dc dotCreds
Certified Ethical Hacker

CEH Practice Test

Start today's 10-question CEH set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 150 Verified Questions

Questions updated at Jul 18, 2026, 1:30 PM CDT

Go Pro - One Time Unlock

Unlock the full CEH bank

150 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$3.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CEH questions

Use this CEH practice test to review Certified Ethical Hacker. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

150 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective CEH-05 Reporting and Evidence

A security assessment identifies a vulnerability in a web application. What is the primary purpose of the remediation guidance provided to the application owner?

Concept tested:
Question 2 of 10
Objective CEH-03 Vulnerability Analysis

A network device is configured with SNMP and uses the default community string 'public'. An ethical hacker is attempting to gather information about the device. What is the primary risk associated with this configuration?

Concept tested:
Question 3 of 10
Objective CEH-06 Remediation and Patch Management

A remediation team has assigned owners for validated findings and completed the planned fixes. What should the program do before closing those findings?

Concept tested:
Question 4 of 10
Objective CEH-07 Program Scope and Defensive Outcomes

A board member is requesting justification for the organization's investment in controlled offensive security testing. Which statement best articulates the primary security value of this activity?

Concept tested:
Question 5 of 10
Objective CEH-04 Web Application Security

Which browser security control can restrict where scripts, images, and other resources may load from?

Concept tested:
Question 6 of 10
Objective CEH-01 Ethics and Scope

A consultant is engaged to assess the security posture of a competitor's domain as a favor. Prior to commencing any technical activities, what is the *most* critical step the consultant must take?

Concept tested:
Question 7 of 10
Objective CEH-02 Reconnaissance and Scanning

Before sending packets to client systems, the team reviews public records and exposed organizational information. What is that work called?

Concept tested:
Question 8 of 10
Objective CEH-03 Vulnerability Analysis

A security finding is identified as internal-only and does not involve any sensitive data exposure. Considering the principles of risk prioritization, how should this finding be initially assessed?

Concept tested:
Question 9 of 10
Objective CEH-06 Remediation and Patch Management

Why does vulnerability remediation often become part of patch and configuration management?

Concept tested:
Question 10 of 10
Objective CEH-07 Program Scope and Defensive Outcomes

A practice item conflicts with current official documentation. What should a learner do?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 140 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CEH Pro $3.99 one-time

Unlock all 150 CEH questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question CEH PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, Certified Ethical Hacker, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CEH bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

150 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 140 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CEH practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official EC-Council resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent EC-Council practice pages too? EC-Council practice hub.

Source-backed answer review

The free daily CEH set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A security assessment identifies a vulnerability in a web application. What is the primary purpose of the remediation guidance provided to the application owner?

Answer choices

  1. A. Detailed remediation steps, official patch links, or configuration workarounds
  2. B. A vague statement to improve security someday
  3. C. Only the name of the scanning tool
  4. D. A demand to remove every affected system immediately

Correct answer

Detailed remediation steps, official patch links, or configuration workarounds

Remediation guidance should be specific enough for owners to act. Patch links, configuration workarounds, compensating controls, and verification steps help turn a finding into risk reduction. The answer "Detailed remediation steps, official patch links, or configuration workarounds" is supported because specific remediation steps and trusted references help teams fix or mitigate the weakness.

Wrong-answer review

  • B. A vague statement to improve security someday: Vague advice leaves teams without a concrete action path.
  • C. Only the name of the scanning tool: The tool name does not explain how to remediate the issue.
  • D. A demand to remove every affected system immediately: Removal may be unnecessary or harmful when a targeted fix is available.

Extra learning features

Why candidates miss this

The desire to sidestep remediation often leads to the incorrect assumption that immediate system removal is the only solution. Remediation guidance aims to provide a path to resolution, which may involve patching, configuration changes, or compensating controls—not necessarily wholesale decommissioning. The phrase 'affected system immediately' suggests a desire to avoid the more complex work of targeted fixes. Likely wrong answer: A demand to remove every affected system immediately Review focus: NIST SP 800-115, Technical Guide to Information Security Testing and Assessment

Question 2 A network device is configured with SNMP and uses the default community string 'public'. An ethical hacker is attempting to gather information about the device. What is the primary risk associated with this configuration?

Answer choices

  1. A. SNMP automatically patches vulnerable network devices
  2. B. SNMP only changes website cookies
  3. C. SNMP prevents all port scanning
  4. D. An attacker can query the SNMP agent to extract detailed system and network information

Correct answer

An attacker can query the SNMP agent to extract detailed system and network information

Objective/domain: Vulnerability Analysis

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 3 A remediation team has assigned owners for validated findings and completed the planned fixes. What should the program do before closing those findings?

Answer choices

  1. A. Close each item as soon as it is assigned
  2. B. Validated findings should be tracked through remediation and verification
  3. C. Ignore verification once a patch window ends
  4. D. Replace remediation tracking with annual awareness training

Correct answer

Validated findings should be tracked through remediation and verification

Objective/domain: Remediation and Patch Management

Source: NIST SP 800-40 Rev. 3, Guide to Enterprise Patch Management Technologies

Question 4 A board member is requesting justification for the organization's investment in controlled offensive security testing. Which statement best articulates the primary security value of this activity?

Answer choices

  1. A. It matters only after a public breach has occurred
  2. B. It replaces authorization with technical skill
  3. C. It is mainly a way to collect dramatic screenshots
  4. D. Authorized testing helps the organization find and fix weaknesses before real attackers exploit them

Correct answer

Authorized testing helps the organization find and fix weaknesses before real attackers exploit them

Objective/domain: Program Scope and Defensive Outcomes

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 5 Which browser security control can restrict where scripts, images, and other resources may load from?

Answer choices

  1. A. LDAP
  2. B. Content Security Policy (CSP)
  3. C. SNMP
  4. D. MTTR

Correct answer

Content Security Policy (CSP)

Objective/domain: Web Application Security

Source: Content-Security-Policy (CSP) header - HTTP | MDN

Question 6 A consultant is engaged to assess the security posture of a competitor's domain as a favor. Prior to commencing any technical activities, what is the *most* critical step the consultant must take?

Answer choices

  1. A. Refuse scanning or exploitation until documented authorization and target ownership are confirmed
  2. B. Run a small scan because it is unlikely to cause harm
  3. C. Use only passive tools and skip documentation
  4. D. Proceed if the requester promises to pay quickly

Correct answer

Refuse scanning or exploitation until documented authorization and target ownership are confirmed

Objective/domain: Ethics and Scope

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 7 Before sending packets to client systems, the team reviews public records and exposed organizational information. What is that work called?

Answer choices

  1. A. Patch deployment
  2. B. Post-incident recovery
  3. C. Change-management approval
  4. D. Footprinting and reconnaissance

Correct answer

Footprinting and reconnaissance

Objective/domain: Reconnaissance and Scanning

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 8 A security finding is identified as internal-only and does not involve any sensitive data exposure. Considering the principles of risk prioritization, how should this finding be initially assessed?

Answer choices

  1. A. Treat it as the highest priority solely because it exists
  2. B. Remove it from all tracking because it is internal
  3. C. Rank it by the number of words in the finding title
  4. D. The risk priority is lower when the finding has no internet exposure and no sensitive data impact

Correct answer

The risk priority is lower when the finding has no internet exposure and no sensitive data impact

Objective/domain: Vulnerability Analysis

Source: Common Vulnerability Scoring System v3.1 Specification Document | FIRST

Question 9 Why does vulnerability remediation often become part of patch and configuration management?

Answer choices

  1. A. Because patching is needed only for audit paperwork
  2. B. Many validated findings depend on software or firmware updates, configuration changes, or mitigations
  3. C. Because every vulnerability is solved by replacing hardware
  4. D. Because remediation should happen without validation

Correct answer

Many validated findings depend on software or firmware updates, configuration changes, or mitigations

Objective/domain: Remediation and Patch Management

Source: NIST SP 800-40 Rev. 3, Guide to Enterprise Patch Management Technologies

Question 10 A practice item conflicts with current official documentation. What should a learner do?

Answer choices

  1. A. Use study material as support, but verify concepts against current official guidance
  2. B. Assume old practice notes override current documentation
  3. C. Ignore primary guidance once a local quiz is passed
  4. D. Treat every online forum post as authoritative

Correct answer

Use study material as support, but verify concepts against current official guidance

Objective/domain: Program Scope and Defensive Outcomes

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Where to go after the daily web set

How are CEH questions generated?

dotCreds builds CEH practice questions from public exam objectives and EC-Council exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CEH practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.