✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Information Security and Ethical Hacking Overview
During an authorized penetration test, you discover a server that is not listed in the signed scope document but appears to belong to the same client organization. According to CEH's ethical hacking methodology, what should you do?
Written authorization defines exactly which assets a tester may touch. Testing anything outside the signed scope, even if it appears to belong to the client, is unauthorized and illegal — the tester must get the scope formally amended before proceeding.
Question 2 of 12 · Reconnaissance Techniques
A penetration tester runs 'snmpwalk -v1 -c public 10.10.10.5' during an authorized engagement and receives a full list of running processes, installed software, and routing tables from the target. Which countermeasure BEST addresses the root cause of this exposure?
SNMPv1/v2c transmit community strings ('public'/'private' by default) in cleartext with no real authentication, allowing anyone who guesses the string to read (and sometimes write) MIB data including processes, routes, and software. SNMPv3 adds authentication (usmHMACMD5/SHA) and encryption (DES/AES), and changing default community strings closes the specific gap exploited here.
Question 3 of 12 · System Hacking Phases and Attack Techniques
A vulnerability is assigned a CVSS v3.1 base score of 9.8. Under the standard CVSS qualitative severity rating scale, which severity rating does this score correspond to?
CVSS v3.1 qualitative ratings map 9.0-10.0 to Critical, and 9.8 falls in that range.
Question 4 of 12 · Network and Perimeter Hacking
A penetration tester is on the same VLAN as two target hosts on a switched network and wants to intercept their traffic by poisoning the ARP cache. Which switch security feature BEST prevents this ARP spoofing-based sniffing attack?
Dynamic ARP Inspection checks the source MAC/IP binding of every ARP packet against a trusted DHCP snooping table and drops mismatched (spoofed) ARP replies, directly stopping ARP cache poisoning used to enable sniffing.
Question 5 of 12 · Web Application Hacking
A web application parses XML files uploaded by users and does not disable external entity resolution in its XML parser. A penetration tester uploads a crafted XML file containing a DOCTYPE with a SYSTEM identifier pointing to a local file path, and the application's response includes the contents of /etc/passwd. Which countermeasure BEST prevents this attack?
XML External Entity (XXE) injection occurs when a parser resolves external entities defined in a DOCTYPE. Disabling DTD processing and external entity resolution at the parser level is the standard, effective countermeasure (e.g., setting FEATURE_SECURE_PROCESSING or disabling external general/parameter entities).
Question 6 of 12 · Wireless Network Hacking
A penetration tester sets up a rogue access point broadcasting the same SSID and spoofed BSSID as a corporate network near a coffee shop frequented by employees. The rogue AP has a stronger signal than the legitimate AP, causing nearby laptops to auto-connect to it. The tester then captures credentials submitted through a fake captive portal. Which wireless attack is being performed?
An evil twin attack involves creating a fraudulent AP mimicking a legitimate network's SSID/BSSID to lure clients into connecting, enabling credential harvesting via a fake portal — exactly as described.
Question 7 of 12 · Mobile Platform, IoT, and OT Hacking
During an authorized black-box engagement, a penetration tester needs to passively discover internet-facing IoT devices (webcams, industrial controllers, routers) that may be running with default credentials, without directly touching the target network. Which tool BEST accomplishes this?
Shodan is a search engine that continuously scans and indexes internet-connected devices, including banners, open ports, and default-credential exposures, allowing passive reconnaissance of exposed IoT devices worldwide without directly interacting with the target network.
Question 8 of 12 · Cloud Computing
During an authorized cloud engagement, a tester finds that a company's object storage bucket is configured with public read access, exposing sensitive customer files. No exploit or credential theft was required to access the data. Which cloud security concept BEST explains why this exposure occurred?
In IaaS/PaaS storage services, the cloud provider secures the underlying infrastructure, but the customer is responsible for configuring access controls (bucket policies, ACLs). Public read access left enabled is a classic customer-side misconfiguration under the shared-responsibility model, and it is the single most heavily tested cloud misconfiguration scenario on the exam.
Question 9 of 12 · Cryptography
A company requires that when a manager approves a financial transfer, the manager cannot later deny having approved it, and the recipient must be able to verify both the origin and integrity of the approval message. Which cryptographic mechanism BEST meets these requirements?
A digital signature is generated by hashing the message and encrypting the hash with the signer's private key. Because only the manager holds that private key, the signature proves origin and provides non-repudiation, and the recipient can verify integrity by recomputing the hash and checking it against the signature using the manager's public key.
Question 10 of 12 · Information Security and Ethical Hacking Overview
In the Diamond Model of Intrusion Analysis, which four core features form the vertices of the event diamond used to analyze a security incident?
The Diamond Model connects four core features for every intrusion event: the Adversary (who), Capability (the tool/technique used), Infrastructure (the delivery mechanism), and Victim (the target), with these four vertices linked to analyze relationships between events.
Question 11 of 12 · Reconnaissance Techniques
During a footprinting engagement, an ethical hacker discovers that a company's DNS server responds to an AXFR request from an arbitrary external IP address, returning the entire zone file including internal host names and IP addresses. Which countermeasure BEST mitigates this specific exposure?
A full zone transfer disclosure occurs because the authoritative name server allows AXFR requests from any client. The correct fix is to explicitly restrict zone transfers to known, authorized secondary DNS server IPs (via ACLs such as BIND's 'allow-transfer'), which directly closes the vector the tester exploited.
Question 12 of 12 · System Hacking Phases and Attack Techniques
A penetration tester needs to identify missing patches, insecure configurations, and known CVEs across every host on a corporate network without exploiting any of the findings. Which category of tool BEST meets this requirement?
Network-based vulnerability scanners are purpose-built to enumerate patch levels, misconfigurations, and CVEs across many hosts without exploiting them.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.
The exam fee is approximately $1199 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 9 domains: Information Security and Ethical Hacking Overview (6%), Reconnaissance Techniques (21%), System Hacking Phases and Attack Techniques (17%), Network and Perimeter Hacking (14%), Web Application Hacking (16%), Wireless Network Hacking (6%), Mobile Platform, IoT, and OT Hacking (8%), Cloud Computing (6%), Cryptography (6%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
How do I get the discount?
Use code SECPREP34 at checkout for $34.99 (list undefined) through Oct 11 — the enroll button applies it automatically.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.