Browse all practice questions for the EC-Council Certified Ethical Hacker (CEH) Certification Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

EC-Council Certified Ethical Hacker (CEH) Certification Practice Exam course image
All questions

These questions are part of the practice quiz. Start practicing

  • Mary is using asymmetric cryptography to send a message to Sam so that only Sam can read it. Which key should she use to encrypt the message?
  • Which short-range wireless personal area network supports low-power, long-use IoT needs?
  • What does malware provide to the attacker on a compromised device?
  • In vulnerability assessment, which phase focuses on identifying externally visible services on a target with limited information?
  • Which of the following describes a honeypot's purpose?
  • What term describes the process of sniffing traffic between a user and server, then redirecting the traffic to the attacker's machine, where malicious traffic can be forwarded to the user or server?
  • Which IoT security challenge is Joelle trying to overcome by requiring strong user passwords and two-factor authentication?
  • A person discovers a vulnerability on a system without permission, anonymously alerts the owner, and instructs how to secure it. What type of hacker is this?
  • Which of the following is a sign of a network-based intrusion?
  • Which law will help him protect his work on YouTube?
  • A cloud vendor added cloud services for new employees after acquisition without hardware changes. Which cloud concept does this illustrate?
  • Which utility is commonly used to clear temporary files and browser history during a system cleanse?
  • Which cryptographic algorithm is used in asymmetric encryption?
  • What countermeasure is described for mitigating a cross-site request forgery attack?
  • Active scanning is best described as?
  • What is the first place to check if you believe your system has been hacked?
  • An attacker conducts a normal port scan on a host and detects protocols used by Windows and Linux operating systems. Which of the following might this indicate?
  • Which honeypot interaction level is most realistic and hardest to compromise, best for observing attacker behavior?
  • Which tool is a smart fuzzer used to automatically deliver inputs and detect vulnerabilities such as buffer overflows?
  • Which malware hides inside legitimate software to trick users into installing it?
  • Which online tool is commonly used to gather information about servers and web servers, including hosting details and technologies?
  • Which IDS detection type compares current activity to baseline profiles or network behavior baselines?
  • Which cloud capability enables automatic scaling of resources to meet demand without manual intervention?
  • A proxy is used when your scanning attempts are blocked. Which of the following is a benefit?
  • Which Bluetooth tool is used to query a device’s Service Discovery Protocol (SDP) information?
  • During a review, sensitive company information was publicly accessible. Which policy was violated?
  • Which term describes social engineering that uses a fabricated scenario to obtain sensitive information?
  • Which type of threat actor uses hacking skills strictly for defensive purposes?
  • What term describes software or code that provides an attacker with ongoing, covert access to a system?
  • What is the primary purpose of deploying a honeypot in a network security environment?
  • Which term best describes registering a domain name that is very similar to a legitimate brand to mislead users?
  • Which command shows currently mounted filesystems on a Linux system?
  • During reconnaissance, which type of information is typically most helpful for identifying domain ownership, IP address ranges, and server details?
  • Which action best enhances security for a tablet used by staff to log events in a secure area?
  • Which of the following is a common indicator that a server supports the HTTP TRACE method, which could pose security concerns?
  • Which security role would most likely trigger an alert when suspicious executable files are present on a workstation?
  • Which program will allow Patrick to create a virus for distribution via email as part of a phishing test?
  • Which technique enables attackers to redirect users to a malicious website by corrupting the DNS cache?
  • What term describes the technique of embedding data within benign-looking files such as images and extracting it at the destination?
  • In IPsec, which component provides data integrity and authentication?
  • Which of the following best describes a stateful inspection?
  • Which of the following is the third step in the ethical hacking methodology?
  • Open-source and commercial tools are both recommended for vulnerability assessment.
  • For a honeypot detection tool capable of packet manipulation, which tool is appropriate?
  • Implementing emergency lighting that operates on protected power and activates automatically when main power fails is an example of which physical security objective?
  • Which Bluetooth hacking tool is a complete framework to perform man-in-the-middle attacks on Bluetooth smart devices?
  • An IDS alert shows a random user has administrative privileges, some files are missing, and other files appear. Which alert type is this?
  • Which social engineering activity is described as part of the penetration test?
  • In a captured data scenario, what is the account manager’s email address?
  • What are the two types of Intrusion Detection Systems (IDSs)?
  • In a merger penetration test scope, which item should be included?
  • Which describes Microsoft Internet Information Services (IIS) most accurately?
  • Which tool uses rainbow tables to crack Windows login passwords?
  • Which regulation focuses on corporate accounting and disclosure to increase transparency?
  • Which statement about worms is true?
  • Which assessment type focuses on all types of user risks, including threats from malicious users, ignorant users, vendors, and administrators?
  • Which of the following is true about spoofing methods ARP, DNS, IP?
  • P0f provides which type of information about a remote host?
  • Daphne has malware on a Linux machine. She prefers to only use open-source software. Which anti-malware software should she use?
  • Which type of assessment focuses on identifying vulnerabilities based on known exploit signatures or weaknesses in a system?
  • Which statement best captures the ongoing nature of security after a penetration test?
  • Which technique involves adding random bits of data to a password before it is stored as a hash?
  • An IDS can perform many types of intrusion detections. Three common detection methods are signature-based, anomaly-based, and protocol-based. Which of the following best describes protocol-based detection?
  • Which virus type is shown in a sample code where execution occurs under a specific condition?
  • In a smart home, a device that communicates directly with other devices without a central server demonstrates which communication model?
  • Which policy governs the use of printed marketing materials to share critical information?
  • In PKI, which action establishes trust within an internal network without relying on public CAs?
  • Which tool could a hacker use to create a backdoor on an unpatched system?
  • What type of scan is used to find system weaknesses such as open ports, access points, and other potential threats?
  • What is a self-signed SSL certificate?
  • Using Wireshark, with a host filter for 192.168.0.34, what packets are captured?
  • After penetration testing and hardening, what should you help the organization understand about threats?
  • Which category includes tools such as Whois, Nslookup, and ARIN?
  • Which password-cracking technique relies on precomputed hashes to speed up cracking attempts?
  • In Nmap, what does the -sV option do?
  • Which practice is used to identify exposed ports by actively sending requests?
  • In risk management, if the cost of addressing risk is greater than the potential damage, the typical risk posture is called what?
  • What describes a session ID?
  • What process does an organization perform to identify vulnerabilities in its network and security systems?
  • Blocking port 389 would primarily affect which directory service protocol?
  • Which statement about SSIDs is true?
  • Which term describes using a fictitious scenario to persuade someone to reveal information they are not authorized to share?
  • Heather used a program hidden inside a legitimate program to gain remote access. What type of malware is she using?
  • Which type of vulnerability research focuses on application flaws in software during security testing?
  • Which type of malware encrypts a victim's files and demands payment to restore access?
  • Which statement best describes the data capacity difference between proximity cards and smart cards?
  • Which of the following describes beSTORM?
  • Which statement correctly describes the difference between proximity cards and smart cards?
  • Which mobile security concern is characterized by malicious code that specifically targets mobile devices?
  • Which of the following are protocols included in the IPsec architecture?
  • What does the ACK evasion scan help determine?
  • Which statement about malware that propagates across a network without user action is true?
  • Mark, an ethical hacker, is looking for a honeypot tool that will simulate a mischievous protocol such as devil or mydoom.
  • Which type of assessment does an ethical hacker perform to expose weaknesses in a system?
  • An attacker may use compromised websites and emails to distribute specially designed malware to poorly secured devices. Which devices can the attacker use?
  • Which information sharing policy addresses the sharing of critical information in press releases, annual reports, product catalogs, and marketing materials?
  • Which embedded operating systems are most likely used by a smart car and its drone for control?
  • Which activity involves querying registries to determine domain ownership and contact information?
  • ARIN is responsible for IP address allocations in which region?
  • What is the primary use of Nslookup in network administration?
  • Blocking port 389 would primarily impact which directory service protocol?
  • A goal-based penetration test needs to have specific goals. Using SMART goals is extremely useful for this. What does SMART stand for?
  • Which statement best describes a suicide hacker?
  • Using Wireshark filtering, you want to see all traffic except IP address 192.168.142.3. Which of the following is the best command to filter a specific source IP address?
  • Which combination of metrics is used to determine a CVSS score?
  • Which type of penetration test is used to ensure compliance with federal laws and regulations?
  • In Wireshark, which display filter would exclude traffic from IP 192.168.142.3?
  • In NTFS, which feature can store additional data alongside a file that FAT cannot?
  • In Nmap, which option is used to retrieve service banners?
  • What is a typical goal of ransomware?
  • Which tool is commonly used as an intrusion detection system and can function as an intrusion prevention system?
  • Which tool is suitable for OS fingerprinting by analyzing network traffic?
  • Mark is moving files from a device that is formatted using NTFS to a device that is formatted using FAT. Which of the following is he trying to get rid of?
  • Which statement describes a session identifier used during client-server communication?
  • When establishing a PKI in a local network without a public CA, what is a typical step?
  • Which term describes adding random data to a password before hashing?
  • Which statement best describes the primary purpose of fuzz testing tools like beSTORM in ethical hacking?
  • Which firewall limitation makes it difficult to determine if a connection originated inside or outside the network?
  • Which Bluetooth discovery tool would produce output indicating Service Discovery Protocol (SDP) data?
  • In SNMP architecture, which component is responsible for collecting data from managed devices and presenting it to administrators?
  • Which option best describes the export-controls framework for cyber intrusion tools among many countries?
  • To launch a denial-of-service attack against a web server, which tool would you most likely use?
  • To perform a ping sweep of 172.125.68.1-255 with Nmap, which command would you use?
  • In packet analysis, what does filtering for a specific host typically accomplish?
  • In User-Mode Linux, which device represents the guest's virtual hard disk?
  • ARP, DNS, and IP are examples of which security concept?
  • Which term best describes publicly accessible information about a DNS zone that can be obtained via certain server configurations?
  • A penetration tester working for a hospital must comply with which federal regulation protecting patient health information?
  • Jerry runs a tool to scan a clean system to create a database. The tool then scans the system again and compares the second scan to the clean database. Which detection method is Jerry using?
  • Proximity (RFID) cards typically communicate at which frequency?
  • What security tool would you most likely use to detect hidden malware in websites and advertisements?
  • Which description best fits an anti-virus sensor system?
  • Which of the following are spoofing methods?
  • Which tool is commonly used on Linux for open-source malware scanning?
  • Which port and protocol are used for a DNS zone transfer?
  • When conducting a remote penetration test for a client in Utah from Florida, what is the recommended approach to legal compliance?
  • During malware analysis, a tester takes a system snapshot before and after running the malware and monitors ports, processes, and event logs for changes. Which security practice is this an example of?
  • Which tool is commonly used to inspect network traffic and can be deployed inline for protection?
  • In analyzing a DHCP-related interception, which observation would suggest a DHCP-based man-in-the-middle attack?
  • What port does LDAP use?
  • Which IDS type monitors network traffic across the network rather than focusing on a single host?
  • An IDS alert indicates an actual intrusion involving privilege escalation and file changes. What is this alert considered?
  • Which of the following best describes what SOX does?
  • Which tool is used to capture and inspect network packets during a pentest?
  • Which type of malware self-propagates without user interaction and spreads through a network?
  • In asymmetric cryptography, which key should be used to encrypt a message intended for the recipient?
  • What is the primary purpose of deploying a honeypot in a security program?
  • Which vulnerability assessment tool is designed to detect vulnerabilities on mobile devices and provide a report with a total risk score, vulnerability summary, and remediation suggestions?
  • Which of the following is an open-source web server technology?
  • Which item is included in the scope of work for a merger penetration test?
  • Diana performed a command during a pentest that indicates a DNS zone transfer. What does this indicate?
  • You have discovered that a hacker is trying to penetrate your network using MAC spoofing. Which description best describes MAC spoofing?
  • What is the correct Nmap command to run the nmap-vulners script with version detection on 10.10.10.195?
  • What is a common consequence of DNS cache poisoning?
  • Which of the following describes high-interaction honeypots?
  • Which escalation method involves loading a malicious DLL to be used by an application?
  • Which description best defines the Wassenaar Arrangement?
  • Which term describes registering a domain name that closely resembles a cloud provider to deceive users?
  • In OS fingerprinting, which attributes of a response are commonly analyzed to guess the target OS?
  • Nmap can be used for banner grabbing. Which of the following is the proper nmap command?
  • When configuring a wireless access point, which statement about the Host Name is most accurate?
  • Which of the following best describes what FISMA does?
  • Which best describes active scanning?
  • During a penetration test with limited information, what type of engagement is being performed if only the target's IP address and hostname are known?
  • Which of the following ports are used by null sessions on your network?
  • Which statement best describes a client-based web app?
  • Which of the following best describes a supply chain?
  • In User-Mode Linux, which option describes the virtual disk provided to the guest?
  • Which cloud service model primarily provides virtualized computing resources that the user can manage themselves?
  • The Simple Network Management Protocol (SNMP) is used to manage devices such as routers, hubs, and switches. SNMP works with an SNMP agent and an SNMP management station in which layer of the OSI model?
  • In wireless network configuration, which statement about SSIDs is true?
  • On a Windows system, an alert about a file named MyFile.txt.exe being found could indicate which security component?
  • Which footprinting method helps identify the ports and services a web server runs?
  • Creating an area of the network where offending traffic is forwarded and dropped is known as _________?
  • Which type of web application requires a separate application to be installed before you can use the app?
  • There are two non-government sites that provide lists of valuable information for ethical hackers. How is the Full Disclosure site best described?
  • Which honeypot interaction level is most realistic and hardest to fully compromise, making it suitable for observing attacker behavior?
  • During a black box penetration test, which tool is most helpful for gathering information about ownership, IP addresses, domain names, locations, and server types during recon?
  • Which utility is commonly used to remove files and clear internet browsing history?
  • Which term describes an ethical hacker who uses hacking skills for defensive purposes?
  • Which type of testing involves delivering malformed inputs to an application and observing its responses?
  • How can an attacker identify that a system is using User-Mode Linux (UML)?
  • Which tool would Allen most likely select to perform network intrusion prevention, intrusion detection, packet capture, and traffic monitoring?
  • Which item includes a list of resolved vulnerabilities?
  • In social engineering, Ron is considered to be in which phase when preparing approaches and pretexts to gain access?
  • What does a service banner typically reveal?
  • Which type of firewall is best suited to protect an internal network from the Internet?
  • In packet crafting for network testing, which program is commonly used to modify packet flags and adjust other packet content?
  • In cloud computing, which service model delivers software applications to a client over the Internet or a local area network?
  • Which tool should be used to scan for outdated Apple iOS versions on a network?
  • Which of the following is considered an out-of-band method for distributing a private key?
  • What term describes a deviation from standard operating security protocols?
  • Which description best fits a cybersquatting cloud computing attack?
  • Which term describes an attack intended to make a service unavailable by overwhelming a server?
  • Which statement best describes a rootkit?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy