312-50 exam dumps

312-50 practice question 165 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 165

Single answer▪ Trojan Concepts

During an internal security assessment, you are asked to demonstrate how a Trojan could provide persistent remote access without relying on an inbound connection to the victim host. The target workstation is behind a stateful firewall and NAT device that block unsolicited inbound traffic, but users are allowed to browse the web over HTTP/HTTPS. Which Trojan communication method would be the most effective in this scenario?

  1. A

    Use a reverse-connecting Trojan that initiates an outbound session from the victim to the attacker's command-and-control server over an allowed port such as 443

  2. B

    Deploy a Trojan that waits for the attacker to initiate a direct inbound TCP connection to a listening port on the victim host

  3. C

    Use a Trojan that relies only on ARP spoofing to maintain long-term remote command execution across the Internet

  4. D

    Deploy a Trojan that communicates exclusively through broadcast NetBIOS name resolution so the attacker can control it remotely from any external network

Show answer and explanation

Correct answer: A

Explanation

This question tests understanding of a core Trojan concept: command-and-control design in real network environments. In practice, attackers commonly use reverse connections because enterprise networks frequently block unsolicited inbound traffic while allowing outbound HTTP/HTTPS. This is why reverse shells and callback Trojans are more effective than bind/listening Trojans on hosts behind NAT or stateful firewalls. From a defensive and ethical hacking perspective, understanding this behavior helps analysts detect suspicious outbound beaconing and unusual encrypted sessions to external systems. This aligns with standard network security behavior documented by major firewall and NAT vendors: inbound sessions are typically denied unless explicitly permitted, while outbound sessions are commonly allowed and tracked as established connections.

  • A. Correct.

    Correct. A reverse-connecting Trojan is designed to bypass common perimeter defenses such as NAT and stateful firewalls by having the compromised host initiate the outbound connection. Since outbound web traffic on ports like 80 or 443 is often permitted, this is a practical and realistic method for command-and-control in environments where unsolicited inbound connections are blocked.

  • B. Incorrect.

    Incorrect. A Trojan that passively listens for inbound connections is much less effective behind NAT and a stateful firewall because external hosts typically cannot directly reach an internal listening service unless port forwarding or a firewall rule has been configured. That is specifically the limitation described in the scenario.

  • C. Incorrect.

    Incorrect. ARP spoofing is a local network attack technique used for man-in-the-middle positioning within the same Layer 2 broadcast domain. It is not a command-and-control method for maintaining remote access across the Internet, and it does not solve the firewall/NAT traversal problem in the scenario.

  • D. Incorrect.

    Incorrect. NetBIOS name resolution and broadcast-based mechanisms are limited to local network segments and are not a viable Internet-scale remote control channel. In addition, broadcasts are not routed across the Internet, so this would not provide practical remote command-and-control from an external attacker.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam