CEH-STYLE PRACTICE: 20 QUESTIONS (one per CEH v13 module). Original questions for revision, not real exam questions. Answer all 20 first, then check the ANSWER KEY at the bottom. For every wrong answer, write a note in ceh_tracker.csv. Q1 (Module 1: Introduction to Ethical Hacking) A DDoS attack makes a shopping website unreachable for 2 hours. Which part of the CIA triad is affected? A) Availability B) Integrity C) Confidentiality D) Non-repudiation Q2 (Module 2: Footprinting and Reconnaissance) Which activity is PASSIVE reconnaissance? A) Running nmap against the target B) Trying passwords on the VPN C) Sending a test phishing email D) Reading the company's public job postings Q3 (Module 3: Scanning Networks) During a TCP SYN scan, what does an OPEN port send back? A) RST B) FIN C) SYN/ACK D) Nothing Q4 (Module 4: Enumeration) Which SNMP community string is the most common insecure default? A) admin B) public C) root D) guest Q5 (Module 5: Vulnerability Analysis) A vulnerability has a CVSS v3 base score of 9.8. What is its severity rating? A) Critical B) Medium C) High D) Low Q6 (Module 6: System Hacking) Which is the BEST way to store user passwords so stolen hashes are hard to crack? A) MD5 B) AES with the key in the same database C) Base64 encoding D) Salted slow hash such as bcrypt or Argon2 Q7 (Module 7: Malware Threats) Malware that encrypts files and demands payment is called: A) Worm B) Adware C) Ransomware D) Rootkit Q8 (Module 8: Sniffing) Which protocol sends login credentials in clear text? A) SSH B) Telnet C) HTTPS D) SFTP Q9 (Module 9: Social Engineering) Someone follows an employee through a badge-controlled door without badging. This is: A) Tailgating B) Phishing C) Vishing D) Pharming Q10 (Module 10: Denial-of-Service) Which Nginx directive limits requests per client IP? A) server_tokens B) gzip C) proxy_pass D) limit_req Q11 (Module 11: Session Hijacking) Which cookie attribute stops JavaScript from reading a cookie? A) Secure B) SameSite C) HttpOnly D) Domain Q12 (Module 12: Evading IDS, Firewalls, and Honeypots) An IDS raises an alert for normal, legitimate traffic. This is a: A) True positive B) False positive C) False negative D) True negative Q13 (Module 13: Hacking Web Servers) Which Nginx setting hides the version number in headers and error pages? A) server_tokens off B) autoindex off C) sendfile on D) keepalive_timeout 0 Q14 (Module 14: Hacking Web Applications) In the OWASP Top 10 (2021 and 2025 editions), which category is ranked #1? A) Injection B) Cryptographic Failures C) Cross-Site Scripting D) Broken Access Control Q15 (Module 15: SQL Injection) What is the PRIMARY fix for SQL injection in application code? A) Limit input length B) Hide error messages C) Parameterised queries D) Rely only on a WAF Q16 (Module 16: Hacking Wireless Networks) Which home Wi-Fi security setting is the strongest? A) WEP B) WPA3-Personal C) WPA2-AES D) WPA-TKIP Q17 (Module 17: Hacking Mobile Platforms) Which Android setting best blocks fake APKs sent over WhatsApp? A) Install unknown apps: Not allowed B) Developer options on C) Bluetooth on D) Battery saver Q18 (Module 18: IoT and OT Hacking) What is usually the FIRST step to secure a new IP camera? A) Share the admin account with family B) Port-forward it for remote access C) Disable firmware updates D) Change the default credentials Q19 (Module 19: Cloud Computing) Under the AWS shared responsibility model, who patches the operating system on an EC2 instance? A) AWS B) The internet provider C) The customer D) Nobody Q20 (Module 20: Cryptography) Which of these provides INTEGRITY checking but not confidentiality? A) AES B) SHA-256 C) RSA encryption D) TLS ============================================================ ANSWER KEY ============================================================ Q1: A - Availability means the service is usable when needed. Q2: D - Passive = no direct interaction with the target systems. Q3: C - Open ports answer SYN with SYN/ACK; closed ports answer RST. Q4: B - "public" is the classic read-only default; remove SNMP or use SNMPv3 (Lab 37). Q5: A - 9.0-10.0 is Critical. Q6: D - Slow, salted hashing makes offline guessing very expensive. Q7: C - Defence: offline backups and patching (Lab 45). Q8: B - Telnet has no encryption (Labs 19 and 24). Q9: A - Tailgating/piggybacking is a physical social-engineering technique. Q10: D - limit_req with limit_req_zone (Lab 40). Q11: C - HttpOnly hides the cookie from document.cookie (Lab 41). Q12: B - False positive = alert without a real attack. Q13: A - Lab 7. Q14: D - Broken Access Control is A01 in both editions. Q15: C - Parameters keep data separate from SQL code (Lab 29). Q16: B - WPA3-Personal (SAE) resists offline password guessing better (Lab 25). Q17: A - Lab 44. Q18: D - Default passwords are the top IoT risk (Lab 43). Q19: C - AWS secures the cloud; the customer secures what they run in it. Q20: B - A hash proves a file did not change (Labs 28 and 33).