CEH Enumeration and System Hacking Practice Question
A security engineer notices repeated log entries showing a user account logging in at odd hours and then clearing event logs. The engineer suspects credential theft. Which phase of the CHPSET methodology involves erasing tracks?
⚠ Common exam trap
The CEH exam often tests the CHPSET methodology by asking which phase corresponds to a specific action, and the trap here is that candidates confuse 'erasing tracks' with 'hiding files' because both involve concealment, but hiding files is about data storage, not log manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Erasing tracks
The CHPSET methodology (Cracking passwords, Hiding files, Planting backdoors, Spying, Erasing tracks, and Transferring files) defines the phases of system hacking. Erasing tracks is the phase where attackers clear event logs, modify log files, or use tools like `wevtutil` or `clearlogs.exe` to remove evidence of their activities, matching the engineer's observation of cleared logs after suspicious logins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Erasing tracks
Why this is correct
When a security engineer observes repeated log entries indicating unauthorized activity, an attacker's immediate priority after gaining access is often to eliminate or alter these digital footprints. Erasing tracks involves anti-forensic techniques like clearing event logs, modifying timestamps, or injecting benign entries to obscure malicious actions. This critical step aims to delay detection, complicate incident response, and prevent security personnel from understanding the full scope of the breach.
- ✗
Hiding files
Why it's wrong here
While an attacker frequently hides malicious tools or exfiltrated data on a compromised system, this action primarily focuses on maintaining persistence or concealing payloads, not directly addressing the 'repeated log entries' themselves. Hiding files typically involves techniques such as using hidden attributes, alternate data streams, or steganography to make files less discoverable. This tactic is distinct from manipulating system logs, which directly record and expose the unauthorized activities that the security engineer is observing.
- ✗
Spying
Why it's wrong here
Spying, or reconnaissance, is a crucial phase where an attacker gathers information about the target environment, often before or during initial compromise, or for data exfiltration post-compromise. However, it does not directly explain the attacker's response to *being detected* via log entries. The observed log entries indicate that an intrusion has likely occurred and the attacker's presence is being recorded, necessitating actions to cover their tracks rather than merely continuing to gather information.
- ✗
Cracking passwords
Why it's wrong here
Cracking passwords is an initial access technique used to gain unauthorized entry or elevate privileges within a system, typically occurring *before* or *during* the initial stages of a breach. The presence of 'repeated log entries showing unusual activity' suggests that access has already been achieved and the attacker's actions are now being recorded. Therefore, cracking passwords is a preceding step to the scenario described, not a subsequent action taken in response to being logged.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.