GAQM CPEH-001 Answers

Page:    1 / 177   
Total 881 questions | Updated On: Jul 14, 2026
Question 1

Jim's organization has just completed a major Linux roll out and now all of the organization's systems are running the Linux 2.5 kernel. The roll out expenses has posed constraints on purchasing other essential security equipment and software. The organization requires an option to control network traffic and also perform stateful inspection of traffic going into and out of the DMZ. Which built-in functionality of Linux can achieve this?


Answer: A
Question 2

Consider the following code:
URL:http://www.certified.com/search.pl?
text=<script>alert([removed])</script>
If an attacker can trick a victim user to click a link like this, and the Web application does not validate input, then the victim's browser will pop up an alert showing the users current set of cookies. An attacker can do much more damage, including stealing passwords, resetting your home page, or redirecting the user to another Web site. What is the countermeasure against XSS scripting?


Answer: B
Question 3

Symmetric encryption algorithms are known to be fast but present great challenges on the key management side. Asymmetric encryption algorithms are slow but allow communication with a remote host without having to transfer a key out of band or in person. If we combine the strength of both crypto systems where we use the symmetric algorithm to encrypt the bulk of the data and then use the asymmetric encryption system to encrypt the symmetric key, what would this type of usage be known as?


Answer: C
Question 4

A covert channel is a channel that


Answer: A
Question 5

Shayla is an IT security consultant, specializing in social engineering and external penetration tests. Shayla has been hired on by Treks Avionics, a subcontractor for the Department of Defense. Shayla has been given authority to perform any and all tests necessary to audit the company's network security. No employees for the company, other than the IT director, know about Shayla's work she will be doing. Shayla's first step is to obtain a list of employees through company website contact pages. Then she befriends a female employee of the company through an online chat website. After meeting with the female employee numerous times, Shayla is able to gain her trust and they become friends. One day, Shayla steals the employee's access badge and uses it to gain unauthorized access to the Treks Avionics offices. What type of insider threat would Shayla be considered?


Answer: A
Page:    1 / 177   
Total 881 questions | Updated On: Jul 14, 2026

Quickly grab our CPEH-001 product now and kickstart your exam preparation today!

Name: Certified Professional Ethical Hacker (CPEH)
Exam Code: CPEH-001
Certification: Information Systems Security
Vendor: GAQM
Total Questions: 881
Last Updated: Jul 14, 2026