20+ practice questions focused on Malware, Social Engineering and Network Attacks — one of the most tested topics on the Certified Ethical Hacker CEH exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Malware, Social Engineering and Network Attacks PracticeAn organization is experiencing repeated DDoS attacks that consume all available bandwidth. Which mitigation technique is MOST effective for handling such volumetric attacks?
Explanation: Scrubbing centers (Option D) are the most effective mitigation for volumetric DDoS attacks because they use specialized hardware and software to filter malicious traffic from legitimate traffic before it reaches the target network. Unlike simpler methods, scrubbing centers can handle massive bandwidth floods by redirecting traffic through high-capacity filtering nodes that inspect packets, drop attack traffic based on signatures or behavioral analysis, and forward only clean traffic. This approach is specifically designed for volumetric attacks that saturate bandwidth, as it offloads the filtering burden from the target's own infrastructure.
A network administrator notices that the switch's CAM table is full, causing the switch to flood all incoming traffic out of all ports. Which attack is MOST likely occurring?
Explanation: MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table by sending thousands of frames with unique, random source MAC addresses. Once the CAM table is full, the switch enters a fail-open state and begins flooding all incoming frames out every port, effectively turning it into a hub and allowing the attacker to sniff traffic. This directly matches the scenario where a full CAM table causes flooding.
Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)
Explanation: B is correct because an HTTP flood attack sends a high volume of seemingly legitimate HTTP GET or POST requests to a web server, overwhelming its connection pool and CPU resources. This targets the application layer (Layer 7) of the OSI model, as it exploits the HTTP protocol's request-handling logic rather than network-layer bandwidth.
A security analyst detects a file named 'invoice.pdf.exe' in an email attachment. When the file is submitted to VirusTotal, multiple engines detect it as a Trojan. The analyst wants to perform dynamic analysis to observe its behavior. Which approach is BEST?
Explanation: Dynamic analysis involves executing malware in a controlled, isolated environment (sandbox) to observe its runtime behavior, such as file system changes, registry modifications, network connections, and process injections. Option C directly enables this by running the Trojan and monitoring system calls, which is the best approach to understand its actual impact and propagation methods.
A penetration tester is performing a session hijacking attack. After capturing packets, the tester successfully predicts the TCP sequence numbers and injects packets to take over the session. Which type of attack is this?
Explanation: TCP session hijacking involves an attacker predicting or spoofing TCP sequence numbers to inject malicious packets into an established TCP connection, effectively taking over the session without the need for authentication. This attack exploits the lack of built-in authentication in TCP's three-way handshake and sequence number generation, allowing the attacker to impersonate one of the communicating parties.
+15 more Malware, Social Engineering and Network Attacks questions available
Practice all Malware, Social Engineering and Network Attacks questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Malware, Social Engineering and Network Attacks. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Malware, Social Engineering and Network Attacks questions on the CEH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Malware, Social Engineering and Network Attacks is tested as part of the Certified Ethical Hacker CEH blueprint. Practicing with targeted Malware, Social Engineering and Network Attacks questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CEH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Malware, Social Engineering and Network Attacks is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Malware, Social Engineering and Network Attacks practice session with instant scoring and detailed explanations.
Start Malware, Social Engineering and Network Attacks Practice →