한 번의 불합격은 재응시 비용과 시간 손실로 이어집니다. DumpTOP의 CEH-001 모의고사로 실전처럼 미리 연습하시면 GAQM Certified Ethical Hacker (CEH) 시험을 보다 체계적으로 준비하실 수 있습니다.
GAQM CEH-001 시험 개요:
| 인증 벤더: | GAQM (Global Association for Quality Management) |
|---|---|
| 시험명: | 공인 윤리적 해커 (CEH v11) |
| 시험 번호: | CEH-001 |
| 응시료: | $500–$700 USD |
| 지원 언어: | Korean, English, Simplified Chinese, Japanese |
| 자격증 유효 기간: | 3년 |
| 시험 시간: | 180–240 |
| 합격 점수: | 70% |
| 시험 형식: | 객관식 문제 |
| 실제 시험 문항 수: | 125 |
| 권장 교육: | GAQM 권장 교육 과정 |
| 시험 등록: | GAQM 공식 등록 절차 |
| 샘플 문제: | GAQM CEH-001 샘플 문제 |
| 응시 방법: | GAQM ProctorNow를 통한 온라인 감독 시험 / 공인 시험 센터에서의 현장 시험 |
| 전제 조건: | 필수 응시 자격 요건은 없음; 권장 배경 지식: 기초 네트워크, 운영체제 및 사이버 보안 관련 지식 |
| 공식 요강 URL: | https://www.gaqm.org/certification/ceh-certified-ethical-hacker/ |
GAQM CEH-001 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| 윤리적 해킹 개요 | 5% | - 윤리적 해킹 방법론 - 침투 테스트 절차 - 정보 보안 통제 및 관련 법규 |
| IDS, 방화벽 및 허니팟 우회 | 5% | - 방화벽 및 IDS 구조 - 탐지 및 예방 방안 - 우회 기법 |
| 웹 서버 및 애플리케이션 해킹 | 12% | - 웹 서버 취약점 - OWASP Top 10 주요 위험 요소 - SQL 삽입, XSS, CSRF 공격 |
| 패킷 스니핑 | 5% | - 패킷 스니핑의 기본 개념 - 유선 및 무선 네트워크 스니핑 기법 - 스니핑 공격에 대한 대응 방안 |
| 정보 수집 및 정찰 | 12% | - 정보 수집 기법 - DNS, WHOIS 및 네트워크 정찰 - 정찰 도구 및 대응 방안 |
| 악성코드 위협 | 6% | - 악성코드 탐지 및 방어 기법 - 악성코드 분석 기초 - 바이러스, 웜, 트로이 목마, 랜섬웨어 |
| 서비스 거부 공격 | 4% | - 공격 도구 및 실행 방법 - 피해 완화 및 대응 전략 - DoS/DDoS 공격 유형 |
| 세션 하이재킹 | 4% | - 애플리케이션 계층 공격 - 세션 하이재킹 기법 - 대응 방안 |
| 네트워크 스캐닝 | 12% | - 운영체제 식별 및 서비스 탐지 - 포트 스캐닝 및 호스트 탐지 - 방화벽/IDS 우회 기법 |
| 시스템 해킹 | 10% | - 흔적 은닉 및 지속적인 접근 확보 - 암호 크래킹 기법 - 권한 상승 |
| 클라우드, IoT 및 암호 기술 | 5% | - 암호화 및 암호 분석 - IoT/OT 공격 경로 - 클라우드 보안 이슈 |
| 무선 네트워크 및 모바일 기기 해킹 | 6% | - Wi-Fi 보안 취약점 - 모바일 플랫폼 취약점 - 방어 대책 |
| 사회 공학 기법 | 6% | - 피싱 및 신분 사칭 공격 - 사회 공학 공격에 대한 방어 방안 - 인적 요인 기반 및 기술 기반 공격 |
| 취약점 분석 | 8% | - 취약점 스캐닝 도구 - 취약점 평가의 기본 개념 - 위험 평가 및 보고서 작성 |
| 열거 기법 | 10% | - 열거 공격에 대한 대응 방안 - 네트워크 자원 정보 열거 - NetBIOS, SNMP, LDAP 정보 열거 |
CEH-001 시험 관련 궁금증을 해결해 드립니다
CEH-001 시험은 GAQM의 공식 인증 시험으로, 통과 시 공인 윤리적 해커 (CEH) 자격을 취득하게 됩니다. 해당 인증은 전문가 수준 등급에 해당합니다. 출제 범위와 평가 항목이 다양한 만큼, DumpTOP의 연습문제와 모의고사로 출제 유형에 미리 익숙해지시는 것이 좋습니다.
CEH-001 시험의 총 문항 수는 125이며, 시험 시간은 180–240입니다. 제한된 시간 안에 모든 문항을 풀어야 하므로, 한 문항에 오래 머무르기보다 전체 시간을 균등하게 배분하는 연습이 필요합니다. 막히는 문제는 표시해 두고 넘어간 뒤 나중에 다시 푸는 전략도 시간 압박을 줄이는 데 효과적입니다. DumpTOP의 테스트 엔진으로 실제 시험과 동일한 제한 시간 모의고사를 반복하시면 시간 배분 감각을 익히실 수 있어, 실제 시험에서 당황하지 않고 실력을 발휘하시는 데 도움이 됩니다.
CEH-001 시험의 합격 기준 점수는 70%이며, 공식 응시료는 $500–$700 USD입니다. 불합격 시 재응시에는 응시료를 다시 전액 납부해야 하므로, 한 번의 응시로 최선의 결과를 내는 것이 비용과 시간을 아끼는 방법입니다. 시험 접수 전 DumpTOP의 모의고사로 실력을 점검하시고, 합격 기준을 안정적으로 넘는 수준에 도달했는지 먼저 확인해 보시기 바랍니다.
CEH-001 시험의 응시 조건은 다음과 같습니다. 필수 응시 자격 요건은 없음; 권장 배경 지식: 기초 네트워크, 운영체제 및 사이버 보안 관련 지식 응시 조건은 변경될 수 있으므로, 접수 전 공식 안내 페이지에서 최신 내용을 반드시 확인해 보시기 바랍니다.
CEH-001 시험은 아래 공식 채널을 통해 접수하실 수 있습니다.
시험 방식은 GAQM ProctorNow를 통한 온라인 감독 시험 / 공인 시험 센터에서의 현장 시험입니다. 접수 전 응시 일정과 시험장 또는 온라인 응시 여부를 함께 확인해 보시기 바랍니다.
GAQM에서는 CEH-001 시험 준비를 위한 공식 추천 교육 과정을 안내하고 있습니다.
공식 교육 과정으로 이론을 다지신 뒤, DumpTOP의 878 문항 연습문제로 실전 감각을 익혀 보시기 바랍니다.
네, 가능합니다. DumpTOP은 CEH-001 무료 샘플을 제공하고 있어, 실제 제품과 동일한 형식의 예시 문항을 직접 확인하신 후 구매를 결정하실 수 있습니다.
구매 후에는 365일 동안 무료 업데이트가 제공되어 최신 출제 경향을 반영한 자료를 계속 받아보실 수 있으며, 업데이트 기간이 만료된 이후에는 50% 할인된 가격으로 갱신하실 수 있습니다.
DumpTOP은 환불 보장을 제공합니다. 구매 후 60일 이내에 해당 시험에 응시하여 불합격한 경우 전액 환불을 신청하실 수 있으며, 응시 등록 확인서 사본과 공식 Score Report PDF를 시험 후 2일 이내에 제출해 주시면 접수 후 7일 이내에 처리됩니다. 단, 구매 후 3일 이내의 응시, 자료 다운로드 후 미응시, 무료 자료 및 만료된 주문은 적용 대상이 아니며, 수험자 이름과 결제자 이름이 동일해야 합니다.
환불을 원하지 않으시면 동일 금액 상당의 다른 시험 자료 두 개를 무료로 받으면서 기존에 구매하신 제품의 업데이트 서비스를 그대로 유지하는 방법도 선택하실 수 있습니다.
제품은 결제 후 1분 이내에 이메일로 즉시 발송되어 바로 다운로드하실 수 있으며, 2시간이 지나도 받지 못하신 경우 고객센터로 연락해 주시기 바랍니다. 설치 가능한 컴퓨터 대수에는 제한이 없습니다.
CEH-001 시험은 총 15개의 출제 영역으로 구성되어 있습니다. 대표적인 영역으로는 클라우드, IoT 및 암호 기술(5%), 네트워크 스캐닝(12%), IDS, 방화벽 및 허니팟 우회(5%) 등이 출제됩니다. 각 영역의 세부 항목과 전체 출제 범위는 위의 Exam Topics 목록에서 확인해 보시기 바랍니다.
최신 GAQM certification CEH-001 무료샘플문제
문제 #1
You receive an e-mail with the following text message.
"Microsoft and HP today warned all customers that a new, highly dangerous virus has been discovered which will erase all your files at midnight. If there's a file called hidserv.exe on your computer, you have been infected and your computer is now running a hidden server that allows hackers to access your computer. Delete the file immediately. Please also pass this message to all your friends and colleagues as soon as possible."
You launch your antivirus software and scan the suspicious looking file hidserv.exe located in c:\windows directory and the AV comes out clean meaning the file is not infected. You view the file signature and confirm that it is a legitimate Windows system file "Human Interface Device Service".
What category of virus is this?
A. Polymorphic Virus
B. Virus hoax
C. Spooky Virus
D. Stealth Virus
문제 #2
Bank of Timbuktu is a medium-sized, regional financial institution in Timbuktu. The bank has deployed a new Internet-accessible Web application recently. Customers can access their account balances, transfer money between accounts, pay bills and conduct online financial business using a Web browser.
John Stevens is in charge of information security at Bank of Timbuktu. After one month in production, several customers have complained about the Internet enabled banking application. Strangely, the account balances of many of the bank's customers had been changed! However, money hasn't been removed from the bank; instead, money was transferred between accounts. Given this attack profile, John Stevens reviewed the Web application's logs and found the following entries:
What kind of attack did the Hacker attempt to carry out at the bank?
A. Brute force attack in which the Hacker attempted guessing login ID and password from password cracking tools.
B. The Hacker attempted Session hijacking, in which the Hacker opened an account with the bank, then logged in to receive a session ID, guessed the next ID and took over Jason's session.
C. The Hacker first attempted logins with suspected user names, then used SQL Injection to gain access to valid bank login IDs.
D. The Hacker used a generator module to pass results to the Web server and exploited Web application CGI vulnerability.
문제 #3
A Trojan horse is a destructive program that masquerades as a benign application. The software initially appears to perform a desirable function for the user prior to installation and/or execution, but in addition to the expected function steals information or harms the system.
The challenge for an attacker is to send a convincing file attachment to the victim, which gets easily executed on the victim machine without raising any suspicion. Today's end users are quite knowledgeable about malwares and viruses. Instead of sending games and fun executables, Hackers today are quite successful in spreading the Trojans using Rogue security software.
What is Rogue security software?
A. A Fake AV program that claims to rid a computer of malware, but instead installs spyware or other malware onto the computer. This kind of software is known as rogue security software.
B. Rogue security software is based on social engineering technique in which the attackers lures victim to visit spear phishing websites
C. A flash file extension to Firefox that gets automatically installed when a victim visits rogue software disabling websites
D. This software disables firewalls and establishes reverse connecting tunnel between the victim's machine and that of the attacker
문제 #4
Your company has blocked all the ports via external firewall and only allows port 80/443 to connect to the Internet. You want to use FTP to connect to some remote server on the Internet. How would you accomplish this?
A. Use HTTP Tunneling
B. Use TOR Network
C. Use Proxy Chaining
D. Use Reverse Chaining
문제 #5
Samantha was hired to perform an internal security test of XYZ. She quickly realized that
all networks are making use of switches instead of traditional hubs. This greatly limits her ability to gather information through network sniffing.
Which of the following techniques can she use to gather information from the switched network or to disable some of the traffic isolation features of the switch? (Choose two)
A. Sniffing in promiscuous mode
B. ARP Spoofing
C. MAC Flooding
D. Ethernet Zapping
질문과 대답:
| 문제 #1 정답: B | 문제 #2 정답: C | 문제 #3 정답: A | 문제 #4 정답: A | 문제 #5 정답: B,C |
485 고객 리뷰



