CEH Certified Ethical Hacker Exam — Questions and Answers
Question 1: Which metric best measures Cryptography effectiveness?
- Amount of documentation produced
- Number of meetings held about the topic
- Budget spent on related tools
- Domain-specific KPIs aligned with defined objectives (Correct answer)
Correct answer: Domain-specific KPIs aligned with defined objectives
Effectiveness of Cryptography is best measured through KPIs that align with defined objectives.
Question 2: What role does automation play in Scanning Networks?
- Replacing all human involvement entirely
- Only automating documentation-related tasks
- Automating repetitive tasks while maintaining human oversight (Correct answer)
- Automation is not applicable to this area
Correct answer: Automating repetitive tasks while maintaining human oversight
Automation enhances Scanning Networks by handling repetitive tasks while humans maintain strategic oversight.
Question 3: How is Cryptography tested or validated in practice?
- Testing is not possible for this area
- Through regular testing, audits, and structured validation exercises (Correct answer)
- Only tested during the initial setup phase
- It is never tested or validated
Correct answer: Through regular testing, audits, and structured validation exercises
Cryptography should be regularly tested and validated through appropriate exercises and audits.
Question 4: How does Web Server and Application Hacking handle change management?
- All changes happen immediately without review
- Changes are not allowed once implemented
- Through controlled processes that assess impact before changes (Correct answer)
- Change management is handled separately
Correct answer: Through controlled processes that assess impact before changes
Changes to Web Server and Application Hacking should follow controlled processes with proper impact assessment.
Question 5: What is the relationship between Web Server and Application Hacking and security?
- Web Server and Application Hacking replaces all other security measures
- Security only applies to network-related topics
- Security is completely unrelated to this topic
- Web Server and Application Hacking includes security considerations as an integral component (Correct answer)
Correct answer: Web Server and Application Hacking includes security considerations as an integral component
Security is an integral part of Web Server and Application Hacking, ensuring that implementations are protected and compliant.
Question 6: How does Vulnerability Analysis handle change management?
- Through controlled processes that assess impact before changes (Correct answer)
- Changes are not allowed once implemented
- All changes happen immediately without review
- Change management is handled separately
Correct answer: Through controlled processes that assess impact before changes
Changes to Vulnerability Analysis should follow controlled processes with proper impact assessment.
Question 7: How does Web Server and Application Hacking contribute to continuous improvement?
- By preventing any changes to existing processes
- Through regular assessment, feedback loops, and iterative enhancement (Correct answer)
- By maintaining the status quo indefinitely
- Through one-time implementation only
Correct answer: Through regular assessment, feedback loops, and iterative enhancement
Continuous improvement in Web Server and Application Hacking comes from regular assessment and iterative enhancement cycles.
Question 8: What is the relationship between Footprinting and Reconnaissance and security?
- Footprinting and Reconnaissance replaces all other security measures
- Security only applies to network-related topics
- Footprinting and Reconnaissance includes security considerations as an integral component (Correct answer)
- Security is completely unrelated to this topic
Correct answer: Footprinting and Reconnaissance includes security considerations as an integral component
Security is an integral part of Footprinting and Reconnaissance, ensuring that implementations are protected and compliant.
Question 9: How does Sniffing and Social Engineering deliver business value?
- It provides no measurable business value
- By reducing risk, improving efficiency, and enabling informed decisions (Correct answer)
- Only through direct cost savings
- By increasing organizational complexity
Correct answer: By reducing risk, improving efficiency, and enabling informed decisions
Sniffing and Social Engineering delivers business value through risk reduction, efficiency gains, and informed decision-making.
Question 10: How should Denial-of-Service Attacks be budgeted?
- No budget allocation is needed for this area
- Allocate maximum available budget always
- Allocate minimum possible budget always
- Based on risk assessment, expected ROI, and organizational priorities (Correct answer)
Correct answer: Based on risk assessment, expected ROI, and organizational priorities
Budget for Denial-of-Service Attacks should be based on risk assessment, expected ROI, and organizational priorities.
Question 11: What risk does poor implementation of System Hacking and Password Cracking create?
- Increased vulnerability to failures and compliance issues (Correct answer)
- No risks exist with any implementation approach
- Only financial risks are relevant
- Risks only affect external stakeholders
Correct answer: Increased vulnerability to failures and compliance issues
Poor System Hacking and Password Cracking implementation increases vulnerability to failures, compliance issues, and operational problems.
Question 12: What tools and platforms support Sniffing and Social Engineering implementation?
- No tools exist for this purpose
- Purpose-built tools and platforms specific to this domain (Correct answer)
- Only spreadsheets are used in practice
- Social media platforms are the primary tool
Correct answer: Purpose-built tools and platforms specific to this domain
Specialized tools and platforms exist to support Sniffing and Social Engineering implementation and management effectively.
Question 13: How should Footprinting and Reconnaissance be communicated to stakeholders?
- Regular updates with clear, actionable information and metrics (Correct answer)
- Only through annual comprehensive reports
- Only when significant problems occur
- Never communicate about this topic
Correct answer: Regular updates with clear, actionable information and metrics
Stakeholder communication about Footprinting and Reconnaissance should be regular with clear, actionable information.
Question 14: What common mistake is made when implementing Footprinting and Reconnaissance?
- Involving too many stakeholders in decisions
- Over-planning before taking any action
- Using too many automation tools at once
- Skipping proper planning and rushing to implementation (Correct answer)
Correct answer: Skipping proper planning and rushing to implementation
A common mistake with Footprinting and Reconnaissance is rushing implementation without proper planning and assessment.
Question 15: What exam preparation tips apply to Sniffing and Social Engineering?
- Memorize everything without understanding the concepts
- Skip this topic entirely on the exam
- Understand core concepts, practice with scenarios, and learn key terminology (Correct answer)
- Only study the night before the exam
Correct answer: Understand core concepts, practice with scenarios, and learn key terminology
For Sniffing and Social Engineering exam preparation, focus on core concepts, scenario practice, and proper terminology.
Question 16: How is Scanning Networks tested or validated in practice?
- Only tested during the initial setup phase
- Through regular testing, audits, and structured validation exercises (Correct answer)
- It is never tested or validated
- Testing is not possible for this area
Correct answer: Through regular testing, audits, and structured validation exercises
Scanning Networks should be regularly tested and validated through appropriate exercises and audits.
Question 17: What is the difference between strategic and tactical approaches to Vulnerability Analysis?
- They are exactly the same approach
- Tactical approaches are never used in practice
- Strategic focuses on long-term goals; tactical on immediate implementation (Correct answer)
- Strategic approaches are always superior
Correct answer: Strategic focuses on long-term goals; tactical on immediate implementation
Strategic Vulnerability Analysis addresses long-term objectives while tactical focuses on immediate implementation.
Question 18: During a wireless penetration test, you use 'aireplay-ng -0 5 -a [BSSID] -c [client MAC]'. What does the '-0 5' parameter accomplish?
- Injects 5 ARP replay packets per second
- Sets the channel to 5 for monitoring
- Reduces transmission power to 5 dBm to avoid detection
- Sends 5 deauthentication frames to the specified client to force reauthentication (Correct answer)
Correct answer: Sends 5 deauthentication frames to the specified client to force reauthentication
The '-0' flag in aireplay-ng specifies a deauthentication attack, and '5' sets the number of deauth packets to send, forcing the client to disconnect and reconnect so the handshake can be captured.
Question 19: How should Scanning Networks be budgeted?
- Allocate minimum possible budget always
- Based on risk assessment, expected ROI, and organizational priorities (Correct answer)
- Allocate maximum available budget always
- No budget allocation is needed for this area
Correct answer: Based on risk assessment, expected ROI, and organizational priorities
Budget for Scanning Networks should be based on risk assessment, expected ROI, and organizational priorities.
Question 20: What is the lifecycle of Web Server and Application Hacking?
- Only plan without ever implementing
- Implement once and never revisit the topic
- Skip directly to monitoring without planning
- Plan, implement, monitor, review, and improve continuously (Correct answer)
Correct answer: Plan, implement, monitor, review, and improve continuously
The Web Server and Application Hacking lifecycle follows plan-implement-monitor-review-improve in a continuous cycle.
Question 21: What role does automation play in Footprinting and Reconnaissance?
- Automating repetitive tasks while maintaining human oversight (Correct answer)
- Only automating documentation-related tasks
- Replacing all human involvement entirely
- Automation is not applicable to this area
Correct answer: Automating repetitive tasks while maintaining human oversight
Automation enhances Footprinting and Reconnaissance by handling repetitive tasks while humans maintain strategic oversight.
Question 22: During a WPA2-Personal attack, an attacker captures the four-way handshake. What is the attacker's next step to crack the passphrase?
- Send deauthentication frames continuously to the client
- Perform a dictionary or brute-force attack against the captured EAPOL handshake offline (Correct answer)
- Inject ARP packets to generate traffic
- Exploit a buffer overflow in the access point firmware
Correct answer: Perform a dictionary or brute-force attack against the captured EAPOL handshake offline
The captured four-way handshake contains enough information to perform an offline dictionary or brute-force attack to guess the pre-shared key without further interaction with the network.
Question 23: What risk does poor implementation of Vulnerability Analysis create?
- Increased vulnerability to failures and compliance issues (Correct answer)
- Only financial risks are relevant
- Risks only affect external stakeholders
- No risks exist with any implementation approach
Correct answer: Increased vulnerability to failures and compliance issues
Poor Vulnerability Analysis implementation increases vulnerability to failures, compliance issues, and operational problems.
Question 24: How is success in System Hacking and Password Cracking measured and evaluated?
- By passing the certification exam only
- By completing all documentation requirements
- By spending the entire allocated budget
- By meeting defined objectives with measurable outcomes and stakeholder satisfaction (Correct answer)
Correct answer: By meeting defined objectives with measurable outcomes and stakeholder satisfaction
Success is defined by meeting objectives with measurable outcomes and stakeholder satisfaction.
Question 25: What prerequisite knowledge is needed for Introduction to Ethical Hacking?
- Ten years of management experience minimum
- Understanding of foundational concepts and organizational context (Correct answer)
- Advanced programming skills only
- No prerequisites exist for this topic
Correct answer: Understanding of foundational concepts and organizational context
Effective work with Introduction to Ethical Hacking requires understanding foundational concepts and organizational context.
Question 26: What common mistake is made when implementing Denial-of-Service Attacks?
- Over-planning before taking any action
- Using too many automation tools at once
- Skipping proper planning and rushing to implementation (Correct answer)
- Involving too many stakeholders in decisions
Correct answer: Skipping proper planning and rushing to implementation
A common mistake with Denial-of-Service Attacks is rushing implementation without proper planning and assessment.
Question 27: What is a best practice for Enumeration Techniques?
- Using ad-hoc approaches each time
- Following established standards and documenting all decisions (Correct answer)
- Ignoring industry standards entirely
- Implementing without any documentation
Correct answer: Following established standards and documenting all decisions
Best practices for Enumeration Techniques include following established standards and maintaining documentation.
Question 28: What role does automation play in Vulnerability Analysis?
- Automating repetitive tasks while maintaining human oversight (Correct answer)
- Automation is not applicable to this area
- Replacing all human involvement entirely
- Only automating documentation-related tasks
Correct answer: Automating repetitive tasks while maintaining human oversight
Automation enhances Vulnerability Analysis by handling repetitive tasks while humans maintain strategic oversight.
Question 29: How does Malware Threats support organizational goals?
- By increasing headcount requirements
- Only through cost reduction measures
- It has no relationship to organizational goals
- By reducing risk and improving operational efficiency (Correct answer)
Correct answer: By reducing risk and improving operational efficiency
Malware Threats supports organizational goals through risk reduction, efficiency improvements, and better outcomes.
Question 30: What prerequisite knowledge is needed for Sniffing and Social Engineering?
- No prerequisites exist for this topic
- Ten years of management experience minimum
- Understanding of foundational concepts and organizational context (Correct answer)
- Advanced programming skills only
Correct answer: Understanding of foundational concepts and organizational context
Effective work with Sniffing and Social Engineering requires understanding foundational concepts and organizational context.
Question 31: How does Web Server and Application Hacking relate to risk management?
- It has absolutely no relationship to risk management
- It identifies, assesses, and mitigates risks specific to this domain (Correct answer)
- It eliminates all risks completely and permanently
- It transfers all risks to insurance providers
Correct answer: It identifies, assesses, and mitigates risks specific to this domain
Web Server and Application Hacking helps identify, assess, and mitigate domain-specific risks as part of risk management.
Question 32: What tools and platforms support Vulnerability Analysis implementation?
- No tools exist for this purpose
- Purpose-built tools and platforms specific to this domain (Correct answer)
- Social media platforms are the primary tool
- Only spreadsheets are used in practice
Correct answer: Purpose-built tools and platforms specific to this domain
Specialized tools and platforms exist to support Vulnerability Analysis implementation and management effectively.
Question 33: What is the governance framework for Vulnerability Analysis?
- A single person makes all governance decisions
- External auditors govern everything exclusively
- No governance is needed for this topic
- Defined roles, responsibilities, policies, and accountability structures (Correct answer)
Correct answer: Defined roles, responsibilities, policies, and accountability structures
Governance for Vulnerability Analysis includes defined roles, responsibilities, policies, and accountability.
Question 34: How does Introduction to Ethical Hacking contribute to continuous improvement?
- By maintaining the status quo indefinitely
- Through regular assessment, feedback loops, and iterative enhancement (Correct answer)
- Through one-time implementation only
- By preventing any changes to existing processes
Correct answer: Through regular assessment, feedback loops, and iterative enhancement
Continuous improvement in Introduction to Ethical Hacking comes from regular assessment and iterative enhancement cycles.
Question 35: How is Sniffing and Social Engineering tested or validated in practice?
- It is never tested or validated
- Through regular testing, audits, and structured validation exercises (Correct answer)
- Only tested during the initial setup phase
- Testing is not possible for this area
Correct answer: Through regular testing, audits, and structured validation exercises
Sniffing and Social Engineering should be regularly tested and validated through appropriate exercises and audits.
Question 36: How does Footprinting and Reconnaissance address compliance requirements?
- Compliance is not relevant to this particular topic
- By ignoring all regulatory requirements
- By outsourcing all compliance activities externally
- By providing documented controls, audit trails, and measurable outcomes (Correct answer)
Correct answer: By providing documented controls, audit trails, and measurable outcomes
Footprinting and Reconnaissance supports compliance through documented controls, measurable outcomes, and clear audit trails.
Question 37: How does Sniffing and Social Engineering handle change management?
- Through controlled processes that assess impact before changes (Correct answer)
- All changes happen immediately without review
- Change management is handled separately
- Changes are not allowed once implemented
Correct answer: Through controlled processes that assess impact before changes
Changes to Sniffing and Social Engineering should follow controlled processes with proper impact assessment.
Question 38: What is the governance framework for Footprinting and Reconnaissance?
- A single person makes all governance decisions
- External auditors govern everything exclusively
- Defined roles, responsibilities, policies, and accountability structures (Correct answer)
- No governance is needed for this topic
Correct answer: Defined roles, responsibilities, policies, and accountability structures
Governance for Footprinting and Reconnaissance includes defined roles, responsibilities, policies, and accountability.
Question 39: How does Vulnerability Analysis deliver business value?
- It provides no measurable business value
- By reducing risk, improving efficiency, and enabling informed decisions (Correct answer)
- Only through direct cost savings
- By increasing organizational complexity
Correct answer: By reducing risk, improving efficiency, and enabling informed decisions
Vulnerability Analysis delivers business value through risk reduction, efficiency gains, and informed decision-making.
Question 40: What is the governance framework for System Hacking and Password Cracking?
- External auditors govern everything exclusively
- Defined roles, responsibilities, policies, and accountability structures (Correct answer)
- A single person makes all governance decisions
- No governance is needed for this topic
Correct answer: Defined roles, responsibilities, policies, and accountability structures
Governance for System Hacking and Password Cracking includes defined roles, responsibilities, policies, and accountability.
Question 41: What is the difference between strategic and tactical approaches to Cryptography?
- They are exactly the same approach
- Strategic focuses on long-term goals; tactical on immediate implementation (Correct answer)
- Tactical approaches are never used in practice
- Strategic approaches are always superior
Correct answer: Strategic focuses on long-term goals; tactical on immediate implementation
Strategic Cryptography addresses long-term objectives while tactical focuses on immediate implementation.
Question 42: Which metric best measures Malware Threats effectiveness?
- Budget spent on related tools
- Domain-specific KPIs aligned with defined objectives (Correct answer)
- Number of meetings held about the topic
- Amount of documentation produced
Correct answer: Domain-specific KPIs aligned with defined objectives
Effectiveness of Malware Threats is best measured through KPIs that align with defined objectives.
Question 43: Which statement best describes Footprinting and Reconnaissance?
- A deprecated concept from older versions
- A topic only relevant to advanced practitioners
- An optional topic not covered in the exam
- A core component of the CEH - Certified Ethical Hacker certification body of knowledge (Correct answer)
Correct answer: A core component of the CEH - Certified Ethical Hacker certification body of knowledge
Footprinting and Reconnaissance is a fundamental topic within the CEH - Certified Ethical Hacker certification covering essential knowledge and skills.
Question 44: What reporting is needed for System Hacking and Password Cracking?
- No reporting is required at any level
- Reports only when significant problems are detected
- Annual reports only to executive leadership
- Regular reports to relevant stakeholders with actionable insights and metrics (Correct answer)
Correct answer: Regular reports to relevant stakeholders with actionable insights and metrics
Reporting on System Hacking and Password Cracking should be regular with actionable insights and meaningful metrics.
Question 45: What training is recommended for Denial-of-Service Attacks?
- Training is only meant for beginners
- Only reading one blog article is sufficient
- Structured training combining theory and practical application (Correct answer)
- No training is needed for this topic
Correct answer: Structured training combining theory and practical application
Effective Denial-of-Service Attacks training combines theoretical knowledge with hands-on practical application.
Question 46: How is Web Server and Application Hacking tested or validated in practice?
- It is never tested or validated
- Testing is not possible for this area
- Through regular testing, audits, and structured validation exercises (Correct answer)
- Only tested during the initial setup phase
Correct answer: Through regular testing, audits, and structured validation exercises
Web Server and Application Hacking should be regularly tested and validated through appropriate exercises and audits.
Question 47: What scalability considerations apply to Malware Threats?
- Scalability is not a concern for this topic
- Scalability is handled automatically without effort
- Maintaining quality and consistency as scope and complexity grow (Correct answer)
- Always scale down to reduce costs
Correct answer: Maintaining quality and consistency as scope and complexity grow
Scaling Malware Threats requires maintaining quality and consistency across growing environments.
Question 48: An attacker sets up an access point with the same SSID as a legitimate network and a stronger signal to lure victims. This attack is called a(n):
- Rogue AP / Evil Twin attack (Correct answer)
- Deauthentication attack
- Bluejacking attack
- WPS Pixie Dust attack
Correct answer: Rogue AP / Evil Twin attack
An Evil Twin (or Rogue AP) attack involves creating a fraudulent access point that mimics a legitimate one, causing clients to connect to it instead and enabling traffic interception.
Question 49: What tools and platforms support Web Server and Application Hacking implementation?
- Purpose-built tools and platforms specific to this domain (Correct answer)
- No tools exist for this purpose
- Only spreadsheets are used in practice
- Social media platforms are the primary tool
Correct answer: Purpose-built tools and platforms specific to this domain
Specialized tools and platforms exist to support Web Server and Application Hacking implementation and management effectively.
Question 50: What is a best practice for Web Server and Application Hacking?
- Following established standards and documenting all decisions (Correct answer)
- Ignoring industry standards entirely
- Implementing without any documentation
- Using ad-hoc approaches each time
Correct answer: Following established standards and documenting all decisions
Best practices for Web Server and Application Hacking include following established standards and maintaining documentation.
Question 51: What is the relationship between Introduction to Ethical Hacking and security?
- Introduction to Ethical Hacking includes security considerations as an integral component (Correct answer)
- Introduction to Ethical Hacking replaces all other security measures
- Security is completely unrelated to this topic
- Security only applies to network-related topics
Correct answer: Introduction to Ethical Hacking includes security considerations as an integral component
Security is an integral part of Introduction to Ethical Hacking, ensuring that implementations are protected and compliant.
Question 52: How should Cryptography be budgeted?
- Allocate minimum possible budget always
- No budget allocation is needed for this area
- Allocate maximum available budget always
- Based on risk assessment, expected ROI, and organizational priorities (Correct answer)
Correct answer: Based on risk assessment, expected ROI, and organizational priorities
Budget for Cryptography should be based on risk assessment, expected ROI, and organizational priorities.
Question 53: What is the impact of neglecting Scanning Networks?
- Actually improves outcomes by saving time
- Increased risk, reduced efficiency, and potential operational failures (Correct answer)
- No impact whatsoever on the organization
- Only minor inconvenience to the team
Correct answer: Increased risk, reduced efficiency, and potential operational failures
Neglecting Scanning Networks leads to increased risk, reduced efficiency, and potential operational failures.
Question 54: What is the lifecycle of Cryptography?
- Implement once and never revisit the topic
- Only plan without ever implementing
- Plan, implement, monitor, review, and improve continuously (Correct answer)
- Skip directly to monitoring without planning
Correct answer: Plan, implement, monitor, review, and improve continuously
The Cryptography lifecycle follows plan-implement-monitor-review-improve in a continuous cycle.
Question 55: What is the first step when implementing Vulnerability Analysis?
- Skipping documentation to save time
- Implementing immediately without planning
- Delegating to an external team without oversight
- Assessing requirements and defining scope for vulnerability analysis (Correct answer)
Correct answer: Assessing requirements and defining scope for vulnerability analysis
The first step is always understanding requirements and scope before implementing Vulnerability Analysis.
Question 56: How does Denial-of-Service Attacks support organizational goals?
- By increasing headcount requirements
- Only through cost reduction measures
- It has no relationship to organizational goals
- By reducing risk and improving operational efficiency (Correct answer)
Correct answer: By reducing risk and improving operational efficiency
Denial-of-Service Attacks supports organizational goals through risk reduction, efficiency improvements, and better outcomes.
Question 57: What training is recommended for Introduction to Ethical Hacking?
- Training is only meant for beginners
- No training is needed for this topic
- Structured training combining theory and practical application (Correct answer)
- Only reading one blog article is sufficient
Correct answer: Structured training combining theory and practical application
Effective Introduction to Ethical Hacking training combines theoretical knowledge with hands-on practical application.
Question 58: What common mistake is made when implementing Malware Threats?
- Skipping proper planning and rushing to implementation (Correct answer)
- Using too many automation tools at once
- Involving too many stakeholders in decisions
- Over-planning before taking any action
Correct answer: Skipping proper planning and rushing to implementation
A common mistake with Malware Threats is rushing implementation without proper planning and assessment.
Question 59: What is the governance framework for Scanning Networks?
- A single person makes all governance decisions
- No governance is needed for this topic
- External auditors govern everything exclusively
- Defined roles, responsibilities, policies, and accountability structures (Correct answer)
Correct answer: Defined roles, responsibilities, policies, and accountability structures
Governance for Scanning Networks includes defined roles, responsibilities, policies, and accountability.
Question 60: What documentation is essential for Denial-of-Service Attacks?
- Only informal email notes
- Policies, procedures, guidelines, and records of decisions (Correct answer)
- No documentation is needed
- Only a one-page summary document
Correct answer: Policies, procedures, guidelines, and records of decisions
Essential Denial-of-Service Attacks documentation includes policies, procedures, guidelines, and decision records.
Question 61: What documentation is essential for Malware Threats?
- Only a one-page summary document
- Policies, procedures, guidelines, and records of decisions (Correct answer)
- No documentation is needed
- Only informal email notes
Correct answer: Policies, procedures, guidelines, and records of decisions
Essential Malware Threats documentation includes policies, procedures, guidelines, and decision records.
Question 62: How does Cryptography relate to risk management?
- It has absolutely no relationship to risk management
- It transfers all risks to insurance providers
- It eliminates all risks completely and permanently
- It identifies, assesses, and mitigates risks specific to this domain (Correct answer)
Correct answer: It identifies, assesses, and mitigates risks specific to this domain
Cryptography helps identify, assess, and mitigate domain-specific risks as part of risk management.
Question 63: What exam preparation tips apply to System Hacking and Password Cracking?
- Memorize everything without understanding the concepts
- Skip this topic entirely on the exam
- Only study the night before the exam
- Understand core concepts, practice with scenarios, and learn key terminology (Correct answer)
Correct answer: Understand core concepts, practice with scenarios, and learn key terminology
For System Hacking and Password Cracking exam preparation, focus on core concepts, scenario practice, and proper terminology.
Question 64: How does Web Server and Application Hacking support audit requirements?
- By restricting auditor access to all systems
- Through documented processes, evidence collection, and traceability (Correct answer)
- Audit requirements do not apply to this area
- By avoiding all documentation to reduce exposure
Correct answer: Through documented processes, evidence collection, and traceability
Web Server and Application Hacking supports audits through documented processes, evidence, and clear traceability.
Question 65: What is the first step when implementing Web Server and Application Hacking?
- Delegating to an external team without oversight
- Skipping documentation to save time
- Implementing immediately without planning
- Assessing requirements and defining scope for web server and application hacking (Correct answer)
Correct answer: Assessing requirements and defining scope for web server and application hacking
The first step is always understanding requirements and scope before implementing Web Server and Application Hacking.
Question 66: What reporting is needed for Enumeration Techniques?
- Annual reports only to executive leadership
- Regular reports to relevant stakeholders with actionable insights and metrics (Correct answer)
- No reporting is required at any level
- Reports only when significant problems are detected
Correct answer: Regular reports to relevant stakeholders with actionable insights and metrics
Reporting on Enumeration Techniques should be regular with actionable insights and meaningful metrics.
Question 67: How should Enumeration Techniques be communicated to stakeholders?
- Regular updates with clear, actionable information and metrics (Correct answer)
- Never communicate about this topic
- Only through annual comprehensive reports
- Only when significant problems occur
Correct answer: Regular updates with clear, actionable information and metrics
Stakeholder communication about Enumeration Techniques should be regular with clear, actionable information.
Question 68: How does Scanning Networks handle change management?
- Through controlled processes that assess impact before changes (Correct answer)
- Changes are not allowed once implemented
- All changes happen immediately without review
- Change management is handled separately
Correct answer: Through controlled processes that assess impact before changes
Changes to Scanning Networks should follow controlled processes with proper impact assessment.
Question 69: How does Footprinting and Reconnaissance support organizational goals?
- It has no relationship to organizational goals
- By reducing risk and improving operational efficiency (Correct answer)
- By increasing headcount requirements
- Only through cost reduction measures
Correct answer: By reducing risk and improving operational efficiency
Footprinting and Reconnaissance supports organizational goals through risk reduction, efficiency improvements, and better outcomes.
Question 70: What is the governance framework for Session Hijacking?
- Defined roles, responsibilities, policies, and accountability structures (Correct answer)
- External auditors govern everything exclusively
- A single person makes all governance decisions
- No governance is needed for this topic
Correct answer: Defined roles, responsibilities, policies, and accountability structures
Governance for Session Hijacking includes defined roles, responsibilities, policies, and accountability.
Question 71: The PMKID attack on WPA2 is advantageous over traditional handshake capture because:
- It works against WEP networks that WPA2 replaced
- It requires only a single EAPOL frame from the AP and does not require a client to be present (Correct answer)
- It only works when the network uses WPS
- It cracks the key faster by using GPU acceleration exclusively
Correct answer: It requires only a single EAPOL frame from the AP and does not require a client to be present
The PMKID attack extracts a cryptographic identifier from a single EAPOL frame sent by the AP, eliminating the need to wait for a client to authenticate, making it faster and more reliable.
Question 72: What is a best practice for Footprinting and Reconnaissance?
- Ignoring industry standards entirely
- Implementing without any documentation
- Following established standards and documenting all decisions (Correct answer)
- Using ad-hoc approaches each time
Correct answer: Following established standards and documenting all decisions
Best practices for Footprinting and Reconnaissance include following established standards and maintaining documentation.
Question 73: What is the governance framework for Denial-of-Service Attacks?
- No governance is needed for this topic
- External auditors govern everything exclusively
- Defined roles, responsibilities, policies, and accountability structures (Correct answer)
- A single person makes all governance decisions
Correct answer: Defined roles, responsibilities, policies, and accountability structures
Governance for Denial-of-Service Attacks includes defined roles, responsibilities, policies, and accountability.
Question 74: How does Enumeration Techniques interact with other CEH - Certified Ethical Hacker domains?
- It operates in complete isolation from other topics
- Other domains are not relevant to this topic
- It integrates with and supports other certification domains (Correct answer)
- It conflicts with other certification domains
Correct answer: It integrates with and supports other certification domains
Enumeration Techniques is interconnected with other CEH - Certified Ethical Hacker domains creating a comprehensive knowledge framework.
Question 75: How does Footprinting and Reconnaissance handle change management?
- Changes are not allowed once implemented
- All changes happen immediately without review
- Change management is handled separately
- Through controlled processes that assess impact before changes (Correct answer)
Correct answer: Through controlled processes that assess impact before changes
Changes to Footprinting and Reconnaissance should follow controlled processes with proper impact assessment.
Question 76: How should Vulnerability Analysis be prioritized against competing organizational needs?
- Based on risk assessment and business impact analysis (Correct answer)
- Always given highest priority over everything else
- Always given lowest priority
- Prioritized randomly without analysis
Correct answer: Based on risk assessment and business impact analysis
Prioritization of Vulnerability Analysis should be based on risk assessment and business impact.
Question 77: What is a best practice for Denial-of-Service Attacks?
- Implementing without any documentation
- Following established standards and documenting all decisions (Correct answer)
- Ignoring industry standards entirely
- Using ad-hoc approaches each time
Correct answer: Following established standards and documenting all decisions
Best practices for Denial-of-Service Attacks include following established standards and maintaining documentation.
Question 78: What vendor considerations apply to Enumeration Techniques?
- Vendor management is completely separate from this topic
- Vendor relationships are irrelevant
- Always select the cheapest vendor available
- Evaluating vendors, managing SLAs, and monitoring ongoing performance (Correct answer)
Correct answer: Evaluating vendors, managing SLAs, and monitoring ongoing performance
Vendor considerations for Enumeration Techniques include evaluation, SLA management, and performance monitoring.
Question 79: How does Malware Threats handle change management?
- Change management is handled separately
- All changes happen immediately without review
- Through controlled processes that assess impact before changes (Correct answer)
- Changes are not allowed once implemented
Correct answer: Through controlled processes that assess impact before changes
Changes to Malware Threats should follow controlled processes with proper impact assessment.
Question 80: How is success in Web Server and Application Hacking measured and evaluated?
- By passing the certification exam only
- By meeting defined objectives with measurable outcomes and stakeholder satisfaction (Correct answer)
- By spending the entire allocated budget
- By completing all documentation requirements
Correct answer: By meeting defined objectives with measurable outcomes and stakeholder satisfaction
Success is defined by meeting objectives with measurable outcomes and stakeholder satisfaction.
Question 81: Which statement best describes Session Hijacking?
- An optional topic not covered in the exam
- A deprecated concept from older versions
- A topic only relevant to advanced practitioners
- A core component of the CEH - Certified Ethical Hacker certification body of knowledge (Correct answer)
Correct answer: A core component of the CEH - Certified Ethical Hacker certification body of knowledge
Session Hijacking is a fundamental topic within the CEH - Certified Ethical Hacker certification covering essential knowledge and skills.
Question 82: How should incidents related to Vulnerability Analysis be handled?
- Through structured incident response with documentation and lessons learned (Correct answer)
- Ignored until they resolve themselves naturally
- Escalated exclusively to external consultants
- Fixed immediately without any documentation
Correct answer: Through structured incident response with documentation and lessons learned
Incidents should follow a structured response process with documentation for future learning.
Question 83: What emerging trends are affecting Enumeration Techniques?
- Trends are irrelevant to fundamental concepts
- Only budget constraints are relevant
- Technology advances, increased automation, and evolving industry practices (Correct answer)
- No trends affect this area whatsoever
Correct answer: Technology advances, increased automation, and evolving industry practices
Technology advances and evolving practices continuously shape how Enumeration Techniques is approached.
Question 84: Which statement best describes Introduction to Ethical Hacking?
- A core component of the CEH - Certified Ethical Hacker certification body of knowledge (Correct answer)
- An optional topic not covered in the exam
- A deprecated concept from older versions
- A topic only relevant to advanced practitioners
Correct answer: A core component of the CEH - Certified Ethical Hacker certification body of knowledge
Introduction to Ethical Hacking is a fundamental topic within the CEH - Certified Ethical Hacker certification covering essential knowledge and skills.
Question 85: How should incidents related to System Hacking and Password Cracking be handled?
- Fixed immediately without any documentation
- Through structured incident response with documentation and lessons learned (Correct answer)
- Escalated exclusively to external consultants
- Ignored until they resolve themselves naturally
Correct answer: Through structured incident response with documentation and lessons learned
Incidents should follow a structured response process with documentation for future learning.
Question 86: What is the impact of neglecting Enumeration Techniques?
- Actually improves outcomes by saving time
- Only minor inconvenience to the team
- Increased risk, reduced efficiency, and potential operational failures (Correct answer)
- No impact whatsoever on the organization
Correct answer: Increased risk, reduced efficiency, and potential operational failures
Neglecting Enumeration Techniques leads to increased risk, reduced efficiency, and potential operational failures.
Question 87: How does System Hacking and Password Cracking interact with other CEH - Certified Ethical Hacker domains?
- It integrates with and supports other certification domains (Correct answer)
- Other domains are not relevant to this topic
- It conflicts with other certification domains
- It operates in complete isolation from other topics
Correct answer: It integrates with and supports other certification domains
System Hacking and Password Cracking is interconnected with other CEH - Certified Ethical Hacker domains creating a comprehensive knowledge framework.
Question 88: How does Web Server and Application Hacking interact with other CEH - Certified Ethical Hacker domains?
- Other domains are not relevant to this topic
- It integrates with and supports other certification domains (Correct answer)
- It conflicts with other certification domains
- It operates in complete isolation from other topics
Correct answer: It integrates with and supports other certification domains
Web Server and Application Hacking is interconnected with other CEH - Certified Ethical Hacker domains creating a comprehensive knowledge framework.
Question 89: What common mistake is made when implementing Introduction to Ethical Hacking?
- Involving too many stakeholders in decisions
- Skipping proper planning and rushing to implementation (Correct answer)
- Using too many automation tools at once
- Over-planning before taking any action
Correct answer: Skipping proper planning and rushing to implementation
A common mistake with Introduction to Ethical Hacking is rushing implementation without proper planning and assessment.
Question 90: What exam preparation tips apply to Web Server and Application Hacking?
- Skip this topic entirely on the exam
- Understand core concepts, practice with scenarios, and learn key terminology (Correct answer)
- Only study the night before the exam
- Memorize everything without understanding the concepts
Correct answer: Understand core concepts, practice with scenarios, and learn key terminology
For Web Server and Application Hacking exam preparation, focus on core concepts, scenario practice, and proper terminology.
Question 91: How should Web Server and Application Hacking be communicated to stakeholders?
- Never communicate about this topic
- Only when significant problems occur
- Regular updates with clear, actionable information and metrics (Correct answer)
- Only through annual comprehensive reports
Correct answer: Regular updates with clear, actionable information and metrics
Stakeholder communication about Web Server and Application Hacking should be regular with clear, actionable information.
Question 92: In 802.11 terminology, what is a 'probe request' and how can attackers exploit it?
- A data frame carrying EAPOL keys; exploited to recover PMK
- A management frame sent by APs to announce their presence; exploited to flood the channel
- A control frame used in WPA3 handshakes; exploited via KRACK
- A management frame sent by clients searching for known networks; exploited to discover hidden SSIDs and track device movement (Correct answer)
Correct answer: A management frame sent by clients searching for known networks; exploited to discover hidden SSIDs and track device movement
Probe requests are sent by client devices to actively search for previously connected networks; attackers use them to discover hidden SSIDs and track users based on their device's preferred network list.
Question 93: How does Denial-of-Service Attacks support audit requirements?
- Audit requirements do not apply to this area
- Through documented processes, evidence collection, and traceability (Correct answer)
- By restricting auditor access to all systems
- By avoiding all documentation to reduce exposure
Correct answer: Through documented processes, evidence collection, and traceability
Denial-of-Service Attacks supports audits through documented processes, evidence, and clear traceability.
Question 94: What prerequisite knowledge is needed for Session Hijacking?
- No prerequisites exist for this topic
- Advanced programming skills only
- Understanding of foundational concepts and organizational context (Correct answer)
- Ten years of management experience minimum
Correct answer: Understanding of foundational concepts and organizational context
Effective work with Session Hijacking requires understanding foundational concepts and organizational context.
Question 95: What documentation is essential for Web Server and Application Hacking?
- Only a one-page summary document
- No documentation is needed
- Only informal email notes
- Policies, procedures, guidelines, and records of decisions (Correct answer)
Correct answer: Policies, procedures, guidelines, and records of decisions
Essential Web Server and Application Hacking documentation includes policies, procedures, guidelines, and decision records.
Question 96: What risk does poor implementation of Scanning Networks create?
- No risks exist with any implementation approach
- Risks only affect external stakeholders
- Only financial risks are relevant
- Increased vulnerability to failures and compliance issues (Correct answer)
Correct answer: Increased vulnerability to failures and compliance issues
Poor Scanning Networks implementation increases vulnerability to failures, compliance issues, and operational problems.
Question 97: How does Enumeration Techniques support audit requirements?
- Audit requirements do not apply to this area
- By avoiding all documentation to reduce exposure
- Through documented processes, evidence collection, and traceability (Correct answer)
- By restricting auditor access to all systems
Correct answer: Through documented processes, evidence collection, and traceability
Enumeration Techniques supports audits through documented processes, evidence, and clear traceability.
Question 98: How should System Hacking and Password Cracking be prioritized against competing organizational needs?
- Prioritized randomly without analysis
- Always given highest priority over everything else
- Based on risk assessment and business impact analysis (Correct answer)
- Always given lowest priority
Correct answer: Based on risk assessment and business impact analysis
Prioritization of System Hacking and Password Cracking should be based on risk assessment and business impact.
Question 99: How does Web Server and Application Hacking support organizational goals?
- Only through cost reduction measures
- It has no relationship to organizational goals
- By increasing headcount requirements
- By reducing risk and improving operational efficiency (Correct answer)
Correct answer: By reducing risk and improving operational efficiency
Web Server and Application Hacking supports organizational goals through risk reduction, efficiency improvements, and better outcomes.
Question 100: What tools and platforms support Enumeration Techniques implementation?
- Social media platforms are the primary tool
- No tools exist for this purpose
- Purpose-built tools and platforms specific to this domain (Correct answer)
- Only spreadsheets are used in practice
Correct answer: Purpose-built tools and platforms specific to this domain
Specialized tools and platforms exist to support Enumeration Techniques implementation and management effectively.
Question 101: What is the primary purpose of Scanning Networks in the context of CEH - Certified Ethical Hacker?
- To eliminate the need for documentation
- To provide a structured framework for scanning networks management and implementation (Correct answer)
- To reduce staffing requirements significantly
- To replace all manual processes entirely
Correct answer: To provide a structured framework for scanning networks management and implementation
Scanning Networks provides a structured approach within CEH - Certified Ethical Hacker, enabling effective management and implementation of related concepts.
Question 102: Which fundamental cryptographic weakness in WEP makes it vulnerable to key recovery attacks?
- Use of static IV values that never change
- Reuse of short 24-bit Initialization Vectors leading to keystream collisions (Correct answer)
- Use of RSA public-key encryption
- Lack of any encryption algorithm
Correct answer: Reuse of short 24-bit Initialization Vectors leading to keystream collisions
WEP uses a 24-bit IV that cycles rapidly in busy networks, causing IV reuse and allowing attackers to recover the RC4 keystream and decrypt traffic.
Question 103: How does Enumeration Techniques relate to risk management?
- It eliminates all risks completely and permanently
- It transfers all risks to insurance providers
- It has absolutely no relationship to risk management
- It identifies, assesses, and mitigates risks specific to this domain (Correct answer)
Correct answer: It identifies, assesses, and mitigates risks specific to this domain
Enumeration Techniques helps identify, assess, and mitigate domain-specific risks as part of risk management.
Question 104: What common mistake is made when implementing Scanning Networks?
- Skipping proper planning and rushing to implementation (Correct answer)
- Using too many automation tools at once
- Involving too many stakeholders in decisions
- Over-planning before taking any action
Correct answer: Skipping proper planning and rushing to implementation
A common mistake with Scanning Networks is rushing implementation without proper planning and assessment.
Question 105: What role does automation play in Denial-of-Service Attacks?
- Replacing all human involvement entirely
- Automation is not applicable to this area
- Only automating documentation-related tasks
- Automating repetitive tasks while maintaining human oversight (Correct answer)
Correct answer: Automating repetitive tasks while maintaining human oversight
Automation enhances Denial-of-Service Attacks by handling repetitive tasks while humans maintain strategic oversight.
Question 106: How does Scanning Networks support audit requirements?
- Audit requirements do not apply to this area
- Through documented processes, evidence collection, and traceability (Correct answer)
- By restricting auditor access to all systems
- By avoiding all documentation to reduce exposure
Correct answer: Through documented processes, evidence collection, and traceability
Scanning Networks supports audits through documented processes, evidence, and clear traceability.
Question 107: What is the impact of neglecting Vulnerability Analysis?
- Only minor inconvenience to the team
- No impact whatsoever on the organization
- Actually improves outcomes by saving time
- Increased risk, reduced efficiency, and potential operational failures (Correct answer)
Correct answer: Increased risk, reduced efficiency, and potential operational failures
Neglecting Vulnerability Analysis leads to increased risk, reduced efficiency, and potential operational failures.
Question 108: How is success in Session Hijacking measured and evaluated?
- By spending the entire allocated budget
- By completing all documentation requirements
- By passing the certification exam only
- By meeting defined objectives with measurable outcomes and stakeholder satisfaction (Correct answer)
Correct answer: By meeting defined objectives with measurable outcomes and stakeholder satisfaction
Success is defined by meeting objectives with measurable outcomes and stakeholder satisfaction.
Question 109: How should Vulnerability Analysis be communicated to stakeholders?
- Only when significant problems occur
- Regular updates with clear, actionable information and metrics (Correct answer)
- Never communicate about this topic
- Only through annual comprehensive reports
Correct answer: Regular updates with clear, actionable information and metrics
Stakeholder communication about Vulnerability Analysis should be regular with clear, actionable information.
Question 110: What reporting is needed for Web Server and Application Hacking?
- No reporting is required at any level
- Regular reports to relevant stakeholders with actionable insights and metrics (Correct answer)
- Annual reports only to executive leadership
- Reports only when significant problems are detected
Correct answer: Regular reports to relevant stakeholders with actionable insights and metrics
Reporting on Web Server and Application Hacking should be regular with actionable insights and meaningful metrics.
Question 111: How should Introduction to Ethical Hacking be communicated to stakeholders?
- Only through annual comprehensive reports
- Never communicate about this topic
- Regular updates with clear, actionable information and metrics (Correct answer)
- Only when significant problems occur
Correct answer: Regular updates with clear, actionable information and metrics
Stakeholder communication about Introduction to Ethical Hacking should be regular with clear, actionable information.
Question 112: What vendor considerations apply to Denial-of-Service Attacks?
- Evaluating vendors, managing SLAs, and monitoring ongoing performance (Correct answer)
- Vendor management is completely separate from this topic
- Always select the cheapest vendor available
- Vendor relationships are irrelevant
Correct answer: Evaluating vendors, managing SLAs, and monitoring ongoing performance
Vendor considerations for Denial-of-Service Attacks include evaluation, SLA management, and performance monitoring.
Question 113: What is the relationship between Malware Threats and security?
- Malware Threats includes security considerations as an integral component (Correct answer)
- Malware Threats replaces all other security measures
- Security only applies to network-related topics
- Security is completely unrelated to this topic
Correct answer: Malware Threats includes security considerations as an integral component
Security is an integral part of Malware Threats, ensuring that implementations are protected and compliant.
Question 114: How does Cryptography support organizational goals?
- Only through cost reduction measures
- By increasing headcount requirements
- By reducing risk and improving operational efficiency (Correct answer)
- It has no relationship to organizational goals
Correct answer: By reducing risk and improving operational efficiency
Cryptography supports organizational goals through risk reduction, efficiency improvements, and better outcomes.
Question 115: What is a best practice for Cryptography?
- Implementing without any documentation
- Ignoring industry standards entirely
- Following established standards and documenting all decisions (Correct answer)
- Using ad-hoc approaches each time
Correct answer: Following established standards and documenting all decisions
Best practices for Cryptography include following established standards and maintaining documentation.
Question 116: How should Web Server and Application Hacking be budgeted?
- No budget allocation is needed for this area
- Allocate minimum possible budget always
- Allocate maximum available budget always
- Based on risk assessment, expected ROI, and organizational priorities (Correct answer)
Correct answer: Based on risk assessment, expected ROI, and organizational priorities
Budget for Web Server and Application Hacking should be based on risk assessment, expected ROI, and organizational priorities.
Question 117: What risk does poor implementation of Session Hijacking create?
- Increased vulnerability to failures and compliance issues (Correct answer)
- Only financial risks are relevant
- No risks exist with any implementation approach
- Risks only affect external stakeholders
Correct answer: Increased vulnerability to failures and compliance issues
Poor Session Hijacking implementation increases vulnerability to failures, compliance issues, and operational problems.
Question 118: What reporting is needed for Sniffing and Social Engineering?
- No reporting is required at any level
- Annual reports only to executive leadership
- Reports only when significant problems are detected
- Regular reports to relevant stakeholders with actionable insights and metrics (Correct answer)
Correct answer: Regular reports to relevant stakeholders with actionable insights and metrics
Reporting on Sniffing and Social Engineering should be regular with actionable insights and meaningful metrics.
Question 119: How does Cryptography contribute to continuous improvement?
- Through one-time implementation only
- Through regular assessment, feedback loops, and iterative enhancement (Correct answer)
- By preventing any changes to existing processes
- By maintaining the status quo indefinitely
Correct answer: Through regular assessment, feedback loops, and iterative enhancement
Continuous improvement in Cryptography comes from regular assessment and iterative enhancement cycles.
Question 120: What scalability considerations apply to Enumeration Techniques?
- Scalability is not a concern for this topic
- Always scale down to reduce costs
- Scalability is handled automatically without effort
- Maintaining quality and consistency as scope and complexity grow (Correct answer)
Correct answer: Maintaining quality and consistency as scope and complexity grow
Scaling Enumeration Techniques requires maintaining quality and consistency across growing environments.
Question 121: How does Session Hijacking contribute to continuous improvement?
- By maintaining the status quo indefinitely
- Through one-time implementation only
- By preventing any changes to existing processes
- Through regular assessment, feedback loops, and iterative enhancement (Correct answer)
Correct answer: Through regular assessment, feedback loops, and iterative enhancement
Continuous improvement in Session Hijacking comes from regular assessment and iterative enhancement cycles.
Question 122: How does System Hacking and Password Cracking deliver business value?
- By increasing organizational complexity
- It provides no measurable business value
- By reducing risk, improving efficiency, and enabling informed decisions (Correct answer)
- Only through direct cost savings
Correct answer: By reducing risk, improving efficiency, and enabling informed decisions
System Hacking and Password Cracking delivers business value through risk reduction, efficiency gains, and informed decision-making.
Question 123: How does Introduction to Ethical Hacking interact with other CEH - Certified Ethical Hacker domains?
- It integrates with and supports other certification domains (Correct answer)
- It operates in complete isolation from other topics
- It conflicts with other certification domains
- Other domains are not relevant to this topic
Correct answer: It integrates with and supports other certification domains
Introduction to Ethical Hacking is interconnected with other CEH - Certified Ethical Hacker domains creating a comprehensive knowledge framework.
Question 124: How does Cryptography address compliance requirements?
- By outsourcing all compliance activities externally
- By ignoring all regulatory requirements
- Compliance is not relevant to this particular topic
- By providing documented controls, audit trails, and measurable outcomes (Correct answer)
Correct answer: By providing documented controls, audit trails, and measurable outcomes
Cryptography supports compliance through documented controls, measurable outcomes, and clear audit trails.
Question 125: What is the impact of neglecting Web Server and Application Hacking?
- Only minor inconvenience to the team
- No impact whatsoever on the organization
- Increased risk, reduced efficiency, and potential operational failures (Correct answer)
- Actually improves outcomes by saving time
Correct answer: Increased risk, reduced efficiency, and potential operational failures
Neglecting Web Server and Application Hacking leads to increased risk, reduced efficiency, and potential operational failures.
Question 126: What emerging trends are affecting Web Server and Application Hacking?
- Technology advances, increased automation, and evolving industry practices (Correct answer)
- No trends affect this area whatsoever
- Only budget constraints are relevant
- Trends are irrelevant to fundamental concepts
Correct answer: Technology advances, increased automation, and evolving industry practices
Technology advances and evolving practices continuously shape how Web Server and Application Hacking is approached.
CEH Certified Ethical Hacker Exam
The EC-Council Certified Ethical Hacker (CEH v13) exam validates knowledge of ethical hacking methodologies, tools, and techniques used to assess the security posture of information systems.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds