GAQM CPEH-001 Answers

Page:    1 / 177   
Total 881 questions | Updated On: Nov 07, 2025
Question 1

Consider the following code:
URL:http://www.certified.com/search.pl?
text=<script>alert([removed])</script>
If an attacker can trick a victim user to click a link like this, and the Web application does not validate input, then the victim's browser will pop up an alert showing the users current set of cookies. An attacker can do much more damage, including stealing passwords, resetting your home page, or redirecting the user to another Web site. What is the countermeasure against XSS scripting?


Answer: B
Question 2

Carl has successfully compromised a web server from behind a firewall by exploiting a vulnerability in the web server program. He wants to proceed by installing a backdoor program. However, he is aware that not all inbound ports on the firewall are in the open state.From the list given below, identify the port that is most likely to be open and allowed to reach the server that Carl has just compromised.


Answer: A
Question 3

Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?


Answer: A
Question 4

Which NMAPfeature can a tester implement or adjust while scanning for open ports to avoid detection by the network's IDS?


Answer: A
Question 5

Symmetric encryption algorithms are known to be fast but present great challenges on the key management side. Asymmetric encryption algorithms are slow but allow communication with a remote host without having to transfer a key out of band or in person. If we combine the strength of both crypto systems where we use the symmetric algorithm to encrypt the bulk of the data and then use the asymmetric encryption system to encrypt the symmetric key, what would this type of usage be known as?


Answer: C
Page:    1 / 177   
Total 881 questions | Updated On: Nov 07, 2025

Quickly grab our CPEH-001 product now and kickstart your exam preparation today!

Name: Certified Professional Ethical Hacker (CPEH)
Exam Code: CPEH-001
Certification: Information Systems Security
Vendor: GAQM
Total Questions: 881
Last Updated: Nov 07, 2025