Browse all practice questions for the Certified Ethical Hacker Certification (CEHv10) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certified Ethical Hacker Certification (CEHv10) Practice Test 2026 - Free CEH Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • What type of privilege escalation involves acquiring privileges of the same level?
  • What is evaluated during a risk assessment?
  • What is the primary characteristic of a management zone?
  • Which type of threat involves a malicious program disrupting a service?
  • Which of the following is NOT one of the three important components of every system?
  • Which category of password cracking involves using offline tools to guess passwords?
  • In double blind testing, what do both the tester and target lack?
  • What technique involves disabling system features to prevent tracking of activities?
  • What defines an integrity attack in a wireless network?
  • What is the primary goal of data recovery?
  • Which of the following describes a scenario with high hack value?
  • What is a key characteristic of suicide hackers?
  • What does access control help to secure against?
  • What are the two operation modes of WPA2?
  • What is the primary goal of a replay attack?
  • Open System Authentication (OSA) is utilized in the context of which type of network access?
  • Which of the following is a method attackers may use to collect IVs for breaking WEP encryption?
  • Which keylogger type operates at a lower level than standard application keyloggers?
  • In a Shared Key Authentication process, what does the access point (AP) send to the client after receiving the authentication request?
  • What is the aim of enumeration in network security?
  • What is reconnaissance in the context of hacking?
  • What is a necessary step to effectively break WEP encryption?
  • What does a TCP connect scan determine?
  • What is the purpose of website footprinting?
  • How are hackers characterized in the context of ethical hacking?
  • How many types of encryption are there?
  • What motivates hacktivists to break into systems?
  • What is one consequence of a confidentiality attack?
  • Which of the following characterizes a Worm in cybersecurity?
  • What is an example of a detective control?
  • What can website mirroring help with, besides offline browsing?
  • What is the strategy behind Advanced Persistent Threats?
  • What is one method used to gain access to a target's operating system?
  • In terms of cybersecurity, what does phishing refer to?
  • What is the first step in a password guessing attack?
  • What is the purpose of Public Key Infrastructure (PKI)?
  • What is a vulnerability in the context of information security?
  • Which of the following best describes Enterprise Information Security Architecture (EISA)?
  • What is the main purpose of NTP enumeration?
  • What type of attack is characterized by having some information about a password, such as its length and content?
  • What is the primary purpose of Network Address Translation (NAT)?
  • What is NOT a purpose of penetration testing?
  • What is the main goal of physical security measures?
  • What does Steganography primarily aim to achieve in information security?
  • What is phishing primarily used for in cyber attacks?
  • Which type of attack involves gaining access through a compromised device to reach another network?
  • Which of the following is a technique commonly used to leak data by insiders?
  • What defines an out-of-band SQL injection attack?
  • Why is network zoning essential for organizations?
  • What is symmetric encryption characterized by?
  • What does access control aim to restrict within a system or network?
  • In access control, what is the process of establishing user identity called?
  • What is the main characteristic of a blind SQL injection attack?
  • What is the main purpose of threat modeling in application security?
  • What is an Offline Attack in the context of WPA/WPA2 encryption?
  • What is the main purpose of ICMP scanning in network security?
  • Which backup type only saves changes made since the last backup?
  • What type of attack involves injecting scripts into web pages?
  • What do technical security policies define?
  • Identity Access Management (IAM) ensures which of the following?
  • What makes passive sniffing effective in certain network environments?
  • What is a primary function of preventive controls in information security?
  • What are external data leakage threats primarily concerned with?
  • Which of the following best describes website mirroring?
  • What is an example of a technique to crack WPA/WPA2 encryption?
  • What does integrity ensure in information security?
  • Which phase follows the reconnaissance phase in a penetration test?
  • Which encryption standard is utilized by WPA2?
  • During which phase do hackers attempt to hide their activities on the system?
  • What is the role of the Access Management Module in Identity Access Management?
  • What does the process of privilege escalation exploit?
  • What is meant by attack vectors in cybersecurity?
  • Who are state-sponsored hackers typically employed by?
  • What is a potential impact of an ICMP flood attack?
  • What does an access control attack aim to bypass?
  • What does the term "improper input validation" refer to?
  • What is the primary purpose of a website defacement attack?
  • Which item is NOT typically covered under a security policy?
  • Which type of warfare involves infecting systems to achieve political goals?
  • What are Trojans typically disguised as?
  • What does the term "dumpster diving" refer to in the context of non-electronic attacks?
  • What is cryptography most commonly used for?
  • Which of the following is a result of proper access control implementation?
  • What advantage does User Behavior Analytics (UBA) provide?
  • Which layer do circuit level gateway firewalls operate on?
  • What does passive sniffing allow attackers to do in a network using hubs?
  • What is the primary purpose of establishing User Behavior Analytics in an organization?
  • What is the primary objective of the HIPAA enforcement rule?
  • What does cryptanalysis aim to achieve in cybersecurity?
  • What is meant by the term 'functionality' in the context of systems?
  • What is passive banner grabbing primarily used for?
  • What is the aim of launching an attack in the wireless hacking methodology?
  • Network scanning is used primarily for what purpose?
  • Which of the following best describes an Intrusion Detection System (IDS)?
  • What describes vertical privilege escalation?
  • What information do software keyloggers primarily capture?
  • Which of the following is NOT one of the five major elements of information security?
  • What is the role of technical controls in network security?
  • How do attackers exploit web application vulnerabilities?
  • What does the term 'hack value' refer to in the context of ethical hacking?
  • Which of the following is a function of enterprise directory services?
  • Which component is essential for administrative services related to user management?
  • Which type of backup restores the entire data set to its last full form?
  • Which organization is part of the Regional Internet Registries?
  • What is the main goal of a confidentiality attack?
  • Which type of control detects violations in security or attempts of intrusion?
  • What type of hacker is typically motivated by political or religious beliefs?
  • What is ARP spoofing primarily used for?
  • What is the goal of DNS enumeration in ethical hacking?
  • What is a worm in the context of cybersecurity?
  • What does non-repudiation ensure in a communication process?
  • Where are MAC addresses and their virtual LAN parameters stored?
  • Which of the following is NOT classified as a host threat type?
  • What technique does malware commonly utilize to achieve its objectives?
  • Which of the following is NOT a part of the access control model?
  • What is the purpose of a Whois query?
  • Which protocol allows an attacker to exploit a vulnerability due to unresolved name queries?
  • Which threat type involves an unauthorized individual gaining access to a network?
  • Which of the following is a stage within the hacking process?
  • What is one of the features of Identity Access Management systems?
  • In a source routing attack, what role does the attacker play?
  • How does UDP scanning determine whether a port is closed?
  • What role does a Reference Monitor play in access control?
  • What is the primary functionality of a kernel keylogger?
  • What is the main risk of insecure deserialization?
  • What is the primary benefit of using network diagrams in security assessments?
  • What does cracking passwords typically involve?
  • What are the three main types of social engineering?
  • Which of the following is NOT a type of software keylogger?
  • What is the main purpose of a botnet?
  • Which aspect of risk management involves prioritizing risks?
  • What role do network diagrams play in cybersecurity?
  • What is data leakage?
  • Which of the following is NOT a common attack vector?
  • What does a ping sweep help a hacker to determine?
  • Which of the following best characterizes proprietary methodologies?
  • How does a Packet Filtering Firewall determine whether to drop a packet?
  • Which of the following best describes the purpose of network accounting?
  • What does passive footprinting involve?
  • How does active sniffing work in a switched network environment?
  • Which type of attack primarily focuses on exploiting programming mistakes that allow unauthorized actions?
  • What is the primary function of a rootkit?
  • What does the last character of a NetBIOS name represent?
  • What does computer-based social engineering primarily involve?
  • What is the main method used by the Slowloris attack?
  • Which of the following is NOT an objective of risk management?
  • What is one process necessary for achieving information assurance?
  • Which step is NOT part of a data backup strategy?
  • Which action involves deleting the logged activities of an attacker?
  • Which of the following is an example of a non-electronic attack?
  • In a password guessing attack, how should passwords be organized prior to testing?
  • Why do hackers prioritize targets with high hack value?
  • What mechanism does a Man-in-the-Browser attack primarily exploit?
  • What role does an IDS play in network security?
  • What information can NTP enumeration provide to hackers?
  • What is the primary goal of network footprinting in ethical hacking?
  • Which method is not typically used in cryptanalysis?
  • Which of these factors could lower a target's hack value?
  • Which protocol is involved in the Shared Key Authentication process?
  • What does DNS footprinting involve?
  • How do ethical hackers utilize the concept of hack value?
  • What is one common cause of security misconfiguration vulnerabilities?
  • What approach do proprietary methodologies typically follow?
  • Which protocol does WEP use to encrypt data?
  • Which of the following is NOT a way of performing penetration testing?
  • What does a protocol attack primarily aim to do?
  • What is a key component of incident management?
  • What does the operation in access control terminology refer to?
  • What does an XSS attack aim to achieve?
  • What does ICMP echo scanning accomplish?
  • What is the purpose of a security policy?
  • Which of the following is NOT considered a preventative control?
  • What does Role Based Access Control (RBAC) provide?
  • What does sensitive data exposure refer to?
  • Which measure is recommended for safeguarding computer equipment when not in use?
  • What is one of the problems that can cause a security misconfiguration?
  • Recovery controls are implemented after what event?
  • What is a defining feature of symmetric encryption?
  • What does a demilitarized zone (DMZ) provide between external and internal networks?
  • What are the stages in the five stages of hacking?
  • Network zoning is primarily used for?
  • What is the primary purpose of DNS poisoning?
  • Which type of hacker relies entirely on publicly available information?
  • Which of the following is a common use for packet sniffing?
  • What are the three categories of scanning techniques?
  • Which of the following describes the behavior of script kiddies?
  • Which term describes operators used in Google hacking?
  • What is a characteristic of DoS attacks?
  • Which of the following roles primarily engages in criminal activities like website shutdowns?
  • What does passive footprinting help avoid when collecting information?
  • What is a primary outcome when using a keylogger?
  • What characterizes a zero-day attack?
  • What is TCP/IP hijacking primarily aimed at?
  • Which scanning technique focuses on IP networks specifically?
  • What does mobile-based social engineering primarily utilize?
  • What kind of firewall filters packets based on rules applied to their source and destination?
  • What is the primary technique used in ARP poisoning?
  • Which type of traffic is actively injected into a LAN to conduct active sniffing?
  • What kind of effort do hackers invest when they determine something has high 'hack value'?
  • What does static malware analysis involve?
  • What does FISMA primarily protect?
  • Which aspect does vulnerability assessment concentrate on?
  • What best describes a web cache poisoning attack?
  • During an HTTP Response Splitting attack, what does the attacker inject into the response headers?
  • What is encompassed in 'Information Assurance'?
  • Which of these best describes the function of CVSS?
  • In a command and control warfare context, what is a primary objective?
  • In access control terminology, what does the term 'Subject' refer to?
  • What does grey box testing combine?
  • What technique is used by an attacker in MAC spoofing?
  • What kind of attacks involve the use of distributed processing to retrieve passwords from hashes?
  • What is a fundamental characteristic of an integrity attack?
  • In how many layers does stateful multilayer inspection evaluate packets?
  • What kind of information might querying LDAP reveal?
  • What does the user management component include?
  • Which type of attack involves breaking into clouds to steal user information?
  • What characterizes a distributed network attack?
  • What is the primary goal of a wire sniffing attack?
  • What is the function of TKIP in WPA?
  • What is the primary function of an application keylogger?
  • Which aspect of WEP's security is primarily compromised?
  • Who are considered script kiddies?
  • Which component is NOT part of a hardware keylogger?
  • What characterizes a virus in terms of malicious software?
  • What does Rules of Engagement (ROE) specify in penetration testing?
  • What does a MAC address represent in a network?
  • What is the primary goal of the pre-attack phase in penetration testing?
  • What is the correct term for the ability to track user actions within a system?
  • What does the Address Resolution Protocol (ARP) do?
  • What is the primary cause of insider threats within an organization?
  • What does manipulating logs prevent?
  • What is unique about thick whois data?
  • What activates a Trojan's malicious code?
  • Which type of information gathering is considered passive?
  • Which of the following is NOT considered a common network threat?
  • What does doxing involve?
  • Which of the following best describes penetration testing?
  • Which vulnerability allows attackers to access sensitive information from a program's memory space?
  • What is a keylogger primarily designed to do?
  • What does list scanning primarily target?
  • What cryptographic method is utilized to create a digital signature?
  • Which technique can be used to bypass IDS and firewall systems?
  • What type of information can be collected during a security incident analysis?
  • What does a backup recovery test help to verify?
  • Which network zone is dedicated to internal network management?
  • Which attack involves flooding a target with a large number of ICMP ECHO request packets?
  • Which of the following best describes the purpose of conducting penetration testing?
  • What is the primary function of spyware?
  • Which type of firewall is implemented as a physical device?
  • What is the best definition of active assessment in vulnerability evaluations?
  • What does stateful multilayer inspection in firewalls combine?
  • Which of the following best describes a risk in cybersecurity?
  • What is defined as an attempt to gain unauthorized access to a network?
  • What type of attack is categorized under "Active online attacks" in password cracking?
  • Which is a typical step in preventing exploitations during security testing?
  • What is one of the activities involved in the post-attack phase?
  • What information does IP Geolocation help to identify?
  • What technique do stealth scans utilize to bypass firewalls?
  • What is the aim of an authentication attack?
  • Which of the following represents a type of high-interaction honeypot?
  • What motivates black hat hackers to exploit security vulnerabilities?
  • What characterizes a Smurf attack?
  • What protocol does WPA2-Enterprise use for authentication?
  • Which of the following best defines eavesdropping?
  • Which of the following is NOT a type of penetration testing?
  • SQL injection and cross-site scripting are examples of which type of threat?
  • Which type of threats are included in physical security categories?
  • What is a common tactic used by ransomware?
  • When assessing the value of a hack, what factor is most significant to hackers?
  • WPA is an acronym for which security protocol?
  • In the post-attack phase, what is a key activity that is performed by the tester?
  • LDAP is an acronym for what protocol?
  • In the context of security operations, what is the role of the Blue Team?
  • What does a DNS server hijacking attack accomplish?
  • How is risk defined in the context of cybersecurity?
  • What does privilege escalation allow an attacker to do?
  • What are the two types of sniffing techniques?
  • What is a characteristic of blind testing in black box testing?
  • What is the consequence of a vast number of incomplete connections in a SYN flood attack?
  • What is the purpose of a vulnerability assessment?
  • What is the process of capturing data packets on a network called?
  • What are the three classifications of hardware keyloggers?
  • What does User Behavior Analytics (UBA) primarily aim to do?
  • What is the result of successfully compromising a Wi-Fi network?
  • What is an exploit?
  • What is the purpose of a device driver keylogger?
  • What type of attack is characterized by preventing legitimate users from accessing resources?
  • What type of attack does phishing typically involve?
  • Which technique uses dictionary or cracking tools against WPA encryption?
  • What does malware analysis primarily involve?
  • In the context of penetration testing, what is announced testing?
  • What problem does the Meltdown vulnerability present?
  • What is one of the main weaknesses of NetBIOS that hackers exploit?
  • In static malware analysis, what is primarily examined?
  • Considering hack value, what might motivate a hacker besides financial gain?
  • In a dictionary attack, what is the primary method used to crack passwords?
  • What is the purpose of a fragmentation attack?
  • What is a key characteristic of advanced persistent threats?
  • What is a characteristic of a SYN flood attack?
  • What is the result of exploiting a vulnerability that the vendor does not know about?
  • How can viruses spread to other computers?
  • What does EAP stand for in the context of WPA2-Enterprise?
  • What characterizes unannounced testing in cybersecurity?
  • What type of encryption does WPA2-Personal use?
  • What is the purpose of compensating controls in cybersecurity?
  • What does application threat refer to?
  • Which of the following reflects user data monitoring in UBA?
  • Which of the following statements about symmetric encryption is true?
  • Which of the following is a common method of attack used in a rule-based attack?
  • In the realm of hacking, the decision to pursue a target often relies on what criteria?
  • What type of attack involves observing a user's actions to obtain sensitive information?
  • What can impact a hacker's perception of a target's hack value?
  • What is a hash injection attack primarily targeting?
  • In networking, what is the Internet DMZ zone used for?
  • What defines ransomware?
  • What does the term 'Host Threat' refer to?
  • What defines Advanced Persistent Threats (APTs)?
  • What is the primary goal of incident management process preparation?
  • How does ARP obtain MAC addresses of devices on a network?
  • What is the primary characteristic of passive vulnerability scanning?
  • Which action is associated with computer-based social engineering?
  • In-band SQL injection is characterized by:
  • What does the term "active probing assaults" refer to in ethical hacking?
  • What characterizes a grey box penetration test?
  • What does the Common Vulnerability Scoring System (CVSS) provide to organizations?
  • What is one of the objectives of footprinting in cybersecurity?
  • What distinguishes white hats from black hats in ethical hacking?
  • What does Google hacking involve?
  • What does SQL Injection primarily target?
  • What is the primary purpose of UDP scanning in network security?
  • What is a key ethical guideline for conducting penetration tests?
  • Which attack involves exploiting vulnerabilities in the UPnP protocol?
  • What is the first step in the wireless hacking methodology?
  • What is the primary aim of an injection attack?
  • The Sarbanes Oxley Act mainly aims to protect which group?
  • What type of assessment looks at the overall security of a network from outside an organization?
  • Which of the following practices helps in maintaining industry standards and regulations during penetration testing?
  • Which rule of HIPAA ensures the confidentiality and integrity of health information?
  • Which of the following items is NOT typically found on a device enumeration sheet?
  • Which classification of attack involves manipulating the operating system?
  • What is often the target of hacktivist attacks?
  • Why is the concept of NAT important for network security?
  • What is a key feature of hardware keyloggers?
  • The NVD includes databases related to what aspects of cybersecurity?
  • What is the main purpose of security testing methodology?
  • What characterizes active online attacks?
  • What is the objective of a Denial of Service (DoS) attack?
  • What is the purpose of penetration testing in cybersecurity?
  • What does the ISO/IEC 27001:2013 standard focus on?
  • What is the primary function of malware in cyber attacks?
  • Which of the following best differentiates between a security audit and penetration testing?
  • When exploiting vulnerabilities, it is important to pay particular attention to which aspect?
  • What is the primary objective of a Security Incident and Event Management (SIEM) system?
  • What type of information can attackers acquire through IP Geolocation?
  • What activity is NOT part of the target acquisition phase in penetration testing?
  • What do bots used by hackers typically allow them to do?
  • Discretionary Access Control (DAC) allows users to:
  • What is the primary function of antivirus software?
  • Which of the following best describes the behavior of spyware?
  • What process is involved in confirming the identity of a user accessing a network?
  • What is the main function of bots in a botnet?
  • What is the main purpose of a DDoS attack?
  • What is the purpose of a honeypot in network security?
  • Which step follows the detection and analysis in the incident management process?
  • Which types of security policies are mentioned?
  • What is one of the primary objectives of system hacking?
  • Which of the following best defines an attack on sensitive information?
  • What is a primary function of a packet sniffer?
  • Which of the following describes administrative security policies?
  • What potential risk does vulnerability pose to a system?
  • Which type of honeypot is designed for production environments?
  • Which of the following is NOT an application threat type?
  • What process does the Identity Management Module in IAM focus on?
  • What is NOT a typical function of data recovery?
  • Which risk level indicates a moderate concern that requires attention?
  • Which of the following attacks primarily targets financial transactions using a trojan?
  • What is the purpose of brute-force WPA key attacks?
  • What vulnerability does WEP primarily suffer from?
  • What skill do ethical hackers primarily use to enhance security?
  • What can be a result of TCP/IP hijacking?
  • What type of target might be deemed high risk, influencing a hacker's decision?
  • What defines session hijacking?
  • In cybersecurity discussions, what does 'high hack value' commonly indicate?
  • Why are security policies important in organizations?
  • Which of the following is typically NOT a characteristic of a man-in-the-middle attack?
  • What does Thin Whois provide?
  • What is the main goal of incident management in cybersecurity?
  • What does SSDP stand for in the context of network scanning?
  • Which warfare classification involves the use of technology to achieve military objectives?
  • What is the ultimate goal for hackers when they prioritize high hack value?
  • What technique involves observing a person's screen or keyboard to obtain sensitive information?
  • Which type of attack allows extraction of information by injecting true/false queries?
  • What might a hacker consider low hack value?
  • Which of the following helps improve the security of an application?
  • A man-in-the-middle attack primarily interferes with what aspect of communication?
  • Which attack method can be employed to crack WPA encryption?
  • What is usually included in the Rules of Engagement for penetration testing?
  • What is an XML External Entity attack?
  • In sensitive data exposure cases, what is a major contributing factor?
  • Which of the following is NOT a goal of EISA?
  • What internal threat involves employees copying information onto external storage?
  • What is the effect of an ICMP port unreachable packet in a UDP scan?
  • Which of the following is an example of session hijacking?
  • What is the primary purpose of ethical hacking?
  • What is the goal of an Information Security Management Program?
  • What does data loss typically refer to?
  • Which type of vulnerability assessment specifically evaluates the security of software applications?
  • What is an important action in managing smurf attacks?
  • Active vulnerability scanning involves which of the following?
  • What defines active type footprinting in ethical hacking?
  • Which element of information security ensures the validity and protection of data?
  • What does the Digital Millennium Copyright Act (DMCA) primarily address?
  • What is the primary function of a hypervisor-based keylogger?
  • Which term describes the set of policies and procedures governing data security?
  • What is the goal of an availability attack?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy