CEH v12 and v13 Exam Practice Questions with Verified
Answers, In-Depth Rationales, and Latest 2026 Updates
– Complete Exam Testbank for Passing the Certified
Ethical Hacker Certification on Your First Attempt.
DOMAIN 1: INFORMATION SECURITY & ETHICAL
HACKING FUNDAMENTALS
Q1. What is the primary difference between white hat
and black hat hackers?
A) White hat hackers only use open-source tools; black
hat hackers use commercial tools
B) White hat hackers have permission; black hat hackers
do not
C) White hat hackers target government systems; black
hat hackers target corporations
D) White hat hackers only test physical security; black hat
hackers test network security
☑VERIFIED ANSWER: B – White hat hackers have
permission; black hat hackers do not
Rationale: White hat (ethical) hackers operate with
explicit authorization from the system owner, following
,rules of engagement and reporting findings. Black hat
hackers operate illegally without permission. The legal
distinction is based on authorization, not methodology or
targets.
Q2. Before beginning an external penetration test, what
is the MOST important document to obtain?
A) A recent vulnerability scan report
B) A signed authorization defining scope and timing
C) A list of employee phone numbers
D) A network diagram of only the DMZ
☑VERIFIED ANSWER: B – A signed authorization defining
scope and timing
Rationale: The most critical document before any ethical
hacking engagement is written authorization (Rules of
Engagement) that clearly defines the scope of work,
timing, and specific targets. Without proper
authorization, any testing activity is illegal hacking.
Q3. An ethical hacker discovers a serious weakness that
is outside the approved scope but could affect the
,client. What should the tester do FIRST?
A) Exploit it fully to prove impact
B) Ignore it because it is out of scope
C) Document the observation and notify the client
through the approved escalation path
D) Postpone reporting until the final presentation
☑VERIFIED ANSWER: C – Document the observation and
notify the client through the approved escalation path
Rationale: When an ethical hacker discovers a
vulnerability outside the agreed scope, the correct
approach is to document the finding and escalate it
through the approved communication channels. This
maintains professionalism, protects the tester legally, and
ensures the client receives important security
information.
Q4. Which of the following is a key legal distinction
between ethical hacking and malicious hacking?
A) The tools used
B) Authorization from the target organization
, C) The technical expertise required
D) The operating system used
☑VERIFIED ANSWER: B – Authorization from the target
organization
Rationale: The key legal distinction is authorization.
Ethical hackers have explicit written permission;
malicious hackers do not. Tools, expertise, and operating
systems are irrelevant to the legal distinction.
Q5. What is the primary difference between a
vulnerability assessment and a penetration test?
A) A vulnerability assessment is automated; a penetration
test is always manual
B) A vulnerability assessment identifies weaknesses; a
penetration test exploits them to validate risk
C) A penetration test is performed only internally; a
vulnerability assessment is external
D) There is no difference; they are synonymous
☑VERIFIED ANSWER: B – A vulnerability assessment
identifies weaknesses; a penetration test exploits them to
validate risk
Answers, In-Depth Rationales, and Latest 2026 Updates
– Complete Exam Testbank for Passing the Certified
Ethical Hacker Certification on Your First Attempt.
DOMAIN 1: INFORMATION SECURITY & ETHICAL
HACKING FUNDAMENTALS
Q1. What is the primary difference between white hat
and black hat hackers?
A) White hat hackers only use open-source tools; black
hat hackers use commercial tools
B) White hat hackers have permission; black hat hackers
do not
C) White hat hackers target government systems; black
hat hackers target corporations
D) White hat hackers only test physical security; black hat
hackers test network security
☑VERIFIED ANSWER: B – White hat hackers have
permission; black hat hackers do not
Rationale: White hat (ethical) hackers operate with
explicit authorization from the system owner, following
,rules of engagement and reporting findings. Black hat
hackers operate illegally without permission. The legal
distinction is based on authorization, not methodology or
targets.
Q2. Before beginning an external penetration test, what
is the MOST important document to obtain?
A) A recent vulnerability scan report
B) A signed authorization defining scope and timing
C) A list of employee phone numbers
D) A network diagram of only the DMZ
☑VERIFIED ANSWER: B – A signed authorization defining
scope and timing
Rationale: The most critical document before any ethical
hacking engagement is written authorization (Rules of
Engagement) that clearly defines the scope of work,
timing, and specific targets. Without proper
authorization, any testing activity is illegal hacking.
Q3. An ethical hacker discovers a serious weakness that
is outside the approved scope but could affect the
,client. What should the tester do FIRST?
A) Exploit it fully to prove impact
B) Ignore it because it is out of scope
C) Document the observation and notify the client
through the approved escalation path
D) Postpone reporting until the final presentation
☑VERIFIED ANSWER: C – Document the observation and
notify the client through the approved escalation path
Rationale: When an ethical hacker discovers a
vulnerability outside the agreed scope, the correct
approach is to document the finding and escalate it
through the approved communication channels. This
maintains professionalism, protects the tester legally, and
ensures the client receives important security
information.
Q4. Which of the following is a key legal distinction
between ethical hacking and malicious hacking?
A) The tools used
B) Authorization from the target organization
, C) The technical expertise required
D) The operating system used
☑VERIFIED ANSWER: B – Authorization from the target
organization
Rationale: The key legal distinction is authorization.
Ethical hackers have explicit written permission;
malicious hackers do not. Tools, expertise, and operating
systems are irrelevant to the legal distinction.
Q5. What is the primary difference between a
vulnerability assessment and a penetration test?
A) A vulnerability assessment is automated; a penetration
test is always manual
B) A vulnerability assessment identifies weaknesses; a
penetration test exploits them to validate risk
C) A penetration test is performed only internally; a
vulnerability assessment is external
D) There is no difference; they are synonymous
☑VERIFIED ANSWER: B – A vulnerability assessment
identifies weaknesses; a penetration test exploits them to
validate risk