Skip to content

Certified Ethical Hacker (CEH v13) Practice Questions

Prepare for 312-50v13 with more than an answer.

320 questions in the full set20 sample questionsUpdated Jan 26, 2026

Unlock the full exam and previous versions

  • v1Version 1 320 questions Current
  • 312-50v10Legacy Certified Ethical Hacker (CEH v10) 321 questions Locked
  • 312-50v11Legacy Certified Ethical Hacker (CEH v11) 124 questions Locked
  • 312-50v9Legacy Certified Ethical Hacker (CEH v9) 613 questions Locked
  • 312-50v9-1349Legacy Certified Ethical Hacker (CEH v9 ext.) 803 questions Locked
Exam fee
$1199 USD
Level
Intermediate
Valid for
3 years
Domains covered on the exam 9
  1. Information Security and Ethical Hacking Overview6%
  2. Reconnaissance Techniques17%
  3. System Hacking Phases and Attack Techniques15%
  4. Network and Perimeter Hacking24%
  5. Web Application Hacking14%
  6. Wireless Network Hacking5%
  7. Mobile Platform, IoT, and OT Hacking10%
  8. Cloud Computing5%
  9. Cryptography5%
  1. 1

    Which of the following are valid countermeasures against ARP poisoning attacks on a switched network? (Select THREE)

    Show answer details

    Correct answer: A, C, E

  2. 2

    True or False: The primary purpose of the 'salting' process in password hashing is to make the resulting hash longer and more complex, thereby increasing the computational cost for an attacker to perform a brute-force attack.

    Show answer details

    Correct answer: B

    This statement is false. While key stretching techniques (like PBKDF2 or bcrypt) increase computational cost, the primary purpose of salting is to ensure that identical passwords hash to different values. A unique, random salt is added to each password before hashing. This defeats pre-computed hash attacks like rainbow tables, as an attacker would need to generate a separate rainbow table for every possible salt, which is computationally infeasible.

  3. 3

    A security consultant is performing an OSINT engagement. The consultant wants to find all publicly available PDF and Excel files on the globex.com corporate website that might contain sensitive metadata. Which of the following Google dorks is correctly formatted to achieve this specific goal?

    Show answer details

    Correct answer: D

    The correct Google dork syntax uses the site: operator to restrict the search to a specific domain. The filetype: operator restricts results to a certain file extension. To search for multiple file types, the OR operator (which must be in uppercase) is used, and the conditions should be grouped with parentheses for clarity and correct precedence. Therefore, site:globex.com (filetype:pdf OR filetype:xls) is the correct query.

  4. 4

    A manufacturing company operates a SCADA system to control its industrial processes. A security analyst is concerned about potential attacks against the Modbus protocol, which is used for communication between PLCs and the central HMI. Which characteristic of the Modbus protocol makes it particularly vulnerable to replay attacks and unauthorized commands?

    Show answer details

    Correct answer: C

    The Modbus protocol, especially the common Modbus TCP variant, was designed in an era when OT networks were considered isolated and secure. As a result, the protocol itself has no built-in security features. It does not include authentication to verify the source of a command, nor does it use encryption to protect the confidentiality and integrity of the data. This allows an attacker on the network to easily sniff traffic, replay commands, or inject malicious commands to disrupt industrial processes.

  5. 5

    Which of the following attack types exploits a vulnerability where a web application allows a user to control a filename that is then used in a file operation, potentially allowing the attacker to access restricted files outside of the intended directory?

    graph TD A[Attacker sends malicious request] -->|`GET /download?file=../../../../etc/passwd`| B(Web Server) B --> C{Application Logic} C -->|Reads file path from request| D[File System Operation] D -->|Accesses `/etc/passwd`| E(Sensitive File) E --> F[Attacker receives file contents]

    Show answer details

    Correct answer: C

    This describes a Directory Traversal (or Path Traversal) attack. The vulnerability exists when an application uses user-supplied input to construct a path to a file without properly sanitizing it. By using 'dot-dot-slash' (../) sequences, an attacker can navigate up the directory tree and access sensitive files outside of the web root, such as /etc/passwd on a Linux system, as shown in the diagram.

  6. 6

    A penetration tester is evaluating a financial institution's internal network. They discover a legacy system running a custom application that is critical for back-office operations. The tester suspects the application is vulnerable to a buffer overflow but finds that Data Execution Prevention (DEP) is enabled on the host operating system. To bypass DEP, the tester plans to use a Return-Oriented Programming (ROP) attack. Which of the following is the primary goal of creating a ROP chain in this scenario?

    Show answer details

    Correct answer: B

    Return-Oriented Programming (ROP) is an advanced exploitation technique used to bypass security measures like DEP. It works by finding small pieces of executable code, called 'gadgets,' within the existing codebase of a program and its loaded libraries. Each gadget typically performs a small operation (like loading a value into a register) and ends with a ret instruction. By carefully crafting a sequence of addresses on the stack, an attacker can chain these gadgets together to perform complex operations, such as calling VirtualProtect to mark a memory region as executable, thus bypassing DEP.

  7. 7

    During a web application assessment, a security analyst is using Burp Suite to test for vulnerabilities. They identify a feature where user-submitted data is serialized and stored in a cookie. The application is built using Java. The analyst wants to test for insecure deserialization vulnerabilities. Which of the following tools would be most effective for creating a malicious serialized Java object to exploit this vulnerability?

    Show answer details

    Correct answer: B

    ysoserial is a specialized tool designed for generating payloads that exploit insecure deserialization vulnerabilities in Java applications. It contains a collection of 'gadget chains' for various common Java libraries (like Apache Commons Collections, Spring, etc.). These chains, when deserialized by a vulnerable application, can lead to arbitrary code execution. The analyst would use ysoserial to generate a payload, then use Burp Suite to insert this payload into the cookie and send it to the application.

  8. 8

    A red team is targeting a corporation that uses a WPA3-Enterprise protected wireless network for its employees. The team wants to gain access to the internal network by exploiting the wireless infrastructure. Which of the following attack techniques would be most relevant for targeting a WPA3-Enterprise network? (Select TWO)

    Show answer details

    Correct answer: B, D

  9. 9

    An ethical hacker is testing a smart thermostat device that communicates with a cloud-based management platform via the MQTT protocol. The hacker captures the network traffic and observes unencrypted MQTT packets containing sensitive information. To further exploit this, the hacker wants to connect their own client to the MQTT broker and subscribe to all topics to eavesdrop on all communications. Which MQTT topic subscription wildcard should be used to achieve this?

    Show answer details

    Correct answer: D

    In the MQTT protocol, wildcards are used to subscribe to multiple topics at once. The single-level wildcard is +, which matches a single topic level. The multi-level wildcard is #, which matches any number of topic levels. To subscribe to all topics and eavesdrop on all communications passing through the broker, the # wildcard must be used. It must be placed as the last character in the topic string.

  10. 10

    True or False: In a Kubernetes environment, if an attacker compromises a pod and finds a service account token mounted, they can only use this token to access the Kubernetes API server from within that same pod.

    Show answer details

    Correct answer: B

    This statement is false. A Kubernetes service account token is a bearer token. If an attacker exfiltrates this token from a compromised pod, they can use it from anywhere (e.g., their own machine) to authenticate to the Kubernetes API server, provided the API server is accessible. The token's permissions are determined by the Roles and ClusterRoles bound to the service account, not by the location from which it is used.

Create an account to continue.