Courseiva
Enumeration and System HackingeasyMultiple ChoiceObjective-mapped

CEH Enumeration and System Hacking Practice Question

Which of the following is the PRIMARY purpose of steganography in the context of covering tracks after a system compromise?

⚠ Common exam trap

Candidates often confuse steganography with encryption or log manipulation, mistakenly thinking its primary purpose is to secure data (like encryption) or to remove evidence (like log deletion), rather than to conceal the existence of the data itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To hide data within other files to avoid detection

The primary purpose of steganography in covering tracks is to hide stolen data or malicious payloads within innocuous files (e.g., images, audio, video) so that forensic tools and analysts do not detect the exfiltration or persistence. Unlike encryption, which makes data unreadable but still visible, steganography conceals the very existence of the hidden data, allowing an attacker to bypass network monitoring and file inspection. This aligns with the CEH objective of covering tracks by avoiding detection of unauthorized data transfers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To hide data within other files to avoid detection

    Why this is correct

    Steganography's core purpose is to embed secret information within seemingly innocuous digital media, such as images, audio, or video files. This technique aims to conceal the very existence of the hidden data, making it difficult for an observer to even suspect that secret communication is taking place. Unlike encryption, which scrambles data, steganography focuses on covert communication by making the data appear as part of a benign carrier file, thereby avoiding detection.

  • To create a backdoor for future access

    Why it's wrong here

    Creating a backdoor involves establishing a covert method to bypass normal authentication or security controls for future unauthorized access to a system. While steganography could potentially be used to hide the communication channel for a backdoor or even the backdoor payload itself, its primary function is data concealment, not the creation of the access mechanism. The act of developing and deploying a backdoor is a distinct malicious activity focused on persistent system access, separate from the technique of hiding information.

  • To delete system logs permanently

    Why it's wrong here

    Deleting system logs permanently is a post-exploitation technique aimed at removing forensic evidence of an attacker's presence and activities on a compromised system. This action directly destroys records of events, making it harder for incident responders to trace the attack chain or identify compromised data. Steganography, conversely, involves embedding data within existing files rather than eradicating system records, serving a fundamentally different purpose in the attack lifecycle.

  • To encrypt log files so they cannot be read

    Why it's wrong here

    Encrypting log files transforms their content into an unreadable format using an algorithm and a key, ensuring confidentiality so that only authorized parties can decrypt and access the information. This process protects the data's content from unauthorized disclosure, but the existence of the encrypted file itself is not hidden. Steganography's objective is to obscure the existence of the secret data altogether, embedding it invisibly within a cover object, which is distinct from merely rendering data unintelligible through encryption.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.