Courseiva
← Back to Certified Ethical Hacker CEH questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Ethical Hacker CEH practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CEH
exam code
EC-Council
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CEH topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which TWO of the following tools are capable of cracking password hashes offline? (Select 2)

Question 2hardmulti select
Full question →

Which THREE of the following are valid techniques for covering tracks after compromising a system? (Select 3 correct answers)

Question 3mediummulti select
Full question →

Which THREE of the following are common indicators of a buffer overflow vulnerability?

Question 4easymulti select
Full question →

Which TWO of the following are considered passive reconnaissance techniques? (Choose TWO.)

Question 5easymulti select
Full question →

Which TWO of the following are examples of session hijacking attacks? (Select 2)

Question 6mediummulti select
Full question →

Which THREE of the following are valid techniques in the system hacking methodology (CHPSET)? (Choose three.)

Which TWO of the following are effective countermeasures against SNMP enumeration attacks? (Select 2)

Question 8easymulti select
Full question →

Which TWO of the following are types of malware analysis? (Select two.)

Question 9hardmulti select
Full question →

Which TWO of the following are effective physical security controls to prevent tailgating?

Question 10mediummulti select
Full question →

Which TWO of the following are valid enumeration techniques? (Select 2)

Question 11mediummulti select
Full question →

Which TWO of the following are examples of amplification attacks used in DDoS?

Question 12hardmulti select
Full question →

Which THREE of the following are effective techniques to prevent ARP poisoning attacks? (Choose three.)

Question 13easymulti select
Full question →

Which TWO of the following are common techniques used to cover tracks after compromising a system? (Choose TWO.)

Which TWO types of information can be obtained through SNMP enumeration on a target device if the community string is 'public'? (Choose two.)

Question 15easymulti select
Full question →

Which TWO of the following are types of malware analysis? (Select 2)

Question 16mediummulti select
Full question →

Which TWO of the following are valid methods for enumerating SMB shares on a target system? (Select 2)

Question 17hardmulti select
Full question →

During a penetration test, the tester successfully cracks a password hash using a hybrid attack. Which THREE characteristics describe a hybrid attack? (Select three.)

Question 18mediummulti select
Full question →

Which TWO of the following are effective mitigations against Cross-Site Request Forgery (CSRF)?

Question 19mediummulti select
Full question →

Which TWO of the following are effective mitigation techniques against DDoS attacks? (Select two)

Question 20hardmulti select
Full question →

Which THREE of the following are components of the CHPSET system hacking methodology? (Select three.)

These CEH practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style CEH questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.