
EC-CouncilCertified Ethical Hacker
Domain 3Objective 2
Password Cracking and Attacks CEH Practice Questions (Page 8)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
A company's authentication database was breached, and the attacker obtained the password hashes. The hashes are unsalted and use a fast hashing algorithm. The company wants to prevent attackers from using precomputed tables to crack the hashes in the future. Which mitigation is most effective?
Select an answer first - 37
A network administrator discovers that several network switches are still using the default administrative password. The administrator wants to remediate this vulnerability quickly across all switches. Which action is the most effective first step?
Select an answer first - 38
A network administrator discovers that several employees use the same default password 'Welcome123' for their domain accounts. Which combination of actions best mitigates the risk posed by this weak-password usage?
Select an answer first - 39
Which scenario best describes an online password attack?
Select an answer first - 40
A system administrator discovers that the company's legacy application stores passwords as unsalted SHA-1 hashes. The admin wants to migrate to a more secure scheme without forcing all users to reset passwords immediately. Which approach is the most practical?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.