48. CEH v13 Exam Modules Map and Practice Questions
48.6 CEH-Style Practice Questions – Set A (Modules 01–10)
Set A = Modules 01–10. Conceptual / defensive. Multiple choice + short answers. Answer line after each. Chala try kara – Hint nako pehle!
Q1. (Module 01) Before any Nmap scan in a professional engagement, what must exist first?
A. A Metasploit workspace
B. Written authorisation and agreed scope
C. A public CVE blog post
D. A honeypot on the target LAN
Answer: B. Ethics and law first – scope on paper.
Q2. (Module 01) CIA triad – which pillar does a ransomware encryption event hit hardest first?
A. Confidentiality only forever
B. Integrity of marketing copy
C. Availability of systems and data for users
D. Physical CCTV only
Answer: C. Availability (and often integrity of data state) – users lose access.
Q3. (Module 02) Passive footprinting mainly uses:
A. Exploit kits against the mail server
B. Public sources without directly touching the target much
C. SQL injection on the login form
D. ARP spoofing on the OT VLAN
Answer: B. OSINT / public sources – lower direct touch.
Q4. (Module 02) Amass in passive mode is best described as:
A. A ransomware encryptor
B. A subdomain discovery approach using public/DNS intelligence sources
C. A wireless cracker
D. A session-cookie editor
Answer: B. See ch36 – purpose awareness, OWN/authorized domains only.
Q5. (Module 03) Which Nmap-style activity belongs only on OWN or authorised ranges?
A. Updating Kali
B. Host/port discovery scans
C. Reading a public CVE page
D. Enabling MFA on your Gmail
Answer: B. Scanning needs authorisation.
Q6. (Module 03) A Blue team sees a sudden burst of SYN packets to many ports on one EIP. Likely interpretation?
A. Normal DNS recursion
B. Possible port scan / recon noise
C. Successful TLS handshake only
D. SPF pass for email
Answer: B. Mass SYN across ports often means scan activity – investigate.
Q7. (Module 04) Enumeration differs from basic port scanning because it:
A. Always encrypts disks
B. Pulls extra details from open services (users, shares, banners) after ports are known
C. Replaces the need for patching
D. Is legal on any cafe Wi-Fi
Answer: B. Extra detail phase – still needs authorisation.
Q8. (Module 04) Closing null-session style SMB risks and logging LDAP binds primarily helps against:
A. DNSSEC misconfig only
B. Over-friendly enumeration of directory/share data
C. AES-GCM
D. Certbot renewals
Answer: B. Enum hardening.
Q9. (Module 05) Best first use of a vulnerability scanner report?
A. Blindly launch every exploit
B. Prioritise by exposure and severity, then patch / mitigate
C. Publish the full report on Twitter
D. Disable all logging
Answer: B. Triage and fix – scanner ≠ automatic attack.
Q10. (Module 05) For Sahyadri’s public web VM, which finding usually jumps the queue?
A. Info-level missing HTTP header on an internal printer
B. Critical CVE on the internet-facing web framework
C. Lab-only outdated package on host-only .20 with no route out
D. A typo in a comment
Answer: B. Internet-facing criticals first.
Q11. (Module 06) Least privilege mainly means:
A. Everyone is Administrator for convenience
B. Accounts get only the access needed for their role
C. Disabling TLS
D. Sharing one root password on WhatsApp
Answer: B.
Q12. (Module 06) After a weak password is guessed on an OWN lab SSH, Blue’s durable fixes include:
A. Posting the password in a gist
B. Key-based auth, fail2ban-style controls, MFA where possible, monitoring failed logins
C. Opening port 22 to 0.0.0.0/0 forever
D. Turning off all logs
Answer: B.
Q13. (Module 07) Which statement is safest training practice for malware?
A. Email mystery samples to friends
B. Study concepts and use isolated lab samples under guidance – never detonate on production
C. Disable AV globally at the shop
D. Pay every ransom immediately without IR advice
Answer: B.
Q14. (Module 07) Offline / tested backups most directly support recovery from:
A. SPF alignment only
B. Ransomware / destructive malware availability loss
C. CSS styling bugs
D. Certificate Transparency logs
Answer: B.
Q15. (Module 08) Cleartext FTP on a shared segment is risky mainly because:
A. FTP cannot transfer files
B. Credentials and data may be sniffed by others on the path
C. FTP forces Argon2
D. FTP disables ARP
Answer: B. Prefer SFTP/FTPS patterns.
Q16. (Module 08) Wireshark in a SOC-oriented story is primarily a tool to:
A. Encrypt S3 buckets
B. Inspect packets for troubleshooting and detection learning
C. Replace IAM
D. Mine Bitcoin on EC2
Answer: B.
Q17. (Module 09) Best single control that stops many credential-phishing successes:
A. Longer company motto
B. MFA plus user reporting culture
C. Disabling HTTPS
D. Public RDP with blank password
Answer: B.
Q18. (Module 09) A consented phishing simulation at Raja-Rani Traders requires:
A. No management awareness
B. Clear authorisation, education goal, and no real harm to customers
C. Targeting a rival shop’s CEO
D. Publishing clicked passwords online
Answer: B.
Q19. (Module 10) DoS/DDoS primarily targets which CIA pillar?
A. Confidentiality of one password file only
B. Integrity of a single JPG
C. Availability for legitimate users
D. Non-repudiation certificates only
Answer: C.
Q20. (Module 10) Which is an acceptable Blue response pattern to volumetric floods?
A. Launch your own flood at the suspected source from home broadband
B. Rate limits, filtering, capacity/DDoS protection services, and an IR playbook
C. Disable all monitoring to save CPU
D. Open every port so traffic "spreads out"
Answer: B. Never counter-attack from your laptop.
Q21. (Short) Name the five high-level ethical hacking phases in order (awareness level).
Answer: Reconnaissance, scanning, gaining access, maintaining access, covering tracks – taught as a model; real work also emphasises reporting and remediation. Always authorised.
Q22. (Short) Why is host-only 192.168.56.0/24 used in this book’s Kali labs?
Answer: To keep offensive traffic inside a private lab network you control, reducing accidental scans of production or neighbour networks.
Q23. (Short) Module 04: give one Blue control for DNS enumeration risk.
Answer: Restrict zone transfers (AXFR) to authorised secondaries; monitor; consider split DNS.
Q24. (Short) Module 06: why are password dumps in exam answers a bad habit?
Answer: Real dumps and crack recipes can be abused; discuss controls (MFA, hashing, rate limits) and OWN-lab practice only.
Q25. (Short) Module 09: name three email authentication building blocks defenders cite.
Answer: SPF, DKIM, and DMARC.
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Practices Set A by hacking random public IPs | Practices on OWN lab; answers emphasise controls |
| Skips Modules 01 ethics questions | Treats Q1-style items as career filters |
Ravindra Bagale's Tip
MCQ madhe "always / never / only" absolute shabda bagha – trap asta. Pan ethics "written authorisation first" almost always right. Samjla ka?
Lab
Score Set A: mark Green/Yellow/Red. Re-read book chapters for every Red item before Set B. Pair with Shraddha – she asks Q, you answer in clean English aloud.