Free GAQM CPEH-001 Practice Test & Real Exam Questions

  • Exam Code/Number: CPEH-001
  • Exam Name/Title: GAQM Certified Professional Ethical Hacker (CPEH) Exam
  • Certification Provider: GAQM
  • Corresponding Certification: GAQM Information Systems Security
  • Exam Questions: 876
  • Updated On: Jul 27, 2026
You run nmap port Scan on 10.0.0.5 and attempt to gain banner/server information from services running on ports 21, 110 and 123. Here is the output of your scan results:

Which of the following nmap command did you run?
Correct Answer: D Vote an answer
Use the traceroute results shown above to answer the following
Question:

The perimeter security at targetcorp.com does not permit ICMP TTL-expired packets out.
Correct Answer: B Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
The follows is an email header. What address is that of the true originator of the message?
Correct Answer: E Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Which of the following programming languages is most vulnerable to buffer overflow attacks?
Correct Answer: D Vote an answer
Which of the following is NOT part of CEH Scanning Methodology?
Correct Answer: C Vote an answer
Which of the following is an example of two factor authentication?
Correct Answer: D Vote an answer
One of the better features of NetWare is the use of packet signature that includes cryptographic signatures. The packet signature mechanism has four levels from 0 to 3.
In the list below which of the choices represent the level that forces NetWare to sign all packets?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
In Trojan terminology, what is a covert channel?
Correct Answer: B Vote an answer
Take a look at the following attack on a Web Server using obstructed URL:
http://www.example.com/script.ext?template%2e%2e%2e%2e%2e%2f%2e%2f%65%74%63%2f%70%61%73%73%77%64
The request is made up of:
* %2e%2e%2f%2e%2e%2f%2e%2f% = ../../../
* %65%74%63 = etc
* %2f = /
* %70%61%73%73%77%64 = passwd
How would you protect information systems from these attacks?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Bret is a web application administrator and has just read that there are a number of surprisingly common web application vulnerabilities that can be exploited by unsophisticated attackers with easily available tools on the Internet. He has also read that when an organization deploys a web application, they invite the world to send HTTP requests. Attacks buried in these requests sail past firewalls, filters, platform hardening, SSL, and IDS without notice because they are inside legal HTTP requests. Bret is determined to weed out vulnerabilities. What are some of the common vulnerabilities in web applications that he should be concerned about?
Correct Answer: A Vote an answer
____________ will let you assume a users identity at a dynamically generated web page or site.
Correct Answer: A Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).