20+ practice questions focused on Enumeration and System Hacking — one of the most tested topics on the Certified Ethical Hacker CEH exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Enumeration and System Hacking PracticeDuring a penetration test, you gain access to a target system as a low-privileged user. Which of the following is the BEST next step according to the CEH system hacking methodology (CHPSET)?
Explanation: The CEH methodology includes phases such as Cracking passwords, Privilege escalation, Hiding files, Executing applications, Spying, and Erasing tracks. After gaining initial access as a low-privileged user, the next logical step is to escalate privileges to gain higher access (e.g., administrator or root).
During a penetration test, you successfully execute a privilege escalation attack by abusing a service running with SYSTEM privileges on a Windows machine. Which of the following techniques is MOST likely being used?
Explanation: DLL hijacking is the most likely technique because it involves placing a malicious DLL where a service that runs with SYSTEM privileges will load it, causing the attacker's code to execute with SYSTEM privileges. Token impersonation relies on stealing or duplicating access tokens and typically requires SeImpersonate/SeAssignPrimaryToken privileges; it does not require modifying what a service loads. Pass-the-hash is primarily credential-based lateral movement, and SUID abuse is a Unix/Linux privilege escalation method.
Which TWO of the following are valid SMTP enumeration commands that can be used to discover valid email addresses? (Select 2)
Explanation: EXPN (C) is a valid SMTP enumeration command because it asks the server to expand a mailing list or alias and return the individual mailbox addresses it contains, directly revealing valid recipients. VRFY (E) is also valid because it asks the SMTP server to verify whether a given username or email address exists, returning a positive or negative response that confirms valid accounts. Both commands are part of the original SMTP specification and, when not disabled, are classic tools for email address enumeration. HELO (A) only initiates an SMTP session and identifies the client, so it does not reveal addresses. RCPT TO (B) is used to specify a message recipient during mail delivery, and while it can be probed, it is not itself an enumeration command in the same sense as EXPN/VRFY. ATRN (D) is not a standard SMTP command and does not perform address enumeration.
A penetration tester obtains password hashes from a Windows system. Which TWO methods would be most efficient for cracking NTLM hashes offline? (Choose two.)
Explanation: Hashcat, when used with a GPU, can perform massively parallel brute-force attacks against NTLM hashes, achieving billions of hash calculations per second. This makes it one of the most efficient tools for offline password cracking of NTLM hashes, especially when the password is not in a dictionary.
Which of the following is the correct order of phases in the system hacking methodology known as CHPSET?
Explanation: The CHPSET methodology in system hacking stands for Cracking, Hiding, Privilege escalation, Executing, Spying, Erasing. Option D correctly lists these phases in order: Cracking (password cracking), Hiding (covering tracks), Privilege escalation (gaining higher access), Executing (running malicious code), Spying (monitoring activity), and Erasing (removing evidence). This sequence follows the logical progression from initial access to maintaining access and finally covering tracks.
+15 more Enumeration and System Hacking questions available
Practice all Enumeration and System Hacking questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Enumeration and System Hacking. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Enumeration and System Hacking questions on the CEH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Enumeration and System Hacking is tested as part of the Certified Ethical Hacker CEH blueprint. Practicing with targeted Enumeration and System Hacking questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CEH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Enumeration and System Hacking is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Enumeration and System Hacking practice session with instant scoring and detailed explanations.
Start Enumeration and System Hacking Practice →