dc dotCreds
Certified Ethical Hacker

CEH Practice Test

Start today's 10-question CEH set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 150 Verified Questions

Questions updated at Aug 12, 2026, 3:38 PM CDT

Go Pro - One Time Unlock

Unlock the full CEH bank

150 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CEH questions

Use this CEH practice test to review Certified Ethical Hacker. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

150 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective CEH-07 Program Scope and Defensive Outcomes

Which group of activities belongs in the technical core of CEH-style assessment work?

Concept tested:
Question 2 of 10
Objective CEH-07 Program Scope and Defensive Outcomes

An organization engages an approved ethical hacking team to assess its network security posture. What is the primary defensive benefit of this engagement?

Concept tested:
Question 3 of 10
Objective CEH-01 Ethics and Scope

During a penetration test, an exploit reveals a vulnerability that could lead to full domain compromise. The tester has established rules of engagement limiting access. What is the most appropriate next step?

Concept tested:
Question 4 of 10
Objective CEH-01 Ethics and Scope

During a penetration test, a vulnerability is confirmed with minimal impact. To maintain adherence to the established rules of engagement, what is the most appropriate follow-up action?

Concept tested:
Question 5 of 10
Objective CEH-03 Vulnerability Analysis

During a penetration test, a developer inadvertently exposes stack traces, internal file paths, and database connection strings on an application error page accessible to unauthenticated users. Which type of security vulnerability does this represent?

Concept tested:
Question 6 of 10
Objective CEH-05 Reporting and Evidence

During a penetration test, a vulnerability scanner identifies several potential weaknesses. A certified ethical hacker separates these findings into 'confirmed' vulnerabilities and 'tool-suspected' issues. Why is this distinction critical for subsequent remediation efforts?

Concept tested:
Question 7 of 10
Objective CEH-02 Reconnaissance and Scanning

During a reconnaissance phase, an ethical hacker is tasked with identifying potential vulnerabilities within a target organization. Which tool is most commonly used to extract metadata from publicly available documents collected through various sources?

Concept tested:
Question 8 of 10
Objective CEH-06 Remediation and Patch Management

A remediation team has assigned owners for validated findings and completed the planned fixes. What should the program do before closing those findings?

Concept tested:
Question 9 of 10
Objective CEH-04 Web Application Security

During a penetration test, an analyst discovers an application deployed with sample files, debug output, and unused features enabled. Which vulnerability category best describes this situation?

Concept tested:
Question 10 of 10
Objective CEH-03 Vulnerability Analysis

A security finding is identified as internal-only and does not involve any sensitive data exposure. Considering the principles of risk prioritization, how should this finding be initially assessed?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 140 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CEH Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CEH PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CEH bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

150 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 140 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CEH practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official EC-Council resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent EC-Council practice pages too? EC-Council practice hub.

Source-backed answer review

The free daily CEH set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Which group of activities belongs in the technical core of CEH-style assessment work?

Answer choices

  1. A. Payroll tax reporting, invoicing, and customer service routing, under the organization’s defined implementation and exception-management process.
  2. B. Office seating plans, cafeteria access, and meeting etiquette, for the described technical objective and its associated operational control requirements, as selected.
  3. C. Brand marketing, ad placement, and social media scheduling, under organization-wide implementation-governance requirements.
  4. D. Reconnaissance, scanning, enumeration, vulnerability analysis, and related technical attack and defense topics, as the organization’s selected response.

Correct answer

Reconnaissance, scanning, enumeration, vulnerability analysis, and related technical attack and defense topics, as the organization’s selected response.

CEH-style technical study covers the progression from information gathering to scanning, enumeration, vulnerability analysis, and related offensive and defensive concepts. These topics help testers understand how weaknesses are discovered and validated. The answer "Reconnaissance, scanning, enumeration, vulnerability analysis, and related technical attack and defense topics" is supported because those activities form the technical core of reconnaissance through vulnerability analysis.

Wrong-answer review

  • A. Payroll tax reporting, invoicing, and customer service routing, under the organization’s defined implementation and exception-management process.: Administrative finance processes are outside the technical assessment domain.
  • B. Office seating plans, cafeteria access, and meeting etiquette, for the described technical objective and its associated operational control requirements, as selected.: Facilities logistics are not technical attack-and-defense topics in the scenario.
  • C. Brand marketing, ad placement, and social media scheduling, under organization-wide implementation-governance requirements.: Marketing operations do not describe CEH technical assessment work.

Extra learning features

Why candidates miss this

Focusing on business operations, some overlook the technical aspects of a CEH assessment. Payroll tax reporting, invoicing, and customer service routing represent administrative functions, not the reconnaissance, scanning, enumeration, or vulnerability analysis that defines the technical core of CEH work. The CEH framework emphasizes hands-on technical skills, not back-office processes. Likely wrong answer: Payroll tax reporting, invoicing, and customer service routing Review focus: CEH v13 Domains

Interview question

Q: Imagine a new team member is joining our security group. What core skills and knowledge would you consider essential for them to understand regarding ethical hacking and assessment? Strong answer: Beyond the technical skills, I'd want them to understand the fundamental principles of reconnaissance, scanning, and vulnerability analysis. It's not just about running tools; it's about understanding *why* we're doing what we're doing and how those techniques mirror real-world attacker behavior. They need to grasp the importance of enumeration and how it informs our defensive strategies. They also need to understand the legal and ethical boundaries of what we do, and the importance of clear communication and documentation.

  • Understanding of attacker methodologies
  • Emphasis on 'why' behind techniques
  • Legal and ethical considerations
  • Importance of communication and documentation
  • Holistic view of assessment

Caution: Focusing solely on tool usage without understanding the underlying principles. Ignoring the legal and ethical aspects of ethical hacking. Saying 'just learn the tools'.

Why this matters

Recognizing CEH Technical Domains connects ethical hacking activity to measurable defensive improvement, not just successful exploitation.

Objective/domain: Program Scope and Defensive Outcomes

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 2 An organization engages an approved ethical hacking team to assess its network security posture. What is the primary defensive benefit of this engagement?

Answer choices

  1. A. Authorized testing helps the organization find and fix weaknesses before real attackers exploit them
  2. B. It matters only after a public breach has occurred, for the described technical objective and its associated operational control requirements, for evaluation.
  3. C. It replaces authorization with technical skill, for the described technical objective and its associated operational control requirements, in practice.
  4. D. It is mainly a way to collect dramatic screenshots, within the program scope and defensive outcomes context.

Correct answer

Authorized testing helps the organization find and fix weaknesses before real attackers exploit them

Objective/domain: Program Scope and Defensive Outcomes

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 3 During a penetration test, an exploit reveals a vulnerability that could lead to full domain compromise. The tester has established rules of engagement limiting access. What is the most appropriate next step?

Answer choices

  1. A. Stop at the level needed to prove the finding and stay within agreed rules of engagement
  2. B. Keep escalating until full administrative control is obtained, as the primary implementation for the described business requirement.
  3. C. Ignore the scope because deeper access gives better evidence, for the described technical objective and its associated operational control requirements.
  4. D. Delete logs so defenders are not alerted during testing, as the recommended implementation across the complete governed service lifecycle.

Correct answer

Stop at the level needed to prove the finding and stay within agreed rules of engagement

Question 4 During a penetration test, a vulnerability is confirmed with minimal impact. To maintain adherence to the established rules of engagement, what is the most appropriate follow-up action?

Answer choices

  1. A. Stop at the level needed to prove the finding and stay within agreed rules of engagement, for the specified implementation requirement.
  2. B. Keep escalating until full administrative control is obtained, under the stated technical, operational, and governance constraints.
  3. C. Ignore the scope because deeper access gives better evidence, for the described technical objective and its associated operational control requirements, as described.
  4. D. Delete logs so defenders are not alerted during testing, for the described technical objective and its associated operational control requirements, within the proposed design.

Correct answer

Stop at the level needed to prove the finding and stay within agreed rules of engagement, for the specified implementation requirement.

Question 5 During a penetration test, a developer inadvertently exposes stack traces, internal file paths, and database connection strings on an application error page accessible to unauthenticated users. Which type of security vulnerability does this represent?

Answer choices

  1. A. Information Disclosure, within this design.
  2. B. Patch Verification, when applied.
  3. C. Purple Teaming, as the recommended response to this scenario.
  4. D. Mean Time to Remediate, within the described context.

Correct answer

Information Disclosure, within this design.

Objective/domain: Vulnerability Analysis

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 6 During a penetration test, a vulnerability scanner identifies several potential weaknesses. A certified ethical hacker separates these findings into 'confirmed' vulnerabilities and 'tool-suspected' issues. Why is this distinction critical for subsequent remediation efforts?

Answer choices

  1. A. It lets the assessor avoid explaining technical evidence, as the recommended implementation across the complete governed service lifecycle.
  2. B. Remediation teams need confidence and validation level when prioritizing work, for the stated reporting and evidence requirement.
  3. C. It proves every low-confidence item is harmless, within the documented scope, ownership, and validation boundaries.
  4. D. It is used only to make the report longer, under the stated decision criteria.

Correct answer

Remediation teams need confidence and validation level when prioritizing work, for the stated reporting and evidence requirement.

Question 7 During a reconnaissance phase, an ethical hacker is tasked with identifying potential vulnerabilities within a target organization. Which tool is most commonly used to extract metadata from publicly available documents collected through various sources?

Answer choices

  1. A. Nmap, under the documented operational and governance requirements.
  2. B. FOCA (Fingerprinting Organizations with Collected Archives)
  3. C. Hydra, within the documented operational, security, ownership, and validation requirements.
  4. D. Wireshark, for the stated security, delivery, and accountability requirements.

Correct answer

FOCA (Fingerprinting Organizations with Collected Archives)

Objective/domain: Reconnaissance and Scanning

Source: Certified Ethical Hacker (CEH) v13 | EC-Council

Question 8 A remediation team has assigned owners for validated findings and completed the planned fixes. What should the program do before closing those findings?

Answer choices

  1. A. Close each item as soon as it is assigned, under organization-wide implementation-governance requirements.
  2. B. Validated findings should be tracked through remediation and verification
  3. C. Ignore verification once a patch window ends, as the organization’s selected response.
  4. D. Replace remediation tracking with annual awareness training, for the stated remediation and patch management requirement.

Correct answer

Validated findings should be tracked through remediation and verification

Objective/domain: Remediation and Patch Management

Source: NIST SP 800-40 Rev. 3, Guide to Enterprise Patch Management Technologies

Question 9 During a penetration test, an analyst discovers an application deployed with sample files, debug output, and unused features enabled. Which vulnerability category best describes this situation?

Answer choices

  1. A. Broken Access Control, for the stated requirement.
  2. B. Cross-Site Request Forgery, for this task.
  3. C. Software Supply Chain Failures, for the specified implementation requirement.
  4. D. Security Misconfiguration, within the web application security context.

Correct answer

Security Misconfiguration, within the web application security context.

Objective/domain: Web Application Security

Source: OWASP Top Ten Web Application Security Risks

Question 10 A security finding is identified as internal-only and does not involve any sensitive data exposure. Considering the principles of risk prioritization, how should this finding be initially assessed?

Answer choices

  1. A. Treat it as the highest priority solely because it exists, under the documented operational and governance requirements.
  2. B. Remove it from all tracking because it is internal, for the described technical objective and its associated operational control requirements, as selected.
  3. C. Rank it by the number of words in the finding title, for the described technical objective and its associated operational control requirements, for evaluation.
  4. D. The risk priority is lower when the finding has no internet exposure and no sensitive data impact, under the proposed approach.

Correct answer

The risk priority is lower when the finding has no internet exposure and no sensitive data impact, under the proposed approach.

Objective/domain: Vulnerability Analysis

Source: Common Vulnerability Scoring System v3.1 Specification Document | FIRST

Where to go after the daily web set

How are CEH questions generated?

dotCreds builds CEH practice questions from public exam objectives and EC-Council exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CEH practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.