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) provide PFS. If the server's static private key (used for signing the key exchange) is stolen, it cannot be used to decrypt previously recorded sessions because each session used a different, temporary key that was discarded.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$189.99
$180.49
one-time
  • Full access to 2,181 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon