Question 1
Which of the following are spoofing methods?
Correct Answer:
All of the above
Explanation:
Spoofing is about deceiving a system or user by pretending to be someone or something else, often to intercept traffic, misdirect requests, or evade detection. ARP spoofing works on the local network by sending forged ARP messages that link the attacker’s MAC address to the IP address of another device (like the gateway or a victim). This lets the attacker intercept or modify traffic between devices on the same LAN, creating a man-in-the-middle position. DNS spoofing involves deceiving name resolution so that a domain name resolves to a fraudulent IP address. This can be done by poisoning a DNS cache or by crafting forged DNS responses so users end up at attacker-controlled sites when they think they’re visiting a legitimate one. IP spoofing is when the source IP address in packets is forged to appear as though it came from a different machine. This is used to impersonate another host, evade traceability, or facilitate certain attack techniques like reflection or amplification. Because each technique involves falsifying information to impersonate or mislead a part of the network, all of these are spoofing methods.
Question 2
Which technique involves adding random bits of data to a password before it is stored as a hash?
Correct Answer:
Password salting
Explanation:
Adding random data to a password before hashing is known as salting. The random value, called a salt, is unique for each password and is stored alongside the resulting hash. This ensures that even if two users have the same password, their hashes will be different, so precomputed rainbow tables can’t be reused. Because each password-hash pair uses its own salt, an attacker would have to compute hashes separately for every possible password with every salt, which greatly increases the effort required. Encryption isn’t used for password storage because it’s reversible, whereas hashing (with a salt) aims to store a one-way representation. Hashing without a salt leaves you vulnerable to rainbow table attacks. Key stretching, while related in practice to slowing down attackers by increasing computation (and often involving a salt), is a separate technique focused on making hash computations intentionally slower. The technique described here is specifically salting.
Question 3
Which tool is suitable for OS fingerprinting by analyzing network traffic?
Correct Answer:
P0f OS fingerprinting
Explanation:
Passive OS fingerprinting focuses on the information already present in network traffic rather than sending probes. P0f is built for this approach: it passively monitors captured traffic, analyzes characteristics of the remote host’s TCP/IP stack (such as TTL, window size, IPID behavior, TCP options, and timing patterns), and matches those fingerprints against a database to infer the operating system. This makes it the best fit for OS fingerprinting by analyzing network traffic because it does not generate additional traffic or detectable probes, reducing impact on the target and remaining covert. By contrast, the other tools have different primary roles: a packet analyzer like Wireshark captures and lets you inspect traffic, but it doesn’t automatically map those observations to an OS; a netstat command shows current connections and ports rather than fingerprinting the host; and active scanners that produce results, like Nmap, rely on sending crafted probes to elicit responses, which is not analyzing existing traffic.
Question 4
In vulnerability assessment, which phase focuses on identifying externally visible services on a target with limited information?
Correct Answer:
External penetration testing
Explanation:
From an outside-in perspective, the goal is to map the attack surface that an external attacker could reach with limited starting information. The phase that focuses on identifying externally visible services on a target in this way is external penetration testing. It involves simulating an attacker coming from outside the organization, with minimal intel, and using network discovery to determine what is exposed—from which hosts to which ports and services are reachable, and what versions or configurations might be vulnerable. This helps establish what an attacker could actually exploit from the internet and guides what needs to be secured or patched. If you think about the other options, wireless auditing targets Wi‑Fi security, not the internet-facing services; internal vulnerability scanning looks at assets inside the network after access is gained; and social engineering assesses human factors rather than technical exposure.
Question 5
What describes a session ID?
Correct Answer:
A unique token that a server assigns for the duration of a client's communications with the server
Explanation:
A session ID is a unique token that the server creates to identify a specific user's session for the duration of their interaction with the application. HTTP is stateless, so the server wouldn’t know who you are from one request to the next. It generates a random, hard-to-guess identifier and associates any session data (like login status, shopping cart contents, preferences) with that ID on the server. The client then presents this token with subsequent requests (typically via a cookie), and the server uses it to fetch the correct session data and continue where you left off. This concept is different from a user name, which identifies the user themselves, and SAMPLEit’s not a per-request nonce. A session cookie is a common transport method for the ID, but what matters is the server-issued token that links requests to a particular session.
Question 1
Exam overview

About this Exam

Prepare with the EC-Council Certified Ethical Hacker (CEH) Certification Practice Exam practice quiz. This question bank includes 10 questions covering tool, vulnerability, power, device, and council. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

EC-Council Certified Ethical Hacker (CEH) Certification Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on tool, vulnerability, power, device, and council. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions