GAQM CPEH-001 Exam
Certified Professional Ethical Hacker (CPEH) Exam (Page 7 )

Updated On: 1-Feb-2026

What ports should be blocked on the firewall to prevent NetBIOS traffic from not coming through the firewall if your network is comprised of Windows NT, 2000, and XP?(Choose all that apply.

  1. 110
  2. 135
  3. 139
  4. 161
  5. 445
  6. 1024

Answer(s): B,C,E

Explanation:

NetBIOS traffic can quickly be used to enumerate and attack Windows computers. Ports 135, 139, and 445 should be blocked.



While reviewing the result of scanning run against a target network you come across the following:



Which among the following can be used to get this output?

  1. A Bo2k system query.
  2. nmap protocol scan
  3. A sniffer
  4. An SNMP walk

Answer(s): D

Explanation:

SNMP lets you "read" information from a device. You make a query of the server (generally known as the "agent"). The agent gathers the information from the host system and returns the answer to your SNMP client. It's like having a single interface for all your informative Unix commands. Output like system.sysContact.0 is called a MIB.



Name two software tools used for OS guessing? (Choose two.

  1. Nmap
  2. Snadboy
  3. Queso
  4. UserInfo
  5. NetBus

Answer(s): A,C

Explanation:

Nmap and Queso are the two best-known OS guessing programs. OS guessing software has the ability to look at peculiarities in the way that each vendor implements the RFC's. These differences are compared with its database of known OS fingerprints. Then a best guess of the OS is provided to the user.



What port scanning method is the most reliable but also the most detectable?

  1. Null Scanning
  2. Connect Scanning
  3. ICMP Scanning
  4. Idlescan Scanning
  5. Half Scanning
  6. Verbose Scanning

Answer(s): B

Explanation:

A TCP Connect scan, named after the Unix connect() system call is the most accurate scanning method. If a port is open the operating system completes the TCP three-way handshake, and the port scanner immediately closes the connection.



What does an ICMP (Code 13) message normally indicates?

  1. It indicates that the destination host is unreachable
  2. It indicates to the host that the datagram which triggered the source quench message will need to be re-sent
  3. It indicates that the packet has been administratively dropped in transit
  4. It is a request to the host to cut back the rate at which it is sending traffic to the Internet destination

Answer(s): C

Explanation:

CODE 13 and type 3 is destination unreachable due to communication administratively prohibited by filtering hence maybe they meant "code 13", therefore would be C).
Note:
A - Type 3
B - Type 4
C - Type 3 Code 13
D - Typ4 4



Viewing page 7 of 177
Viewing questions 31 - 35 out of 878 questions



Post your Comments and Discuss GAQM CPEH-001 exam prep with other Community members:

Join the CPEH-001 Discussion