Question 151
This form of encryption algorithm is a symmetric key block cipher that is characterized by a 128- bit block size, and its key size can be up to 256 bits. Which among the following is this encryption algorithm?
Question 152
A penetration tester suspects that a web application's product search feature is vulnerable to SQL injection.
The tester needs to confirm this by manipulating the SQL query. What is the best technique to test for SQL injection?
The tester needs to confirm this by manipulating the SQL query. What is the best technique to test for SQL injection?
Question 153
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run?
Question 154
FILL BLANK
Scenario
Instructions
You have been hired as a part of the Red Team at CEHORG, an IT and ITES organization that deals with advanced research and development in the field of information security. It has offices all over the country connected in real-time by its network infrastructure.
Your organization is worried about rising cybersecurity incidents and has entrusted you with a comprehensive security audit of the complete infrastructure.
CEHORG's internal network consists of several subnets housing various organizational units like any large organization. The front office is connected to a separate subnet that connects to the company's public-facing computers. The company has installed multiple kiosks to help customers understand their products and services. The front office also has Wi-Fi connectivity to cater to the users who carry their smartphones and laptops.
The CEHORG's internal network is made up of Militarized and Demilitarized zones. As a security precaution and by design, all the internal resource zones are configured with different subnet IPs.
The militarized zone houses the application servers that provide application frameworks for various departments. The Demilitarized Zone contains public-facing systems of the organization, such as web and mail servers. The headquarters' network topology and protocols are replicated worldwide in all its satellite offices for efficient communication with the headquarters.
Description
CEH Practical exam presents you with 20 challenges built on the ethical hacking domains covered in the C|EH program. The exam hosts multiple hidden machines, each containing a set of vulnerable applications and services. You must apply your knowledge and skills in various ethical hacking domains and solve the challenges. The exam duration is 6 hours. Each challenge in CEH Practical weighs 10 points, and you are required to solve a minimum of 14 challenges out of 20, which would sum up to 140 points, to become a CEH (Practical) Credential Holder.
On the cyber range, you will have access to Ethical Hacker Workstations, EH Workstation - 1 and EH Workstation - 2. EH Workstation - 1 is a Parrot Security machine and EH Workstation
- 2 is a Windows 11 machine. You can switch to these machines from the Resources tab.
Please note that there are a maximum of 3 attempts for each challenge.
Available target networks:
10.10.55.0/24
192.168.44.0/24
192.168.200.0/24
Exclusions:
10.10.55.1, 10.10.55.2
192.168.44.1, 192.168.44.2
192.168.200.1, 192.168.200.2
The credentials to access EH Workstation - 1 (Parrot Security) machine are as below:
Username: attacker Password: toor
The credentials to access EH Workstation - 2 (Windows 11) are as below:
Username: Admin Password: Pa$$w0rd
The credentials to access OpenVAS on EH Workstation - 1 (Parrot Security) machine are as below:
Username: admin Password: password
To open OpenVAS tool, click Applications at the top of the Desktop window and navigate to Pentesting → Vulnerability Analysis → Openvas - Greenbone → Start Greenbone Vulnerability Manager Service to launch OpenVAS tool.
Note: You can use username.txt and password.txt available on the Desktop of the EH Workstation - 1 (Parrot Security) machine for any credentials/password cracking attempt.
Flags
Challenge:
Leverage a remote login and command-line execution application on a Linux target within the
10.10.55.0/24 subnet to access the sensitive file, StealthNet.txt. Retrieve the contents of the file and provide them as the answer. (Format: Aa*a**A**a)
Scenario
Instructions
You have been hired as a part of the Red Team at CEHORG, an IT and ITES organization that deals with advanced research and development in the field of information security. It has offices all over the country connected in real-time by its network infrastructure.
Your organization is worried about rising cybersecurity incidents and has entrusted you with a comprehensive security audit of the complete infrastructure.
CEHORG's internal network consists of several subnets housing various organizational units like any large organization. The front office is connected to a separate subnet that connects to the company's public-facing computers. The company has installed multiple kiosks to help customers understand their products and services. The front office also has Wi-Fi connectivity to cater to the users who carry their smartphones and laptops.
The CEHORG's internal network is made up of Militarized and Demilitarized zones. As a security precaution and by design, all the internal resource zones are configured with different subnet IPs.
The militarized zone houses the application servers that provide application frameworks for various departments. The Demilitarized Zone contains public-facing systems of the organization, such as web and mail servers. The headquarters' network topology and protocols are replicated worldwide in all its satellite offices for efficient communication with the headquarters.
Description
CEH Practical exam presents you with 20 challenges built on the ethical hacking domains covered in the C|EH program. The exam hosts multiple hidden machines, each containing a set of vulnerable applications and services. You must apply your knowledge and skills in various ethical hacking domains and solve the challenges. The exam duration is 6 hours. Each challenge in CEH Practical weighs 10 points, and you are required to solve a minimum of 14 challenges out of 20, which would sum up to 140 points, to become a CEH (Practical) Credential Holder.
On the cyber range, you will have access to Ethical Hacker Workstations, EH Workstation - 1 and EH Workstation - 2. EH Workstation - 1 is a Parrot Security machine and EH Workstation
- 2 is a Windows 11 machine. You can switch to these machines from the Resources tab.
Please note that there are a maximum of 3 attempts for each challenge.
Available target networks:
10.10.55.0/24
192.168.44.0/24
192.168.200.0/24
Exclusions:
10.10.55.1, 10.10.55.2
192.168.44.1, 192.168.44.2
192.168.200.1, 192.168.200.2
The credentials to access EH Workstation - 1 (Parrot Security) machine are as below:
Username: attacker Password: toor
The credentials to access EH Workstation - 2 (Windows 11) are as below:
Username: Admin Password: Pa$$w0rd
The credentials to access OpenVAS on EH Workstation - 1 (Parrot Security) machine are as below:
Username: admin Password: password
To open OpenVAS tool, click Applications at the top of the Desktop window and navigate to Pentesting → Vulnerability Analysis → Openvas - Greenbone → Start Greenbone Vulnerability Manager Service to launch OpenVAS tool.
Note: You can use username.txt and password.txt available on the Desktop of the EH Workstation - 1 (Parrot Security) machine for any credentials/password cracking attempt.
Flags
Challenge:
Leverage a remote login and command-line execution application on a Linux target within the
10.10.55.0/24 subnet to access the sensitive file, StealthNet.txt. Retrieve the contents of the file and provide them as the answer. (Format: Aa*a**A**a)
Question 155
An organization implements multi-factor authentication (MFA) for remote VPN access. Which attack is MOST directly mitigated by this control when passwords are compromised?
