Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.
No matching practice exams yet.
Know why every answer is right or wrong.
What CEH covers: Ethics, Scope, and Assessment Foundations (21%) • Reconnaissance and Adversary Behavior (20%) • Vulnerability Management and Web Application Risk (20%)
New set every day. Start today's questions before they rotate.
Certified Ethical Hacker
A. Incorrect: Broken Object Property Level Authorization because the API allows unauthorized modification of sensitive properties.
B. Correct: Injection because it involves inserting malicious code or data into an application, not modifying object properties.
C. Incorrect: Cross-Site Scripting (XSS) because XSS attacks involve injecting scripts into web pages viewed by other users, not altering API responses directly.
D. Incorrect: Server Side Request Forgery because this attack involves making unauthorized requests from the server to another system, unrelated to property modification.
A. Correct: Circumventing elevation control mechanisms directly aims to gain higher-level permissions, which is essential for executing critical tasks with elevated privileges.
B. Incorrect: Establishing persistence involves maintaining access over time rather than immediately gaining elevated permissions.
C. Incorrect: Reconnaissance activities focus on gathering information about the target environment and do not necessarily involve privilege escalation.
D. Incorrect: Exfiltrating data pertains to transferring sensitive information out of a system, which is unrelated to gaining higher-level permissions.
A. Incorrect: A digital certificate does not solely serve to manage keys; it binds public keys to identities.
B. Correct: A digital certificate verifies an entity's identity by associating its public key with verified information, ensuring secure communications in PKI.
C. Incorrect: While certificates do include public keys, they are primarily used for verifying the holder’s identity and not just storing keys.
D. Incorrect: Although certificates can be revoked, this is a management function rather than their primary purpose of binding identities to keys.
Unlock the full question set, timed exam mode, practice mode, saved progress, previous tests, and readiness scoring.
191 more questions, timed exam mode, and saved history are waiting in the full unlock.
Pro is active. Use the full bank, Exam mode, and saved box scores when you want deeper review.
A. Correct: Lack of input validation allows attackers to inject malicious data into queries or commands, leading to injection vulnerabilities such as SQL injection.
B. Incorrect: They can lead to unauthorized access but do not directly cause injection vulnerabilities if proper validation and sanitization are in place.
C. Incorrect: Compromise the security of stored or transmitted data but do not contribute to injection vulnerabilities.
D. Incorrect: Hinders detection and response efforts but does not prevent injection attacks from occurring.
A. Correct: It accurately reflects the concept of negative risk as defined by NIST SP 800-221, focusing on the potential for adverse impact.
B. Incorrect: An actual breach would be considered a security incident rather than a potential event or circumstance.
C. Incorrect: While vulnerabilities are important in assessing risks, they do not define negative risk as per NIST's guidelines.
D. Incorrect: Mitigating threats and vulnerabilities is part of risk management but does not constitute the definition of negative risk.
A. Correct: Cloud computing enables on-demand network access to a shared pool of configurable resources, as per NIST's definition.
B. Incorrect: Physical isolation contradicts the concept of sharing resources in cloud environments.
C. Incorrect: High-performance computing clusters are not exclusive characteristics of cloud computing and do not align with its definition of shared resources.
D. Incorrect: Secure file transmission via FTP does not relate to the on-demand network access and resource pooling aspects of cloud computing.
A. Incorrect: PowerShell cmdlets like Invoke-Command typically require administrative privileges for remote execution on a target system.
B. Correct: Adversaries can abuse cloud management services to execute commands within virtual machines without needing direct administrative access, leveraging installed virtual machine agents.
C. Incorrect: AppleScript requires local interaction and does not inherently support running scripts remotely on Windows systems.
D. Incorrect: The Windows Command Shell generally requires administrative privileges for remote execution.
A. Correct: Authentication involves verifying a user's identity before granting access to resources, as per NIST SP 800-63-4.
B. Incorrect: It refers to the process of determining what actions a user can perform after their identity has been verified.
C. Incorrect: It does not specifically refer to the verification step required for authentication.
D. Incorrect: As it describes an unrelated security concept.
A. Correct: Using hard-coded passwords can lead to sensitive data exposure if the source code or configuration files are compromised.
B. Incorrect: Insecure design patterns relate more broadly to architecture flaws, not specifically cryptographic failures.
C. Incorrect: Security misconfiguration involves improper settings in software and systems that could be exploited, but it is not a direct cryptographic failure.
D. Incorrect: Vulnerable components refer to outdated or compromised libraries and dependencies, which do not directly involve cryptographic practices.
A. Correct: The core activity performed by a Certified Ethical Hacker (CEH) during an engagement involves identifying vulnerabilities, evaluating security measures, testing systems for weaknesses, and reporting findings to improve cybersecurity. This encompasses the full scope of ethical hacking activities as defined by EC-Council.
B. Incorrect: They are creating incident response plans, but they are crucial for organizations, it falls under the responsibilities of roles such as Incident Handlers or SOC Analysts rather than Certified Ethical Hackers who focus on proactive security assessments.
C. Incorrect: Conducting forensic investigations to recover data from compromised systems is more aligned with the Computer Hacking Forensic Investigator (CHFI) certification. The CEH's role does not primarily involve post-incident recovery but rather prevention and detection of vulnerabilities.
D. Incorrect: Managing cloud security involves responsibilities related to securing cloud environments, which is covered by the Certified Cloud Security Engineer (C|CSE) certification. While a CEH may assess cloud-based systems for vulnerabilities, managing cloud security is not their primary focus.
Go beyond sample questions with the full source-backed bank, objective practice, exam mode, saved progress, and readiness scoring.
201 verified questions are ready behind the full unlock.
Pro is active. Use the full bank, readiness score, and saved exams when you want deeper reps.
Get the full source-backed bank, timed exam mode, practice mode, saved progress, previous tests, and readiness scoring for this exam.
You've answered 0/10 free questions today.
Locked: 191 more questions in the full bank.
Locked: exam simulation mode and end-of-exam review.
Today's free set refreshes soon. Upgrade to continue with the full bank.
Unlock this exam, or compare the career path and bundle options when you want a broader guided route.
Choose the question count, question set, mode, and timer for your full-bank practice.
Set a target once. We will keep the next study action visible before every Pro session.
Answer more questions to start your readiness trend on this browser.
Box scores, domain breakdowns, and full answer explanations for Pro exam attempts on this browser.
Answer questions today and this will become a rolling 7-day scorecard.
Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CEH practice in sync across browsers.
Guest progress saves on this device automatically
201 verified questions are currently in the live bank. Questions updated at May 13, 2026, 1:02 PM CDT. The daily set rotates at 10:00 AM local time, and each explanation links back to the source used to write it. Use the web set for quick practice, then switch to the app when available for larger banks and deeper review.
CEH is most useful when offensive-security concepts, attacker thinking, and vulnerability exploitation language are relevant to the role.
CEH is easiest once you understand what this exam is really rewarding beyond surface memorization.
The fastest path is to turn this exam into a repeatable pattern-recognition loop instead of a one-time cram session.
The usual misses happen when learners recognize keywords but do not slow down enough to match the scenario to the exact decision the exam is testing.
The fastest path is simple: answer the set, review the reasoning, then use the score history and source links to decide what to hit next.
Use these official EC-Council resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.
Need adjacent EC-Council practice pages too? EC-Council practice hub.
dotCreds builds CEH practice questions from EC-Council documentation and source-backed references, with official or primary sources preferred first. The questions are written for realistic study practice, not copied from exam dumps.
Each question includes a source-backed explanation and a link to the documentation or reference used to validate the answer. If an official page is too broad, dotCreds uses a reputable answer-level reference instead of pretending a generic page proves the answer.
The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.
The site is the fastest way to start CEH practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.
The web page is the quick free sampler. If a dotCreds app is available for CEH, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.