You must classify a scenario as black-, white-, or gray-box, name the correct hacking phase or attacker type, and order Netcat reverse-shell steps. The single most important thing: match the tester's stated knowledge level to the correct box type before answering.
Start practicing
Introduction to Ethical Hacking — choose a session length
Free · No account required
Domain overview
Domain 1 of the CEH exam covers hacking phases, hacker classes (white/black/gray hat), attack types, and testing methodologies. Questions test reconnaissance vs. scanning vs.
gaining access, black-box vs. white-box vs. gray-box assessments, and tool usage such as Netcat, Nmap, and footprinting utilities.
Expect scenario-based items requiring you to identify attack type, tester role, or correct command sequence.
Exam objectives
Black-box, white-box, and gray-box testing scopes and tester knowledge levels
Reconnaissance vs. scanning vs. gaining access vs. maintaining access vs. covering tracks
Hacker classifications: white hat, black hat, gray hat, script kiddie, hacktivist
Netcat reverse shell setup order and basic Nmap footprinting usage
Confusing gray-box (partial knowledge) with black-box (zero knowledge) when the scenario mentions some internal documentation or credentials.
Mixing up passive reconnaissance (no direct target contact) with active scanning that sends packets and may be logged.
Reversing Netcat listener and target order, or forgetting the -l -p flags on the listening host before connecting.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security analyst suspects that an attacker is scanning their network. They notice a large number of TCP SYN packets being sent to various ports on a single host, but no SYN-ACK responses are returned. Which type of scan is most likely being used?
2During a penetration test, an ethical hacker needs to evade an IDS that detects port scans based on the number of packets per second. Which technique would be most effective to avoid detection?
3A company wants to test the security of its web application by simulating attacks from an external perspective. They have no prior knowledge of the internal network or application architecture. Which type of test should they perform?
4Refer to the exhibit. An ethical hacker runs the shown Nmap scan against a target. Which port state indicates that the port is reachable but no service is listening?
5You are an ethical hacker hired to assess the security of a mid-sized company's internal network. The company has three departments: Sales, Engineering, and HR, each on separate VLANs. The network uses a single firewall with default-deny rules, but inter-VLAN routing is allowed for specific ports (e.g., HR needs to access Sales database on TCP 1433). During reconnaissance, you discover that the Engineering VLAN has a web server running on port 80 that is accessible from all VLANs. You also find that the Sales VLAN has a file share (SMB) on port 445 that is accessible only from HR. The firewall logs show numerous failed SSH attempts from an external IP to the Engineering web server. Which action should you recommend as the most effective immediate step to reduce the attack surface?
6Which THREE of the following are essential phases in the ethical hacking methodology as defined by EC-Council?
7Based on the exhibit, what type of attack is being attempted?
8You are a penetration tester hired by a financial services company to assess the security of their external web application. The application is a customer portal hosted on a Linux server with Apache 2.4.6 and PHP 7.2. During reconnaissance, you discover that the server responds to HTTP OPTIONS requests and the Allow header includes PUT and DELETE methods. The application uses a MySQL database backend. You also find a file upload feature in the profile section that accepts JPEG images. While testing, you notice that uploading a file with a .php extension returns a '403 Forbidden' error, but uploading a file with .php5 or .phtml extension succeeds. The uploaded files are stored in /uploads/ directory. What should be your next step to escalate the attack?
9Drag and drop the steps to perform a TCP three-way handshake into the correct order.
10Drag and drop the steps to set up a reverse shell using Netcat into the correct order.
11A junior security consultant is preparing to conduct an authorized penetration test for a retail client. Before any scanning begins, the client's legal team asks the consultant to confirm which document defines the exact IP ranges, testing window, and prohibited actions such as denial-of-service attempts. Which document should the consultant reference?
12An ethical hacker is hired to assess a hospital's network. The contract permits vulnerability discovery but explicitly forbids exploiting a flaw to access patient records. During testing, the hacker finds a SQL injection that would expose the patient database. Which action best reflects the ethical hacking principle of maintaining integrity and minimizing harm?
13A penetration tester is reviewing the difference between a white-box, black-box, and gray-box assessment for a client's new e-commerce platform. The client wants the most realistic simulation of an external attacker with no inside knowledge, but also wants the tester to spend time efficiently rather than performing lengthy reconnaissance. Which assessment type best matches the client's stated priorities?
14An ethical hacker is preparing the final report after a penetration test for a logistics company. The client's compliance officer asks which elements are essential to include so the report supports remediation and satisfies audit expectations. Which two elements are essential to include in the final penetration testing report? (Choose two.)
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must classify a scenario as black-, white-, or gray-box, name the correct hacking phase or attacker type, and order Netcat reverse-shell steps. The single most important thing: match the tester's stated knowledge level to the correct box type before answering.
The Courseiva CEH question bank contains 14 questions in the Introduction to Ethical Hacking domain, covering the 8% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Introduction to Ethical Hacking domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included