CEH v12 Practice Questions (Latest 2025/ 2026 Update) Qs & As | Grade A| 100% Correct (Verified Answers) CEH v12 Practice 485 Questions With Correct Answer Which of the following tools is a command-line vulnerability scanner that scans web servers for dangerous files/CGIs?
- Snort
- Kon-Boot
- John the Ripper
- Nikto - ANSWER Nikto
- The laptop is using an invalid IP address
- The laptop and the gateway are not on the same network
- The laptop isn't using a private IP address
- The gateway is not routing to a public IP address - ANSWER The
Michael, a technical specialist, discovered that the laptop of one of the employees connecting to a wireless point couldn't access the internet, but at the same time, it can transfer files locally. He checked the IP address and the default gateway. They are both on 192.168.1.0/24. Which of the following caused the problem?
gateway is not routing to a public IP address 1 / 4
Josh, a security analyst, wants to choose a tool for himself to examine links between data. One of the main requirements is to present data using graphs and link analysis. Which of the following tools will meet John's requirements?
- Palantir
- Maltego
- Analyst's Notebook
- Metasploit - ANSWER Maltego
- Something you know and something you are
- Something you have and something you know
- Something you are and something you remember
- Something you have and something you are - ANSWER
- SSL/TLS Renegotiation Vulnerability
What describes two-factor authentication for a credit card (using a card and pin)?
Something you have and something you know Identify a vulnerability in OpenSSL that allows stealing the information protected under normal conditions by the SSL/TLS encryption used to secure the internet?
B) POODLE
- Heartbleed Bug
- Shellshock - ANSWER Heartbleed Bug 2 / 4
You make a series of interactive queries, choosing subsequent plaintexts based on the information from the previous encryption. What type of attack are you trying to perform?
- Adaptive chosen-plaintext attack
- Ciphertext-only attack
- Known-plaintext attack
- Chosen-plaintext attack - ANSWER Adaptive chosen-plaintext
- Provides authentication
- Use key exchange
- Encrypts the payloads
- Work at the Data Link Layer - ANSWER Work at the Data Link
- NULL Scan
- Half-open Scan
- TCP Connect/Full Open Scan
- Xmas Scan - ANSWER TCP Connect/Full Open Scan 3 / 4
attack Which of the following does not apply to IPsec?
Layer Alex, a cybersecurity specialist, received a task from the head to scan open ports.One of the main conditions was to use the most reliable type of TCP scanning.Which of the following types of scanning would Alex use?
Which of the following Nmap options will you use if you want to scan fewer ports than the default?
- -p
- -sP
- -T
D) -F - ANSWER -F
You conduct an investigation and finds out that the browser of one of your employees sent malicious request that the employee knew nothing about. Identify the web page vulnerability that the attacker used to attack your employee?
- Cross-Site Request Forgery (CSRF)
- Command Injection Attacks
- File Inclusion Attack
- Hidden Field Manipulation Attack - ANSWER Cross-Site
- Stealth virus
- Polymorphic virus
- Macro virus
- Multipartite virus - ANSWER Multipartite virus
- / 4
Request Forgery (CSRF) Which of the following program attack both the boot sector and executable files?
Which of the following is the type of violation when an unauthorized individual enters a building following an employee through the employee entrance?