Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

CEH v13 312-50v13 Passing Score

Page: 39 / 60
Total 797 questions

Certified Ethical Hacker Exam (CEHv13) Questions and Answers

Question 153

A healthcare technology company deploys internet-connected cardiac monitoring devices across several hospitals in Minneapolis, Minnesota. During a controlled security review, an analyst discovers that administrative configuration features can be accessed remotely through components that interact with external management platforms.

Further analysis reveals that these externally reachable components process user-supplied data without sufficient validation checks. Additionally, authentication controls protecting remote configuration features rely solely on basic credential verification without additional safeguards against automated misuse.

According to the OWASP Top 10 IoT Vulnerabilities, how should this weakness be classified?

Options:

A.

Insecure Ecosystem Interfaces

B.

Insecure Default Settings

C.

Insecure Network Services

D.

Lack of Device Management

Question 154

A penetration tester finds that a web application does not properly validate user input and is vulnerable to reflected Cross-Site Scripting (XSS). What is the most appropriate approach to exploit this vulnerability?

Options:

A.

Perform a brute-force attack on the user login form to steal credentials

B.

Embed a malicious script in a URL and trick a user into clicking the link

C.

Inject a SQL query into the search form to attempt SQL injection

D.

Use directory traversal to access sensitive files on the server

Question 155

A compromised admin account is used to disable logging services. What is the attacker attempting?

Options:

A.

Anti-forensics

B.

Exfiltration

C.

Recon

D.

Privilege escalation

Question 156

A penetration tester discovers that a web application uses unsanitized user input to dynamically generate file paths. The tester identifies that the application is vulnerable to Remote File Inclusion (RFI). Which action should the tester take to exploit this vulnerability?

Options:

A.

Inject a SQL query into the input field to perform SQL injection

B.

Use directory traversal to access sensitive system files on the server

C.

Provide a URL pointing to a remote malicious script to include it in the web application

D.

Upload a malicious shell to the server and execute commands remotely

Page: 39 / 60
Total 797 questions