
EC-CouncilCertified Ethical Hacker
Domain 4Objective 5
Evading IDS, Firewalls and Honeypots CEH Practice Questions (Page 6)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 26–30
- 26
Which defensive measure can help an IDS detect fragmented attacks that are designed to evade signature matching?
Select an answer first - 27
A security engineer is testing firewall rules. The firewall blocks all inbound traffic except for TCP port 53 (DNS) and TCP port 443 (HTTPS). The engineer needs to run a vulnerability scan against an internal host from the internet. Which technique is most likely to allow the scan traffic to pass through the firewall?
Select an answer first - 28
Which statement best describes the typical placement of a network-based intrusion detection system (NIDS) in a corporate network?
Select an answer first - 29
A penetration tester is assessing a network protected by a stateful inspection firewall and a signature-based IDS. The tester needs to send a series of exploit attempts to a target web server without the IDS matching any known attack signature. The tester controls the source IP and can fragment packets at the IP layer. Which approach is most likely to evade the signature-based IDS while still reaching the target?
Select an answer first - 30
Which type of honeypot provides a real operating system and applications, allowing an attacker to interact with a fully functional system, but at a higher risk of being compromised?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.