20+ practice questions focused on Malware, Social Engineering and Network Attacks — one of the most tested topics on the Certified Ethical Hacker CEH exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Malware, Social Engineering and Network Attacks PracticeA user receives a phone call from someone claiming to be from IT support, asking for their password to troubleshoot an issue. Which social engineering technique is being used?
Explanation: Pretexting is a social engineering technique where the attacker creates a fabricated scenario (pretext) to trick the victim into divulging sensitive information. In this case, the caller impersonates IT support to establish a false sense of authority and urgency, directly asking for the password. This differs from vishing, which is voice-based phishing but typically involves a generic, automated or scripted request rather than a crafted, interactive pretext.
An analyst observes the following output from Wireshark: a TCP packet with the SYN flag set, followed by a SYN-ACK, then an ACK, and then a RST. The sequence numbers show a pattern: initial seq=100, ack=300, then seq=300, ack=101. What is the MOST likely interpretation?
Explanation: The observed sequence numbers (initial seq=100, ack=300, then seq=300, ack=101) indicate that the ACK packet acknowledges a sequence number that was never sent by the original sender, which is a classic sign of TCP sequence number prediction. An attacker who predicts the next expected sequence number can inject a spoofed packet to hijack the session, and the subsequent RST is often used by the attacker to tear down the legitimate connection or cover their tracks.
An IDS alerts on a large number of outbound DNS queries from an internal host to a suspicious domain. The queries have random subdomains and the response size is large. Which attack is MOST likely in progress?
Explanation: The described behavior—large numbers of outbound DNS queries with random subdomains and large response sizes—is the hallmark of a DNS amplification attack. In this attack, the attacker spoofs the victim's IP address and sends queries with random subdomains to open DNS resolvers, which then send large responses (often 10x to 50x larger than the query) to the victim, overwhelming their bandwidth. The IDS alerts on the outbound queries from the internal host because that host is the victim receiving the amplified responses, not the attacker.
A security analyst receives an alert indicating that a host on the internal network is sending a high volume of ICMP echo requests to multiple external IP addresses. The analyst notices that the source IP address is spoofed. Which type of attack is MOST likely occurring?
Explanation: The attack described is a Ping flood (option D). A Ping flood involves sending a high volume of ICMP echo requests (pings) directly to multiple target IP addresses, often with a spoofed source IP to hide the attacker's identity. This overwhelms the targets' network resources. Unlike a Smurf attack, which uses a network broadcast address to amplify traffic, this scenario shows direct flooding of multiple external IPs, characteristic of a Ping flood.
Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)
Explanation: HTTP flood (A) is an application-layer (Layer 7) DDoS attack because it sends massive volumes of seemingly legitimate HTTP GET or POST requests to exhaust a web server's resources, such as worker threads, database connections, or CPU. Slowloris (E) is also an application-layer attack: it opens many partial HTTP connections and sends incomplete headers slowly, keeping sockets open and tying up the web server's connection pool without ever completing a request. By contrast, ICMP flood (B) operates at the network layer (Layer 3) using ICMP echo requests, SYN flood (C) targets the transport layer (Layer 4) by abusing the TCP three-way handshake with half-open connections, and UDP flood (D) is a transport/network-layer volumetric attack that saturates bandwidth with UDP datagrams — none of these three are application-layer attacks.
+15 more Malware, Social Engineering and Network Attacks questions available
Practice all Malware, Social Engineering and Network Attacks questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Malware, Social Engineering and Network Attacks. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Malware, Social Engineering and Network Attacks questions on the CEH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Malware, Social Engineering and Network Attacks is tested as part of the Certified Ethical Hacker CEH blueprint. Practicing with targeted Malware, Social Engineering and Network Attacks questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CEH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Malware, Social Engineering and Network Attacks is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Malware, Social Engineering and Network Attacks practice session with instant scoring and detailed explanations.
Start Malware, Social Engineering and Network Attacks Practice →