CEH v13 Domain 9.1 Practice Test 004

This practice test covers Domain 9 (Cryptography) Subdomain 1 (Cryptography) from the CEH v13 (312-50v13) exam blueprint (v5).

These questions are inspired by the EC-Council CEH exam and are designed to help you test your knowledge of ethical hacking tools, techniques, and methodologies. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CEH exam.

Note: CEH and Certified Ethical Hacker are registered trademarks of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CEH practice tests based on specific domains and subdomains, click that link

CEH v13 Domain 9.1 Practice Test 004
10 questions • 8 single-answer, 2 multi-select
Question 1
Elijah, a security engineer, must select a symmetric block cipher operating on 128-bit blocks that supports 128, 192, and 256-bit keys for an enterprise VPN. He needs the NIST-approved standard that replaced the aging Data Encryption Standard. Which algorithm should he choose?
    Question 2
    Jane, a PKI administrator, configures the trusted entity that issues, digitally signs, and revokes certificates within an enterprise hierarchy. She must name the authority that ultimately binds a verified identity to its public key. Which entity is described?
      Question 3
      A penetration tester captures a fixed-length digest produced from a password file and must identify the one-way function used. The algorithm belongs to the SHA-2 family and outputs a 32-byte hash widely used for integrity verification. Which hashing algorithm produced it?
        Question 4
        Kevin intercepts both a plaintext message and its corresponding ciphertext, then uses these pairs to deduce the secret key of a cipher. He recognizes this method as a specific class of cryptanalytic attack. Which attack is he performing?
          Question 5
          A security team must deploy full-disk encryption on Windows enterprise laptops to protect data at rest by integrating with the TPM chip. They want the native Microsoft solution rather than a third-party product. Which tool meets the requirement?
            Question 6
            Select all that apply
            Elena, a security architect, reviews her organization's cryptographic deployment to defend against key-recovery and downgrade attacks. She compiles a list of recommended hardening measures for the encryption stack. Which of the following are valid countermeasures? (Select all that apply)
              Question 7
              Robert needs to send a signed and encrypted email using a standard that relies on X.509 certificates and is built into most enterprise mail clients. He compares it against PGP-based alternatives before deciding. Which standard relies on X.509 certificates for this purpose?
                Question 8
                A developer must implement an asymmetric algorithm whose security rests on the difficulty of factoring the product of two large prime numbers. The keys are used for both encryption and digital signatures. Which algorithm is based on this hard problem?
                  Question 9
                  Marcus discovers that two distinct input files produce the identical hash value, undermining the integrity guarantee of the algorithm. He recognizes this as the exploitation of a specific hash weakness. What is this condition called?
                    Question 10
                    Select all that apply
                    Nadia, a penetration tester, assembles a toolkit to perform password hash cracking and cryptanalysis during an engagement. She selects tools designed specifically to recover plaintext from captured hashes. Which of the following are cryptographic cracking tools? (Choose two)

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top