CEH Enumeration and System Hacking Practice Question
Which THREE of the following are valid techniques in the system hacking methodology (CHPSET)? (Choose three.)
⚠ Common exam trap
Test-takers frequently confuse the CHPSET system hacking methodology with the broader ethical hacking phases (reconnaissance, scanning, gaining access, etc.), leading them to incorrectly select social engineering or network sniffing as valid CHPSET steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privilege escalation
In the CEH system hacking methodology (often summarized as CHPSET: Cracking passwords, Hiding files, Privilege escalation, Executing applications, Covering tracks/erasing tracks, and Creating backdoors), privilege escalation (A) is a core step because after gaining initial access the attacker elevates from a low-privileged account to root/SYSTEM or administrator rights to fully control the target. Erasing tracks (C) is also a core step, covering log tampering, clearing event logs, disabling auditing, and removing artifacts so the intrusion is not detected or attributed. Cracking passwords (E) is the first phase of CHPSET, where techniques such as dictionary, brute-force, rainbow-table, and hybrid attacks recover or bypass credentials to obtain valid access. Social engineering (B) is not part of the system hacking methodology; it belongs to the earlier footprinting/scanning or social-engineering phase of the CEH attack lifecycle. Network sniffing (D) is likewise a separate CEH domain (sniffing), used for capturing traffic, not a step in the CHPSET system hacking sequence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privilege escalation
Why this is correct
This technique is fundamental to system hacking, involving the attacker gaining higher-level access rights than initially obtained on a compromised system. It is crucial for achieving full control, accessing sensitive data, or installing persistent backdoors. Methods often include exploiting kernel vulnerabilities, misconfigured services, or weak file permissions to transition from a standard user to an administrator or root user.
- ✗
Social engineering
Why it's wrong here
Social engineering is an initial access vector that manipulates individuals into divulging confidential information or performing actions that compromise security, rather than a direct system hacking technique. While it can lead to system compromise, it operates on human psychology and trust, preceding the technical actions performed on a system during the system hacking phase. It's distinct from the post-exploitation activities within a compromised host.
- ✓
Erasing tracks
Why this is correct
Erasing tracks is a critical post-exploitation phase in system hacking, where an attacker meticulously removes all evidence of their presence and activities on the compromised system. This involves clearing system logs, modifying file timestamps, deleting temporary files, and removing any installed tools or backdoors. The primary goal is to maintain stealth, prevent detection by forensic analysis, and ensure continued access without alerting administrators.
- ✗
Network sniffing
Why it's wrong here
Network sniffing involves passively capturing and analyzing data packets traversing a network segment. While it is a valuable reconnaissance and information gathering technique, often used to obtain credentials or sensitive data from the network, it is not considered a core system hacking technique. System hacking focuses on direct interaction and manipulation of the compromised host's operating system and applications, whereas sniffing primarily operates at the network layer.
- ✓
Cracking passwords
Why this is correct
Cracking passwords is a vital system hacking technique used to obtain plain-text credentials from hashed or encrypted forms found on a compromised system. Attackers often extract password hashes from system files (e.g., SAM database, /etc/shadow) and then employ brute-force, dictionary, or rainbow table attacks offline to recover the original passwords. This enables access to other user accounts, privilege escalation, or lateral movement within the network.
Go deeper
Related to this question
Learn chapter
Hacking Web Applications
Key term
Nmap Scanning
Nmap scanning is a method used to discover devices running on a network and find open ports, services, and security weaknesses.
Key term
Covering Tracks
Covering tracks is the process attackers use to hide their activity and remove evidence of a security breach after gaining unauthorized access to a system.
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.