DumpTOP의 CPEH-001 시험 대비 자료는 PDF, Desktop Test Engine, Online Test Engine 세 가지 형태로 제공됩니다. 학습 환경에 맞는 형태를 선택해 GAQM Certified Professional Ethical Hacker (CPEH) 준비를 바로 시작해 보시기 바랍니다.
GAQM CPEH-001 시험 개요:
| 인증 벤더: | GAQM |
|---|---|
| 시험명: | Certified Professional Ethical Hacker (CPEH) |
| 시험 번호: | CPEH-001 |
| 시험 시간: | 120분 |
| 응시료: | USD 190 (바우처) / USD 210 (e-book 포함 프리미엄 패키지) |
| 합격 점수: | 70% (100문항 중 70문항 정답) |
| 지원 언어: | 영어 |
| 시험 형식: | 객관식 문항, AI 감독 온라인 시험 |
| 관련 자격증: | Certified Information Security Professional (CISP) Certified Advanced Penetration Tester (CAPT) Certified Penetration Tester (CPT) |
| 실제 시험 문항 수: | 100 |
| 자격증 유효 기간: | 평생 |
| 샘플 문제: | GAQM CPEH-001 샘플 문제 |
| 응시 방법: | 바우처 코드를 통한 AI 감독 온라인 시험이며, 바우처당 2회의 응시 기회가 포함되어 있습니다. |
| 전제 조건: | 공식적인 선수 조건은 없습니다. 최선의 준비를 위해 GAQM e-코스를 수료하는 것을 권장합니다. |
| 공식 요강 URL: | https://gaqm.org/certifications/information_systems_security/cpeh |
GAQM CPEH-001 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| 주제 1: 포스트 익스플로잇 및 시스템 해킹 | - 공격 후 개념
|
| 주제 2: 사회공학 및 미래 위협 | - 인적 위협
|
| 주제 3: 고급 해킹 주제 | - 비밀번호 및 무선 해킹
|
| 주제 4: 에시컬 해킹 개론 | - 기초 개념
|
| 주제 5: 정찰 및 열거 | - 스캐닝 및 열거
|
| 주제 6: 웹 및 애플리케이션 해킹 | - 웹 보안
|
| 주제 7: 네트워크 및 익스플로잇 기술 | - 네트워크 공격
|
GAQM CPEH-001 응시 전 꼭 확인해야 할 질문들
CPEH-001 시험은 GAQM의 공식 인증 시험으로, 통과 시 GAQM Information Systems Security 자격을 취득하게 됩니다. 해당 인증은 Professional 등급에 해당합니다. Certified Penetration Tester (CPT), Certified Advanced Penetration Tester (CAPT), Certified Information Security Professional (CISP) 등 관련 인증과 함께 커리어를 넓혀 나가실 수 있습니다. 출제 범위와 평가 항목이 다양한 만큼, DumpTOP의 연습문제와 모의고사로 출제 유형에 미리 익숙해지시는 것이 좋습니다.
CPEH-001 시험의 총 문항 수는 100이며, 시험 시간은 120분입니다. 제한된 시간 안에 모든 문항을 풀어야 하므로, 한 문항에 오래 머무르기보다 전체 시간을 균등하게 배분하는 연습이 필요합니다. 막히는 문제는 표시해 두고 넘어간 뒤 나중에 다시 푸는 전략도 시간 압박을 줄이는 데 효과적입니다. DumpTOP의 테스트 엔진으로 실제 시험과 동일한 제한 시간 모의고사를 반복하시면 시간 배분 감각을 익히실 수 있어, 실제 시험에서 당황하지 않고 실력을 발휘하시는 데 도움이 됩니다.
CPEH-001 시험의 합격 기준 점수는 70% (100문항 중 70문항 정답)이며, 공식 응시료는 USD 190 (바우처) / USD 210 (e-book 포함 프리미엄 패키지)입니다. 불합격 시 재응시에는 응시료를 다시 전액 납부해야 하므로, 한 번의 응시로 최선의 결과를 내는 것이 비용과 시간을 아끼는 방법입니다. 시험 접수 전 DumpTOP의 모의고사로 실력을 점검하시고, 합격 기준을 안정적으로 넘는 수준에 도달했는지 먼저 확인해 보시기 바랍니다.
CPEH-001 시험의 응시 조건은 다음과 같습니다. 공식적인 선수 조건은 없습니다. 최선의 준비를 위해 GAQM e-코스를 수료하는 것을 권장합니다. 응시 조건은 변경될 수 있으므로, 접수 전 공식 안내 페이지에서 최신 내용을 반드시 확인해 보시기 바랍니다.
네, 가능합니다. DumpTOP은 CPEH-001 무료 샘플을 제공하고 있어, 실제 제품과 동일한 형식의 예시 문항을 직접 확인하신 후 구매를 결정하실 수 있습니다.
구매 후에는 365일 동안 무료 업데이트가 제공되어 최신 출제 경향을 반영한 자료를 계속 받아보실 수 있으며, 업데이트 기간이 만료된 이후에는 50% 할인된 가격으로 갱신하실 수 있습니다.
DumpTOP은 환불 보장을 제공합니다. 구매 후 60일 이내에 해당 시험에 응시하여 불합격한 경우 전액 환불을 신청하실 수 있으며, 응시 등록 확인서 사본과 공식 Score Report PDF를 시험 후 2일 이내에 제출해 주시면 접수 후 7일 이내에 처리됩니다. 단, 구매 후 3일 이내의 응시, 자료 다운로드 후 미응시, 무료 자료 및 만료된 주문은 적용 대상이 아니며, 수험자 이름과 결제자 이름이 동일해야 합니다.
환불을 원하지 않으시면 동일 금액 상당의 다른 시험 자료 두 개를 무료로 받으면서 기존에 구매하신 제품의 업데이트 서비스를 그대로 유지하는 방법도 선택하실 수 있습니다.
제품은 결제 후 1분 이내에 이메일로 즉시 발송되어 바로 다운로드하실 수 있으며, 2시간이 지나도 받지 못하신 경우 고객센터로 연락해 주시기 바랍니다. 설치 가능한 컴퓨터 대수에는 제한이 없습니다.
CPEH-001 시험은 총 7개의 출제 영역으로 구성되어 있습니다. 대표적인 영역으로는 정찰 및 열거, 사회공학 및 미래 위협, 고급 해킹 주제 등이 출제됩니다. 각 영역의 세부 항목과 전체 출제 범위는 위의 Exam Topics 목록에서 확인해 보시기 바랍니다.
최신 GAQM Information Systems Security CPEH-001 무료샘플문제
When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is
- A. OSSTMM is gray box testing and OWASP is black box testing.
- B. OWASP is for web applications and OSSTMM does not include web applications.
- C. OSSTMM addresses controls and OWASP does not.
- D. OWASP addresses controls and OSSTMM does not.
정답: C 🗳️
In the context of using PKI, when Sven wishes to send a secret message to Bob, he looks up Bob's public key in a directory, uses it to encrypt the message before sending it off. Bob then uses his private key to decrypt the message and reads it. No one listening on can decrypt the message. Anyone can send an encrypted message to Bob but only Bob can read it. Thus, although many people may know Bob's public key and use it to verify Bob's signature, they cannot discover Bob's private key and use it to forge digital signatures. What does this principle refer to?
- A. Symmetry
- B. Non-repudiation
- C. Irreversibility
- D. Asymmetry
정답: D 🗳️
설명: (DumpTOP 회원만 볼 수 있음)
Attacking well-known system defaults is one of the most common hacker attacks. Most software is shipped with a default configuration that makes it easy to install and setup the application. You should change the default settings to secure the system. Which of the following is NOT an example of default installation?
- A. Enabling firewall and anti-virus software on the local system
- B. Many systems come with default user accounts with well-known passwords that administrators forget to change
- C. Often, the default location of installation files can be exploited which allows a hacker to retrieve a file from the system
- D. Many software packages come with "samples" that can be exploited, such as the sample programs on IIS web services
정답: A 🗳️
Exhibit:
You are conducting pen-test against a company's website using SQL Injection techniques. You enter "anuthing or 1=1-" in the username filed of an authentication form. This is the output returned from the server. What is the next step you should do?
- A. Reboot the web server by running:
http://www.example.com/order/include_rsa.asp?pressReleaseID=5
AND xp_cmdshell 'iisreset -reboot'; -- - B. Identify the user context of the web application by running_
http://www.example.com/order/include_rsa_asp?pressReleaseID=5
AND
USER_NAME() = 'dbo' - C. Format the C: drive and delete the database by running:
http://www.example.com/order/include_rsa.asp?pressReleaseID=5 AND
xp_cmdshell 'format c: /q /yes '; drop database myDB; -- - D. Identify the database and table name by running:
http://www.example.com/order/include_rsa.asp?pressReleaseID=5
AND
ascii(lower(substring((SELECT TOP 1 name FROM sysobjects WHERE
xtype='U'), 1))) > 109
정답: B 🗳️
434 고객 리뷰



