Certified Ethical Hacker (CEH v13) — Questions and Answers
Question 1: What firewall type inspects traffic at Layer 7 and can identify and block specific applications regardless of port?
- Circuit-Level Gateway
- Next-Generation Firewall (NGFW) (Correct answer)
- Packet Filtering Firewall
- Stateful Inspection Firewall
Correct answer: Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) performs deep packet inspection at the application layer, enabling it to identify and control specific applications independent of port or protocol.
Question 2: What is the primary goal of the 'maintaining access' phase of the methodology?
- Map the network topology
- Erase log files
- Establish persistent access for return entry (Correct answer)
- Identify open ports
Correct answer: Establish persistent access for return entry
Maintaining access focuses on creating persistence such as backdoors so the attacker can return.
Question 3: What is a keylogger and how can it be detected?
- A password manager application
- A tool for logging into key management systems
- A type of keyboard with built-in logging
- Software or hardware that records keystrokes; detected through antimalware, process monitoring, and physical inspection (Correct answer)
Correct answer: Software or hardware that records keystrokes; detected through antimalware, process monitoring, and physical inspection
Keyloggers capture every keystroke typed on a system, either through software (running as a hidden process) or hardware (a device between the keyboard and computer), stealing passwords and sensitive data.
Question 4: How can telnet be used to fingerprint a web server?
- telnet webserverAddress 80 HEAD / HTTP/1.0 (Correct answer)
- telnet webserverAddress 80 HEAD / HTTP/2.0
- telnet webserverAddress 80 PUT / HTTP/2.0
- telnet webserverAddress 80 PUT / HTTP/1.0
Correct answer: telnet webserverAddress 80 HEAD / HTTP/1.0
Fingerprinting a web server involves identifying its software and version for reconnaissance. The `HEAD / HTTP/1.0` command sent via telnet to port 80 (standard HTTP port) requests only the header information of the web page. The server's response headers often reveal crucial details like the server type (e.g., Apache, Nginx, IIS) and its version, which is vital for ethical hacking assessments.
Question 5: Which practice most reduces risk from vulnerable third-party JavaScript libraries?
- Maintaining a software bill of materials and patching dependencies (Correct answer)
- Minifying code
- Adding more cookies
- Increasing timeout values
Correct answer: Maintaining a software bill of materials and patching dependencies
Tracking and updating dependencies addresses the Vulnerable and Outdated Components risk.
Question 6: What does a TCP SYN scan rely on to avoid completing the full handshake?
- Sending RST after SYN-ACK (Correct answer)
- Spoofing the MAC address
- Sending a FIN packet first
- Encrypting the payload
Correct answer: Sending RST after SYN-ACK
A SYN scan sends a RST after receiving SYN-ACK, never completing the three-way handshake (half-open scan).
Question 7: During a security audit of IT processes, an IS auditor found that there were no documented security procedures.<br> What should the IS auditor do?
- Conduct compliance testing
- Identify and evaluate existing practices (Correct answer)
- Terminate the audit
- Create a procedures document
Correct answer: Identify and evaluate existing practices
When documented procedures are absent during an audit, the IS auditor's primary responsibility is to understand the actual operational landscape. Identifying and evaluating existing, undocumented practices allows the auditor to assess the current state of security controls. This step is crucial for determining compliance, identifying gaps, and providing actionable recommendations for improvement and proper documentation.
Question 8: During OS fingerprinting, what value primarily helps distinguish operating systems?
- The DNS PTR record
- TCP/IP stack characteristics like TTL and window size (Correct answer)
- The hostname
- MAC address vendor only
Correct answer: TCP/IP stack characteristics like TTL and window size
Different OSes implement the TCP/IP stack with distinctive default TTL and window size values.
Question 9: What is fileless malware and why is it difficult to detect?
- Malware that only affects file servers
- Malware with no file size
- Malware that operates entirely in memory without writing files to disk, evading traditional file-based scanning (Correct answer)
- Malware that deletes all files on a system
Correct answer: Malware that operates entirely in memory without writing files to disk, evading traditional file-based scanning
Fileless malware executes entirely in RAM using legitimate system tools (PowerShell, WMI, macros), leaving no traditional file artifacts on disk, making it invisible to conventional antivirus that scans files.
Question 10: Which technique is used to exploit a vulnerability in a client application by luring a victim to visit a malicious webpage?
- Server-Side Exploitation
- Remote Code Execution
- Client-Side Exploitation (Correct answer)
- SQL Injection
Correct answer: Client-Side Exploitation
Client-side exploitation targets vulnerabilities in browsers, plugins, or document readers by tricking the user into visiting a malicious page or opening a malicious file.
Question 11: What WPS feature makes it vulnerable to brute-force attacks such as those performed by Reaver?
- The RADIUS server timeout
- The hidden SSID broadcast
- The 8-digit PIN validated in two halves (Correct answer)
- The 802.1X authenticator
Correct answer: The 8-digit PIN validated in two halves
WPS validates the PIN in two halves, drastically reducing the number of guesses needed to brute-force it.
Question 12: During privilege escalation on Linux, an attacker finds a SUID binary owned by root. What does exploiting it most directly grant?
- A reverse DNS record
- Persistent cron access only
- Network sniffing ability
- Execution with the file owner's (root) privileges (Correct answer)
Correct answer: Execution with the file owner's (root) privileges
A SUID binary runs with the privileges of its owner, so a root-owned SUID can yield root execution.
Question 13: What is ARP spoofing primarily used to achieve?
- Redirecting traffic to the attacker for a man-in-the-middle attack (Correct answer)
- Speeding up switching
- Assigning static IPs
- Encrypting LAN traffic
Correct answer: Redirecting traffic to the attacker for a man-in-the-middle attack
ARP spoofing associates the attacker's MAC with another host's IP to intercept traffic in a MITM attack.
Question 14: Which type of session hijacking intercepts a session between two parties without requiring prediction of a sequence number?
- UDP Hijacking
- Active Hijacking
- Passive Hijacking (Correct answer)
- Blind Hijacking
Correct answer: Passive Hijacking
Passive hijacking involves monitoring a session to capture sensitive data without actively injecting packets, avoiding detection by not disrupting the session.
Question 15: What is banner grabbing used for during the reconnaissance phase of a penetration test?
- Mapping all internal network subnets from a single host
- Downloading entire website content for offline analysis
- Capturing authentication tokens from active web sessions
- Identifying software names and versions running on open ports (Correct answer)
Correct answer: Identifying software names and versions running on open ports
Banner grabbing captures the service banners returned when connecting to open ports, revealing the software type, version, and sometimes OS information.
Question 16: Which Google search operator is used to search for specific file types hosted on a target website?
- inurl:
- intitle:
- filetype: (Correct answer)
- site:
Correct answer: filetype:
The 'filetype:' Google dork operator restricts results to specific file extensions (e.g., PDF, XLS, DOC) which may expose sensitive documents.
Question 17: What is tailgating (piggybacking) in physical security?
- Parking too close to a building
- Following an authorized person through a secured door without presenting credentials (Correct answer)
- Tracking someone's online activities
- Monitoring network traffic from behind a firewall
Correct answer: Following an authorized person through a secured door without presenting credentials
Tailgating is a physical social engineering technique where an unauthorized person follows closely behind an authorized individual through a secured entrance, bypassing access controls through social pressure or stealth.
Question 18: Which scanning technique uses banner grabbing to gather information?
- Connecting to a service to read its response header (Correct answer)
- Poisoning the ARP table
- Sending malformed ICMP packets
- Spoofing the source MAC
Correct answer: Connecting to a service to read its response header
Banner grabbing connects to a service (e.g., via Telnet or netcat) to read identifying header text.
Question 19: What is the primary security purpose of a 'clean desk policy'?
- Prevent sensitive documents and credentials from being exposed or stolen (Correct answer)
- Improve office aesthetics only
- Speed up network performance
- Reduce electricity usage
Correct answer: Prevent sensitive documents and credentials from being exposed or stolen
A clean desk policy reduces the risk of confidential information being viewed, photographed, or removed.
Question 20: Which Google dork operator restricts search results to pages that contain specific text within the HTML page title?
- site:
- filetype:
- intitle: (Correct answer)
- inurl:
Correct answer: intitle:
The 'intitle:' operator searches Google for pages containing the specified keyword within the HTML <title> tag, useful for finding specific types of exposed pages.
Question 21: What does the Nmap -sV flag accomplish?
- Runs a vulnerability exploit
- Performs a UDP scan
- Detects service and version information on open ports (Correct answer)
- Disables ping
Correct answer: Detects service and version information on open ports
The -sV flag probes open ports to determine the running service and its version.
Question 22: Which technique uses legitimate system tools already present on a host (like PowerShell or WMI) to avoid dropping detectable malware files?
- Living off the land (LOLBins) (Correct answer)
- Typosquatting
- Drive-by download
- Watering hole
Correct answer: Living off the land (LOLBins)
Living-off-the-land attacks abuse built-in trusted binaries to operate without dropping new files.
Question 23: In a black-box engagement, what does the tester start with?
- Little to no prior knowledge of the target (Correct answer)
- Administrative credentials
- Full source code access
- Complete network diagrams
Correct answer: Little to no prior knowledge of the target
Black-box testing simulates an outside attacker with no prior internal knowledge.
Question 24: What is the best defense against SQL injection?
- Using HTTP instead of HTTPS
- Longer passwords
- Disabling cookies
- Parameterized queries (Correct answer)
Correct answer: Parameterized queries
Parameterized (prepared) statements separate code from data, preventing injection.
Question 25: Which IDS evasion technique involves breaking a single exploit into multiple small packets that individually appear harmless?
- TTL Manipulation
- Obfuscation
- Session Splicing (Correct answer)
- Protocol Anomaly
Correct answer: Session Splicing
Session splicing fragments an attack payload across multiple TCP segments so that the IDS does not reconstruct the full attack signature.
Question 26: What type of IDS evasion injects extra packets into a stream that the IDS accepts but the target host rejects, causing the IDS to build a different view of the session?
- Obfuscation Attack
- Fragmentation Attack
- Evasion Attack
- Insertion Attack (Correct answer)
Correct answer: Insertion Attack
An insertion attack sends packets with invalid checksums or TTLs that the IDS accepts but the end host drops, causing the IDS to reconstruct a different data stream.
Question 27: Which command-line tool is primarily used for querying DNS records such as MX records to identify a domain's mail servers?
- nslookup (Correct answer)
- Wireshark
- Nmap
- Netcat
Correct answer: nslookup
nslookup is used to query DNS servers and retrieve specific record types including MX records that identify mail servers for a domain.
Question 28: What type of sensitive organizational information can an attacker gather by analyzing a company's job postings?
- Technology stack, software versions, and internal roles used by the organization (Correct answer)
- Employee passwords and hashed credentials
- Direct credentials to access internal systems
- Physical security details such as access card systems
Correct answer: Technology stack, software versions, and internal roles used by the organization
Job postings commonly list required technologies, frameworks, and software versions that reveal the organization's technical environment and potential attack vectors.
Question 29: The KRACK attack against WPA2 exploits a flaw in which part of the protocol?
- The SSID beacon interval
- The four-way handshake key reinstallation (Correct answer)
- The DHCP lease renewal
- The RADIUS shared secret
Correct answer: The four-way handshake key reinstallation
KRACK forces nonce reuse by replaying message 3 of the four-way handshake, reinstalling an already-in-use key.
Question 30: What does TTL (Time To Live) manipulation help an attacker achieve?
- Encrypting payloads
- Speeding up DNS resolution
- Evading some IDS by controlling packet hop expiration (Correct answer)
- Bypassing all firewalls automatically
Correct answer: Evading some IDS by controlling packet hop expiration
Crafting TTL values can cause packets to expire before reaching the IDS, aiding evasion.
Question 31: Which phase of the CEH hacking methodology comes immediately after gaining access?
- Reconnaissance
- Scanning
- Covering tracks
- Maintaining access (Correct answer)
Correct answer: Maintaining access
After gaining access, the attacker focuses on maintaining access to keep persistence.
Question 32: What is the primary function of an Intrusion Detection System (IDS)?
- To encrypt network packets
- To monitor traffic and alert on suspicious activity (Correct answer)
- To block all inbound traffic
- To assign IP addresses
Correct answer: To monitor traffic and alert on suspicious activity
An IDS monitors network or host activity and raises alerts on suspicious or malicious patterns.
Question 33: What is the primary purpose of a WHOIS lookup during the footprinting phase?
- Retrieve domain registration and ownership information (Correct answer)
- Test for SQL injection vulnerabilities
- Capture network packets in transit
- Scan open ports on a target system
Correct answer: Retrieve domain registration and ownership information
WHOIS lookup retrieves registration details about a domain including owner contact information, registrar, registration dates, and name servers.
Question 34: An attacker performs a DNS zone transfer (AXFR). What is the risk if it succeeds?
- All emails are intercepted
- The attacker can reset all passwords
- The full list of DNS records for the domain is exposed (Correct answer)
- The web server crashes
Correct answer: The full list of DNS records for the domain is exposed
A successful zone transfer hands over the complete DNS records, revealing internal hostnames and structure.
Question 35: What is the purpose of performing a reverse DNS lookup during the footprinting phase?
- Transfer a DNS zone database from a name server
- Resolve an IP address back to its associated hostname (Correct answer)
- Convert domain names to their corresponding IP addresses
- Bypass firewall rules using DNS tunneling techniques
Correct answer: Resolve an IP address back to its associated hostname
Reverse DNS lookup maps an IP address back to its hostname, helping attackers identify servers and services associated with specific IP addresses found during scanning.
Question 36: Which TCP flags are set in a packet during an Xmas scan?
- SYN only
- SYN, ACK, RST
- FIN, PSH, URG (Correct answer)
- ACK only
Correct answer: FIN, PSH, URG
An Xmas scan lights up the FIN, PSH, and URG flags like a Christmas tree.
Question 37: What is the goal of a DHCP starvation attack?
- Encrypt all DHCP traffic
- Exhaust the DHCP pool so legitimate clients cannot get addresses (Correct answer)
- Disable ARP
- Speed up address leasing
Correct answer: Exhaust the DHCP pool so legitimate clients cannot get addresses
DHCP starvation floods the server with bogus requests to exhaust its address pool, denying service.
Question 38: What is the purpose of 'fuzzing' in vulnerability research?
- Scanning for open ports with varying timing
- Obfuscating malware to evade antivirus
- Encrypting exploit payloads for delivery
- Sending malformed or random data to an application to discover crashes and bugs (Correct answer)
Correct answer: Sending malformed or random data to an application to discover crashes and bugs
Fuzzing (fuzz testing) inputs large volumes of random or malformed data into an application to trigger unexpected behavior, crashes, or security vulnerabilities.
Question 39: Which DNS record type maps a domain name to an IPv6 address?
- CNAME record
- AAAA record (Correct answer)
- MX record
- A record
Correct answer: AAAA record
The AAAA (quad-A) record maps a domain name to a 128-bit IPv6 address, while the A record maps to a 32-bit IPv4 address.
Question 40: Which encryption protocol is considered insecure for Wi-Fi and easily cracked?
- AES-CCMP
- WPA3
- WEP (Correct answer)
- WPA2
Correct answer: WEP
WEP uses weak RC4 keying and is trivially cracked, making it obsolete.
Question 41: What distinguishes an IPS from an IDS?
- An IPS can actively block or drop malicious traffic (Correct answer)
- An IPS assigns DHCP leases
- An IPS cannot inspect packets
- An IPS only logs events
Correct answer: An IPS can actively block or drop malicious traffic
An IPS is inline and can actively block or drop malicious traffic, while an IDS only detects and alerts.
Question 42: An attacker observes employees' daily routines, badge styles, and entry times before attempting an intrusion. This preparatory phase is called:
- Data encryption
- Privilege escalation
- Exfiltration
- Reconnaissance/surveillance (Correct answer)
Correct answer: Reconnaissance/surveillance
Reconnaissance gathers details about targets and routines to plan a more convincing physical or social attack.
Question 43: Which attack denies wireless service by transmitting high-power noise on the same frequency as the target network?
- ARP spoofing
- RF jamming (Correct answer)
- SQL injection
- DNS poisoning
Correct answer: RF jamming
RF jamming floods the channel with interference, preventing legitimate devices from communicating.
Question 44: How does a signature-based IDS detect attacks?
- By scanning open ports
- By matching traffic against a database of known attack patterns (Correct answer)
- By learning normal baseline behavior
- By blocking all encrypted traffic
Correct answer: By matching traffic against a database of known attack patterns
Signature-based IDS compares traffic to a database of known malicious patterns or signatures.
Question 45: Which hashing algorithm is considered cryptographically broken and should not be used for security?
- MD5 (Correct answer)
- bcrypt
- SHA-256
- SHA-3
Correct answer: MD5
MD5 is vulnerable to collision attacks and is unsuitable for security-sensitive hashing.
Question 46: Which type of IDS analyzes network traffic patterns against a learned baseline to detect anomalies?
- Signature-Based IDS
- Stateful IDS
- Anomaly-Based IDS (Correct answer)
- Host-Based IDS
Correct answer: Anomaly-Based IDS
Anomaly-based IDS establishes a baseline of normal behavior and triggers alerts when traffic deviates significantly from that baseline.
Question 47: What is the primary weakness of WEP that allows its encryption key to be recovered?
- Short, reused initialization vectors (IVs) (Correct answer)
- Use of EAP-TLS
- Lack of any encryption
- Use of AES in CBC mode
Correct answer: Short, reused initialization vectors (IVs)
WEP's 24-bit IVs are short and frequently reused, enabling statistical attacks like FMS to recover the key.
Question 48: Which type of testing occurs when individuals know the entire layout of the network?
- Blind testing
- Gray box
- White box (Correct answer)
- Black box
Correct answer: White box
White box testing, also known as clear box testing, is a method where the tester has complete knowledge of the system's internal structure, design, and implementation. This includes access to network diagrams, source code, and architectural details. This comprehensive understanding allows for a detailed and thorough assessment of vulnerabilities from an insider's perspective, ensuring all components are examined.
Question 49: What security risk does an improperly configured DNS zone transfer (AXFR) present to an organization?
- Creates a denial-of-service vulnerability in the DNS infrastructure
- Enables man-in-the-middle attacks on all SSL connections
- Allows remote code execution on the DNS server
- Exposes the entire DNS database including all internal hostnames to unauthorized parties (Correct answer)
Correct answer: Exposes the entire DNS database including all internal hostnames to unauthorized parties
An unrestricted DNS zone transfer exposes all DNS records for a domain, giving attackers a complete map of the internal network infrastructure and hostnames.
Question 50: Which tool is specifically designed for automated web crawling, email harvesting, and subdomain enumeration from public sources?
- Nmap
- theHarvester (Correct answer)
- Aircrack-ng
- Metasploit Framework
Correct answer: theHarvester
theHarvester gathers emails, names, subdomains, IPs, and URLs from public sources like search engines and LinkedIn during the passive reconnaissance phase.
Question 51: What is spear phishing and how does it differ from regular phishing?
- Using a fishing metaphor to describe hacking
- Targeted phishing aimed at specific individuals using personalized information, versus mass generic emails (Correct answer)
- A type of network scanning technique
- Phishing that uses spear-like USB devices
Correct answer: Targeted phishing aimed at specific individuals using personalized information, versus mass generic emails
Spear phishing targets specific individuals or organizations with highly personalized messages using researched information (name, position, projects), making them much more convincing and dangerous than generic phishing campaigns.
Question 52: Which countermeasure best defends against ARP spoofing?
- Disabling ICMP
- Increasing the TTL
- Dynamic ARP Inspection (DAI) on switches (Correct answer)
- Closing all UDP ports
Correct answer: Dynamic ARP Inspection (DAI) on switches
Dynamic ARP Inspection validates ARP packets against trusted bindings to block spoofed entries.
Question 53: What is the difference between a virus, worm, and Trojan?
- Worms require user action while viruses don't
- Trojans self-replicate but viruses don't
- They are all the same type of malware
- Viruses attach to files and need user action; worms self-replicate across networks; Trojans disguise as legitimate software (Correct answer)
Correct answer: Viruses attach to files and need user action; worms self-replicate across networks; Trojans disguise as legitimate software
Viruses attach to host files and require user action to spread, worms self-propagate across networks without user interaction, and Trojans appear legitimate but contain hidden malicious functionality.
Question 54: What is Shodan primarily used for during the reconnaissance phase of ethical hacking?
- Performing automated SQL injection attacks
- Cracking WPA2 wireless passwords
- Searching social media profiles for target employees
- Finding internet-connected devices and their exposed services (Correct answer)
Correct answer: Finding internet-connected devices and their exposed services
Shodan is a search engine that indexes internet-connected devices, revealing open ports, running services, and banners useful for identifying exposed infrastructure.
Question 55: What is footprinting through social engineering in the context of reconnaissance?
- Gathering information by interacting with or deceiving target employees (Correct answer)
- Using SQL injection against social networking sites
- Automating social media profile scraping with bots
- Exploiting software vulnerabilities in social media platforms
Correct answer: Gathering information by interacting with or deceiving target employees
Social engineering during reconnaissance involves manipulating or deceiving target employees through phone calls, emails, or impersonation to extract organizational information.
Question 56: Which tool is used to perform session hijacking by capturing and replaying network packets?
- Hamster and Ferret (Correct answer)
- Wireshark
- Burp Suite
- Nessus
Correct answer: Hamster and Ferret
Hamster and Ferret are tools used together to sidejack HTTP sessions by capturing cookies from wireless traffic and replaying them to impersonate victims.
Question 57: Which attack forces an authenticated user to execute unwanted actions on a web app?
- SSRF
- CSRF (Correct answer)
- IDOR
- RCE
Correct answer: CSRF
Cross-Site Request Forgery tricks a logged-in user's browser into sending forged requests.
Question 58: What does OSINT stand for in the context of ethical hacking reconnaissance?
- Online System Integration Technique
- Offensive Security Intrusion Network Testing
- Operational Security Intelligence
- Open Source Intelligence (Correct answer)
Correct answer: Open Source Intelligence
OSINT (Open Source Intelligence) refers to gathering information exclusively from publicly available sources without direct interaction with the target.
Question 59: Stored cross-site scripting (XSS) is dangerous primarily because:
- The payload persists and affects many users (Correct answer)
- It only affects the attacker
- It requires physical access
- It cannot run JavaScript
Correct answer: The payload persists and affects many users
Stored XSS saves the malicious script on the server, executing for every user who views the page.
Question 60: An attacker compromises a website frequently visited by employees of a target company to infect them. This technique is known as a:
- Dumpster dive
- Whaling attack
- Watering hole attack (Correct answer)
- Mantrap bypass
Correct answer: Watering hole attack
A watering hole attack poisons a trusted, commonly visited site to compromise its specific visitors.
Question 61: Which tool is commonly used to capture and analyze network packets?
- Nessus
- Wireshark (Correct answer)
- Metasploit
- John the Ripper
Correct answer: Wireshark
Wireshark is a packet capture and protocol analyzer used to inspect network traffic.
Question 62: What is privilege escalation and what are the two types?
- Increasing network bandwidth privileges
- Gaining higher access rights than authorized; vertical (user to admin) and horizontal (accessing another user's resources) (Correct answer)
- Upgrading software to premium versions
- Climbing the corporate hierarchy
Correct answer: Gaining higher access rights than authorized; vertical (user to admin) and horizontal (accessing another user's resources)
Privilege escalation exploits vulnerabilities to gain elevated access. Vertical escalation moves from lower to higher privileges (user to root/admin), while horizontal accesses resources of another user with similar privileges.
Question 63: Which OWASP IoT Top 10 issue does using hardcoded passwords in firmware represent?
- Lack of physical hardening
- Insecure data transfer
- Weak, guessable, or hardcoded passwords (Correct answer)
- Insufficient privacy protection
Correct answer: Weak, guessable, or hardcoded passwords
Hardcoded credentials fall under the OWASP IoT category of weak, guessable, or hardcoded passwords.
Question 64: When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy?
- A senior creation approach
- An IT assurance approach
- A top-down approach (Correct answer)
- A bottom-up approach
Correct answer: A top-down approach
A top-down approach to creating a security program means that security policies and initiatives are driven and actively supported by senior management. This ensures that security is integrated into the organization's overall strategy, receives adequate resources, and is enforced throughout all levels of the company. Senior management's endorsement is critical for the success, effectiveness, and widespread adoption of any security policy or program.
Question 65: What is OS fingerprinting in ethical hacking?
- Scanning for fingerprint readers on the network
- Creating a digital fingerprint for biometric authentication
- Identifying the target's operating system by analyzing network packet characteristics (Correct answer)
- Copying the target's operating system
Correct answer: Identifying the target's operating system by analyzing network packet characteristics
OS fingerprinting analyzes unique characteristics of network packets (TTL values, TCP window size, DF bit) to identify the target's operating system and version, using tools like Nmap.
Question 66: A honeypot is best described as what?
- A load balancer
- A type of firewall rule
- A decoy system designed to attract and study attackers (Correct answer)
- An encryption algorithm
Correct answer: A decoy system designed to attract and study attackers
A honeypot is a deliberately vulnerable decoy used to lure, detect, and analyze attackers.
Question 67: What is Maltego primarily used for during the footprinting and reconnaissance phase?
- Visual link analysis and open-source intelligence gathering (Correct answer)
- Password cracking and hash analysis
- Network packet capture and analysis
- Automated vulnerability scanning
Correct answer: Visual link analysis and open-source intelligence gathering
Maltego is an OSINT and forensics tool that graphically visualizes relationships between entities such as people, organizations, domains, and IP addresses discovered during reconnaissance.
Question 68: What is 'shoulder surfing' in the context of physical security?
- Observing a victim's screen or keypad to steal information (Correct answer)
- Cloning an RFID badge
- Searching trash for documents
- Riding behind an authorized person through a door
Correct answer: Observing a victim's screen or keypad to steal information
Shoulder surfing is directly watching someone enter credentials, PINs, or view confidential data.
Question 69: Which type of footprinting does NOT involve direct interaction with the target system?
- Active footprinting
- Internal footprinting
- Passive footprinting (Correct answer)
- Network footprinting
Correct answer: Passive footprinting
Passive footprinting gathers information through indirect means such as search engines and public databases, leaving no trace on the target's logs.
Question 70: Which web vulnerability allows an attacker to inject malicious SQL into a query?
- Clickjacking
- XSS
- SQL injection (Correct answer)
- CSRF
Correct answer: SQL injection
SQL injection inserts malicious SQL into input fields to manipulate the backend database.
Question 71: A keylogger implemented as a small hardware device inserted between the keyboard and the computer is which type?
- Software keylogger
- Kernel keylogger
- Hardware keylogger (Correct answer)
- API-hooking keylogger
Correct answer: Hardware keylogger
A physical device placed inline with the keyboard cable is a hardware keylogger.
Question 72: What is the primary defense against Cross-Site Request Forgery?
- Disabling JavaScript
- Minifying JavaScript
- Anti-CSRF tokens (Correct answer)
- Input length limits
Correct answer: Anti-CSRF tokens
Unpredictable anti-CSRF tokens ensure requests originate from the legitimate application.
Question 73: What is a watering hole attack?
- Poisoning a physical water supply
- Compromising a website frequently visited by the target group to infect their systems (Correct answer)
- Flooding a network with data packets
- Creating fake Wi-Fi hotspots near water features
Correct answer: Compromising a website frequently visited by the target group to infect their systems
A watering hole attack identifies websites commonly visited by the target organization's employees, compromises those websites with malware, and waits for targets to visit and become infected.
Question 74: An open redirect vulnerability is commonly abused to:
- Inject SQL
- Crash the parser
- Send users to malicious sites while appearing trusted (Correct answer)
- Read server files
Correct answer: Send users to malicious sites while appearing trusted
Open redirects forward users to attacker-controlled URLs, aiding phishing.
Question 75: Which technology is expected to threaten RSA and ECC by efficiently factoring large numbers?
- Cloud computing
- Edge computing
- Blockchain
- Quantum computing (Correct answer)
Correct answer: Quantum computing
Quantum computers running Shor's algorithm could break current public-key cryptography.
Question 76: What is the function of a rootkit once installed on a compromised system?
- Send spam emails to contacts
- Encrypt all user files for ransom
- Hide malicious activity and maintain stealthy access (Correct answer)
- Scan the local network for hosts
Correct answer: Hide malicious activity and maintain stealthy access
A rootkit conceals processes and files to maintain undetected privileged access.
Question 77: What does a stateful firewall track that a stateless (packet-filtering) firewall does not?
- Layer 7 application data
- The state of active network connections (Correct answer)
- Source and destination IP addresses
- DNS query responses
Correct answer: The state of active network connections
A stateful firewall maintains a connection state table and tracks the full context of active sessions, allowing it to detect out-of-state packets that stateless firewalls miss.
Question 78: What is the difference between active and passive reconnaissance?
- Active uses automated tools; passive uses manual methods
- There is no practical difference
- Active directly interacts with the target system; passive gathers information without direct contact (Correct answer)
- Active is legal; passive is illegal
Correct answer: Active directly interacts with the target system; passive gathers information without direct contact
Active reconnaissance involves direct interaction with the target (port scanning, vulnerability scanning), while passive reconnaissance gathers publicly available information (WHOIS, social media, DNS records) without alerting the target.
Question 79: Which frequency band is used by most LoRaWAN IoT deployments to achieve long-range, low-power communication?
- 5 GHz only
- 2.4 GHz only
- 60 GHz mmWave
- Sub-GHz ISM bands (e.g., 868/915 MHz) (Correct answer)
Correct answer: Sub-GHz ISM bands (e.g., 868/915 MHz)
LoRaWAN uses sub-GHz ISM bands such as 868 MHz (EU) and 915 MHz (US) for long-range, low-power links.
Question 80: What type of attack extracts keys by measuring power consumption or timing of a device?
- Collision attack
- Replay attack
- Side-channel attack (Correct answer)
- Man-in-the-middle attack
Correct answer: Side-channel attack
Side-channel attacks analyze physical leakage like timing, power, or electromagnetic emissions.
Question 81: Which Nmap timing template is the most aggressive and fastest?
- -T0 (paranoid)
- -T5 (insane) (Correct answer)
- -T3 (normal)
- -T2 (polite)
Correct answer: -T5 (insane)
-T5 (insane) is the fastest, most aggressive timing template at the cost of accuracy and stealth.
Question 82: Which response BEST reduces the impact of a successful social engineering breach once detected?
- Publicly blaming the employee
- Turning off all CCTV
- Incident response activation and credential revocation (Correct answer)
- Ignoring it until the next audit
Correct answer: Incident response activation and credential revocation
Activating incident response and revoking compromised credentials quickly contains and limits the damage.
Question 83: A tester uses the OSINT framework to gather intelligence. What does OSINT stand for?
- Open Systems Internal Network Testing
- Open Source Intelligence (Correct answer)
- Online Scanning Internet Tool
- Operational Security Intelligence
Correct answer: Open Source Intelligence
OSINT stands for Open Source Intelligence, gathered from publicly available sources.
Question 84: During footprinting, which tool would best retrieve domain registration and ownership details?
- WHOIS (Correct answer)
- Wireshark
- John the Ripper
- Metasploit
Correct answer: WHOIS
WHOIS queries return domain registration, ownership, and contact information.
Question 85: What information can an attacker extract by analyzing the headers of an email received from a target organization?
- Employee login credentials for email systems
- Internal IP addresses, mail server names, and email routing paths (Correct answer)
- A list of all email addresses in the organization's directory
- Decrypted email body content regardless of encryption
Correct answer: Internal IP addresses, mail server names, and email routing paths
Email headers contain routing metadata showing each mail server the email passed through, potentially revealing internal IP addresses and mail server infrastructure.
Question 86: What is a digital certificate and what role does it play in PKI?
- An electronic document binding a public key to an identity, verified by a Certificate Authority (Correct answer)
- A digital copy of a paper certificate
- A license to perform penetration testing
- A software installation key
Correct answer: An electronic document binding a public key to an identity, verified by a Certificate Authority
A digital certificate (X.509) is issued by a trusted Certificate Authority, containing the entity's public key, identity information, validity period, and the CA's digital signature, enabling trust in public key authenticity.
Question 87: What is the primary goal of footprinting in ethical hacking?
- Gather information about the target to plan an attack (Correct answer)
- Intercept network traffic
- Install malware on target systems
- Exploit vulnerabilities in the target system
Correct answer: Gather information about the target to plan an attack
Footprinting is the first phase of ethical hacking where information is collected about the target organization to identify potential attack surfaces before any exploitation.
Question 88: What countermeasure best prevents session hijacking caused by predictable session tokens?
- Disabling cookies
- Enforcing password complexity
- Using long, randomly generated session IDs (Correct answer)
- Enabling ICMP filtering
Correct answer: Using long, randomly generated session IDs
Long, cryptographically random session IDs are computationally infeasible to predict, preventing attackers from guessing valid session tokens.
Question 89: A rootkit that operates by modifying the kernel's system call table is classified as which type?
- Application-level rootkit
- Library-level rootkit
- Kernel-level rootkit (Correct answer)
- Boot-sector rootkit
Correct answer: Kernel-level rootkit
Kernel-level rootkits hook or modify kernel structures such as the system call table.
Question 90: What does a MAC flooding attack attempt to do to a switch?
- Crack WPA2 keys
- Spoof DNS records
- Overflow the CAM table so the switch behaves like a hub (Correct answer)
- Disable the firewall
Correct answer: Overflow the CAM table so the switch behaves like a hub
MAC flooding overflows the switch CAM table, forcing it to broadcast frames so the attacker can sniff them.
Question 91: What is the primary purpose of a packer when used by malware authors?
- To add legitimate digital signatures
- To speed up program execution
- To improve memory management
- To compress and obfuscate the binary to evade signature detection (Correct answer)
Correct answer: To compress and obfuscate the binary to evade signature detection
Packers compress and obfuscate malware binaries to evade signature-based detection.
Question 92: Which password attack tries every possible character combination until success?
- Credential stuffing
- Rainbow table attack
- Dictionary attack
- Brute-force attack (Correct answer)
Correct answer: Brute-force attack
A brute-force attack systematically tries all possible combinations until the password is found.
Question 93: Which protocol is vulnerable to sniffing because it transmits credentials in cleartext?
- Telnet (Correct answer)
- SFTP
- HTTPS
- SSH
Correct answer: Telnet
Telnet sends usernames and passwords in cleartext, making them easy to capture via sniffing.
Question 94: What is the main goal of network enumeration after scanning?
- To extract usernames, shares, and services from identified hosts (Correct answer)
- To encrypt the target's disk
- To physically locate the server
- To register a new domain
Correct answer: To extract usernames, shares, and services from identified hosts
Enumeration actively extracts resources like usernames, shares, and services from discovered systems.
Question 95: What is the primary purpose of using Traceroute/Tracert during network footprinting?
- Detect and identify malware running on the network
- Map the network path and identify intermediate routers between attacker and target (Correct answer)
- Crack passwords by tracing authentication packet sequences
- Intercept and decrypt HTTPS web traffic
Correct answer: Map the network path and identify intermediate routers between attacker and target
Traceroute maps the route packets take to reach a destination, revealing intermediate routers, network topology, TTL values, and potential firewall or IDS locations.
Question 96: Which tool is most commonly used for network discovery and port scanning?
- Nmap (Correct answer)
- Metasploit
- John the Ripper
- Wireshark
Correct answer: Nmap
Nmap is the standard tool for host discovery, port scanning, and service/version detection.
Question 97: Which technique allows an attacker to monitor traffic on a switched network passively?
- SYN flooding
- ICMP flooding
- Brute forcing SSH
- Port mirroring / SPAN port abuse (Correct answer)
Correct answer: Port mirroring / SPAN port abuse
Abusing a port mirror or SPAN configuration copies traffic to the attacker's port for passive monitoring.
Question 98: Which type of cloud attack involves injecting malicious content into a cloud service to be executed by other users or services?
- Data Diddling
- Hyperjacking
- Cloud Cryptojacking
- Cross-Cloud Scripting (XCS) (Correct answer)
Correct answer: Cross-Cloud Scripting (XCS)
Cross-Cloud Scripting (XCS) is similar to XSS but targets cloud-hosted applications, injecting malicious scripts that execute in the context of other cloud users.
Question 99: Which automated exploitation framework is most commonly referenced in CEH for developing and testing exploits?
- Metasploit Framework (Correct answer)
- Nessus
- OWASP ZAP
- Burp Suite Pro
Correct answer: Metasploit Framework
The Metasploit Framework is the most widely used open-source exploitation framework, providing tools for exploit development, delivery, and post-exploitation.
Question 100: Which container escape technique exploits a misconfigured Docker socket mounted inside a container?
- Docker socket abuse (Correct answer)
- Kernel exploit
- Namespace pivot
- Privileged container breakout
Correct answer: Docker socket abuse
Mounting the Docker socket (/var/run/docker.sock) inside a container allows an attacker to control the host Docker daemon and escape the container.
Question 101: What is the purpose of using Unicode or hex encoding in IDS evasion?
- To obscure attack strings so signature-based IDS does not detect them (Correct answer)
- To compress attack payloads for faster delivery
- To prevent logging of the attack
- To bypass SSL inspection
Correct answer: To obscure attack strings so signature-based IDS does not detect them
Encoding attack strings in Unicode or hex can bypass signature-based IDS that only match ASCII patterns, while the target server decodes and executes the payload normally.
Question 102: A security guard who verifies badges, signs in visitors, and watches monitors is an example of which control category?
- Administrative/physical control performed by personnel (Correct answer)
- Network firewall control
- Compiler-level control
- Cryptographic control
Correct answer: Administrative/physical control performed by personnel
Human guards enforce physical and procedural controls and can respond dynamically to threats.
Question 103: Which command-line tool is used to capture and analyze network packets from the terminal?
- tcpdump (Correct answer)
- traceroute
- netstat
- ipconfig
Correct answer: tcpdump
tcpdump captures and displays network packets directly from the command line.
Question 104: An attacker captures and retransmits a valid encrypted authentication token. What attack is this?
- Replay attack (Correct answer)
- Birthday attack
- Side-channel attack
- Collision attack
Correct answer: Replay attack
A replay attack reuses captured valid data to gain unauthorized access.
Question 105: What is banner grabbing and what information does it reveal?
- Capturing screenshots of target websites
- Blocking banner advertisements
- Creating advertising banners for websites
- Connecting to services to capture their version information and software details (Correct answer)
Correct answer: Connecting to services to capture their version information and software details
Banner grabbing connects to network services (HTTP, FTP, SMTP) and captures the service banner which typically reveals the software name, version, and sometimes OS information, helping identify exploitable vulnerabilities.
Question 106: Which firewall evasion technique uses a series of intermediate hosts to hide the true source of an attack?
- Fragmentation
- Source Routing
- Proxy Chaining (Correct answer)
- Tunneling
Correct answer: Proxy Chaining
Proxy chaining routes attack traffic through multiple proxy servers, masking the original source IP and making attribution difficult.
Question 107: What is the term for digging through an organization's trash to recover sensitive documents, sticky notes, or discarded media?
- Pretexting
- Dumpster diving (Correct answer)
- Shoulder surfing
- Tailgating
Correct answer: Dumpster diving
Dumpster diving recovers improperly discarded information that may contain credentials or internal data.
Question 108: What is 'covert channel' communication in the context of firewall evasion?
- Transmitting data through protocols not intended for data transfer (Correct answer)
- Using HTTPS to bypass DPI
- Exfiltrating data via cloud storage APIs
- Encrypted VPN tunnels between trusted hosts
Correct answer: Transmitting data through protocols not intended for data transfer
Covert channels exploit non-standard use of protocols (e.g., hiding data in ICMP ping payloads or DNS queries) to bypass firewalls that only filter known data channels.
Question 109: Which attack technique do attackers use to steal session cookies by injecting a script into a vulnerable web application?
- Cross-Site Scripting (XSS) (Correct answer)
- Command Injection
- SQL Injection
- CSRF
Correct answer: Cross-Site Scripting (XSS)
XSS can be used to inject malicious scripts that read and exfiltrate the victim's session cookies to the attacker's server.
Question 110: What is the purpose of a DMZ in network architecture?
- To replace the firewall entirely
- To speed up DNS lookups
- To isolate public-facing servers from the internal network (Correct answer)
- To store all passwords
Correct answer: To isolate public-facing servers from the internal network
A DMZ places public-facing servers in a segmented zone to limit exposure of the internal network.
Question 111: Which protocol is widely used for IoT messaging and, if left unauthenticated on port 1883, can leak sensor data?
- SNMP
- FTP
- SMTP
- MQTT (Correct answer)
Correct answer: MQTT
MQTT is a lightweight publish/subscribe IoT protocol that, when unauthenticated on port 1883, exposes topics and data.
Question 112: Which technique systematically queries a DNS server with a wordlist of possible names to enumerate subdomains of a target?
- ARP poisoning
- DNS brute-forcing (Correct answer)
- Port scanning
- Passive packet sniffing
Correct answer: DNS brute-forcing
DNS brute-forcing queries DNS servers with a large list of potential subdomain names to discover all valid subdomains associated with a target domain.
Question 113: Which countermeasure is MOST effective against tailgating into a secure facility?
- Mantraps with anti-passback controls (Correct answer)
- Stronger Wi-Fi passwords
- Email spam filters
- Endpoint antivirus
Correct answer: Mantraps with anti-passback controls
A mantrap allows only one authenticated person through at a time, preventing an unauthorized follower.
Question 114: What port number is used by LDAP protocol?
- 445
- 110
- 464
- 389 (Correct answer)
Correct answer: 389
The Lightweight Directory Access Protocol (LDAP) uses TCP port 389 for unencrypted communication. LDAP is a widely used application protocol for accessing and maintaining distributed directory information services, such as user accounts and network resources. For secure, encrypted communication, a variant known as LDAPS (LDAP Secure) typically operates over TCP port 636, using SSL/TLS encryption.
Question 115: Which of the following BEST mitigates risk from lost or stolen laptops containing sensitive data?
- Disabling the trackpad
- A louder keyboard
- Full-disk encryption (Correct answer)
- A brighter screen
Correct answer: Full-disk encryption
Full-disk encryption renders data unreadable to anyone without the proper credentials if the device is stolen.
Question 116: What is 'ARP spoofing' primarily used for in session hijacking attacks on a LAN?
- Associating the attacker's MAC with a legitimate IP to intercept traffic (Correct answer)
- Generating fake ARP broadcasts to flood the network
- Bypassing 802.1X port authentication
- Crashing the ARP cache of routers
Correct answer: Associating the attacker's MAC with a legitimate IP to intercept traffic
ARP spoofing sends fake ARP replies that associate the attacker's MAC address with a victim's IP, redirecting LAN traffic through the attacker for man-in-the-middle interception.
Question 117: What is 'IP spoofing' used for in the context of session hijacking?
- Bypassing firewall rules via port forwarding
- Encrypting session data
- Amplifying DoS traffic
- Masquerading as a trusted host to hijack a TCP session (Correct answer)
Correct answer: Masquerading as a trusted host to hijack a TCP session
In session hijacking, IP spoofing allows the attacker to forge packets with a trusted source IP to impersonate a legitimate party in the TCP session.
Question 118: During post-exploitation, an attacker dumps credentials from the LSASS process memory on Windows. Which tool is most associated with this?
- Burp Suite
- Mimikatz (Correct answer)
- Aircrack-ng
- sqlmap
Correct answer: Mimikatz
Mimikatz extracts credentials, hashes, and tickets from LSASS memory.
Question 119: What is the purpose of enumeration in the ethical hacking methodology?
- Counting the number of computers on a network
- Extracting detailed information like usernames, shares, and services from a target system (Correct answer)
- Creating a network diagram automatically
- Numbering all ports sequentially
Correct answer: Extracting detailed information like usernames, shares, and services from a target system
Enumeration involves establishing active connections to target systems to extract detailed information including user accounts, network shares, group memberships, SNMP data, and DNS zone transfers.
Question 120: Which technique do attackers use to bypass firewalls by encapsulating malicious traffic within an allowed protocol such as DNS or ICMP?
- Port Knocking
- ARP Spoofing
- Protocol Tunneling (Correct answer)
- Fragmentation
Correct answer: Protocol Tunneling
Protocol tunneling encapsulates unauthorized traffic inside permitted protocols (like DNS or ICMP), allowing it to pass through firewalls that only filter by protocol type.
Question 121: An attacker escalates from a standard user to SYSTEM by exploiting a service running as SYSTEM with a writable executable path. This is an example of what?
- Vertical privilege escalation (Correct answer)
- Credential stuffing
- Lateral movement
- Horizontal privilege escalation
Correct answer: Vertical privilege escalation
Gaining higher privileges (user to SYSTEM) is vertical privilege escalation.
Question 122: Which Nmap scan type sends only a SYN packet and never completes the TCP handshake?
- FIN scan (-sF)
- SYN stealth scan (-sS) (Correct answer)
- TCP connect scan (-sT)
- ACK scan (-sA)
Correct answer: SYN stealth scan (-sS)
The SYN stealth scan sends a SYN and tears down the connection with RST before the handshake completes.
Question 123: Which Regional Internet Registry (RIR) manages IP address allocation for the United States and Canada?
- RIPE NCC
- LACNIC
- ARIN (Correct answer)
- APNIC
Correct answer: ARIN
ARIN (American Registry for Internet Numbers) manages IP address allocation and WHOIS data for the United States, Canada, and many Caribbean and North Atlantic territories.
Question 124: An attacker sends an email claiming to be from the IT helpdesk, urgently requesting the user reset their password via an included link. Which social engineering principle is MOST being exploited?
- Reciprocity
- Authority and urgency (Correct answer)
- Scarcity of resources
- Social proof
Correct answer: Authority and urgency
Impersonating IT (authority) plus an urgent deadline pressures the victim into acting without verifying.
Question 125: What is the Wayback Machine (web.archive.org) primarily used for during the footprinting phase?
- Viewing archived versions of websites to find previously exposed sensitive information (Correct answer)
- Scanning for open ports on historical IP address ranges
- Testing web application vulnerabilities against live targets
- Capturing real-time network traffic from target websites
Correct answer: Viewing archived versions of websites to find previously exposed sensitive information
The Wayback Machine archives historical website snapshots, enabling attackers to find removed pages, old configuration files, or exposed sensitive data no longer visible on the live site.
Question 126: An attacker impersonates a delivery courier to gain access to a building's loading dock and then wanders into restricted areas. This highlights the importance of:
- Faster internet speeds
- Visitor escort and access zoning policies (Correct answer)
- Stronger email filters
- More monitors per desk
Correct answer: Visitor escort and access zoning policies
Visitor escorting and zoned access prevent outsiders from freely moving into restricted areas.
Certified Ethical Hacker (CEH v13)
The CEH v13 certification validates an individual's ability to think and act like a malicious hacker, covering attack phases, countermeasures, and ethical hacking techniques across 20 security domains. Awarded by EC-Council, it is one of the most recognized cybersecurity certifications worldwide.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds