Courseiva
Enumeration and System HackinghardMultiple SelectObjective-mapped

CEH CHPSET Practice Question

Which THREE of the following are components of the CHPSET system hacking methodology? (Select three.)

⚠ Common exam trap

Candidates may incorrectly select Hiding files (B) as a separate phase, but the CHPSET methodology lists 'Hiding' as a broad phase that can include various hiding techniques. The specific term 'Hiding files' is not a phase. Others may include Scanning ports (D) due to its prevalence in earlier stages, but it is not part of the system hacking phases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sniffing network traffic

The CHPSET system hacking methodology includes six phases: Cracking (C), Hiding (H), Privilege Escalation (P), Sniffing (S), Executing (E), and Targeting (T). Among the given options, Sniffing network traffic (A) corresponds to Sniffing, Cracking passwords (C) to Cracking, and Executing applications (E) to Executing. Hiding files (B) is a specific activity under the Hiding phase but is not a distinct phase itself. Scanning ports (D) is a reconnaissance step performed during the pre-hacking phase, not part of CHPSET. Therefore, the three correct components are A, C, and E.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sniffing network traffic

    Why this is correct

    Sniffing network traffic is a fundamental component of the CHPSET (Cracking, Hiding, Planting, Sniffing, Executing, Erasing) methodology, specifically corresponding to the 'Sniffing' phase. This involves passively capturing and analyzing data packets traversing a network segment to intercept sensitive information such as credentials, session tokens, or proprietary data. Attackers utilize tools like Wireshark or tcpdump to monitor network communications, gaining insights into network topology and identifying potential vulnerabilities for further exploitation.

  • Hiding files

    Why it's wrong here

    "Hiding files" is an incorrect answer because while "Hiding" is indeed a phase within the CHPSET methodology, the term "Hiding files" is overly narrow and specific. The comprehensive 'Hiding' phase encompasses a broader range of post-exploitation activities, including concealing malicious processes, rootkits, and backdoors, as well as manipulating log files to cover tracks, not solely limited to file-level concealment. This phase aims to maintain persistence and evade detection by security mechanisms.

  • Cracking passwords

    Why this is correct

    Cracking passwords is a direct and critical component of the CHPSET methodology, aligning with the 'Cracking' phase. This process involves attempting to discover user passwords, often from captured hashes or by brute-forcing login attempts, to gain unauthorized access to systems, applications, or user accounts. Tools like Hashcat or John the Ripper are commonly employed to accelerate this computationally intensive process, leveraging dictionary attacks, rainbow tables, or brute-force techniques.

  • Scanning ports

    Why it's wrong here

    Scanning ports is an incorrect answer because it primarily constitutes a reconnaissance activity, typically performed during the initial phases of an attack, such as footprinting and scanning, which precede the system hacking (CHPSET) methodology. While crucial for identifying open services and potential entry points, port scanning is a discovery mechanism rather than a direct component of the post-exploitation or system interaction phases defined by CHPSET. It helps identify targets for CHPSET, but is not part of CHPSET itself.

  • Executing applications

    Why this is correct

    Executing applications is a core phase within the CHPSET methodology, specifically the 'Executing' component. This involves running malicious code, scripts, or programs on a compromised system to achieve various objectives, such as escalating privileges, installing backdoors, or exfiltrating data. Attackers leverage this phase to deploy payloads, establish command-and-control communication, and further their control over the target environment.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.