Free Certified Ethical Hacker (CEH v13) practice — 6 questions on Network and Perimeter Hacking, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Network and Perimeter Hacking
During an incident review, analysts determine that an attacker hijacked an authenticated TCP session by predicting the sequence numbers used by a legitimate client, then injected spoofed packets to desynchronize and take over the connection before the real client could respond. Which countermeasure would BEST prevent this specific attack in the future?
IPsec ESP encrypts and cryptographically authenticates every packet in the session, making sequence-number prediction and injection of spoofed packets computationally infeasible — directly neutralizing TCP session hijacking.
Question 2 of 6 · Network and Perimeter Hacking
A security team discovers that an unauthorized host on the internal LAN sent forged ARP replies binding its own MAC address to the IP address of the default gateway, allowing it to intercept and read cleartext traffic from nearby hosts. DHCP snooping is already enabled on all access switches. Which additional switch feature should be configured to stop this specific attack from succeeding again?
Dynamic ARP Inspection (DAI) cross-checks the IP-to-MAC bindings in ARP packets against the trusted DHCP snooping binding table and drops any ARP reply that does not match, directly stopping ARP cache poisoning of the gateway address.
Question 3 of 6 · Network and Perimeter Hacking
During a DDoS attack investigation, the response team observes a massive volume of inbound UDP traffic destined for port 123 on the victim's public IP. Analysis of upstream flow logs shows that each single-packet request sent toward third-party servers was spoofed with the victim's IP as the source, and the resulting replies received by the victim were dramatically larger than the original requests. Which type of attack does this describe?
NTP amplification abuses UDP port 123 NTP servers with spoofed source IPs; a small query (e.g., the legacy monlist request) triggers a disproportionately large reply directed at the spoofed victim, producing high-bandwidth amplification exactly as described.
Question 4 of 6 · Network and Perimeter Hacking
A penetration tester needs to bypass a signature-based network IDS that inspects payload contents for a known malicious string. The tester crafts the attack so that the malicious payload is split across multiple small TCP segments, ensuring no single packet captured by the IDS ever contains the complete matching signature. What is this IDS evasion technique called?
Session splicing delivers the malicious payload across multiple small TCP segments over the session, so the IDS never sees the complete signature string in any single packet unless it fully reassembles the stream — a classic CEH-tested IDS evasion technique.
Question 5 of 6 · Network and Perimeter Hacking
While performing external reconnaissance, a tester notes that one host responds to scans with unusually consistent latency, exposes several services with unmodified default banners, and shows no legitimate outbound connections or user-driven traffic in the collected NetFlow logs over several days. Which type of system does this MOST likely describe?
A honeypot is a decoy system deliberately configured with default, unpatched-looking services and no real user activity, designed purely to attract and log attacker interaction — matching the artificial consistency and absence of legitimate traffic described.
Question 6 of 6 · Network and Perimeter Hacking
An attacker calls a company's IT help desk, claiming to be the CFO who is traveling and urgently needs a password reset because they are locked out before a board meeting. The attacker uses confident, authoritative language and references real internal details to appear legitimate. Under CEH social engineering categorization, this technique is BEST classified as which of the following?
Impersonation involves an attacker pretending to be a legitimate, often authoritative, individual (such as an executive) to manipulate a target into performing an action like resetting a password — exactly the scenario described.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.