Courseiva

CEH · topic practice

Malware, Social Engineering and Network Attacks practice questions

This CEH domain covers malware types and behavior, social-engineering techniques, and network-layer attacks such as sniffing, session hijacking, DoS, and switch attacks. Questions present a scenario or traffic symptom and ask you to identify the attack, malware category, or the tool/protocol involved, so you must map evidence to the correct technique.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Malware, Social Engineering and Network Attacks

What the exam tests

What to know about Malware, Social Engineering and Network Attacks

Be able to read a scenario or packet symptom and name the exact malware type or network attack, plus the protocol or tool evidence that proves it. The single most important skill is distinguishing similar attacks by their mechanism, such as CAM-table overflow versus ARP cache poisoning.

Identifying malware families: virus, worm, trojan, ransomware, rootkit, spyware, keylogger, logic bomb, and their propagation or payload behavior

Recognizing social-engineering vectors: phishing, spear phishing, vishing, smishing, pretexting, baiting, tailgating, and impersonation

Detecting network attacks: ARP poisoning, MAC flooding, DHCP starvation, DNS tunneling, session hijacking, and DoS/DDoS

Using tools and protocols such as Wireshark, tcpdump, Nmap, Netcat, and analyzing TCP sequence numbers, DNS, and CAM tables

Watch out for

Common Malware, Social Engineering and Network Attacks exam traps

  • ▸Confusing worms with viruses: worms self-propagate across networks without user action, while viruses need a host file or user execution to spread
  • ▸Mixing up MAC flooding and ARP poisoning: MAC flooding overflows the CAM table to force flooding, while ARP poisoning maps an attacker's MAC to a victim's IP
  • ▸Assuming any large DNS response means DNS tunneling: large TXT or encoded responses to one host suggest exfiltration, but normal CDN or DNSSEC traffic can also be large

Practice set

Malware, Social Engineering and Network Attacks questions

20 questions · select your answer, then reveal the explanation

A user receives a phone call from someone claiming to be from IT support, asking for their password to troubleshoot an issue. Which social engineering technique is being used?

An analyst observes the following output from Wireshark: a TCP packet with the SYN flag set, followed by a SYN-ACK, then an ACK, and then a RST. The sequence numbers show a pattern: initial seq=100, ack=300, then seq=300, ack=101. What is the MOST likely interpretation?

Question 3hardmultiple choice
Read the full DNS explanation →

An IDS alerts on a large number of outbound DNS queries from an internal host to a suspicious domain. The queries have random subdomains and the response size is large. Which attack is MOST likely in progress?

A security analyst receives an alert indicating that a host on the internal network is sending a high volume of ICMP echo requests to multiple external IP addresses. The analyst notices that the source IP address is spoofed. Which type of attack is MOST likely occurring?

Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)

Which TWO types of malware typically require user interaction (e.g., opening a file or clicking a link) to activate? (Select two.)

A security analyst notices repeated failed login attempts from a single external IP address targeting the company's webmail portal. The attempts use common usernames like 'admin', 'user', and 'test'. Which type of social engineering attack is MOST likely being attempted?

Which THREE of the following are examples of application-layer DDoS attacks? (Select 3)

Which TWO of the following are characteristics of a polymorphic virus? (Select 2)

Which THREE of the following are effective DDoS mitigation techniques? (Select 3)

A security analyst observes repeated failed login attempts from a single IP address targeting multiple user accounts. Which type of social engineering attack is being attempted?

During a penetration test, you discover a process named 'svch0st.exe' running on a Windows server with high CPU usage. The file is not digitally signed. Which type of malware is MOST likely present?

An attacker sends an email that appears to come from the CEO, requesting that the recipient urgently transfer funds to a specified account. Which type of social engineering attack is this?

An attacker wants to perform a man-in-the-middle attack on a local network. Which two tools from the following list would be most effective? (Select the best answer from the options below; note: this is a multiple choice, not multi-select) A) Wireshark B) Ettercap C) Nmap D) Metasploit E) Aircrack-ng

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

Which of the following is a characteristic of a polymorphic virus?

Question 17mediummultiple choice
Read the full DNS explanation →

A company wants to defend against DNS amplification attacks. Which mitigation technique would be MOST effective?

Which THREE of the following are common indicators of a man-in-the-middle attack using ARP spoofing? (Choose three.)

Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)

Which THREE of the following are static malware analysis techniques? (Select 3)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Malware, Social Engineering and Network Attacks sessions

Start a Malware, Social Engineering and Network Attacks only practice session

Every question in these sessions is drawn from the Malware, Social Engineering and Network Attacks domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Frequently asked questions

What does the CEH exam test about Malware, Social Engineering and Network Attacks?
Be able to read a scenario or packet symptom and name the exact malware type or network attack, plus the protocol or tool evidence that proves it. The single most important skill is distinguishing similar attacks by their mechanism, such as CAM-table overflow versus ARP cache poisoning.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Malware, Social Engineering and Network Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Malware, Social Engineering and Network Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.