Courseiva

CEH Enumeration and System Hacking Practice Question

During a system hacking phase, a tester successfully gains access to a Windows machine and wants to hide a malicious executable. Which of the following techniques is MOST effective for hiding files from standard directory listings without using third-party tools?

⚠ Common exam trap

The trap here is that candidates might choose `attrib +h +s` (Option A) because it's a simpler, more commonly known hiding technique. However, ADS (Option D) offers a significantly higher level of concealment from standard directory listings and can be managed using built-in Windows commands, making it the 'MOST effective' choice under the given constraints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the executable in an Alternate Data Stream (ADS)

Storing the executable in an Alternate Data Stream (ADS) is a highly effective method for hiding files on NTFS file systems. Files stored in ADS are not visible in standard directory listings (e.g., `dir` command or Windows Explorer) and require specific knowledge or commands to discover. This technique can be implemented using built-in Windows commands like `type` or `echo` for creation, and `start` or PowerShell for execution, thus adhering to the 'no third-party tools' constraint. It offers a greater degree of concealment than simply setting hidden and system attributes, which can be easily revealed by changing folder options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the `attrib +h +s` command to set hidden and system attributes

    Why it's wrong here

    Using `attrib +h +s` sets both the hidden and system file attributes, making the file invisible to standard directory listings (e.g., `dir` without the `/a` flag) and many graphical file explorers unless specific options to show hidden and system files are enabled. This method effectively conceals the file from casual user inspection, fulfilling the objective of hiding an executable post-compromise. While not foolproof against determined analysis, it significantly increases stealth against typical user interaction.

  • ✗

    Rename the file to a system filename like svchost.exe and place it in C:\Windows\System32

    Why it's wrong here

    Renaming an executable to a common system filename like `svchost.exe` and placing it in a legitimate system directory such as `C:\Windows\System32` attempts to blend it in with legitimate files. However, this approach does not actually *hide* the file; it remains fully visible in directory listings and can be easily discovered by simply browsing the directory or using file search tools. Furthermore, advanced detection methods can identify discrepancies like different file sizes, digital signatures, or process behavior compared to the legitimate `svchost.exe`.

  • ✗

    Encrypt the file using EFS

    Why it's wrong here

    Encrypting a file using the Encrypting File System (EFS) is designed to protect the confidentiality of its contents, ensuring that unauthorized users cannot read the data even if they gain access to the file. While EFS secures the information within the executable, it does not alter the file's visibility or attributes within the filesystem. The encrypted file will still appear in all directory listings and file explorers, making it readily discoverable and failing to achieve the objective of hiding the executable.

  • ✓

    Store the executable in an Alternate Data Stream (ADS)

    Why this is correct

    Storing an executable in an Alternate Data Stream (ADS) on an NTFS filesystem can indeed hide data from standard file enumeration tools, as ADSs are not typically listed by default. However, directly executing a program from an ADS is not straightforward and often requires specific loader utilities or API calls, making it less practical for simple, persistent execution compared to a standard file. While ADS is excellent for data concealment, the complexity of running an executable from it makes it a less suitable primary method for hiding an *executable* that needs to be run easily.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.