Browse all practice questions for the EC-Council Certified Ethical Hacker (CEH) Certification Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certified Ethical Hacker (CEH) Practice Exam 2026 - Complete Prep Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which of the following are protocols included in the IPsec architecture?
  • Which firewall limitation makes it difficult to determine if a connection originated inside or outside the network?
  • Which regulation focuses on corporate accounting and disclosure to increase transparency?
  • Which statement best describes the data capacity difference between proximity cards and smart cards?
  • Which statement best describes the primary purpose of fuzz testing tools like beSTORM in ethical hacking?
  • Which term best describes publicly accessible information about a DNS zone that can be obtained via certain server configurations?
  • Which information sharing policy addresses the sharing of critical information in press releases, annual reports, product catalogs, and marketing materials?
  • In cloud computing, which service model delivers software applications to a client over the Internet or a local area network?
  • Which type of firewall is best suited to protect an internal network from the Internet?
  • Which statement best describes a suicide hacker?
  • Which statement about malware that propagates across a network without user action is true?
  • Which term describes an attack intended to make a service unavailable by overwhelming a server?
  • Blocking port 389 would primarily impact which directory service protocol?
  • In Wireshark, which display filter would exclude traffic from IP 192.168.142.3?
  • Which activity involves querying registries to determine domain ownership and contact information?
  • Which of the following best describes what SOX does?
  • Which of the following is the third step in the ethical hacking methodology?
  • Which of the following best describes a supply chain?
  • Which statement best describes a client-based web app?
  • To perform a ping sweep of 172.125.68.1-255 with Nmap, which command would you use?
  • P0f provides which type of information about a remote host?
  • Which term describes registering a domain name that closely resembles a cloud provider to deceive users?
  • A proxy is used when your scanning attempts are blocked. Which of the following is a benefit?
  • What is the primary purpose of deploying a honeypot in a security program?
  • In PKI, which action establishes trust within an internal network without relying on public CAs?
  • What term describes software or code that provides an attacker with ongoing, covert access to a system?
  • Which malware hides inside legitimate software to trick users into installing it?
  • An attacker may use compromised websites and emails to distribute specially designed malware to poorly secured devices. Which devices can the attacker use?
  • Which type of malware self-propagates without user interaction and spreads through a network?
  • A penetration tester working for a hospital must comply with which federal regulation protecting patient health information?
  • A person discovers a vulnerability on a system without permission, anonymously alerts the owner, and instructs how to secure it. What type of hacker is this?
  • In analyzing a DHCP-related interception, which observation would suggest a DHCP-based man-in-the-middle attack?
  • Which IDS type monitors network traffic across the network rather than focusing on a single host?
  • In SNMP architecture, which component is responsible for collecting data from managed devices and presenting it to administrators?
  • You have discovered that a hacker is trying to penetrate your network using MAC spoofing. Which description best describes MAC spoofing?
  • Which of the following best describes what FISMA does?
  • Which law will help him protect his work on YouTube?
  • Which tool is commonly used as an intrusion detection system and can function as an intrusion prevention system?
  • Diana performed a command during a pentest that indicates a DNS zone transfer. What does this indicate?
  • Using Wireshark filtering, you want to see all traffic except IP address 192.168.142.3. Which of the following is the best command to filter a specific source IP address?
  • Which action best enhances security for a tablet used by staff to log events in a secure area?
  • Which security role would most likely trigger an alert when suspicious executable files are present on a workstation?
  • Which mobile security concern is characterized by malicious code that specifically targets mobile devices?
  • Using Wireshark, with a host filter for 192.168.0.34, what packets are captured?
  • What are the two types of Intrusion Detection Systems (IDSs)?
  • Which term describes using a fictitious scenario to persuade someone to reveal information they are not authorized to share?
  • An IDS alert shows a random user has administrative privileges, some files are missing, and other files appear. Which alert type is this?
  • What term describes the technique of embedding data within benign-looking files such as images and extracting it at the destination?
  • Mary is using asymmetric cryptography to send a message to Sam so that only Sam can read it. Which key should she use to encrypt the message?
  • Which best describes active scanning?
  • What security tool would you most likely use to detect hidden malware in websites and advertisements?
  • In vulnerability assessment, which phase focuses on identifying externally visible services on a target with limited information?
  • Which term describes adding random data to a password before hashing?
  • Which assessment type focuses on all types of user risks, including threats from malicious users, ignorant users, vendors, and administrators?
  • What does the ACK evasion scan help determine?
  • Which statement about SSIDs is true?
  • In social engineering, Ron is considered to be in which phase when preparing approaches and pretexts to gain access?
  • An attacker conducts a normal port scan on a host and detects protocols used by Windows and Linux operating systems. Which of the following might this indicate?
  • In packet crafting for network testing, which program is commonly used to modify packet flags and adjust other packet content?
  • What does a service banner typically reveal?
  • Which of the following is a sign of a network-based intrusion?
  • Which virus type is shown in a sample code where execution occurs under a specific condition?
  • Which description best defines the Wassenaar Arrangement?
  • Which honeypot interaction level is most realistic and hardest to fully compromise, making it suitable for observing attacker behavior?
  • ARP, DNS, and IP are examples of which security concept?
  • Which online tool is commonly used to gather information about servers and web servers, including hosting details and technologies?
  • Which escalation method involves loading a malicious DLL to be used by an application?
  • What port does LDAP use?
  • The Simple Network Management Protocol (SNMP) is used to manage devices such as routers, hubs, and switches. SNMP works with an SNMP agent and an SNMP management station in which layer of the OSI model?
  • Jerry runs a tool to scan a clean system to create a database. The tool then scans the system again and compares the second scan to the clean database. Which detection method is Jerry using?
  • Which of the following describes beSTORM?
  • Which item includes a list of resolved vulnerabilities?
  • A goal-based penetration test needs to have specific goals. Using SMART goals is extremely useful for this. What does SMART stand for?
  • Mark, an ethical hacker, is looking for a honeypot tool that will simulate a mischievous protocol such as devil or mydoom.
  • Nmap can be used for banner grabbing. Which of the following is the proper nmap command?
  • What countermeasure is described for mitigating a cross-site request forgery attack?
  • Which category includes tools such as Whois, Nslookup, and ARIN?
  • On a Windows system, an alert about a file named MyFile.txt.exe being found could indicate which security component?
  • When configuring a wireless access point, which statement about the Host Name is most accurate?
  • Which vulnerability assessment tool is designed to detect vulnerabilities on mobile devices and provide a report with a total risk score, vulnerability summary, and remediation suggestions?
  • Active scanning is best described as?
  • After penetration testing and hardening, what should you help the organization understand about threats?
  • Which description best fits an anti-virus sensor system?
  • Proximity (RFID) cards typically communicate at which frequency?
  • Which term describes an ethical hacker who uses hacking skills for defensive purposes?
  • In a smart home, a device that communicates directly with other devices without a central server demonstrates which communication model?
  • In wireless network configuration, which statement about SSIDs is true?
  • What is a typical goal of ransomware?
  • An IDS can perform many types of intrusion detections. Three common detection methods are signature-based, anomaly-based, and protocol-based. Which of the following best describes protocol-based detection?
  • What is the first place to check if you believe your system has been hacked?
  • In risk management, if the cost of addressing risk is greater than the potential damage, the typical risk posture is called what?
  • Which statement about worms is true?
  • In IPsec, which component provides data integrity and authentication?
  • Which statement describes a session identifier used during client-server communication?
  • In NTFS, which feature can store additional data alongside a file that FAT cannot?
  • What is a self-signed SSL certificate?
  • Which type of assessment does an ethical hacker perform to expose weaknesses in a system?
  • Which cryptographic algorithm is used in asymmetric encryption?
  • Which type of vulnerability research focuses on application flaws in software during security testing?
  • During reconnaissance, which type of information is typically most helpful for identifying domain ownership, IP address ranges, and server details?
  • During malware analysis, a tester takes a system snapshot before and after running the malware and monitors ports, processes, and event logs for changes. Which security practice is this an example of?
  • Which policy governs the use of printed marketing materials to share critical information?
  • Which Bluetooth hacking tool is a complete framework to perform man-in-the-middle attacks on Bluetooth smart devices?
  • Which of the following describes high-interaction honeypots?
  • How can an attacker identify that a system is using User-Mode Linux (UML)?
  • Which type of web application requires a separate application to be installed before you can use the app?
  • Which command shows currently mounted filesystems on a Linux system?
  • Which utility is commonly used to clear temporary files and browser history during a system cleanse?
  • Mark is moving files from a device that is formatted using NTFS to a device that is formatted using FAT. Which of the following is he trying to get rid of?
  • Which IoT security challenge is Joelle trying to overcome by requiring strong user passwords and two-factor authentication?
  • Which program will allow Patrick to create a virus for distribution via email as part of a phishing test?
  • In Nmap, which option is used to retrieve service banners?
  • What is a common consequence of DNS cache poisoning?
  • Daphne has malware on a Linux machine. She prefers to only use open-source software. Which anti-malware software should she use?
  • Which Bluetooth tool is used to query a device’s Service Discovery Protocol (SDP) information?
  • ARIN is responsible for IP address allocations in which region?
  • Which option best describes the export-controls framework for cyber intrusion tools among many countries?
  • Which port and protocol are used for a DNS zone transfer?
  • In OS fingerprinting, which attributes of a response are commonly analyzed to guess the target OS?
  • Which IDS detection type compares current activity to baseline profiles or network behavior baselines?
  • Which type of malware encrypts a victim's files and demands payment to restore access?
  • Which short-range wireless personal area network supports low-power, long-use IoT needs?
  • Which combination of metrics is used to determine a CVSS score?
  • What is the correct Nmap command to run the nmap-vulners script with version detection on 10.10.10.195?
  • Which of the following are spoofing methods?
  • Open-source and commercial tools are both recommended for vulnerability assessment.
  • Which of the following is an open-source web server technology?
  • Which type of threat actor uses hacking skills strictly for defensive purposes?
  • What type of scan is used to find system weaknesses such as open ports, access points, and other potential threats?
  • Which password-cracking technique relies on precomputed hashes to speed up cracking attempts?
  • What process does an organization perform to identify vulnerabilities in its network and security systems?
  • What is the primary use of Nslookup in network administration?
  • During a black box penetration test, which tool is most helpful for gathering information about ownership, IP addresses, domain names, locations, and server types during recon?
  • Which of the following is true about spoofing methods ARP, DNS, IP?
  • Which tool uses rainbow tables to crack Windows login passwords?
  • Creating an area of the network where offending traffic is forwarded and dropped is known as _________?
  • During a penetration test with limited information, what type of engagement is being performed if only the target's IP address and hostname are known?
  • In User-Mode Linux, which device represents the guest's virtual hard disk?
  • During a review, sensitive company information was publicly accessible. Which policy was violated?
  • To launch a denial-of-service attack against a web server, which tool would you most likely use?
  • Which type of penetration test is used to ensure compliance with federal laws and regulations?
  • Which of the following describes a honeypot's purpose?
  • Which honeypot interaction level is most realistic and hardest to compromise, best for observing attacker behavior?
  • Heather used a program hidden inside a legitimate program to gain remote access. What type of malware is she using?
  • Which term best describes registering a domain name that is very similar to a legitimate brand to mislead users?
  • In a captured data scenario, what is the account manager’s email address?
  • Which item is included in the scope of work for a merger penetration test?
  • Which Bluetooth discovery tool would produce output indicating Service Discovery Protocol (SDP) data?
  • Which cloud service model primarily provides virtualized computing resources that the user can manage themselves?
  • Which tool should be used to scan for outdated Apple iOS versions on a network?
  • Which utility is commonly used to remove files and clear internet browsing history?
  • A cloud vendor added cloud services for new employees after acquisition without hardware changes. Which cloud concept does this illustrate?
  • Which tool is suitable for OS fingerprinting by analyzing network traffic?
  • What is the primary purpose of deploying a honeypot in a network security environment?
  • In a merger penetration test scope, which item should be included?
  • What does malware provide to the attacker on a compromised device?
  • In packet analysis, what does filtering for a specific host typically accomplish?
  • Implementing emergency lighting that operates on protected power and activates automatically when main power fails is an example of which physical security objective?
  • Which statement best captures the ongoing nature of security after a penetration test?
  • Which tool is a smart fuzzer used to automatically deliver inputs and detect vulnerabilities such as buffer overflows?
  • Which footprinting method helps identify the ports and services a web server runs?
  • Which describes Microsoft Internet Information Services (IIS) most accurately?
  • Which of the following is considered an out-of-band method for distributing a private key?
  • Which technique enables attackers to redirect users to a malicious website by corrupting the DNS cache?
  • Which tool could a hacker use to create a backdoor on an unpatched system?
  • What term describes a deviation from standard operating security protocols?
  • Which of the following ports are used by null sessions on your network?
  • Blocking port 389 would primarily affect which directory service protocol?
  • Which term describes social engineering that uses a fabricated scenario to obtain sensitive information?
  • Which type of assessment focuses on identifying vulnerabilities based on known exploit signatures or weaknesses in a system?
  • In Nmap, what does the -sV option do?
  • Which statement best describes a rootkit?
  • When conducting a remote penetration test for a client in Utah from Florida, what is the recommended approach to legal compliance?
  • Which tool is commonly used to inspect network traffic and can be deployed inline for protection?
  • Which type of testing involves delivering malformed inputs to an application and observing its responses?
  • Which cloud capability enables automatic scaling of resources to meet demand without manual intervention?
  • In User-Mode Linux, which option describes the virtual disk provided to the guest?
  • There are two non-government sites that provide lists of valuable information for ethical hackers. How is the Full Disclosure site best described?
  • For a honeypot detection tool capable of packet manipulation, which tool is appropriate?
  • Which technique involves adding random bits of data to a password before it is stored as a hash?
  • When establishing a PKI in a local network without a public CA, what is a typical step?
  • Which practice is used to identify exposed ports by actively sending requests?
  • Which description best fits a cybersquatting cloud computing attack?
  • Which social engineering activity is described as part of the penetration test?
  • What describes a session ID?
  • In asymmetric cryptography, which key should be used to encrypt a message intended for the recipient?
  • Which tool is used to capture and inspect network packets during a pentest?
  • Which of the following best describes a stateful inspection?
  • Which of the following is a common indicator that a server supports the HTTP TRACE method, which could pose security concerns?
  • What term describes the process of sniffing traffic between a user and server, then redirecting the traffic to the attacker's machine, where malicious traffic can be forwarded to the user or server?
  • Which statement correctly describes the difference between proximity cards and smart cards?
  • Which embedded operating systems are most likely used by a smart car and its drone for control?
  • An IDS alert indicates an actual intrusion involving privilege escalation and file changes. What is this alert considered?
  • Which tool is commonly used on Linux for open-source malware scanning?
  • Which tool would Allen most likely select to perform network intrusion prevention, intrusion detection, packet capture, and traffic monitoring?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy