Courseiva

CEH Enumeration and System Hacking Practice Question

Which THREE of the following are valid techniques in the system hacking methodology (CHPSET)? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse the CHPSET system hacking methodology with the broader ethical hacking phases (reconnaissance, scanning, gaining access, etc.), leading them to incorrectly select social engineering or network sniffing as valid CHPSET steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privilege escalation

In the CEH system hacking methodology (often summarized as CHPSET: Cracking passwords, Hiding files, Privilege escalation, Executing applications, Covering tracks/erasing tracks, and Creating backdoors), privilege escalation (A) is a core step because after gaining initial access the attacker elevates from a low-privileged account to root/SYSTEM or administrator rights to fully control the target. Erasing tracks (C) is also a core step, covering log tampering, clearing event logs, disabling auditing, and removing artifacts so the intrusion is not detected or attributed. Cracking passwords (E) is the first phase of CHPSET, where techniques such as dictionary, brute-force, rainbow-table, and hybrid attacks recover or bypass credentials to obtain valid access. Social engineering (B) is not part of the system hacking methodology; it belongs to the earlier footprinting/scanning or social-engineering phase of the CEH attack lifecycle. Network sniffing (D) is likewise a separate CEH domain (sniffing), used for capturing traffic, not a step in the CHPSET system hacking sequence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Privilege escalation

    Why this is correct

    This technique is fundamental to system hacking, involving the attacker gaining higher-level access rights than initially obtained on a compromised system. It is crucial for achieving full control, accessing sensitive data, or installing persistent backdoors. Methods often include exploiting kernel vulnerabilities, misconfigured services, or weak file permissions to transition from a standard user to an administrator or root user.

  • ✗

    Social engineering

    Why it's wrong here

    Social engineering is an initial access vector that manipulates individuals into divulging confidential information or performing actions that compromise security, rather than a direct system hacking technique. While it can lead to system compromise, it operates on human psychology and trust, preceding the technical actions performed on a system during the system hacking phase. It's distinct from the post-exploitation activities within a compromised host.

  • ✓

    Erasing tracks

    Why this is correct

    Erasing tracks is a critical post-exploitation phase in system hacking, where an attacker meticulously removes all evidence of their presence and activities on the compromised system. This involves clearing system logs, modifying file timestamps, deleting temporary files, and removing any installed tools or backdoors. The primary goal is to maintain stealth, prevent detection by forensic analysis, and ensure continued access without alerting administrators.

  • ✗

    Network sniffing

    Why it's wrong here

    Network sniffing involves passively capturing and analyzing data packets traversing a network segment. While it is a valuable reconnaissance and information gathering technique, often used to obtain credentials or sensitive data from the network, it is not considered a core system hacking technique. System hacking focuses on direct interaction and manipulation of the compromised host's operating system and applications, whereas sniffing primarily operates at the network layer.

  • ✓

    Cracking passwords

    Why this is correct

    Cracking passwords is a vital system hacking technique used to obtain plain-text credentials from hashed or encrypted forms found on a compromised system. Attackers often extract password hashes from system files (e.g., SAM database, /etc/shadow) and then employ brute-force, dictionary, or rainbow table attacks offline to recover the original passwords. This enables access to other user accounts, privilege escalation, or lateral movement within the network.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.