CEH CHPSET Practice Question
Which THREE of the following are components of the CHPSET system hacking methodology? (Select three.)
⚠ Common exam trap
Candidates may incorrectly select Hiding files (B) as a separate phase, but the CHPSET methodology lists 'Hiding' as a broad phase that can include various hiding techniques. The specific term 'Hiding files' is not a phase. Others may include Scanning ports (D) due to its prevalence in earlier stages, but it is not part of the system hacking phases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sniffing network traffic
The CHPSET system hacking methodology includes six phases: Cracking (C), Hiding (H), Privilege Escalation (P), Sniffing (S), Executing (E), and Targeting (T). Among the given options, Sniffing network traffic (A) corresponds to Sniffing, Cracking passwords (C) to Cracking, and Executing applications (E) to Executing. Hiding files (B) is a specific activity under the Hiding phase but is not a distinct phase itself. Scanning ports (D) is a reconnaissance step performed during the pre-hacking phase, not part of CHPSET. Therefore, the three correct components are A, C, and E.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sniffing network traffic
Why this is correct
Sniffing network traffic is a fundamental component of the CHPSET (Cracking, Hiding, Planting, Sniffing, Executing, Erasing) methodology, specifically corresponding to the 'Sniffing' phase. This involves passively capturing and analyzing data packets traversing a network segment to intercept sensitive information such as credentials, session tokens, or proprietary data. Attackers utilize tools like Wireshark or tcpdump to monitor network communications, gaining insights into network topology and identifying potential vulnerabilities for further exploitation.
- ✗
Hiding files
Why it's wrong here
"Hiding files" is an incorrect answer because while "Hiding" is indeed a phase within the CHPSET methodology, the term "Hiding files" is overly narrow and specific. The comprehensive 'Hiding' phase encompasses a broader range of post-exploitation activities, including concealing malicious processes, rootkits, and backdoors, as well as manipulating log files to cover tracks, not solely limited to file-level concealment. This phase aims to maintain persistence and evade detection by security mechanisms.
- ✓
Cracking passwords
Why this is correct
Cracking passwords is a direct and critical component of the CHPSET methodology, aligning with the 'Cracking' phase. This process involves attempting to discover user passwords, often from captured hashes or by brute-forcing login attempts, to gain unauthorized access to systems, applications, or user accounts. Tools like Hashcat or John the Ripper are commonly employed to accelerate this computationally intensive process, leveraging dictionary attacks, rainbow tables, or brute-force techniques.
- ✗
Scanning ports
Why it's wrong here
Scanning ports is an incorrect answer because it primarily constitutes a reconnaissance activity, typically performed during the initial phases of an attack, such as footprinting and scanning, which precede the system hacking (CHPSET) methodology. While crucial for identifying open services and potential entry points, port scanning is a discovery mechanism rather than a direct component of the post-exploitation or system interaction phases defined by CHPSET. It helps identify targets for CHPSET, but is not part of CHPSET itself.
- ✓
Executing applications
Why this is correct
Executing applications is a core phase within the CHPSET methodology, specifically the 'Executing' component. This involves running malicious code, scripts, or programs on a compromised system to achieve various objectives, such as escalating privileges, installing backdoors, or exfiltrating data. Attackers leverage this phase to deploy payloads, establish command-and-control communication, and further their control over the target environment.
Go deeper
Related to this question
Learn chapter
Introduction to Ethical Hacking
Key term
Covering Tracks
Covering tracks is the process attackers use to hide their activity and remove evidence of a security breach after gaining unauthorized access to a system.
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.