CEH v13 Practice Questions With Answers: 22 Original Questions (No Dumps)
CEH v12 Mock Tests to Get Guaranteed success by WebAsha Technologies’ Cheapest CEH v12 Exam Mock Tests verified RedHat CEH v12 Exam Questions & Answers (2022). CEH v12 Questions, CEH v12 Mock Tests, CEH v12 Exam Questions, CEH v12 Exam Mock Tests, CEH v12 PDF Questions, CEH v12 PDF Mock Tests, CEH v12 Mock Tests PDF, CEH v12 PDF Mock Tests, RedHat Mock Tests, RedHat CEH v12 Questions, CEH v12 Mock Tests Questions
Quick answer: There is no legitimate PDF of real CEH exam questions: EC-Council's candidate agreement forbids sharing them, and CEH v12 is retired. The current CEH v13 theory exam (312-50) has 125 multiple-choice questions in 4 hours. This page gives 22 original practice questions with explanations across all major topics, so you can test your understanding without risking your certification.
Key takeaways
- Real-question dumps are outdated, often wrong, and using leaked content can get a certification revoked.
- The current CEH v13 theory exam is 312-50: 125 multiple-choice questions in 4 hours. Confirm details with EC-Council before booking.
- Practice questions work when you read the explanation and fix the gap, not when you memorise letters.
- Every question below includes the defensive angle, because CEH tests detection and prevention as well as attack knowledge.
- After a practice set, go back to a lab and repeat the topic you missed.
Are there real CEH exam questions you can download?
No legitimate source offers them. Candidates agree not to share exam content, so a PDF of "real CEH questions" is either leaked, invented or copied from an old version. Using leaked material can lead to a ban or revoked certification, and many "dump" answers are simply wrong. They also fail the real purpose: a security job interview will ask you to explain how an attack works and how to stop it. This page gives you original questions instead.
What does the CEH v13 theory exam look like?
| Item | Detail |
|---|---|
| Exam code | 312-50 (CEH v13, branded CEH v13 AI) |
| Format | 125 multiple-choice questions |
| Time | 4 hours |
| Passing score | Set by exam form; check EC-Council |
| Retired versions | CEH v10, v11 and v12 |
Check the EC-Council CEH page for current details before you book. CEH Practical is a separate hands-on exam; CEH Master means you passed both.
How should you use these practice questions?
- Answer all 22 without notes, in one sitting.
- Read every explanation, including for the ones you got right.
- Write down each topic you missed. Go back to your lab or notes and practise it, for example run Nmap against your own test VM.
- Wait a few days, then try to explain each missed question aloud without looking at the options.
Ethics note: where the questions touch attacks, the point is to understand and defend. Test only systems you own or are authorised in writing to test, and use lab targets such as DVWA or Metasploitable.
22 original CEH practice questions
Question 1: Reconnaissance
Which activity is an example of passive reconnaissance?
- Running a TCP SYN scan against a target range
- Reading the target organisation's public job advertisements and WHOIS records
- Sending crafted packets to find open ports
- Logging in with a list of common passwords
Answer: B. Passive reconnaissance gathers information without touching the target's systems. Public job posts and WHOIS data are open sources. Scans and logins are active and need written authorisation. Defence: limit what you publish about internal technology.
Question 2: Scanning
Which Nmap option performs a TCP SYN (half-open) scan?
- -sT
- -sS
- -sU
- -sn
Answer: B. -sS sends SYN packets and does not complete the handshake. -sT is the full connect scan, -sU scans UDP and -sn only checks which hosts are up. A SYN scan usually needs raw-socket privileges. Defence: firewalls and IDS can log repeated half-open probes.
Question 3: Scanning
An open TCP port 445 on a Windows host most likely indicates which service?
- SMB file sharing
- SMTP mail
- DNS zone transfer
- Telnet
Answer: A. TCP 445 is SMB. Exposing SMB to the internet is a long-standing risk. Defence: block 445 at the perimeter, disable SMBv1 and patch promptly.
Question 4: Enumeration
A network device answers to the SNMP community string 'public'. What is the main risk, and the best fix?
- No risk, since SNMP is read-only
- An attacker can read device information; move to SNMPv3 with authentication and encryption
- DNS cache poisoning; disable DNS
- Buffer overflow; recompile the device software
Answer: B. Default community strings are shared secrets known to everyone, and SNMPv1 and v2c send them in clear text. Information leakage helps later attacks. SNMPv3 adds authentication and privacy. Also restrict SNMP by source address.
Question 5: Vulnerability analysis
A vulnerability has a CVSS v3.1 base score of 9.8. What qualitative rating is that?
- Medium
- High
- Critical
- Low
Answer: C. Scores of 9.0 to 10.0 are Critical, 7.0 to 8.9 are High, 4.0 to 6.9 Medium and 0.1 to 3.9 Low. A base score measures severity, not your business risk, so combine it with exposure and asset value.
Question 6: Vulnerability analysis
A scanner reports a vulnerability that does not actually exist on the host. This is a:
- False negative
- True positive
- False positive
- Zero-day
Answer: C. A false positive is a reported issue that is not real. A false negative is a real issue the scanner missed, which is more dangerous. Verify scanner findings manually before reporting.
Question 7: System hacking
Which control best reduces the success of credential stuffing against a company portal?
- Longer session timeouts
- Unique passwords per site plus multi-factor authentication and rate limiting
- Hiding the login page URL
- Blocking ping
Answer: B. Credential stuffing reuses leaked passwords. Unique passwords stop reuse, MFA blocks logins with only a password, and rate limiting or bot detection slows automated tries. Obscurity does not help.
Question 8: Malware
Software that looks like a useful program but carries a hidden malicious function is called a:
- Worm
- Trojan
- Rootkit
- Logic bomb
Answer: B. A trojan disguises itself as legitimate software. A worm spreads by itself, a rootkit hides its presence, and a logic bomb triggers on a condition. Defence: install from trusted sources and use application allow-listing.
Question 9: Sniffing
Which switch feature helps defend a LAN against ARP spoofing?
- Dynamic ARP Inspection
- Port mirroring
- Spanning Tree Protocol
- VLAN trunking
Answer: A. Dynamic ARP Inspection checks ARP packets against trusted bindings, usually learned through DHCP snooping, and drops forged ones. Port mirroring is an analysis feature, not a protection.
Question 10: Social engineering
An unknown person follows an employee through a secured door without badging in. This is:
- Shoulder surfing
- Tailgating
- Dumpster diving
- Pharming
Answer: B. Tailgating (also called piggybacking) is gaining physical entry by following an authorised person. Defences include mantraps, badge checks, guard presence and staff awareness training.
Question 11: Denial of service
Which technique helps a server resist a TCP SYN flood?
- SYN cookies
- Larger log files
- Disabling TLS
- Opening more ports
Answer: A. SYN cookies let the server avoid holding state for half-open connections until the handshake completes. Rate limiting and upstream DDoS protection also help.
Question 12: Session hijacking
Which measure most directly reduces the risk of session hijacking on a web application?
- Using HTTPS with Secure and HttpOnly cookies and issuing a new session ID after login
- Storing the session ID in the URL
- Using longer usernames
- Allowing sessions that never expire
Answer: A. Encryption stops sniffing, the Secure and HttpOnly flags limit cookie exposure, and regenerating the ID at login prevents session fixation. Session IDs in URLs leak through logs and referrers.
Question 13: Evasion
What is the main difference between an IDS and an IPS?
- An IDS is always hardware, an IPS is always software
- An IPS sits inline and can block traffic, while an IDS monitors and alerts
- An IDS encrypts traffic, an IPS decrypts it
- There is no difference
Answer: B. An intrusion prevention system is placed in the traffic path and can drop packets. A detection system usually watches a copy and raises alerts. Both need tuning to limit false positives.
Question 14: Web servers
What does the HTTP Strict-Transport-Security (HSTS) header do?
- Tells browsers to always use HTTPS for the site
- Blocks all cookies
- Hides the server version
- Forces a password change
Answer: A. HSTS instructs browsers to connect over HTTPS only for a set period, which reduces downgrade and SSL-stripping attacks. It does not hide server details.
Question 15: SQL injection
Which is the most effective primary defence against SQL injection?
- Parameterised queries (prepared statements)
- Blocking the word SELECT
- Using a longer database password
- Hiding error pages only
Answer: A. Parameterised queries keep user input as data, never as code. Input validation and least-privilege database accounts add depth. Keyword blocking is easy to bypass and hiding errors does not remove the flaw. See the OWASP cheat sheets.
Question 16: Web applications
What distinguishes stored XSS from reflected XSS?
- Stored XSS is saved on the server and served to later visitors; reflected XSS comes back in the immediate response to a crafted request
- Stored XSS only affects databases
- Reflected XSS only works on mobile
- They are the same thing
Answer: A. Stored XSS persists, for example in a comment field, and hits every viewer. Reflected XSS needs a victim to follow a crafted link. Defences: contextual output encoding, input validation and a Content Security Policy.
Question 17: Wireless
What is the main security improvement of WPA3-Personal over WPA2-Personal?
- It uses a longer SSID
- Its SAE handshake resists offline dictionary attacks on a captured handshake
- It hides the network automatically
- It removes the need for a password
Answer: B. With WPA2-PSK, a captured handshake can be attacked offline. WPA3 uses Simultaneous Authentication of Equals so each guess needs live interaction. Strong passphrases still matter.
Question 18: Mobile
Why is a rooted or jailbroken device a higher risk for corporate data?
- It removes platform security controls, so apps and malware can gain more access
- It always runs slower
- It cannot connect to Wi-Fi
- It disables the camera
Answer: A. Rooting bypasses sandboxing and the integrity checks the OS provides. Mobile device management can detect compromised devices and block them from corporate resources.
Question 19: IoT and OT
Why do many IoT botnets succeed in compromising devices at scale?
- Devices ship with default or weak credentials and are exposed to the internet
- IoT devices use quantum encryption
- They are always offline
- They have no network interface
Answer: A. Default credentials and exposed management interfaces are the common entry. Defences: change defaults, update firmware, segment IoT on its own VLAN and block inbound access.
Question 20: Cloud
In an IaaS model such as virtual machines in a public cloud, who is normally responsible for patching the guest operating system?
- The cloud provider
- The customer
- The internet service provider
- The hardware vendor
Answer: B. Under the shared responsibility model the provider secures the underlying infrastructure, while the customer secures the operating system, applications, data and access. The split changes by service model, so read the provider's documentation.
Question 21: Cryptography
Which is the best choice for storing user passwords in a database?
- A fast unsalted hash such as MD5
- Reversible encryption with one shared key
- A slow, salted password hashing function such as bcrypt or Argon2
- Plain text in a protected table
Answer: C. Password storage should resist guessing at high speed. Slow, salted functions make each guess expensive and stop identical passwords from sharing a hash. Fast unsalted hashes are quickly cracked.
Question 22: Process
What must be in place before any penetration test begins?
- A signed authorisation and agreed scope and rules of engagement
- A copy of the target's source code
- An internet-facing test server
- A list of employee passwords
Answer: A. Written permission defines what may be tested and when. Without it, testing can be unlawful under the IT Act, 2000. Authorisation is the line between ethical hacking and a crime.
How to read your result
Count by topic, not by total. If you missed two questions in the same module, that module needs another pass. A strong score on this set does not predict the real exam, since the real one is longer and uses different wording. What it does show is whether you understand the reasoning. For the hands-on side, work through a lab for each module. See the Nmap reference guide and the OWASP Top 10 for the scanning and web topics.
Next steps
Pick your three weakest topics and spend this week on them in a lab. If you want a trainer-led route, see our CEH v13 AI course, or the CEH v13 AI Master route if you plan to take the practical exam too. For strategy, read how to pass CEH in the first attempt.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0