Courseiva
Enumeration and System HackingeasyMultiple ChoiceObjective-mapped

CEH Enumeration and System Hacking Practice Question

In the context of system hacking methodology (CHPSET), which phase involves removing evidence of the attacker's activities from logs and system files?

⚠ Common exam trap

Many exam-takers confuse 'Erasing tracks' with 'Privilege escalation' because both involve post-exploitation actions, but the key distinction is that erasing tracks is solely about covering forensic evidence, not gaining higher privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Erasing tracks

In the CEH system hacking methodology (CHPSET), the 'Erasing tracks' phase is specifically defined as the step where attackers remove evidence of their activities, such as clearing logs, modifying timestamps, or deleting system files. This ensures that intrusion detection systems or system administrators cannot trace the attack back to the source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Spying

    Why it's wrong here

    Spying, within system hacking, involves covertly monitoring a target's activities, network communications, or data transfers after initial compromise. This phase is typically focused on reconnaissance, data collection, or maintaining surveillance, rather than the final act of removing evidence of the intrusion itself. It's an ongoing information gathering process, not a cleanup operation.

  • Privilege escalation

    Why it's wrong here

    Privilege escalation is a post-exploitation technique where an attacker, having gained initial access with limited user rights, exploits system vulnerabilities or misconfigurations to obtain higher-level permissions, such as root or Administrator. This critical step enables full control over the compromised system but occurs before the final stage of covering one's tracks. It's about gaining authority, not about erasing forensic artifacts.

  • Erasing tracks

    Why this is correct

    Erasing tracks is the crucial final phase in the system hacking methodology, where an attacker meticulously removes all forensic evidence of their presence and activities from a compromised system. This involves clearing system logs, modifying file timestamps, deleting malicious tools, and altering audit trails to prevent detection by security analysts and incident responders. The objective is to maintain persistence and avoid attribution, making it appear as if no intrusion occurred.

  • Cracking passwords

    Why it's wrong here

    Cracking passwords involves employing various techniques, such as brute-force attacks, dictionary attacks, or rainbow tables, to discover user credentials, often from collected password hashes. This activity is primarily part of the 'Gaining Access' phase of system hacking, as it directly facilitates initial entry into a system or network, or enables lateral movement. It serves as a means to obtain authentication, not as a method for removing evidence after an attack.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.