EC-Council Certified Ethical Hacker (CEH) v12 practice questions

212 free questions with answers and explanations.

Practice test
  1. 151.A security auditor is performing a penetration test on an industrial control system (ICS) environment. They discover several programmable logic controllers (PLCs) that are directly accessible from the internet without any firewall protection. Which of the following is the most immediate and critical concern regarding these exposed PLCs?Mobile Platform, IoT, and OT Hacking
  2. 152.A software development team discovers a malicious code snippet embedded within a legitimate application's source code. This snippet is designed to remain dormant until a specific date, at which point it will activate and delete critical database files. The team is concerned about the potential for future, similar attacks. Which type of malware best describes this specific code snippet based on its activation mechanism?Malware Threats
  3. 153.An ethical hacker is tasked with identifying vulnerabilities in a custom Android application that processes sensitive financial data. They suspect that the application might be storing unencrypted user credentials or API keys directly within its local storage, violating secure coding practices. Which of the following tools or techniques would be most effective for an ethical hacker to examine the application's local data storage for such vulnerabilities on a rooted device?Mobile Platform, IoT, and OT Hacking
  4. 154.A security team is analyzing a new type of ransomware that specifically targets Android devices. They observe that the ransomware encrypts user data and then attempts to gain root privileges to prevent removal and ensure persistence. Which Android vulnerability or mechanism is the ransomware most likely exploiting to achieve root privilege escalation on unrooted devices?Mobile Platform, IoT, and OT Hacking
  5. 155.A smart factory is implementing a new generation of industrial robots that are interconnected and communicate over a wireless mesh network. Each robot controller uses a unique digital certificate for authentication and encryption. To further enhance the security posture against a compromised individual robot, the security architect proposes a measure that ensures if one robot is compromised, it cannot easily spread malware or control commands to others in the network. Which of the following countermeasures best fits this description?Mobile Platform, IoT, and OT Hacking
  6. 156.A team of ethical hackers is performing a red team exercise against a critical national infrastructure (CNI) target. Their objective is to cause a physical disruption to a specific industrial process controlled by a PLC. They have gained remote access to an engineering workstation on the IT network, which has direct network access to the target PLC. Which OT attack tool category would be most appropriate for them to use next to manipulate the PLC's control logic and achieve their objective?Mobile Platform, IoT, and OT Hacking
  7. 157.A security analyst is investigating a web server compromise. The attacker gained initial access by exploiting a vulnerability in a web application. The analyst discovers that the attacker then used a script to download and execute additional malicious components directly into the server's memory, without writing any files to disk. This technique allows the malware to evade traditional endpoint detection systems that rely on file-based signatures. Which term best describes this type of malware execution?Malware Threats
  8. 158.A mobile application developer is integrating a third-party advertising SDK into their new Android application. During a security review, it's discovered that the SDK requests the `READ_CALL_LOG` and `PROCESS_OUTGOING_CALLS` permissions, which are not explicitly required for its advertising functionality. The developer is concerned about potential data exfiltration and privacy violations. Which of the following mobile attack vectors is MOST likely being enabled by these unnecessary permissions?Mobile Platform, IoT, and OT Hacking
  9. 159.Which of the following best describes the primary characteristic of a polymorphic virus?Malware Threats
  10. 160.A security analyst is investigating a network intrusion where several internal systems have been compromised. The attacker appears to have gained initial access through a phishing email and subsequently installed a persistent backdoor. The analyst observes that outbound traffic from the compromised hosts includes frequent, small UDP packets to a C2 server, disguised as legitimate DNS queries. This technique is commonly used to evade detection and exfiltrate data. Which type of malware communication channel is being leveraged in this scenario?Malware Threats
  11. 161.A smart city project is deploying numerous IoT sensors across public infrastructure to monitor traffic flow and air quality. These sensors transmit data wirelessly to a central cloud platform. A critical security requirement is to ensure the confidentiality and integrity of the data during transmission, especially given the public nature of the network. Which IoT attack countermeasure is most effective for addressing this specific requirement?Mobile Platform, IoT, and OT Hacking
  12. 162.A security assessment of a critical infrastructure facility reveals that several legacy PLCs are still communicating using Modbus TCP over the facility's main corporate network. There are no firewalls or access control lists (ACLs) specifically segmenting the OT network from the IT network. What is the primary security risk introduced by this lack of segmentation and the use of Modbus TCP?Mobile Platform, IoT, and OT Hacking
  13. 163.A mobile device management (MDM) solution is being deployed in an enterprise to secure corporate-owned Android and iOS devices. One of the primary requirements is to prevent users from installing applications from untrusted sources (e.g., third-party app stores or sideloaded APKs) to mitigate malware risks. Which MDM feature is specifically designed to enforce this policy?Mobile Platform, IoT, and OT Hacking
  14. 164.A security operations center (SOC) analyst is reviewing network flow logs and observes an unusual pattern: a large number of outbound connections from an internal server to various external IP addresses on port 25 (SMTP). Further investigation reveals that the server is not authorized to send external email and appears to be sending unsolicited messages. This behavior is indicative of the server being compromised and used to distribute which type of malware?Malware Threats
  15. 165.A security administrator is configuring endpoint protection for a critical server. To prevent the execution of unauthorized or unknown malicious applications, the administrator decides to implement a policy that only allows applications explicitly approved by IT to run. All other applications, by default, are blocked. Which malware countermeasure is being implemented?Malware Threats
  16. 166.An organization relies heavily on a legacy industrial control system (ICS) that is isolated from the internet. However, a recent security audit revealed that an employee inadvertently introduced malware to the ICS network by connecting an infected USB drive, previously used on their home computer, to an engineering workstation. The malware then spread autonomously across the ICS network without any further human interaction or internet connectivity. Which type of malware best describes this behavior?Malware Threats
  17. 167.A penetration tester is evaluating an organization's internal network security. During the reconnaissance phase, they discover several Windows systems running outdated software versions with known vulnerabilities. The tester then crafts a malicious executable that exploits one of these vulnerabilities, gaining remote code execution without any user interaction. This type of malware is specifically designed to take advantage of software flaws. Which term best describes this malicious executable?Malware Threats
  18. 168.A mobile application developer is concerned about the security of their Android application. They want to prevent attackers from analyzing the application's source code, debugging it, or modifying its behavior at runtime. Which technique is primarily used to obscure the logic and make reverse engineering more difficult for Android applications?Mobile Platform, IoT, and OT Hacking
  19. 169.A security analyst discovers a malicious program that, when executed, attempts to disable security software, modify system registry settings, and establish persistent communication with a command-and-control server. This program appears legitimate to the user and requires user interaction to execute. Which category of malware best describes this behavior?Malware Threats
  20. 170.A security analyst is investigating a persistent infection on several Windows workstations. The malware appears to execute every time the system starts, even after attempts to remove it using standard antivirus software. Further analysis reveals that the malware has modified the system's boot records to ensure its continuous execution. Which type of malware is most likely responsible for this behavior?Malware Threats
  21. 171.A security auditor is evaluating the security posture of an organization's software development environment. They discover that developers are frequently downloading third-party libraries and tools from unverified sources. During a code review, a malicious function is found embedded within a seemingly legitimate open-source library, designed to exfiltrate source code whenever the library is compiled into an application. This malicious library was intentionally disguised as harmless. Which type of malware best describes this scenario?Malware Threats
  22. 172.A security researcher is analyzing the firmware of a smart home device to identify potential vulnerabilities. They extract the firmware image and notice that it contains hardcoded credentials for accessing an internal diagnostic interface, as well as several unpatched libraries with known exploits. Which mobile platform attack tool category would be most useful for systematically identifying these types of vulnerabilities within the extracted firmware?Mobile Platform, IoT, and OT Hacking
  23. 173.A penetration tester is evaluating the security of a Supervisory Control and Data Acquisition (SCADA) system in a water treatment facility. They gain access to the human-machine interface (HMI) and discover that it directly communicates with remote terminal units (RTUs) using an unencrypted, proprietary protocol over a wide area network (WAN). The RTUs control critical pumps and valves. Which of the following attack types is the most significant threat due to this specific communication vulnerability?Mobile Platform, IoT, and OT Hacking
  24. 174.A cybersecurity researcher is analyzing a sophisticated piece of malware that employs advanced evasion techniques. The malware dynamically generates its code and uses various encryption methods for different parts of its payload, making signature-based detection extremely difficult. Furthermore, it modifies its decryption routine with each infection, presenting a unique signature for every infected host. Which specific type of malware exhibits this behavior?Malware Threats
  25. 175.A security team is analyzing a suspicious executable found on a critical server. Initial static analysis reveals that the executable contains highly obfuscated code, making it difficult to understand its functionality. When executed in a sandbox environment, it attempts to modify system DLLs and inject code into legitimate processes. Which malware analysis technique would be most effective for understanding the full behavior of this executable, given its evasive characteristics?Malware Threats
  26. 176.A company's financial department experiences a widespread attack where critical accounting files are encrypted, and a demand for cryptocurrency is displayed on all affected screens. The IT team confirms no data was exfiltrated, only encrypted. Which malware type is most accurately described by this scenario?Malware Threats
  27. 177.A critical infrastructure organization is implementing a new Supervisory Control and Data Acquisition (SCADA) system for its power grid. To enhance security, they are considering a network architecture that physically separates the operational technology (OT) network from the information technology (IT) network, allowing one-way data flow from OT to IT, but strictly preventing any direct inbound connections from IT to OT. Which of the following security concepts does this architecture BEST exemplify?Mobile Platform, IoT, and OT Hacking
  28. 178.A user reports receiving an email with an attached PDF document. Upon opening the PDF, nothing visible happens, but the user's antivirus software immediately flags a 'Heap Spray' exploit attempt. Which type of malware attack is this indicative of?Malware Threats
  29. 179.A penetration tester is evaluating a web application that handles sensitive customer data. They identify an input field that is vulnerable to SQL injection, allowing them to extract database schema information. However, the web application firewall (WAF) blocks direct attempts to use SQL keywords like 'UNION SELECT'. To bypass this WAF, the tester encodes the SQL injection payload using URL encoding and character obfuscation. This technique is an example of which aspect of vulnerability analysis and exploitation?System Hacking Phases and Attack Techniques
  30. 180.A blue team analyst is investigating a Windows server after a successful phishing attack led to initial compromise. They discover that a legitimate system utility, `svchost.exe`, is running from an unusual directory (`C:\Temp\` instead of `C:\Windows\System32\`) and is making suspicious outbound connections. What type of attack technique is this most indicative of?System Hacking Phases and Attack Techniques
  31. 181.A security auditor is performing a black-box assessment on a new web application. They use an automated tool to scan for common vulnerabilities. The tool reports a 'SQL Injection' vulnerability on a login page, indicating that input validation is insufficient. Which category of vulnerability analysis does this tool primarily fall under?System Hacking Phases and Attack Techniques
  32. 182.A security analyst is investigating a suspected intrusion on a Linux server. They need to determine if any unauthorized modifications have been made to critical system files. Which of the following tools is BEST suited for this purpose by comparing current file states against a known good baseline?System Hacking Phases and Attack Techniques
  33. 183.A system administrator is reviewing network traffic logs and observes unusual inbound connections on port 3389 (RDP) from external IP addresses that are not part of the organization's VPN range. Upon further investigation, it is discovered that a user's credentials were compromised, and the attacker is attempting to log in directly. Which phase of the system hacking process does this activity represent?System Hacking Phases and Attack Techniques
  34. 184.A penetration tester has successfully exploited a vulnerable web application and gained initial access to a Linux server as a low-privileged user. They now need to elevate their privileges to 'root'. They discover that a cron job is configured to run a script, '/opt/cleanup.sh', every 5 minutes with root privileges. The permissions on '/opt/cleanup.sh' are 'rwxrwxrwx' (777). Which of the following is the most direct and effective method for privilege escalation in this scenario?System Hacking Phases and Attack Techniques
  35. 185.A penetration tester is performing an internal assessment. They notice that a critical web application is running on an outdated version of Apache Tomcat. They consult public vulnerability databases and find several known high-severity vulnerabilities (e.g., CVEs) associated with this specific version. Which step in the vulnerability analysis process is the tester currently performing?System Hacking Phases and Attack Techniques
  36. 186.A security analyst is investigating a suspected breach on a Linux server. They notice that the `/var/log/auth.log` file, which normally records authentication attempts, has been completely emptied. What is the most likely reason for this observation?System Hacking Phases and Attack Techniques
  37. 187.A blue team analyst is investigating a suspected breach and discovers that an attacker has modified the system's `utmp`, `wtmp`, and `btmp` files on a Linux server. What is the primary purpose of modifying these specific files?System Hacking Phases and Attack Techniques
  38. 188.A red team operator has successfully exploited a vulnerable service on a Windows server and obtained a low-privileged shell. To elevate their privileges to 'SYSTEM', they attempt to exploit a known kernel vulnerability. Which system hacking technique are they primarily employing?System Hacking Phases and Attack Techniques
  39. 189.A red team operator has successfully gained initial access to a client's internal network via a phishing campaign. They now need to enumerate internal systems and identify potential targets for further exploitation. Which of the following techniques is most appropriate for discovering active hosts and open ports within the newly accessed internal network segment, without generating excessive noise?System Hacking Phases and Attack Techniques
  40. 190.A penetration tester is conducting an internal vulnerability assessment. They discover a legacy Windows server running an outdated service that is known to be vulnerable to a remote code execution exploit. The server is critical for a specific line-of-business application and cannot be immediately patched. Which of the following techniques is the MOST appropriate for the penetration tester to recommend to maintain access to the compromised system without immediately disrupting the critical service?System Hacking Phases and Attack Techniques
  41. 191.A forensic investigator is analyzing a Linux system after a suspected breach. They notice that the attacker attempted to remove their tracks by deleting critical log files and modifying timestamps. Which file system utility could help the investigator recover deleted files or at least identify remnants of the attacker's activity by examining the raw disk image?System Hacking Phases and Attack Techniques
  42. 192.A penetration tester is conducting a black-box assessment against a client's web application. They discover that the application is vulnerable to SQL injection. Which phase of system hacking does this discovery primarily fall under?System Hacking Phases and Attack Techniques
  43. 193.A cybersecurity consultant is advising a small business on improving their security posture. The business has limited resources but wants to ensure they have basic visibility into potential system compromises. The consultant recommends implementing a system that collects and aggregates logs from various operating systems and network devices into a central repository for analysis. Which type of system is the consultant recommending?System Hacking Phases and Attack Techniques
  44. 194.A cybersecurity team is conducting a post-incident analysis on a compromised server. They suspect that an attacker used a remote access Trojan (RAT) to maintain long-term control. Which of the following locations is a common and stealthy place for a RAT to establish persistence on a Windows operating system?System Hacking Phases and Attack Techniques
  45. 195.A security analyst is investigating a compromised Linux server. They find evidence of an attacker maintaining persistent access. The attacker created a new user account and then modified the '/etc/sudoers' file to grant this new user password-less sudo privileges. Which phase of system hacking does this activity primarily fall under?System Hacking Phases and Attack Techniques
  46. 196.A penetration tester is evaluating a Windows server. They aim to exploit a misconfiguration to gain elevated privileges. During their reconnaissance, they discover that a scheduled task is running with 'SYSTEM' privileges, executing a script from a world-writable directory. Which of the following attack techniques would be most effective for privilege escalation in this scenario?System Hacking Phases and Attack Techniques
  47. 197.A security team is reviewing their vulnerability management program. They are debating whether to primarily rely on automated vulnerability scanning or manual penetration testing. Which of the following is a key advantage of manual penetration testing over automated vulnerability scanning?System Hacking Phases and Attack Techniques
  48. 198.A client has engaged an ethical hacker to perform a penetration test on their internal network. During the 'Gaining Access' phase, the hacker discovers a critical vulnerability in a legacy application that allows arbitrary code execution. Which of the following best describes the immediate objective of exploiting this vulnerability?System Hacking Phases and Attack Techniques
  49. 199.An ethical hacker is conducting a penetration test against an organization with a strong endpoint detection and response (EDR) solution. They need to deploy a custom payload on a target Windows machine without being detected. To bypass signature-based EDR, they decide to encrypt their shellcode and then use a legitimate, signed executable (e.g., PowerShell) to decrypt and execute it in memory, without writing the payload to disk. What is this technique commonly referred to as?System Hacking Phases and Attack Techniques
  50. 200.A system administrator notices unusual outbound network traffic from a critical database server during off-hours. Upon investigation, they find a suspicious executable running with system privileges. The executable appears to communicate with an external IP address over port 53 (DNS). What technique is the attacker MOST likely employing to maintain covert communication and control?System Hacking Phases and Attack Techniques