CEH Certified Ethical Hacker Practice

Practice 60 original CEH questions covering ethical hacking phases, reconnaissance, scanning, exploitation, web attacks, and security controls, with answers and explanations.

Level: Certified Ethical Hacker (CEH) Difficulty: intermediate 60 questions 60 min
Choose a practice mode, answer each CEH question, then review the explanation. Wrong answers are saved locally for review.
Day streak: 0 days Saved only on this device
Progress 0 / 60
Question 1

What is ethical hacking?

Select an answer
Question 2

What is a penetration test?

Select an answer
Question 3

What is usually the first phase of ethical hacking?

Select an answer
Question 4

What is scope in a penetration test?

Select an answer
Question 5

What is a vulnerability?

Select an answer
Question 6

What is an exploit?

Select an answer
Question 7

What is risk in security?

Select an answer
Question 8

What is a red team?

Select an answer
Question 9

What is a blue team?

Select an answer
Question 10

Which of the following are phases of ethical hacking? Select all that apply.

Select an answer
Question 11

What is footprinting?

Select an answer
Question 12

What is OSINT?

Select an answer
Question 13

What is passive reconnaissance?

Select an answer
Question 14

What is active reconnaissance?

Select an answer
Question 15

What is social engineering?

Select an answer
Question 16

What is phishing?

Select an answer
Question 17

What does a WHOIS lookup reveal?

Select an answer
Question 18

What is DNS enumeration?

Select an answer
Question 19

What is pretexting?

Select an answer
Question 20

What is a search engine footprint?

Select an answer
Question 21

What is port scanning?

Select an answer
Question 22

Which tool is commonly used for port scanning?

Select an answer
Question 23

What is a SYN scan?

Select an answer
Question 24

What is an open port?

Select an answer
Question 25

What is service enumeration?

Select an answer
Question 26

What is vulnerability scanning?

Select an answer
Question 27

What is banner grabbing?

Select an answer
Question 28

What is a ping sweep?

Select an answer
Question 29

What is OS fingerprinting?

Select an answer
Question 30

Banner grabbing can reveal service versions.

Select an answer
Question 31

What is exploitation?

Select an answer
Question 32

What is Metasploit?

Select an answer
Question 33

What is a payload?

Select an answer
Question 34

What is privilege escalation?

Select an answer
Question 35

What is lateral movement?

Select an answer
Question 36

What is persistence?

Select an answer
Question 37

What is a backdoor?

Select an answer
Question 38

What is post-exploitation?

Select an answer
Question 39

What is a reverse shell?

Select an answer
Question 40

A reverse shell connects from the target back to the attacker.

Select an answer
Question 41

What is SQL injection?

Select an answer
Question 42

What is cross-site scripting (XSS)?

Select an answer
Question 43

What is CSRF?

Select an answer
Question 44

What is the OWASP Top 10?

Select an answer
Question 45

What is input validation?

Select an answer
Question 46

What is a session cookie?

Select an answer
Question 47

What is directory traversal?

Select an answer
Question 48

What is a web application firewall (WAF)?

Select an answer
Question 49

What is IDOR?

Select an answer
Question 50

What is a security misconfiguration?

Select an answer
Question 51

What is cryptography?

Select an answer
Question 52

What is hashing?

Select an answer
Question 53

What is a salt in password hashing?

Select an answer
Question 54

What is WPA2?

Select an answer
Question 55

What is malware?

Select an answer
Question 56

What is a trojan?

Select an answer
Question 57

What is a rootkit?

Select an answer
Question 58

What is a honeypot?

Select an answer
Question 59

What is patch management?

Select an answer
Question 60

Match each security tool to its main purpose.