Courseiva

CEH · topic practice

Enumeration and System Hacking practice questions

This domain covers post-exploitation fundamentals: enumerating users, shares, and services (SMB, LDAP, SNMP, NetBIOS), then gaining access via password attacks and privilege escalation, and finally covering tracks. CEH tests tool-to-task matching, offline hash cracking, and Windows event log manipulation commands, so expect scenario-based questions with multi-select answers.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Enumeration and System Hacking

What the exam tests

What to know about Enumeration and System Hacking

You must match enumeration tools to protocols, identify offline hash-cracking tools, and recognize track-covering commands like wevtutil cl system. The most important thing: know which tools work without authentication and which commands destroy evidence.

Anonymous LDAP enumeration of Windows domain users and groups using ldapsearch or enum4linux

Offline password hash cracking with John the Ripper, Hashcat, or Cain & Abel

Covering tracks by clearing Windows event logs with wevtutil cl system

SMB, SNMP, and NetBIOS enumeration using nmap, snmpwalk, and nbtstat

Watch out for

Common Enumeration and System Hacking exam traps

  • ▸Assuming LDAP enumeration always requires credentials; anonymous binds are often enabled and tested
  • ▸Confusing online password attacks (brute-force against live services) with offline hash cracking tools
  • ▸Mixing up wevtutil cl (clear log) with wevtutil qe (query events) or other log manipulation commands

Practice set

Enumeration and System Hacking questions

20 questions · select your answer, then reveal the explanation

During a penetration test, you gain access to a target system as a low-privileged user. Which of the following is the BEST next step according to the CEH system hacking methodology (CHPSET)?

During a penetration test, you successfully execute a privilege escalation attack by abusing a service running with SYSTEM privileges on a Windows machine. Which of the following techniques is MOST likely being used?

Which TWO of the following are valid SMTP enumeration commands that can be used to discover valid email addresses? (Select 2)

A penetration tester obtains password hashes from a Windows system. Which TWO methods would be most efficient for cracking NTLM hashes offline? (Choose two.)

Which of the following is the correct order of phases in the system hacking methodology known as CHPSET?

Question 6mediummultiple choice
Read the full VRF explanation →

During a penetration test, a tester uses the SMTP VRFY command against a mail server. The server responds with '252 Cannot VRFY user, but will accept message' for most usernames. Which action should the tester take to enumerate valid email addresses more effectively?

Which TWO of the following are common techniques for covering tracks after compromising a system? (Select 2)

An attacker has gained access to a Linux server and wants to cover their tracks. They edit the `.bash_history` file, modify system logs in `/var/log`, and install a kernel module that hides their processes. Which two steps of the system hacking methodology (CHPSET) are being performed?

An attacker gains access to a Linux web server as the 'www-data' user. They run `find / -perm -4000 -type f 2>/dev/null` and see that `/usr/bin/passwd` has the SUID bit set. Which privilege escalation technique is this command checking for?

Which TWO of the following are enumeration techniques used to gather information from Windows systems? (Select 2)

A penetration tester runs the following Nmap command: nmap -sS -sV -O -p 22,80,443,3389 192.168.1.0/24. Which of the following BEST describes what this scan will accomplish?

A security consultant is performing a penetration test against an Active Directory environment. The consultant has obtained domain user credentials but no administrative access. The consultant runs 'net user /domain' and observes a list of domain users. To identify which accounts have elevated privileges, the consultant wants to enumerate members of the Domain Admins group without using LDAP queries that might be logged. Which command should the consultant use?

A penetration tester has gained access to a Windows 10 workstation and wants to escalate privileges to SYSTEM. The tester decides to use the Windows Task Scheduler to create a task that runs with highest privileges. Which two actions must the tester perform to successfully create and execute the task for privilege escalation? (Choose two.)

A penetration tester is performing a password attack against a Windows Active Directory environment. The tester has captured NTLM hashes from a compromised workstation and wants to crack them offline. Which tool is specifically designed for cracking NTLM hashes and supports both brute-force and dictionary attacks?

A security analyst wants to enumerate NetBIOS names on a Windows network. Which built-in Windows command-line tool should they use?

A security analyst observes a suspicious SUID binary /usr/bin/evil in a Linux system. Which type of vulnerability does this indicate, and what is the MOST likely objective of an attacker who placed it?

A penetration tester runs the following command against a target Linux server: smbclient -L 192.168.1.10 -N. The output lists several shares including 'Admin$', 'C$', and 'IPC$'. Which of the following is the MOST likely next step for further enumeration?

Question 18mediummultiple choice
Read the full VRF explanation →

An attacker uses the VRFY command on an SMTP server to check the existence of email addresses. The server responds with '250 OK' for 'admin@company.com' and '550 No such user' for 'fake@company.com'. Which SMTP enumeration technique is being used?

A security analyst finds multiple failed login attempts in the system logs, followed by a successful login from an unusual IP address. The attacker then deleted the log entries for that session. Which step of the system hacking methodology (CHPSET) does the log deletion represent?

Which of the following tools is specifically designed to perform password cracking using rainbow tables?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Enumeration and System Hacking sessions

Start a Enumeration and System Hacking only practice session

Every question in these sessions is drawn from the Enumeration and System Hacking domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Frequently asked questions

What does the CEH exam test about Enumeration and System Hacking?
You must match enumeration tools to protocols, identify offline hash-cracking tools, and recognize track-covering commands like wevtutil cl system. The most important thing: know which tools work without authentication and which commands destroy evidence.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Enumeration and System Hacking questions in a focused session?
Yes — the session launcher on this page draws every question from the Enumeration and System Hacking domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.