Ethical Hacking Phases: Reconnaissance, Scanning, Maintaining Access
Which THREE of the following are essential phases in the ethical hacking methodology as defined by EC-Council?
Quick Answer
The answer is Reconnaissance, Scanning, and Maintaining Access. These three are essential phases in the EC-Council ethical hacking methodology because they represent the core lifecycle of a real-world attack: Reconnaissance involves passive and active information gathering to map the target, Scanning uses tools like Nmap to identify live hosts and open ports, and Maintaining Access ensures persistent control through backdoors or rootkits, simulating an advanced persistent threat. On the Certified Ethical Hacker CEH exam, this question tests your understanding of the official five-phase methodology—often confused with the seven-step penetration testing process—so a common trap is mixing in phases like “Exploitation” or “Reporting,” which are distinct steps. A reliable memory tip is to think of the acronym RMS: Reconnaissance to find the target, Scanning to probe it, and Maintaining Access to own it long-term.
⚠ Common exam trap
Candidates often confuse enumeration as a distinct phase when it is actually a sub-component of the Scanning phase, and they mistake social engineering for a phase rather than recognizing it as a technique that can be used within Reconnaissance or Gaining Access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining Access
Maintaining Access is a core phase in the EC-Council ethical hacking methodology because after gaining initial access, the attacker must ensure persistent control over the target system. This involves installing backdoors, rootkits, or creating privileged user accounts to bypass re-authentication. Without this phase, the penetration test would not simulate a real-world advanced persistent threat (APT) scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Maintaining Access
Why this is correct
Maintaining Access is a phase after gaining initial entry.
- ✓
Scanning
Why this is correct
Scanning involves active probing of the target network.
- ✗
Enumeration
Why it's wrong here
Enumeration is a sub-phase within Scanning, not a separate phase.
- ✓
Reconnaissance
Why this is correct
Reconnaissance is the first phase, involving information gathering.
- ✗
Social Engineering
Why it's wrong here
Social Engineering is a technique used within phases, not a phase itself.
Go deeper
Related to this question
Learn chapter
Introduction to Ethical Hacking
Key term
WiFi Encryption Cracking
WiFi encryption cracking is the process of breaking the security on a wireless network to gain unauthorized access to the data or the network itself.
Key term
Persistence Mechanisms
Techniques used by attackers to maintain long-term access to a compromised system after an initial breach.
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are recognized phases of the Ethical Hacking process? (Select TWO.)
medium- ✓ A.Maintaining Access
- ✓ B.Scanning
- ✓ C.Reconnaissance
- ✓ D.Hiding Evidence
- E.Cracking
Why A: Maintaining Access is a recognized phase in the Ethical Hacking process, as defined by the EC-Council's CEH methodology. After gaining initial access, the ethical hacker must establish persistent access to the target system, often by installing backdoors, rootkits, or creating user accounts. This phase ensures the hacker can return to the system without repeating the exploitation steps, which is critical for simulating a real attacker's long-term presence.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.