312-50v13 Exam Question 21

An AWS security operations team receives an alert regarding abnormal outbound traffic from an EC2 instance. The instance begins transmitting encrypted data packets to an external domain that resolves to a Dropbox account not associated with the organization. Further analysis reveals that a malicious executable silently modified the Dropbox sync configuration to use the attacker ' s access token, allowing automatic synchronization of internal files to the attacker's cloud storage. What type of attack has likely occurred?
  • 312-50v13 Exam Question 22

    A network administrator reviews logs and observes that an attacker sends packets requesting the target system' s internal clock value. The response includes timing information that can be used to calculate round-trip delay and analyze host characteristics.
    What host discovery technique is being used in this scenario?
  • 312-50v13 Exam Question 23

    During an external security review of a manufacturing firm in Detroit, Michigan, you ' re asked to prioritize patch baselines for internet-facing servers without logging in or establishing full sessions. To achieve this, you analyze network-level responses and capture application output in order to determine the underlying system and its software release. Which technique best fits this objective?
  • 312-50v13 Exam Question 24

    During an authorized engagement at IronClad Financial Services in Charlotte, the red team successfully exploits a weakness and obtains administrative access to a critical server. After achieving this objective, the team installs a backdoor mechanism to ensure continued access even if the original vulnerability is remediated. The team documents this activity as part of demonstrating long-term adversary behavior within the approved scope.
    Within the CEH ethical hacking framework, which phase does this activity represent?
  • 312-50v13 Exam Question 25

    A mid-sized manufacturing firm in Des Moines, Iowa reported that several employee workstations were periodically communicating with an unfamiliar external server over an IRC channel. The affected systems showed no visible interface for remote control, yet investigators confirmed that the machines were receiving instructions and executing distributed traffic bursts at scheduled intervals.
    Further review revealed that the initial infection occurred after employees opened a phishing email attachment. Once executed, the infected systems silently connected outward and began awaiting commands from a centralized remote controller.
    Determine the Trojan classification that best matches this behavior.