Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 49 pages
Exam (elaborations)

CERTIFIED ETHICAL HACKER (CEH) CERTIFICATION: COMPLETE PRACTICE EXAM WITH ANSWERS AND RATIONALES

Document preview thumbnail
Preview 4 out of 49 pages

CERTIFIED ETHICAL HACKER (CEH) CERTIFICATION: COMPLETE PRACTICE EXAM WITH ANSWERS AND RATIONALES

Content preview

CERTIFIED ETHICAL HACKER (CEH) CERTIFICATION:
COMPLETE PRACTICE EXAM WITH ANSWERS AND
RATIONALES

DOMAIN 1: INFORMATION SECURITY AND ETHICAL HACKING OVERVIEW
Question 1
Which of the following best describes the primary objective of ethical hacking?
A) To identify vulnerabilities in a system and fix them without authorization
B) To use the same tools and techniques as malicious hackers, but in a lawful and
legitimate manner to assess security posture
C) To exploit vulnerabilities for personal gain
D) To ensure all systems are 100% secure with no vulnerabilities


Answer: B
Rationale: Ethical hacking involves using the same knowledge, tools, and
techniques as a malicious hacker, but in a lawful and legitimate manner to assess
the security posture of a target system . Option A is incorrect because ethical
hackers must have proper authorization. Option C describes malicious hacking, not
ethical hacking. Option D is unrealistic—no system can be 100% secure, and
ethical hacking helps reduce risk rather than eliminate it entirely .


Question 2
In the context of information security, what is the "Cyber Kill Chain"
methodology?
A) A framework that outlines the stages of a cyberattack, from reconnaissance to
actions on objectives
B) A tool used to encrypt data

,C) A type of firewall configuration
D) A legal framework for cybersecurity compliance


Answer: A
Rationale: The Cyber Kill Chain is a framework developed by Lockheed Martin that
outlines the stages of a cyberattack, from initial reconnaissance through to the
final objective. It is used in domain 1 to understand attacker methodologies and
develop defensive strategies. Options B, C, and D are unrelated to the Cyber Kill
Chain .


Question 3
A "zero-day" attack refers to:
A) An attack that occurs exactly at midnight
B) A vulnerability that is unknown to the vendor and for which no patch is
available
C) An attack that uses social engineering techniques
D) A type of denial-of-service attack


Answer: B
Rationale: A zero-day attack exploits a vulnerability that is unknown to the vendor
and for which no patch or fix is available. The term "zero-day" refers to the fact
that the vendor has zero days to address the vulnerability before it is exploited.
Option A is incorrect as the term has nothing to do with time of day. Options C and
D describe other types of attacks .


Question 4
The concept of "defense in depth" in information security means:

,A) Using a single, highly effective security control
B) Implementing multiple layers of security controls so that if one fails, others are
in place
C) Focusing only on perimeter security
D) Eliminating all security controls to reduce complexity


Answer: B
Rationale: Defense in depth is a layered security approach that uses multiple
security controls (administrative, technical, and physical) to provide redundancy. If
one control fails, others are still in place to protect the system. Option A describes
a single control approach. Option C ignores internal security. Option D is the
opposite of the concept .


Question 5
What is the difference between a vulnerability and a threat?
A) A vulnerability is a weakness; a threat is a potential cause of harm
B) A threat is a weakness; a vulnerability is a potential cause of harm
C) They are the same thing
D) Vulnerabilities only exist in software


Answer: A
Rationale: A vulnerability is a weakness or flaw in a system that could be
exploited. A threat is a potential cause of harm that could exploit that
vulnerability. Understanding the distinction is fundamental to risk assessment in
ethical hacking. Options B and C reverse or conflate the definitions. Option D is
incorrect because vulnerabilities exist in hardware, networks, and human
processes as well .

, Question 6
What is "daisy chaining" in the context of ethical hacking?
A) A network topology where devices are connected in series
B) A technique where an attacker uses one compromised system to attack another
system
C) A type of password attack
D) A method of encryption


Answer: B
Rationale: Daisy chaining is a technique where an attacker uses one compromised
system as a pivot point to attack other systems within the network. This is a key
concept in ethical hacking terminology. Option A describes a physical network
topology, not the hacking technique. Options C and D are unrelated .


DOMAIN 2: RECONNAISSANCE TECHNIQUES (Questions 7-23)


Question 7
Which of the following is an example of passive reconnaissance?
A) Scanning a target network with Nmap
B) Using Google search to gather information about a company
C) Performing a port scan on a target system
D) Using a vulnerability scanner to identify weaknesses


Answer: B
Rationale: Passive reconnaissance involves gathering information without directly
interacting with the target system. Using search engines like Google to gather
information is passive reconnaissance. Options A, C, and D are active

Document information

Uploaded on
July 15, 2026
Number of pages
49
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$24.09

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
docwillowivy
5.0
(1)
Sold
9
Followers
1
Items
2518
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions