Courseiva

CEH · domain

Vulnerability Analysis and System Hacking

This domain covers finding and exploiting weaknesses in systems and applications, then escalating access on the target. CEH tests it through scenario questions on buffer overflows, Windows SAM/LSASS credential dumping with tools like Mimikatz and hashcat, Linux privilege escalation, and configuring iptables firewall rules to block or allow specific traffic.

15 questions4 easy7 medium4 hard

Focused practice

Practice Vulnerability Analysis and System Hacking questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Vulnerability Analysis and System Hacking

You must identify vulnerability indicators, dump and crack Windows credentials, escalate privileges on Linux and Windows, and write correct iptables rules. The single most important thing is knowing which tool or command targets which credential store and applying rules in the right order.

Recognizing buffer overflow indicators such as crashes, stack canaries, and unexpected input handling

Dumping and cracking Windows SAM/NTLM hashes with Mimikatz, pwdump, and hashcat

Linux privilege escalation via SUID binaries, sudo misconfiguration, and kernel exploits

Ordering iptables rules to block or permit services like SSH on specific ports

Watch out for

Common Vulnerability Analysis and System Hacking exam traps

  • ▸Confusing SAM and LSASS: SAM holds local account hashes at rest, while LSASS holds credentials in memory and requires different dumping techniques.
  • ▸Placing iptables rules in the wrong order, since the first matching rule wins and a permissive rule above a deny rule nullifies it.
  • ▸Assuming a successful exploit equals full compromise, when privilege escalation and persistence are separate required steps.

Question index

All Vulnerability Analysis and System Hacking questions (15)

Click any question to see the full explanation, or start a practice session above.

1

Refer to the exhibit. An analyst runs netstat on a Windows server and observes multiple established connections to port 3389 from internal IPs. Which attack is most likely occurring?

Hard
2

Refer to the exhibit. A penetration tester runs hashcat to crack NTLM hashes. Which hash mode (-m) would be correct for NTLM?

Medium
3

Match each type of attack to its description.

Medium
4

An ethical hacker is performing a vulnerability scan against a Windows Server 2019 host using Nessus. The scan returns a finding titled 'Microsoft Windows SMB Registry Remotely Accessible' with a CVSS base score of 5.0. The report marks the vulnerability as 'Medium' severity but does not provide a specific patch. Which of the following should the tester do NEXT to determine the actual risk and remediation?

Medium
5

Which TWO vulnerabilities are associated with buffer overflow attacks?

Easy
6

A penetration tester is analyzing a Windows 10 system and runs the following command to dump password hashes from the SAM database. The output shows hashes for local users but some are missing. Which step is most likely missing?

Hard
7

A security analyst runs a vulnerability scan and finds that a server is vulnerable to CVE-2021-44228 (Log4j). Which of the following is the best immediate remediation step?

Easy
8

An ethical hacker is testing a web application that uses cookies for session management. The tester notices that the session cookie does not have the HttpOnly or Secure flags set. Which attack is most likely to succeed due to this misconfiguration?

Medium
9

Drag and drop the steps to configure a firewall rule in iptables to block incoming SSH traffic into the correct order.

Medium
10

Refer to the exhibit. During a penetration test, the results show port 80 as 'filtered'. Which of the following is the most likely reason?

Hard
11

A penetration tester discovers that a target Windows system has port 445 open and responds to SMB requests. Which tool should the tester use to enumerate users, shares, and OS information from this system?

Easy
12

A security analyst is reviewing a vulnerability scan report for a web server that hosts an e-commerce application. The report lists a finding: 'SSL Certificate Expired' with a severity of High. The analyst confirms the certificate expired yesterday. Which of the following is the MOST appropriate immediate action?

Easy
13

Which THREE of the following are common indicators of a buffer overflow vulnerability?

Medium
14

During a penetration test, a tester gains access to a Linux system and needs to escalate privileges. The tester finds that the user has sudo privileges to run /usr/bin/less as root without a password. Which technique should the tester use to escalate privileges?

Hard
15

You are a penetration tester hired by a medium-sized financial company. The company has a network consisting of 50 Windows workstations (Windows 10 Pro) and 5 Windows Server 2019 servers (domain controller, file server, web server, database server, and mail server). The network is segmented into three VLANs: User VLAN (192.168.1.0/24), Server VLAN (192.168.2.0/24), and DMZ (192.168.3.0/24). The web server is in the DMZ and hosts a public-facing e-commerce application built on ASP.NET with a SQL Server backend. The database server is in the Server VLAN and is not directly accessible from the internet. You are given a standard user account on a workstation in the User VLAN. After initial reconnaissance, you discover that the web server is running an outdated version of IIS (7.5) and is vulnerable to a known privilege escalation vulnerability (CVE-2020-0613) that allows local privilege escalation if an attacker has already gained initial access. You also find that the web application has a SQL injection vulnerability in the login page. You successfully exploit the SQL injection to extract the password hash of the web application's service account, which is 'web_svc'. You crack the hash offline and obtain the plaintext password. The 'web_svc' account has local administrative privileges on the web server. Using these credentials, you authenticate to the web server via RDP. From there, you want to pivot to the database server to extract credit card information stored in the database. The database server only allows connections from the web server on port 1433 (SQL Server). Using the 'web_svc' account, you are able to connect to the database server using SQL Server Management Studio. However, you find that the 'web_svc' account has only 'public' and 'guest' database roles, which do not allow reading any sensitive tables. You need to escalate privileges on the database server. What is the most effective next step?

Medium

Frequently asked questions

What does the Vulnerability Analysis and System Hacking domain cover on the CEH exam?
You must identify vulnerability indicators, dump and crack Windows credentials, escalate privileges on Linux and Windows, and write correct iptables rules. The single most important thing is knowing which tool or command targets which credential store and applying rules in the right order.
How many questions are in this domain?
This page lists all 15 Vulnerability Analysis and System Hacking questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Vulnerability Analysis and System Hacking questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-ceh EC-CEH vuln analysis hacking Practice Questions