Free Certified Ethical Hacker (CEH v13) practice — 6 questions on System Hacking Phases and Attack Techniques, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · System Hacking Phases and Attack Techniques
A vulnerability scanner reports a finding with CVSS v3.1 vector string: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which statement BEST describes the exploitability characteristics represented by this vector?
AV:N (network), AC:L (low complexity), PR:N (no privileges required), and UI:N (no user interaction) combine to describe a remotely exploitable, easily triggered attack, with C/I/A:H indicating high impact across all three security properties.
Question 2 of 6 · System Hacking Phases and Attack Techniques
An organization suspects fileless malware is running entirely in memory via PowerShell and WMI, leaving no executable artifact on disk. Which detection approach is MOST effective against this threat?
Fileless malware abuses legitimate living-off-the-land binaries (PowerShell, WMI) and resides only in memory or the registry, so behavioral analytics and memory forensics via EDR are required to detect anomalous process behavior since no malicious file exists to scan.
Question 3 of 6 · System Hacking Phases and Attack Techniques
Which rootkit type operates at the same privilege level as the operating system kernel, intercepting system calls directly and making it exceptionally difficult to detect using standard OS-level tools?
Kernel-level rootkits run within the OS kernel itself, at the same privilege level, allowing direct interception and modification of system calls, which is why standard user-mode and OS-native detection tools cannot reliably identify them.
Question 4 of 6 · System Hacking Phases and Attack Techniques
An attacker used a timestomping tool to alter a malicious file's creation and modification timestamps to match legitimate system files, attempting to evade timeline analysis. Which NTFS artifact should a forensic investigator examine to detect this manipulation?
Most timestomping utilities modify only the $STANDARD_INFORMATION timestamps (visible via Explorer or 'dir') but fail to also alter the $FILE_NAME attribute timestamps stored separately in the MFT, creating a detectable discrepancy between the two.
Question 5 of 6 · System Hacking Phases and Attack Techniques
CEH v13 curriculum introduces WormGPT and FraudGPT as examples of which emerging threat category?
WormGPT and FraudGPT are jailbroken/uncensored LLM variants sold on underground forums specifically to help attackers craft convincing phishing lures, malicious code, and social engineering scripts without the ethical guardrails of mainstream AI models.
Question 6 of 6 · System Hacking Phases and Attack Techniques
During a post-exploitation privilege escalation assessment, a penetration tester discovers a Windows service configured with the unquoted path C:\Program Files\Some App\service.exe, running under the SYSTEM account. The tester also has write access to C:\Program.exe. Which statement BEST describes the risk and the appropriate remediation?
When a service path contains unescaped spaces and no quotes, Windows tries each space-delimited segment as a potential executable path in order, so a planted C:\Program.exe would execute first; since the service runs as SYSTEM, this yields SYSTEM-level code execution. Proper remediation is quoting the path and restricting write access to parent directories.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.