Question 1
Which tool would you use to obtain system information such as host name and uptime?
Correct Answer:
PsInfo
Explanation:
To quickly gather basic system details like the host name and how long the system has been running, PsInfo is the right choice. This Sysinternals tool is designed to query a machine and display essential system information, including the host name, uptime, OS version, and other details, either locally or on a remote computer. The other tools in the Ps family serve different purposes—PsLoggedOn shows who’s logged on, PsList lists processes, and PsShutdown handles shutdown/reboot actions—so they wouldn’t provide a straightforward view of host name and uptime.
Question 2
Which publication is a paid resource known for publishing industry reports?
Correct Answer:
The Wall Street Transcript
Explanation:
The Wall Street Transcript stands out because it operates on a subscription model and is known for delivering in-depth industry reports and analyses for investors. This publication curates and publishes detailed sector-focused reports that readers pay to access, making it a paid resource specifically dedicated to industry insights. MarketWatch provides market news and data, often free or with optional premium services, but it isn’t primarily a repository of targeted industry reports you subscribe to. LexisNexis is a paid research platform for legal, news, and business information, not a publication known for publishing standalone industry reports to subscribers. Business Wire distributes press releases, not in-depth industry reports published for subscribers. So the paid resource known for publishing industry reports is The Wall Street Transcript.
Question 3
Which command scans the target IP address for an open NFS port (2049) and the NFS services running on it?
Correct Answer:
rpcinfo
Explanation:
NFS runs over RPC, so to find an open NFS port and the services it provides you check the RPC service registry on the target. The tool that asks the registry (the portmapper) what RPC programs are registered, their versions, and which ports they listen on is ideally suited for this. By querying the target, you’ll see the NFS program (with its versions) and the port it’s using, which commonly appears as the NFS port 2049. This confirms both that NFS is available and exactly which port it’s on. Other options are focused on time synchronization or NTP-related tasks, not on discovering RPC-based services like NFS.
Question 4
Which technique can be used to determine if an IP or service is a threat source within a security framework?
Correct Answer:
Cisco IPS Source IP Reputation Filtering
Explanation:
Reputation-based filtering uses threat intelligence to classify IP addresses and other sources as known threats. In a security framework, evaluating whether an IP or service is a threat source lets the system block or limit traffic from that source before it reaches sensitive resources. Cisco IPS Source IP Reputation Filtering does this directly by consulting threat-intelligence feeds to mark certain source IPs as malicious or suspicious and enforce blocking or restrictions accordingly, reducing exposure from compromised hosts, botnets, or scanners. RFC 3704 Filtering is about preventing spoofed addresses by ensuring packets have believable source addresses, not about judging whether the source itself is harmful. Traffic Pattern Analysis examines how traffic behaves to spot anomalies, which helps detect potential threats but doesn’t inherently tag a source as a threat by reputation. Event Log Analysis involves reviewing logs to detect and investigate incidents after they occur, rather than proactively identifying threat sources at the entry point.
Question 5
Which technology detects runtime attacks and provides visibility into vulnerabilities in real-time apps?
Correct Answer:
Runtime Application Self Protection
Explanation:
Runtime Application Self-Protection is a security technology that sits inside the running application and watches its own execution in real time. It monitors data flows, code paths, and inputs as requests come in, applying security policies to detect suspicious activity that indicates an attack. When something malicious is detected, it can block or mitigate the attack immediately and provide detailed telemetry about what’s happening in the live app. This combination of real-time attack detection and visibility into the app’s vulnerabilities as it runs is what makes RASP the right choice for detecting runtime attacks in real-time applications. Other options are not designed to do this. A security misconfiguration refers to a type of vulnerability or risk, not a runtime protection mechanism. A web app security scanner like the N-Stalker is used to discover weaknesses by probing the app, not to protect and monitor it as it runs. BeEF focuses on browser exploitation and post-compromise activities, not on in-application runtime protection or real-time visibility.
Question 1
Exam overview

About this Exam

Prepare with the Certified Ethical Hacker Version 11 (CEHv11) Practice Test practice quiz. This question bank includes 10 questions covering tool, host, target, provides, and ethical. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Certified Ethical Hacker Version 11 (CEHv11) Practice Test

This practice set contains 10 questions from the matching question bank and focuses on tool, host, target, provides, and ethical. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions