
EC-CouncilCertified Ethical Hacker
Domain 9Objective 3
Cryptanalysis and Attacks CEH Practice Questions (Page 9)
Part of the Cryptography domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
16concepts
Questions 41–45
- 41
A password hash database has been exfiltrated from a company. The hashes are unsalted MD5. The security team wants to quickly identify which users have weak passwords. Which attack would be most efficient for this purpose?
Select an answer first - 42
A penetration tester is using a tool to crack password hashes obtained from a Windows system. The hashes are NTLM hashes, and the tester has a wordlist of common passwords. The tester also wants to apply rule-based transformations to the wordlist (e.g., appending numbers, capitalizing). Which tool is most appropriate for this task?
Select an answer first - 43
A software developer is using a hash function to verify file integrity. The security team warns that the hash function is vulnerable to a birthday attack. What is the primary risk associated with this vulnerability?
Select an answer first - 44
How can an attacker use a known plaintext-ciphertext pair?
Select an answer first - 45
Which countermeasure is most effective at defeating rainbow table attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.