Sample questions
Certified Ethical Hacker CEH practice questions
A security analyst runs `nmap -sS -sV -A 192.168.1.100` and obtains open ports and service versions. However, the analyst suspects the target is behind an IDS/IPS. Which Nmap techn…
Footprinting, Reconnaissance and ScanningmediumSee the answer and why each option is right or wrong →A security analyst runs the Nmap command: nmap -sI 192.168.1.50 -p 80 10.0.0.1. The scan completes, but the target shows no open ports. What is the MOST likely explanation?
Which TWO of the following tools are capable of cracking password hashes offline? (Select 2)
An organization's security team observes a surge in outgoing DNS queries to external servers from a single internal host, with each query returning unusually large responses (e.g.,…
Malware, Social Engineering and Network AttackshardSee the answer and why each option is right or wrong →A security team suspects a session hijacking attack. The analyst examines network traffic and sees packets with sequence numbers that increment by predictable values. Which attack…
Malware, Social Engineering and Network AttackshardSee the answer and why each option is right or wrong →Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
Malware, Social Engineering and Network AttackseasySee the answer and why each option is right or wrong →Which THREE of the following are valid techniques for covering tracks after compromising a system? (Select 3 correct answers)
Which command-line tool is specifically designed to extract email addresses, subdomains, and other information from public sources (e.g., search engines, social media) for a given…
Which wireless security standard introduced in 2018 uses Simultaneous Authentication of Equals (SAE) to replace the pre-shared key exchange in WPA2, providing forward secrecy and r…
Advanced Topics: Wireless, Cloud, IoT, CryptographyeasySee the answer and why each option is right or wrong →A network administrator receives an alert that the switch's CAM table is full, causing the switch to flood frames out all ports. Which attack has likely occurred?
Malware, Social Engineering and Network AttacksmediumSee the answer and why each option is right or wrong →Which THREE of the following are common indicators of a buffer overflow vulnerability?
Vulnerability Analysis and System HackingmediumSee the answer and why each option is right or wrong →A forensic analyst finds a system where the user's password hash was obtained and cracked offline. The attacker then used stolen credentials to log in and run `wevtutil cl system`.…
Which TWO of the following are considered passive reconnaissance techniques? (Choose TWO.)
Which of the following is a form of social engineering where an attacker physically follows an authorized person into a restricted area without proper authentication?
Malware, Social Engineering and Network AttacksmediumSee the answer and why each option is right or wrong →An attacker discovers that a web application's login form allows unlimited login attempts. The attacker uses a list of usernames and passwords obtained from a previous breach to ga…
Which of the following is the most effective defense against Cross-Site Request Forgery (CSRF) attacks?
An attacker uses an idle scan with Nmap to probe a target. This technique relies on a third-party host with a predictable IP ID sequence to infer port states. Which Nmap flag enabl…
A penetration tester wants to enumerate users and groups from a Windows domain controller via LDAP without logging in. Which of the following tools is MOST appropriate for anonymou…
Which of the following tools is PRIMARILY used for passive OSINT gathering and can query multiple search engines, social media platforms, and public databases to collect informatio…
Which TWO of the following are examples of session hijacking attacks? (Select 2)
Malware, Social Engineering and Network AttackseasySee the answer and why each option is right or wrong →During a penetration test, you discover an LDAP server on port 389 that allows anonymous binds. Which of the following enumeration techniques would provide the MOST comprehensive i…
Which THREE of the following are valid techniques in the system hacking methodology (CHPSET)? (Choose three.)
Which of the following is a passive OS fingerprinting technique?
A penetration tester runs the following command: masscan 10.0.0.0/24 -p80,443,8080 --rate=10000. Compared to Nmap, what is the PRIMARY advantage of using Masscan for this scan?
Footprinting, Reconnaissance and ScanningmediumSee the answer and why each option is right or wrong →