Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 4Objective 5

Evading IDS, Firewalls and Honeypots CEH Practice Questions (Page 7)

Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
9concepts

Questions 31–35

  1. 31application · medium

    A red team is testing the effectiveness of the organization's network defenses. They need to send a series of exploit attempts to a target server while avoiding detection by the signature-based IDS. They also want to test whether the firewall allows certain types of traffic. Which tool is specifically designed to fragment packets and modify packet headers to evade IDS and firewall rules?

    Select an answer first
  2. 32application · medium

    A company's security team has noticed that attackers are using fragmented packets to evade their signature-based IDS. The IDS is placed inline and can be reconfigured. Which countermeasure is most effective at preventing this evasion technique?

    Select an answer first
  3. 33expert · hard

    A red team is testing the organization's network defenses. They need to evade both a signature-based IDS and a stateful firewall. The IDS is placed inline and can reassemble fragments. The firewall allows inbound TCP on port 443 only. Which combination of tools and techniques is most likely to succeed?

    Select an answer first
  4. 34application · medium

    A company's firewall is configured to allow inbound TCP port 443 to a web server. An attacker is attempting to bypass the firewall by sending traffic that appears to be HTTPS but is actually a covert channel. Which firewall architecture would be most effective at blocking this type of evasion?

    Select an answer first
  5. 35foundation · easy

    A firewall creates a table that tracks the state of active connections, including the source and destination IP addresses, ports, and sequence numbers. Which firewall architecture does this describe?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.