Certified Ethical Hacker (CEH v13) — Questions and Answers
Question 1: Which tool is an industry-standard open-source vulnerability scanner used in CEH assessments?
- John the Ripper
- Metasploit
- Burp Suite
- OpenVAS (Correct answer)
Correct answer: OpenVAS
OpenVAS (Greenbone Vulnerability Manager) is a widely used open-source vulnerability scanner that checks systems against thousands of known vulnerability tests.
Question 2: What is Maltego primarily used for during the footprinting and reconnaissance phase?
- Network packet capture and analysis
- Visual link analysis and open-source intelligence gathering (Correct answer)
- Password cracking and hash analysis
- Automated vulnerability scanning
Correct answer: Visual link analysis and open-source intelligence gathering
Maltego is an OSINT and forensics tool that graphically visualizes relationships between entities such as people, organizations, domains, and IP addresses discovered during reconnaissance.
Question 3: Which protocol does a ping sweep typically use to identify live hosts?
- ICMP echo request (Correct answer)
- DNS zone transfer
- ARP cache poisoning
- SNMP walk
Correct answer: ICMP echo request
A ping sweep sends ICMP echo requests across a range to find responsive hosts.
Question 4: Which of these is the strongest authentication factor to add to badge access for high-security areas?
- A second door handle
- A bigger badge
- Biometric verification (multi-factor) (Correct answer)
- A longer hallway
Correct answer: Biometric verification (multi-factor)
Combining a badge with biometrics adds a second factor that is hard to clone or share.
Question 5: Which technique uses an authoritative-looking but malicious phone charging station or cable to compromise mobile devices in public?
- Dumpster diving
- Whaling
- Juice jacking (Correct answer)
- Smishing
Correct answer: Juice jacking
Juice jacking uses compromised charging ports or cables to steal data or install malware on connected devices.
Question 6: Which Google dork operator restricts search results to pages that contain specific text within the HTML page title?
- intitle: (Correct answer)
- site:
- inurl:
- filetype:
Correct answer: intitle:
The 'intitle:' operator searches Google for pages containing the specified keyword within the HTML <title> tag, useful for finding specific types of exposed pages.
Question 7: Which technique involves manipulating the TTL field of packets to confuse IDS reassembly while the target host still receives the attack?
- Protocol Mutation
- Fragmentation Overlap
- Insertion Attack
- TTL Manipulation (Correct answer)
Correct answer: TTL Manipulation
TTL manipulation sets different TTL values so that some decoy packets expire before reaching the IDS but the actual attack payload reaches the target.
Question 8: A client only wants the tester to assess externally facing web applications. Where is this restriction defined?
- In the banner of each service
- In the covering-tracks phase
- In the exploit database
- In the scope of the engagement (Correct answer)
Correct answer: In the scope of the engagement
The scope defines exactly which systems and assets are authorized for testing.
Question 9: What is the primary purpose of a WHOIS lookup during the footprinting phase?
- Test for SQL injection vulnerabilities
- Retrieve domain registration and ownership information (Correct answer)
- Capture network packets in transit
- Scan open ports on a target system
Correct answer: Retrieve domain registration and ownership information
WHOIS lookup retrieves registration details about a domain including owner contact information, registrar, registration dates, and name servers.
Question 10: A polymorphic virus evades antivirus primarily by doing what on each infection?
- Changing its decryption routine/code signature (Correct answer)
- Encrypting the entire disk
- Sending email to contacts
- Deleting the host file
Correct answer: Changing its decryption routine/code signature
Polymorphic viruses mutate their code or decryption routine each time to alter their signature.
Question 11: What WPS feature makes it vulnerable to brute-force attacks such as those performed by Reaver?
- The hidden SSID broadcast
- The 802.1X authenticator
- The RADIUS server timeout
- The 8-digit PIN validated in two halves (Correct answer)
Correct answer: The 8-digit PIN validated in two halves
WPS validates the PIN in two halves, drastically reducing the number of guesses needed to brute-force it.
Question 12: Which tool is commonly used to test for misconfigured AWS S3 bucket permissions?
- Hydra
- Gobuster
- Maltego
- S3Scanner (Correct answer)
Correct answer: S3Scanner
S3Scanner enumerates and checks the permissions of Amazon S3 buckets to identify publicly accessible or misconfigured buckets.
Question 13: What is SQL injection and how is it typically exploited?
- Modifying SQL Server configuration files
- Inserting malicious SQL code into application input fields to manipulate the database (Correct answer)
- Injecting JavaScript into web pages
- Overflowing a buffer with SQL commands
Correct answer: Inserting malicious SQL code into application input fields to manipulate the database
SQL injection exploits applications that incorporate user input into SQL queries without proper sanitization, allowing attackers to read, modify, or delete database data, bypass authentication, or execute OS commands.
Question 14: A phishing attack specifically targeting a company's CEO or other high-value executives is known as:
- Pharming
- Spear phishing of interns
- Whaling (Correct answer)
- Smishing
Correct answer: Whaling
Whaling is spear phishing aimed at senior executives or 'big fish' for high-impact access.
Question 15: What information can an attacker extract by analyzing the headers of an email received from a target organization?
- Employee login credentials for email systems
- Internal IP addresses, mail server names, and email routing paths (Correct answer)
- Decrypted email body content regardless of encryption
- A list of all email addresses in the organization's directory
Correct answer: Internal IP addresses, mail server names, and email routing paths
Email headers contain routing metadata showing each mail server the email passed through, potentially revealing internal IP addresses and mail server infrastructure.
Question 16: Which response BEST reduces the impact of a successful social engineering breach once detected?
- Turning off all CCTV
- Publicly blaming the employee
- Ignoring it until the next audit
- Incident response activation and credential revocation (Correct answer)
Correct answer: Incident response activation and credential revocation
Activating incident response and revoking compromised credentials quickly contains and limits the damage.
Question 17: What firewall type inspects traffic at Layer 7 and can identify and block specific applications regardless of port?
- Packet Filtering Firewall
- Circuit-Level Gateway
- Stateful Inspection Firewall
- Next-Generation Firewall (NGFW) (Correct answer)
Correct answer: Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) performs deep packet inspection at the application layer, enabling it to identify and control specific applications independent of port or protocol.
Question 18: What is a 'zero-day vulnerability'?
- A previously unknown vulnerability with no available patch (Correct answer)
- A vulnerability with a CVSS score of zero
- A vulnerability that has existed for zero days
- A vulnerability that only affects systems on day zero of deployment
Correct answer: A previously unknown vulnerability with no available patch
A zero-day vulnerability is a security flaw that is unknown to the vendor and has no available patch, making it particularly dangerous and valuable to attackers.
Question 19: What is the difference between active and passive reconnaissance?
- Active is legal; passive is illegal
- Active uses automated tools; passive uses manual methods
- Active directly interacts with the target system; passive gathers information without direct contact (Correct answer)
- There is no practical difference
Correct answer: Active directly interacts with the target system; passive gathers information without direct contact
Active reconnaissance involves direct interaction with the target (port scanning, vulnerability scanning), while passive reconnaissance gathers publicly available information (WHOIS, social media, DNS records) without alerting the target.
Question 20: What is a vulnerability assessment versus a penetration test?
- Pentests only test physical security
- They are the same thing
- VA identifies vulnerabilities without exploitation; a pentest actively exploits vulnerabilities to prove impact (Correct answer)
- VA is more comprehensive than a pentest
Correct answer: VA identifies vulnerabilities without exploitation; a pentest actively exploits vulnerabilities to prove impact
A vulnerability assessment scans and identifies potential security weaknesses, while a penetration test goes further by actively attempting to exploit discovered vulnerabilities to demonstrate real-world impact.
Question 21: What is the main goal of network enumeration after scanning?
- To physically locate the server
- To register a new domain
- To extract usernames, shares, and services from identified hosts (Correct answer)
- To encrypt the target's disk
Correct answer: To extract usernames, shares, and services from identified hosts
Enumeration actively extracts resources like usernames, shares, and services from discovered systems.
Question 22: What is a watering hole attack?
- Flooding a network with data packets
- Compromising a website frequently visited by the target group to infect their systems (Correct answer)
- Creating fake Wi-Fi hotspots near water features
- Poisoning a physical water supply
Correct answer: Compromising a website frequently visited by the target group to infect their systems
A watering hole attack identifies websites commonly visited by the target organization's employees, compromises those websites with malware, and waits for targets to visit and become infected.
Question 23: You work as a Security Analyst for a retail organization. In securing the company's network, you set up a firewall and an IDS. However, hackers are able to attack the network.<br> After investigating, you discover that your IDS is not configured properly and therefore is unable to trigger alarms when needed.<br> What type of alert is the IDS giving?
- False Negative (Correct answer)
- True Negative
- True Positive
- False Positive
Correct answer: False Negative
A false negative occurs when a security system, such as an Intrusion Detection System (IDS), fails to detect an actual attack or malicious activity. In this scenario, hackers successfully attacked the network, but the misconfigured IDS did not trigger an alarm, allowing the breach to go unnoticed. This is a critical failure as it means a real threat was missed, compromising the network's security.
Question 24: Which countermeasure best defends against ARP spoofing?
- Closing all UDP ports
- Increasing the TTL
- Dynamic ARP Inspection (DAI) on switches (Correct answer)
- Disabling ICMP
Correct answer: Dynamic ARP Inspection (DAI) on switches
Dynamic ARP Inspection validates ARP packets against trusted bindings to block spoofed entries.
Question 25: What security risk does an improperly configured DNS zone transfer (AXFR) present to an organization?
- Enables man-in-the-middle attacks on all SSL connections
- Allows remote code execution on the DNS server
- Creates a denial-of-service vulnerability in the DNS infrastructure
- Exposes the entire DNS database including all internal hostnames to unauthorized parties (Correct answer)
Correct answer: Exposes the entire DNS database including all internal hostnames to unauthorized parties
An unrestricted DNS zone transfer exposes all DNS records for a domain, giving attackers a complete map of the internal network infrastructure and hostnames.
Question 26: How does a signature-based IDS detect attacks?
- By scanning open ports
- By learning normal baseline behavior
- By blocking all encrypted traffic
- By matching traffic against a database of known attack patterns (Correct answer)
Correct answer: By matching traffic against a database of known attack patterns
Signature-based IDS compares traffic to a database of known malicious patterns or signatures.
Question 27: Which attack targets the cloud management plane to gain administrative control over an entire cloud environment?
- Container Escape
- SSRF
- Wrapping Attack (Correct answer)
- Hypervisor Attack
Correct answer: Wrapping Attack
A wrapping attack (XML Signature Wrapping) manipulates SOAP messages to the cloud management API, potentially granting attacker admin access.
Question 28: Which cipher mode requires an initialization vector (IV) to randomize the first block?
- ECB
- Hash mode
- Plaintext mode
- CBC (Correct answer)
Correct answer: CBC
CBC mode uses an IV to ensure identical plaintext blocks encrypt differently.
Question 29: What is Shodan primarily used for during the reconnaissance phase of ethical hacking?
- Cracking WPA2 wireless passwords
- Performing automated SQL injection attacks
- Searching social media profiles for target employees
- Finding internet-connected devices and their exposed services (Correct answer)
Correct answer: Finding internet-connected devices and their exposed services
Shodan is a search engine that indexes internet-connected devices, revealing open ports, running services, and banners useful for identifying exposed infrastructure.
Question 30: Which Regional Internet Registry (RIR) manages IP address allocation for the United States and Canada?
- RIPE NCC
- ARIN (Correct answer)
- APNIC
- LACNIC
Correct answer: ARIN
ARIN (American Registry for Internet Numbers) manages IP address allocation and WHOIS data for the United States, Canada, and many Caribbean and North Atlantic territories.
Question 31: Why is a UDP scan generally slower and less reliable than a TCP scan?
- UDP is connectionless and open ports often send no response (Correct answer)
- UDP encrypts all packets
- UDP uses a three-way handshake
- UDP requires authentication
Correct answer: UDP is connectionless and open ports often send no response
UDP is connectionless, so open ports frequently stay silent, forcing slow timeout-based inference.
Question 32: Which physical control prevents an attacker from cloning a proximity badge by capturing its RFID signal from a distance?
- Brighter lobby lighting
- Disabling Bluetooth on phones
- Longer Wi-Fi keys
- Shielded badge holders (RFID-blocking sleeves) (Correct answer)
Correct answer: Shielded badge holders (RFID-blocking sleeves)
RFID-blocking sleeves prevent unauthorized reading or cloning of proximity card signals.
Question 33: Which OWASP IoT Top 10 issue does using hardcoded passwords in firmware represent?
- Lack of physical hardening
- Insufficient privacy protection
- Insecure data transfer
- Weak, guessable, or hardcoded passwords (Correct answer)
Correct answer: Weak, guessable, or hardcoded passwords
Hardcoded credentials fall under the OWASP IoT category of weak, guessable, or hardcoded passwords.
Question 34: Which IDS evasion technique involves breaking a single exploit into multiple small packets that individually appear harmless?
- Protocol Anomaly
- TTL Manipulation
- Obfuscation
- Session Splicing (Correct answer)
Correct answer: Session Splicing
Session splicing fragments an attack payload across multiple TCP segments so that the IDS does not reconstruct the full attack signature.
Question 35: What is the primary defense against network sniffing of sensitive data?
- Using longer hostnames
- Encrypting traffic with protocols like TLS/SSH (Correct answer)
- Disabling logging
- Increasing bandwidth
Correct answer: Encrypting traffic with protocols like TLS/SSH
Encryption such as TLS or SSH renders captured packets unreadable, defeating sniffing of sensitive data.
Question 36: Which type of footprinting does NOT involve direct interaction with the target system?
- Active footprinting
- Network footprinting
- Passive footprinting (Correct answer)
- Internal footprinting
Correct answer: Passive footprinting
Passive footprinting gathers information through indirect means such as search engines and public databases, leaving no trace on the target's logs.
Question 37: What countermeasure best prevents session hijacking caused by predictable session tokens?
- Disabling cookies
- Enforcing password complexity
- Using long, randomly generated session IDs (Correct answer)
- Enabling ICMP filtering
Correct answer: Using long, randomly generated session IDs
Long, cryptographically random session IDs are computationally infeasible to predict, preventing attackers from guessing valid session tokens.
Question 38: What does the Nmap -sV flag accomplish?
- Disables ping
- Runs a vulnerability exploit
- Performs a UDP scan
- Detects service and version information on open ports (Correct answer)
Correct answer: Detects service and version information on open ports
The -sV flag probes open ports to determine the running service and its version.
Question 39: Which encryption protocol replaced TKIP in WPA2 to provide stronger confidentiality?
- DES
- RC4
- MD5
- CCMP (AES) (Correct answer)
Correct answer: CCMP (AES)
WPA2 uses CCMP based on AES, replacing the weaker RC4-based TKIP used in WPA.
Question 40: An attacker re-times malicious commands to run during off-hours and routes traffic over port 443 to blend with normal HTTPS. This primarily aims to achieve what?
- Privilege escalation
- Defense evasion / detection avoidance (Correct answer)
- Password cracking
- Data deduplication
Correct answer: Defense evasion / detection avoidance
Blending malicious traffic with legitimate HTTPS and off-hours timing is defense evasion.
Question 41: Which tool is used to perform session hijacking by capturing and replaying network packets?
- Nessus
- Wireshark
- Hamster and Ferret (Correct answer)
- Burp Suite
Correct answer: Hamster and Ferret
Hamster and Ferret are tools used together to sidejack HTTP sessions by capturing cookies from wireless traffic and replaying them to impersonate victims.
Question 42: Which technique allows an attacker to monitor traffic on a switched network passively?
- SYN flooding
- Port mirroring / SPAN port abuse (Correct answer)
- ICMP flooding
- Brute forcing SSH
Correct answer: Port mirroring / SPAN port abuse
Abusing a port mirror or SPAN configuration copies traffic to the attacker's port for passive monitoring.
Question 43: An attacker performs a DNS zone transfer (AXFR). What is the risk if it succeeds?
- The full list of DNS records for the domain is exposed (Correct answer)
- The attacker can reset all passwords
- All emails are intercepted
- The web server crashes
Correct answer: The full list of DNS records for the domain is exposed
A successful zone transfer hands over the complete DNS records, revealing internal hostnames and structure.
Question 44: Which firewall evasion technique uses a series of intermediate hosts to hide the true source of an attack?
- Source Routing
- Proxy Chaining (Correct answer)
- Tunneling
- Fragmentation
Correct answer: Proxy Chaining
Proxy chaining routes attack traffic through multiple proxy servers, masking the original source IP and making attribution difficult.
Question 45: What is the purpose of an Nmap idle (zombie) scan?
- To flood the target with traffic
- To brute-force passwords
- To scan without revealing the attacker's IP by using a third host (Correct answer)
- To crash the target service
Correct answer: To scan without revealing the attacker's IP by using a third host
The idle scan spoofs packets via a zombie host so the target never sees the attacker's real IP.
Question 46: What type of sensitive organizational information can an attacker gather by analyzing a company's job postings?
- Direct credentials to access internal systems
- Physical security details such as access card systems
- Employee passwords and hashed credentials
- Technology stack, software versions, and internal roles used by the organization (Correct answer)
Correct answer: Technology stack, software versions, and internal roles used by the organization
Job postings commonly list required technologies, frameworks, and software versions that reveal the organization's technical environment and potential attack vectors.
Question 47: What does the term 'privilege escalation' refer to?
- Gaining higher access rights than originally granted (Correct answer)
- Scanning for open ports
- Encrypting files for ransom
- Spoofing a MAC address
Correct answer: Gaining higher access rights than originally granted
Privilege escalation exploits flaws to obtain elevated permissions beyond the initial access level.
Question 48: What is the primary purpose of a packer when used by malware authors?
- To speed up program execution
- To improve memory management
- To compress and obfuscate the binary to evade signature detection (Correct answer)
- To add legitimate digital signatures
Correct answer: To compress and obfuscate the binary to evade signature detection
Packers compress and obfuscate malware binaries to evade signature-based detection.
Question 49: What does the shared responsibility model in cloud security define?
- The SLA for cloud uptime guarantees
- Which security tasks belong to the provider versus the customer (Correct answer)
- How costs are split between provider and customer
- How data is replicated across regions
Correct answer: Which security tasks belong to the provider versus the customer
The shared responsibility model delineates which security controls are managed by the cloud provider and which are the customer's responsibility.
Question 50: What is 'IP spoofing' used for in the context of session hijacking?
- Encrypting session data
- Bypassing firewall rules via port forwarding
- Masquerading as a trusted host to hijack a TCP session (Correct answer)
- Amplifying DoS traffic
Correct answer: Masquerading as a trusted host to hijack a TCP session
In session hijacking, IP spoofing allows the attacker to forge packets with a trusted source IP to impersonate a legitimate party in the TCP session.
Question 51: What type of IDS evasion injects extra packets into a stream that the IDS accepts but the target host rejects, causing the IDS to build a different view of the session?
- Insertion Attack (Correct answer)
- Obfuscation Attack
- Evasion Attack
- Fragmentation Attack
Correct answer: Insertion Attack
An insertion attack sends packets with invalid checksums or TTLs that the IDS accepts but the end host drops, causing the IDS to reconstruct a different data stream.
Question 52: An attacker escalates from a standard user to SYSTEM by exploiting a service running as SYSTEM with a writable executable path. This is an example of what?
- Horizontal privilege escalation
- Credential stuffing
- Lateral movement
- Vertical privilege escalation (Correct answer)
Correct answer: Vertical privilege escalation
Gaining higher privileges (user to SYSTEM) is vertical privilege escalation.
Question 53: What is banner grabbing used for during the reconnaissance phase of a penetration test?
- Identifying software names and versions running on open ports (Correct answer)
- Mapping all internal network subnets from a single host
- Downloading entire website content for offline analysis
- Capturing authentication tokens from active web sessions
Correct answer: Identifying software names and versions running on open ports
Banner grabbing captures the service banners returned when connecting to open ports, revealing the software type, version, and sometimes OS information.
Question 54: What is vishing and how does it differ from phishing?
- Video-based phishing using fake video calls
- A visual form of phishing using images
- A type of phishing that uses virtual reality
- Voice-based phishing using phone calls to extract information, versus email-based phishing (Correct answer)
Correct answer: Voice-based phishing using phone calls to extract information, versus email-based phishing
Vishing (voice phishing) uses phone calls or voicemail to impersonate trusted entities (banks, tech support, government) and manipulate victims into revealing sensitive information, as opposed to email-based phishing.
Question 55: What is Cross-Site Scripting (XSS) and what are its types?
- A browser extension for scripting
- A method for cross-referencing websites
- Injecting malicious scripts into web pages viewed by other users; types include stored, reflected, and DOM-based (Correct answer)
- A technique for copying scripts between servers
Correct answer: Injecting malicious scripts into web pages viewed by other users; types include stored, reflected, and DOM-based
XSS allows attackers to inject client-side scripts into web pages. Stored XSS persists in the database, reflected XSS bounces off the server in responses, and DOM-based XSS manipulates the page's DOM directly.
Question 56: During OS fingerprinting, what value primarily helps distinguish operating systems?
- The hostname
- TCP/IP stack characteristics like TTL and window size (Correct answer)
- MAC address vendor only
- The DNS PTR record
Correct answer: TCP/IP stack characteristics like TTL and window size
Different OSes implement the TCP/IP stack with distinctive default TTL and window size values.
Question 57: Which tool captures and analyzes network packets in real time?
- Nessus
- Hydra
- Wireshark (Correct answer)
- Nikto
Correct answer: Wireshark
Wireshark is a packet analyzer used to capture and inspect network traffic.
Question 58: What does OSINT stand for in the context of ethical hacking reconnaissance?
- Operational Security Intelligence
- Offensive Security Intrusion Network Testing
- Open Source Intelligence (Correct answer)
- Online System Integration Technique
Correct answer: Open Source Intelligence
OSINT (Open Source Intelligence) refers to gathering information exclusively from publicly available sources without direct interaction with the target.
Question 59: Which technique systematically queries a DNS server with a wordlist of possible names to enumerate subdomains of a target?
- Passive packet sniffing
- Port scanning
- ARP poisoning
- DNS brute-forcing (Correct answer)
Correct answer: DNS brute-forcing
DNS brute-forcing queries DNS servers with a large list of potential subdomain names to discover all valid subdomains associated with a target domain.
Question 60: Let's say you want to find information about a website by crawling through it. Which application do you apply?
- Web Bug
- Web Scorpion
- Web Spiders (Correct answer)
- Web Ant
Correct answer: Web Spiders
Web spiders (also known as web crawlers or bots) are automated programs that systematically browse the World Wide Web. They are used by search engines to index web content and by security professionals or attackers to gather information about a website's structure, links, and content through crawling. This reconnaissance helps in identifying potential targets or vulnerabilities.
Question 61: Which container escape technique exploits a misconfigured Docker socket mounted inside a container?
- Privileged container breakout
- Namespace pivot
- Docker socket abuse (Correct answer)
- Kernel exploit
Correct answer: Docker socket abuse
Mounting the Docker socket (/var/run/docker.sock) inside a container allows an attacker to control the host Docker daemon and escape the container.
Question 62: What is the difference between a vulnerability assessment and a penetration test?
- A pen test only uses automated tools; a vulnerability assessment uses manual techniques
- A vulnerability assessment identifies weaknesses; a pen test actively exploits them (Correct answer)
- A vulnerability assessment is performed externally; a pen test is internal only
- They are identical processes
Correct answer: A vulnerability assessment identifies weaknesses; a pen test actively exploits them
A vulnerability assessment identifies and reports security weaknesses without exploiting them, while a penetration test actively exploits vulnerabilities to demonstrate real-world impact.
Question 63: An attacker carries a large box and asks an employee to 'hold the door' to a secured area, bypassing badge access. This is an example of:
- Piggybacking/tailgating with a pretext (Correct answer)
- A pharming attack
- A SQL injection
- Credential stuffing
Correct answer: Piggybacking/tailgating with a pretext
Carrying items to elicit help is a common social engineering pretext to gain unauthorized physical entry.
Question 64: What is the purpose of performing a reverse DNS lookup during the footprinting phase?
- Bypass firewall rules using DNS tunneling techniques
- Transfer a DNS zone database from a name server
- Convert domain names to their corresponding IP addresses
- Resolve an IP address back to its associated hostname (Correct answer)
Correct answer: Resolve an IP address back to its associated hostname
Reverse DNS lookup maps an IP address back to its hostname, helping attackers identify servers and services associated with specific IP addresses found during scanning.
Question 65: Which command-line tool is used to capture and analyze network packets from the terminal?
- ipconfig
- tcpdump (Correct answer)
- traceroute
- netstat
Correct answer: tcpdump
tcpdump captures and displays network packets directly from the command line.
Question 66: What is shoulder surfing and how can it be prevented?
- A type of network packet sniffing
- Observing someone's screen or keyboard to steal credentials; prevented with privacy screens and awareness (Correct answer)
- Surfing the internet over someone's shoulder using their Wi-Fi
- A physical attack on server room equipment
Correct answer: Observing someone's screen or keyboard to steal credentials; prevented with privacy screens and awareness
Shoulder surfing involves visually observing someone entering passwords, PINs, or viewing sensitive information on their screen. Prevention includes privacy screen filters, awareness training, and using biometric authentication.
Question 67: Which Nmap scan type sends only a SYN packet and never completes the TCP handshake?
- TCP connect scan (-sT)
- ACK scan (-sA)
- FIN scan (-sF)
- SYN stealth scan (-sS) (Correct answer)
Correct answer: SYN stealth scan (-sS)
The SYN stealth scan sends a SYN and tears down the connection with RST before the handshake completes.
Question 68: An attacker injects ' OR '1'='1 into a login form and gains access. Which vulnerability is exploited?
- Path Traversal
- CSRF
- SQL Injection (Correct answer)
- Cross-Site Scripting
Correct answer: SQL Injection
The injected condition always evaluates true, bypassing authentication via SQL Injection.
Question 69: Which of these is not an element of security?
- Confidentiality
- Fraternity (Correct answer)
- Availability
- Integrity
Correct answer: Fraternity
The fundamental elements of information security are typically referred to as the CIA triad: Confidentiality, Integrity, and Availability. These three principles guide the protection of information assets and are core to cybersecurity. 'Fraternity' is a social term and has no relevance to the core concepts of information security.
Question 70: Claire is surfing the Web and, after some time, a message pops up stating her system has been infected by malware and offering a button to click for removal of the virus. After she clicks the button, another message window appears stating the system has been quarantined due to the nature of the infection and provides a link with instructions to pay in order to regain control and to clear the virus. Which of the following best describes this infection?
- Trojan
- Adware
- Ransomware (Correct answer)
- Spyware
Correct answer: Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks their computer system, then demands a payment (ransom) to restore access. The scenario explicitly describes the system being 'quarantined' and requiring payment 'to regain control and to clear the virus.' These actions are hallmark characteristics of a ransomware attack, where control is withheld until a payment is made.
Question 71: What does a MAC flooding attack attempt to do to a switch?
- Overflow the CAM table so the switch behaves like a hub (Correct answer)
- Spoof DNS records
- Disable the firewall
- Crack WPA2 keys
Correct answer: Overflow the CAM table so the switch behaves like a hub
MAC flooding overflows the switch CAM table, forcing it to broadcast frames so the attacker can sniff them.
Question 72: What is 'ARP spoofing' primarily used for in session hijacking attacks on a LAN?
- Crashing the ARP cache of routers
- Bypassing 802.1X port authentication
- Associating the attacker's MAC with a legitimate IP to intercept traffic (Correct answer)
- Generating fake ARP broadcasts to flood the network
Correct answer: Associating the attacker's MAC with a legitimate IP to intercept traffic
ARP spoofing sends fake ARP replies that associate the attacker's MAC address with a victim's IP, redirecting LAN traffic through the attacker for man-in-the-middle interception.
Question 73: DOM-based XSS differs from reflected XSS because the payload is processed:
- Only on the server
- Entirely in the client-side JavaScript (Correct answer)
- By the firewall
- By the database
Correct answer: Entirely in the client-side JavaScript
DOM-based XSS executes when client-side scripts write untrusted data into the DOM.
Question 74: What is the Wayback Machine (web.archive.org) primarily used for during the footprinting phase?
- Scanning for open ports on historical IP address ranges
- Testing web application vulnerabilities against live targets
- Capturing real-time network traffic from target websites
- Viewing archived versions of websites to find previously exposed sensitive information (Correct answer)
Correct answer: Viewing archived versions of websites to find previously exposed sensitive information
The Wayback Machine archives historical website snapshots, enabling attackers to find removed pages, old configuration files, or exposed sensitive data no longer visible on the live site.
Question 75: A honeypot is best described as what?
- An encryption algorithm
- A type of firewall rule
- A decoy system designed to attract and study attackers (Correct answer)
- A load balancer
Correct answer: A decoy system designed to attract and study attackers
A honeypot is a deliberately vulnerable decoy used to lure, detect, and analyze attackers.
Question 76: What is the main risk of 'pretexting' over the phone to a help desk?
- The phone line may overheat
- The help desk may reset credentials or disclose info to an impostor (Correct answer)
- It triggers a DDoS attack
- It encrypts the help desk data
Correct answer: The help desk may reset credentials or disclose info to an impostor
Without proper identity verification, help desks can be tricked into resetting passwords or leaking data.
Question 77: Which command-line tool is primarily used for querying DNS records such as MX records to identify a domain's mail servers?
- nslookup (Correct answer)
- Wireshark
- Netcat
- Nmap
Correct answer: nslookup
nslookup is used to query DNS servers and retrieve specific record types including MX records that identify mail servers for a domain.
Question 78: What is the purpose of using Unicode or hex encoding in IDS evasion?
- To bypass SSL inspection
- To obscure attack strings so signature-based IDS does not detect them (Correct answer)
- To prevent logging of the attack
- To compress attack payloads for faster delivery
Correct answer: To obscure attack strings so signature-based IDS does not detect them
Encoding attack strings in Unicode or hex can bypass signature-based IDS that only match ASCII patterns, while the target server decodes and executes the payload normally.
Question 79: What is the main goal of a session hijacking attack?
- Take over an authenticated user's session (Correct answer)
- Flood a server with requests
- Crack a password hash
- Intercept DNS queries
Correct answer: Take over an authenticated user's session
Session hijacking steals or predicts a valid session token to impersonate a legitimate user.
Question 80: What type of vulnerability assessment is performed without any prior knowledge of the target environment?
- Gray Box Assessment
- White Box Assessment
- Black Box Assessment (Correct answer)
- Crystal Box Assessment
Correct answer: Black Box Assessment
A black box assessment simulates an external attacker with no prior knowledge, testing the target purely from an outsider's perspective.
Question 81: Which Google search operator is used to search for specific file types hosted on a target website?
- site:
- inurl:
- filetype: (Correct answer)
- intitle:
Correct answer: filetype:
The 'filetype:' Google dork operator restricts results to specific file extensions (e.g., PDF, XLS, DOC) which may expose sensitive documents.
Question 82: What does a stateful firewall track that a stateless (packet-filtering) firewall does not?
- The state of active network connections (Correct answer)
- Layer 7 application data
- Source and destination IP addresses
- DNS query responses
Correct answer: The state of active network connections
A stateful firewall maintains a connection state table and tracks the full context of active sessions, allowing it to detect out-of-state packets that stateless firewalls miss.
Question 83: Why is the lack of a secure firmware update mechanism a critical IoT vulnerability?
- It improves signal strength
- It prevents patching of discovered vulnerabilities (Correct answer)
- It increases device battery life
- It encrypts all stored data automatically
Correct answer: It prevents patching of discovered vulnerabilities
Without secure updates, known vulnerabilities cannot be patched, leaving devices exploitable indefinitely.
Question 84: Which attack involves sending unsolicited messages to nearby Bluetooth devices?
- Blueprinting
- Bluesnarfing
- Bluejacking (Correct answer)
- Bluebugging
Correct answer: Bluejacking
Bluejacking sends unsolicited messages to Bluetooth devices, typically as a nuisance rather than data theft.
Question 85: Which tool is commonly used for session hijacking and man-in-the-middle attacks on a LAN?
- Nikto
- Ettercap (Correct answer)
- Nessus
- Nmap
Correct answer: Ettercap
Ettercap is a comprehensive suite for man-in-the-middle attacks, capable of sniffing, session hijacking, and filtering live connections on a LAN.
Question 86: A firewall responds to an Nmap ACK scan with no reply (filtered). What does this indicate?
- The port is open
- A stateful firewall is filtering the port (Correct answer)
- The host is offline
- The port is closed
Correct answer: A stateful firewall is filtering the port
An ACK scan maps firewall rules, and no response means a stateful firewall is filtering that port.
Question 87: A fraudulent SMS message claiming a package delivery failed and asking the user to click a link is an example of:
- Whaling
- Baiting
- Pharming
- Smishing (Correct answer)
Correct answer: Smishing
Smishing is phishing conducted through SMS text messages.
Question 88: What is the purpose of a DMZ in network architecture?
- To isolate public-facing servers from the internal network (Correct answer)
- To replace the firewall entirely
- To speed up DNS lookups
- To store all passwords
Correct answer: To isolate public-facing servers from the internal network
A DMZ places public-facing servers in a segmented zone to limit exposure of the internal network.
Question 89: Blind SQL injection is identified primarily by:
- Stack traces in the browser
- Verbose database errors
- HTTP 500 every time
- Differences in true/false responses or timing (Correct answer)
Correct answer: Differences in true/false responses or timing
Blind SQLi infers data from boolean response changes or time delays, without direct output.
Question 90: Which attack technique do attackers use to steal session cookies by injecting a script into a vulnerable web application?
- CSRF
- Command Injection
- Cross-Site Scripting (XSS) (Correct answer)
- SQL Injection
Correct answer: Cross-Site Scripting (XSS)
XSS can be used to inject malicious scripts that read and exfiltrate the victim's session cookies to the attacker's server.
Question 91: An attacker clears the Windows Security event log to cover their tracks. Which command-line tool can wipe a specific event log?
- ipconfig
- wevtutil (Correct answer)
- chkdsk
- tasklist
Correct answer: wevtutil
wevtutil cl Security clears the Windows Security event log.
Question 92: What is the primary purpose of using Traceroute/Tracert during network footprinting?
- Intercept and decrypt HTTPS web traffic
- Map the network path and identify intermediate routers between attacker and target (Correct answer)
- Detect and identify malware running on the network
- Crack passwords by tracing authentication packet sequences
Correct answer: Map the network path and identify intermediate routers between attacker and target
Traceroute maps the route packets take to reach a destination, revealing intermediate routers, network topology, TTL values, and potential firewall or IDS locations.
Question 93: Which tool is specifically designed for automated web crawling, email harvesting, and subdomain enumeration from public sources?
- Nmap
- theHarvester (Correct answer)
- Metasploit Framework
- Aircrack-ng
Correct answer: theHarvester
theHarvester gathers emails, names, subdomains, IPs, and URLs from public sources like search engines and LinkedIn during the passive reconnaissance phase.
Question 94: A keylogger implemented as a small hardware device inserted between the keyboard and the computer is which type?
- Software keylogger
- Kernel keylogger
- API-hooking keylogger
- Hardware keylogger (Correct answer)
Correct answer: Hardware keylogger
A physical device placed inline with the keyboard cable is a hardware keylogger.
Question 95: What is the primary function of an Intrusion Detection System (IDS)?
- To monitor traffic and alert on suspicious activity (Correct answer)
- To assign IP addresses
- To block all inbound traffic
- To encrypt network packets
Correct answer: To monitor traffic and alert on suspicious activity
An IDS monitors network or host activity and raises alerts on suspicious or malicious patterns.
Question 96: What is OS fingerprinting in ethical hacking?
- Creating a digital fingerprint for biometric authentication
- Scanning for fingerprint readers on the network
- Identifying the target's operating system by analyzing network packet characteristics (Correct answer)
- Copying the target's operating system
Correct answer: Identifying the target's operating system by analyzing network packet characteristics
OS fingerprinting analyzes unique characteristics of network packets (TTL values, TCP window size, DF bit) to identify the target's operating system and version, using tools like Nmap.
Question 97: A medium-sized healthcare IT business decides to implement a risk management strategy. <br> Which of the following is NOT one of the five basic responses to risk?
- Avoid
- Delegate (Correct answer)
- Mitigate
- Accept
Correct answer: Delegate
The five basic responses to risk in risk management are typically: Avoid (eliminate the activity causing the risk), Mitigate (reduce the likelihood or impact of the risk), Accept (live with the risk), and Transfer (shift the risk to another party, often through insurance). 'Delegate' is not considered one of these fundamental risk responses. While tasks related to risk management can be delegated, the ultimate responsibility for the risk itself remains with the organization.
Question 98: Which header helps mitigate cross-site scripting by restricting script sources?
- Set-Cookie
- Cache-Control
- X-Frame-Options
- Content-Security-Policy (Correct answer)
Correct answer: Content-Security-Policy
Content-Security-Policy restricts which sources can load scripts, limiting XSS impact.
Question 99: What is banner grabbing and what information does it reveal?
- Capturing screenshots of target websites
- Connecting to services to capture their version information and software details (Correct answer)
- Creating advertising banners for websites
- Blocking banner advertisements
Correct answer: Connecting to services to capture their version information and software details
Banner grabbing connects to network services (HTTP, FTP, SMTP) and captures the service banner which typically reveals the software name, version, and sometimes OS information, helping identify exploitable vulnerabilities.
Question 100: What is the purpose of a SYN scan (half-open scan) in network reconnaissance?
- To flood the target with SYN packets
- To encrypt network traffic
- To identify open ports without completing the TCP handshake, making it stealthier (Correct answer)
- To establish a full connection to every port
Correct answer: To identify open ports without completing the TCP handshake, making it stealthier
A SYN scan sends SYN packets and analyzes responses (SYN-ACK = open, RST = closed) without completing the three-way handshake, making it faster and harder to detect than full connect scans.
Question 101: What is the goal of a DHCP starvation attack?
- Disable ARP
- Exhaust the DHCP pool so legitimate clients cannot get addresses (Correct answer)
- Speed up address leasing
- Encrypt all DHCP traffic
Correct answer: Exhaust the DHCP pool so legitimate clients cannot get addresses
DHCP starvation floods the server with bogus requests to exhaust its address pool, denying service.
Question 102: An attacker sends an email claiming to be from the IT helpdesk, urgently requesting the user reset their password via an included link. Which social engineering principle is MOST being exploited?
- Reciprocity
- Social proof
- Scarcity of resources
- Authority and urgency (Correct answer)
Correct answer: Authority and urgency
Impersonating IT (authority) plus an urgent deadline pressures the victim into acting without verifying.
Question 103: Which type of session hijacking intercepts a session between two parties without requiring prediction of a sequence number?
- UDP Hijacking
- Active Hijacking
- Passive Hijacking (Correct answer)
- Blind Hijacking
Correct answer: Passive Hijacking
Passive hijacking involves monitoring a session to capture sensitive data without actively injecting packets, avoiding detection by not disrupting the session.
Question 104: An attacker captures and retransmits a valid encrypted authentication token. What attack is this?
- Side-channel attack
- Collision attack
- Birthday attack
- Replay attack (Correct answer)
Correct answer: Replay attack
A replay attack reuses captured valid data to gain unauthorized access.
Question 105: An attacker sets up a fake but legitimate-looking login portal that mirrors a company's SSO page to harvest credentials. This is BEST described as:
- Shoulder surfing
- A mantrap
- A credential harvesting/phishing site (Correct answer)
- Dumpster diving
Correct answer: A credential harvesting/phishing site
A cloned login portal is used to capture (harvest) credentials entered by deceived users.
Question 106: An attacker impersonates a delivery courier to gain access to a building's loading dock and then wanders into restricted areas. This highlights the importance of:
- Stronger email filters
- Visitor escort and access zoning policies (Correct answer)
- Faster internet speeds
- More monitors per desk
Correct answer: Visitor escort and access zoning policies
Visitor escorting and zoned access prevent outsiders from freely moving into restricted areas.
Question 107: An attacker captures the PMKID directly from an AP without needing a client. This clientless attack targets which technology?
- NFC
- WEP
- WPA/WPA2 with roaming enabled (Correct answer)
- Bluetooth LE
Correct answer: WPA/WPA2 with roaming enabled
The PMKID attack extracts a hash from the AP's first handshake message, enabling clientless WPA/WPA2 cracking.
Question 108: An attacker compromises a website frequently visited by employees of a target company to infect them. This technique is known as a:
- Dumpster dive
- Whaling attack
- Watering hole attack (Correct answer)
- Mantrap bypass
Correct answer: Watering hole attack
A watering hole attack poisons a trusted, commonly visited site to compromise its specific visitors.
Question 109: What is 'privilege escalation' in the context of exploitation?
- Increasing the attacker's level of access beyond the initial compromise (Correct answer)
- Gaining access to the target for the first time
- Escalating a vulnerability report to the vendor
- Elevating CVSS score of a discovered vulnerability
Correct answer: Increasing the attacker's level of access beyond the initial compromise
Privilege escalation involves leveraging vulnerabilities or misconfigurations to gain higher-level permissions (e.g., from a standard user to administrator or root).
Question 110: What are common password cracking techniques?
- Dictionary attacks, brute force, rule-based attacks, rainbow tables, and credential stuffing (Correct answer)
- Only guessing common passwords
- Only using brute force
- Only using social engineering
Correct answer: Dictionary attacks, brute force, rule-based attacks, rainbow tables, and credential stuffing
Password cracking employs multiple techniques: dictionary attacks (common words), brute force (all combinations), rule-based (dictionary with modifications), rainbow tables (precomputed hashes), and credential stuffing (reusing leaked credentials).
Question 111: A penetration tester is hired to do a risk assessment of a company's DMZ. <br> The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the internal IT systems.<br> What kind of test is being performed?
- black box (Correct answer)
- grey box
- red box
- white box
Correct answer: black box
A black box penetration test is conducted with no prior knowledge of the target system's internal structure, architecture, or source code. The tester simulates an external attacker who has no insider information, relying solely on publicly available information and reconnaissance to identify vulnerabilities. This approach provides a realistic assessment of what an external, unauthorized attacker could achieve against the organization's systems.
Question 112: A 'reverse social engineering' attack typically involves the attacker:
- Hacking the database remotely
- Mailing a malicious USB drive
- Calling the victim directly to demand a password
- Creating a problem, then offering to be the 'helper' the victim seeks out (Correct answer)
Correct answer: Creating a problem, then offering to be the 'helper' the victim seeks out
In reverse social engineering, the attacker engineers a situation so the victim voluntarily requests their help.
Question 113: Which evasion technique splits a malicious payload across multiple packets?
- Banner grabbing
- Port knocking
- DNS tunneling
- Fragmentation (Correct answer)
Correct answer: Fragmentation
Fragmentation breaks the payload across packets so an IDS may fail to reassemble and detect it.
Question 114: Which is the BEST first response if an employee suspects they fell for a phishing email and entered their credentials?
- Reboot the computer and ignore it
- Delete the email and say nothing
- Forward the email to all colleagues
- Immediately report it and change the affected password (Correct answer)
Correct answer: Immediately report it and change the affected password
Prompt reporting and password changes limit the window an attacker can use the stolen credentials.
Question 115: What is steganography?
- Exchanging keys securely
- Hashing passwords
- Encrypting data with a public key
- Hiding data within other non-secret files (Correct answer)
Correct answer: Hiding data within other non-secret files
Steganography conceals the existence of a message by embedding it in other media.
Question 116: Which type of testing occurs when individuals know the entire layout of the network?
- Blind testing
- Gray box
- White box (Correct answer)
- Black box
Correct answer: White box
White box testing, also known as clear box testing, is a method where the tester has complete knowledge of the system's internal structure, design, and implementation. This includes access to network diagrams, source code, and architectural details. This comprehensive understanding allows for a detailed and thorough assessment of vulnerabilities from an insider's perspective, ensuring all components are examined.
Question 117: An attacker calls an employee pretending to be tech support and asks them to read out a one-time code just texted to them. This voice-based attack is called:
- Tailgating
- Watering hole
- Smishing
- Vishing (Correct answer)
Correct answer: Vishing
Vishing (voice phishing) uses phone calls to socially engineer victims into revealing sensitive data.
Question 118: What is the purpose of enumeration in the ethical hacking methodology?
- Counting the number of computers on a network
- Extracting detailed information like usernames, shares, and services from a target system (Correct answer)
- Numbering all ports sequentially
- Creating a network diagram automatically
Correct answer: Extracting detailed information like usernames, shares, and services from a target system
Enumeration involves establishing active connections to target systems to extract detailed information including user accounts, network shares, group memberships, SNMP data, and DNS zone transfers.
Question 119: Which technique best prevents SQL injection in application code?
- Using HTTPS
- Disabling cookies
- Hiding error messages
- Parameterized queries (Correct answer)
Correct answer: Parameterized queries
Parameterized (prepared) statements separate code from data, neutralizing injection.
Question 120: What is the primary goal of footprinting in ethical hacking?
- Install malware on target systems
- Gather information about the target to plan an attack (Correct answer)
- Exploit vulnerabilities in the target system
- Intercept network traffic
Correct answer: Gather information about the target to plan an attack
Footprinting is the first phase of ethical hacking where information is collected about the target organization to identify potential attack surfaces before any exploitation.
Question 121: Which scanning technique uses banner grabbing to gather information?
- Poisoning the ARP table
- Sending malformed ICMP packets
- Spoofing the source MAC
- Connecting to a service to read its response header (Correct answer)
Correct answer: Connecting to a service to read its response header
Banner grabbing connects to a service (e.g., via Telnet or netcat) to read identifying header text.
Question 122: What is the primary goal of TCP session hijacking?
- To take over an established TCP connection (Correct answer)
- To perform a SYN flood attack
- To crash the target server
- To decrypt TLS traffic
Correct answer: To take over an established TCP connection
TCP session hijacking aims to take control of an active TCP session by predicting or stealing sequence numbers to inject malicious packets.
Question 123: Which Nmap timing template is the most aggressive and fastest?
- -T2 (polite)
- -T5 (insane) (Correct answer)
- -T3 (normal)
- -T0 (paranoid)
Correct answer: -T5 (insane)
-T5 (insane) is the fastest, most aggressive timing template at the cost of accuracy and stealth.
Question 124: What is footprinting through social engineering in the context of reconnaissance?
- Automating social media profile scraping with bots
- Exploiting software vulnerabilities in social media platforms
- Using SQL injection against social networking sites
- Gathering information by interacting with or deceiving target employees (Correct answer)
Correct answer: Gathering information by interacting with or deceiving target employees
Social engineering during reconnaissance involves manipulating or deceiving target employees through phone calls, emails, or impersonation to extract organizational information.
Question 125: What distinguishes a vulnerability assessment from a penetration test?
- Vulnerability assessment exploits findings; pentest only lists them
- Penetration tests never require authorization
- They are identical processes
- Vulnerability assessment identifies weaknesses; pentest actively exploits them (Correct answer)
Correct answer: Vulnerability assessment identifies weaknesses; pentest actively exploits them
A vulnerability assessment identifies and lists weaknesses, while a penetration test attempts to exploit them.
Question 126: Which DNS record type maps a domain name to an IPv6 address?
- AAAA record (Correct answer)
- MX record
- CNAME record
- A record
Correct answer: AAAA record
The AAAA (quad-A) record maps a domain name to a 128-bit IPv6 address, while the A record maps to a 32-bit IPv4 address.
Certified Ethical Hacker (CEH v13)
The CEH v13 certification validates an individual's ability to think and act like a malicious hacker, covering attack phases, countermeasures, and ethical hacking techniques across 20 security domains. Awarded by EC-Council, it is one of the most recognized cybersecurity certifications worldwide.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds