CERTIFIED ETHICAL HACKER (CEH) CERTIFICATION:
COMPLETE PRACTICE EXAM WITH ANSWERS AND
RATIONALES
DOMAIN 1: INFORMATION SECURITY AND ETHICAL HACKING OVERVIEW
Question 1
Which of the following best describes the primary objective of ethical hacking?
A) To identify vulnerabilities in a system and fix them without authorization
B) To use the same tools and techniques as malicious hackers, but in a lawful and
legitimate manner to assess security posture
C) To exploit vulnerabilities for personal gain
D) To ensure all systems are 100% secure with no vulnerabilities
Answer: B
Rationale: Ethical hacking involves using the same knowledge, tools, and
techniques as a malicious hacker, but in a lawful and legitimate manner to assess
the security posture of a target system . Option A is incorrect because ethical
hackers must have proper authorization. Option C describes malicious hacking, not
ethical hacking. Option D is unrealistic—no system can be 100% secure, and
ethical hacking helps reduce risk rather than eliminate it entirely .
Question 2
In the context of information security, what is the "Cyber Kill Chain"
methodology?
A) A framework that outlines the stages of a cyberattack, from reconnaissance to
actions on objectives
B) A tool used to encrypt data
,C) A type of firewall configuration
D) A legal framework for cybersecurity compliance
Answer: A
Rationale: The Cyber Kill Chain is a framework developed by Lockheed Martin that
outlines the stages of a cyberattack, from initial reconnaissance through to the
final objective. It is used in domain 1 to understand attacker methodologies and
develop defensive strategies. Options B, C, and D are unrelated to the Cyber Kill
Chain .
Question 3
A "zero-day" attack refers to:
A) An attack that occurs exactly at midnight
B) A vulnerability that is unknown to the vendor and for which no patch is
available
C) An attack that uses social engineering techniques
D) A type of denial-of-service attack
Answer: B
Rationale: A zero-day attack exploits a vulnerability that is unknown to the vendor
and for which no patch or fix is available. The term "zero-day" refers to the fact
that the vendor has zero days to address the vulnerability before it is exploited.
Option A is incorrect as the term has nothing to do with time of day. Options C and
D describe other types of attacks .
Question 4
The concept of "defense in depth" in information security means:
,A) Using a single, highly effective security control
B) Implementing multiple layers of security controls so that if one fails, others are
in place
C) Focusing only on perimeter security
D) Eliminating all security controls to reduce complexity
Answer: B
Rationale: Defense in depth is a layered security approach that uses multiple
security controls (administrative, technical, and physical) to provide redundancy. If
one control fails, others are still in place to protect the system. Option A describes
a single control approach. Option C ignores internal security. Option D is the
opposite of the concept .
Question 5
What is the difference between a vulnerability and a threat?
A) A vulnerability is a weakness; a threat is a potential cause of harm
B) A threat is a weakness; a vulnerability is a potential cause of harm
C) They are the same thing
D) Vulnerabilities only exist in software
Answer: A
Rationale: A vulnerability is a weakness or flaw in a system that could be
exploited. A threat is a potential cause of harm that could exploit that
vulnerability. Understanding the distinction is fundamental to risk assessment in
ethical hacking. Options B and C reverse or conflate the definitions. Option D is
incorrect because vulnerabilities exist in hardware, networks, and human
processes as well .
, Question 6
What is "daisy chaining" in the context of ethical hacking?
A) A network topology where devices are connected in series
B) A technique where an attacker uses one compromised system to attack another
system
C) A type of password attack
D) A method of encryption
Answer: B
Rationale: Daisy chaining is a technique where an attacker uses one compromised
system as a pivot point to attack other systems within the network. This is a key
concept in ethical hacking terminology. Option A describes a physical network
topology, not the hacking technique. Options C and D are unrelated .
DOMAIN 2: RECONNAISSANCE TECHNIQUES (Questions 7-23)
Question 7
Which of the following is an example of passive reconnaissance?
A) Scanning a target network with Nmap
B) Using Google search to gather information about a company
C) Performing a port scan on a target system
D) Using a vulnerability scanner to identify weaknesses
Answer: B
Rationale: Passive reconnaissance involves gathering information without directly
interacting with the target system. Using search engines like Google to gather
information is passive reconnaissance. Options A, C, and D are active
COMPLETE PRACTICE EXAM WITH ANSWERS AND
RATIONALES
DOMAIN 1: INFORMATION SECURITY AND ETHICAL HACKING OVERVIEW
Question 1
Which of the following best describes the primary objective of ethical hacking?
A) To identify vulnerabilities in a system and fix them without authorization
B) To use the same tools and techniques as malicious hackers, but in a lawful and
legitimate manner to assess security posture
C) To exploit vulnerabilities for personal gain
D) To ensure all systems are 100% secure with no vulnerabilities
Answer: B
Rationale: Ethical hacking involves using the same knowledge, tools, and
techniques as a malicious hacker, but in a lawful and legitimate manner to assess
the security posture of a target system . Option A is incorrect because ethical
hackers must have proper authorization. Option C describes malicious hacking, not
ethical hacking. Option D is unrealistic—no system can be 100% secure, and
ethical hacking helps reduce risk rather than eliminate it entirely .
Question 2
In the context of information security, what is the "Cyber Kill Chain"
methodology?
A) A framework that outlines the stages of a cyberattack, from reconnaissance to
actions on objectives
B) A tool used to encrypt data
,C) A type of firewall configuration
D) A legal framework for cybersecurity compliance
Answer: A
Rationale: The Cyber Kill Chain is a framework developed by Lockheed Martin that
outlines the stages of a cyberattack, from initial reconnaissance through to the
final objective. It is used in domain 1 to understand attacker methodologies and
develop defensive strategies. Options B, C, and D are unrelated to the Cyber Kill
Chain .
Question 3
A "zero-day" attack refers to:
A) An attack that occurs exactly at midnight
B) A vulnerability that is unknown to the vendor and for which no patch is
available
C) An attack that uses social engineering techniques
D) A type of denial-of-service attack
Answer: B
Rationale: A zero-day attack exploits a vulnerability that is unknown to the vendor
and for which no patch or fix is available. The term "zero-day" refers to the fact
that the vendor has zero days to address the vulnerability before it is exploited.
Option A is incorrect as the term has nothing to do with time of day. Options C and
D describe other types of attacks .
Question 4
The concept of "defense in depth" in information security means:
,A) Using a single, highly effective security control
B) Implementing multiple layers of security controls so that if one fails, others are
in place
C) Focusing only on perimeter security
D) Eliminating all security controls to reduce complexity
Answer: B
Rationale: Defense in depth is a layered security approach that uses multiple
security controls (administrative, technical, and physical) to provide redundancy. If
one control fails, others are still in place to protect the system. Option A describes
a single control approach. Option C ignores internal security. Option D is the
opposite of the concept .
Question 5
What is the difference between a vulnerability and a threat?
A) A vulnerability is a weakness; a threat is a potential cause of harm
B) A threat is a weakness; a vulnerability is a potential cause of harm
C) They are the same thing
D) Vulnerabilities only exist in software
Answer: A
Rationale: A vulnerability is a weakness or flaw in a system that could be
exploited. A threat is a potential cause of harm that could exploit that
vulnerability. Understanding the distinction is fundamental to risk assessment in
ethical hacking. Options B and C reverse or conflate the definitions. Option D is
incorrect because vulnerabilities exist in hardware, networks, and human
processes as well .
, Question 6
What is "daisy chaining" in the context of ethical hacking?
A) A network topology where devices are connected in series
B) A technique where an attacker uses one compromised system to attack another
system
C) A type of password attack
D) A method of encryption
Answer: B
Rationale: Daisy chaining is a technique where an attacker uses one compromised
system as a pivot point to attack other systems within the network. This is a key
concept in ethical hacking terminology. Option A describes a physical network
topology, not the hacking technique. Options C and D are unrelated .
DOMAIN 2: RECONNAISSANCE TECHNIQUES (Questions 7-23)
Question 7
Which of the following is an example of passive reconnaissance?
A) Scanning a target network with Nmap
B) Using Google search to gather information about a company
C) Performing a port scan on a target system
D) Using a vulnerability scanner to identify weaknesses
Answer: B
Rationale: Passive reconnaissance involves gathering information without directly
interacting with the target system. Using search engines like Google to gather
information is passive reconnaissance. Options A, C, and D are active