CEH v13 Practice Questions With Answers: 22 Original Questions (No Dumps)

CEH v12 Mock Tests to Get Guaranteed success by WebAsha Technologies’ Cheapest CEH v12 Exam Mock Tests verified RedHat CEH v12 Exam Questions & Answers (2022). CEH v12 Questions, CEH v12 Mock Tests, CEH v12 Exam Questions, CEH v12 Exam Mock Tests, CEH v12 PDF Questions, CEH v12 PDF Mock Tests, CEH v12 Mock Tests PDF, CEH v12 PDF Mock Tests, RedHat Mock Tests, RedHat CEH v12 Questions, CEH v12 Mock Tests Questions

Sep 12, 2022 - 04:53
Updated: 3 days ago
104.3k
CEH v13 Practice Questions With Answers: 22 Original Questions (No Dumps)

Quick answer: There is no legitimate PDF of real CEH exam questions: EC-Council's candidate agreement forbids sharing them, and CEH v12 is retired. The current CEH v13 theory exam (312-50) has 125 multiple-choice questions in 4 hours. This page gives 22 original practice questions with explanations across all major topics, so you can test your understanding without risking your certification.

Key takeaways

  • Real-question dumps are outdated, often wrong, and using leaked content can get a certification revoked.
  • The current CEH v13 theory exam is 312-50: 125 multiple-choice questions in 4 hours. Confirm details with EC-Council before booking.
  • Practice questions work when you read the explanation and fix the gap, not when you memorise letters.
  • Every question below includes the defensive angle, because CEH tests detection and prevention as well as attack knowledge.
  • After a practice set, go back to a lab and repeat the topic you missed.

Are there real CEH exam questions you can download?

No legitimate source offers them. Candidates agree not to share exam content, so a PDF of "real CEH questions" is either leaked, invented or copied from an old version. Using leaked material can lead to a ban or revoked certification, and many "dump" answers are simply wrong. They also fail the real purpose: a security job interview will ask you to explain how an attack works and how to stop it. This page gives you original questions instead.

What does the CEH v13 theory exam look like?

ItemDetail
Exam code312-50 (CEH v13, branded CEH v13 AI)
Format125 multiple-choice questions
Time4 hours
Passing scoreSet by exam form; check EC-Council
Retired versionsCEH v10, v11 and v12

Check the EC-Council CEH page for current details before you book. CEH Practical is a separate hands-on exam; CEH Master means you passed both.

How should you use these practice questions?

  1. Answer all 22 without notes, in one sitting.
  2. Read every explanation, including for the ones you got right.
  3. Write down each topic you missed. Go back to your lab or notes and practise it, for example run Nmap against your own test VM.
  4. Wait a few days, then try to explain each missed question aloud without looking at the options.

Ethics note: where the questions touch attacks, the point is to understand and defend. Test only systems you own or are authorised in writing to test, and use lab targets such as DVWA or Metasploitable.

22 original CEH practice questions

Question 1: Reconnaissance

Which activity is an example of passive reconnaissance?

  1. Running a TCP SYN scan against a target range
  2. Reading the target organisation's public job advertisements and WHOIS records
  3. Sending crafted packets to find open ports
  4. Logging in with a list of common passwords

Answer: B. Passive reconnaissance gathers information without touching the target's systems. Public job posts and WHOIS data are open sources. Scans and logins are active and need written authorisation. Defence: limit what you publish about internal technology.

Question 2: Scanning

Which Nmap option performs a TCP SYN (half-open) scan?

  1. -sT
  2. -sS
  3. -sU
  4. -sn

Answer: B. -sS sends SYN packets and does not complete the handshake. -sT is the full connect scan, -sU scans UDP and -sn only checks which hosts are up. A SYN scan usually needs raw-socket privileges. Defence: firewalls and IDS can log repeated half-open probes.

Question 3: Scanning

An open TCP port 445 on a Windows host most likely indicates which service?

  1. SMB file sharing
  2. SMTP mail
  3. DNS zone transfer
  4. Telnet

Answer: A. TCP 445 is SMB. Exposing SMB to the internet is a long-standing risk. Defence: block 445 at the perimeter, disable SMBv1 and patch promptly.

Question 4: Enumeration

A network device answers to the SNMP community string 'public'. What is the main risk, and the best fix?

  1. No risk, since SNMP is read-only
  2. An attacker can read device information; move to SNMPv3 with authentication and encryption
  3. DNS cache poisoning; disable DNS
  4. Buffer overflow; recompile the device software

Answer: B. Default community strings are shared secrets known to everyone, and SNMPv1 and v2c send them in clear text. Information leakage helps later attacks. SNMPv3 adds authentication and privacy. Also restrict SNMP by source address.

Question 5: Vulnerability analysis

A vulnerability has a CVSS v3.1 base score of 9.8. What qualitative rating is that?

  1. Medium
  2. High
  3. Critical
  4. Low

Answer: C. Scores of 9.0 to 10.0 are Critical, 7.0 to 8.9 are High, 4.0 to 6.9 Medium and 0.1 to 3.9 Low. A base score measures severity, not your business risk, so combine it with exposure and asset value.

Question 6: Vulnerability analysis

A scanner reports a vulnerability that does not actually exist on the host. This is a:

  1. False negative
  2. True positive
  3. False positive
  4. Zero-day

Answer: C. A false positive is a reported issue that is not real. A false negative is a real issue the scanner missed, which is more dangerous. Verify scanner findings manually before reporting.

Question 7: System hacking

Which control best reduces the success of credential stuffing against a company portal?

  1. Longer session timeouts
  2. Unique passwords per site plus multi-factor authentication and rate limiting
  3. Hiding the login page URL
  4. Blocking ping

Answer: B. Credential stuffing reuses leaked passwords. Unique passwords stop reuse, MFA blocks logins with only a password, and rate limiting or bot detection slows automated tries. Obscurity does not help.

Question 8: Malware

Software that looks like a useful program but carries a hidden malicious function is called a:

  1. Worm
  2. Trojan
  3. Rootkit
  4. Logic bomb

Answer: B. A trojan disguises itself as legitimate software. A worm spreads by itself, a rootkit hides its presence, and a logic bomb triggers on a condition. Defence: install from trusted sources and use application allow-listing.

Question 9: Sniffing

Which switch feature helps defend a LAN against ARP spoofing?

  1. Dynamic ARP Inspection
  2. Port mirroring
  3. Spanning Tree Protocol
  4. VLAN trunking

Answer: A. Dynamic ARP Inspection checks ARP packets against trusted bindings, usually learned through DHCP snooping, and drops forged ones. Port mirroring is an analysis feature, not a protection.

Question 10: Social engineering

An unknown person follows an employee through a secured door without badging in. This is:

  1. Shoulder surfing
  2. Tailgating
  3. Dumpster diving
  4. Pharming

Answer: B. Tailgating (also called piggybacking) is gaining physical entry by following an authorised person. Defences include mantraps, badge checks, guard presence and staff awareness training.

Question 11: Denial of service

Which technique helps a server resist a TCP SYN flood?

  1. SYN cookies
  2. Larger log files
  3. Disabling TLS
  4. Opening more ports

Answer: A. SYN cookies let the server avoid holding state for half-open connections until the handshake completes. Rate limiting and upstream DDoS protection also help.

Question 12: Session hijacking

Which measure most directly reduces the risk of session hijacking on a web application?

  1. Using HTTPS with Secure and HttpOnly cookies and issuing a new session ID after login
  2. Storing the session ID in the URL
  3. Using longer usernames
  4. Allowing sessions that never expire

Answer: A. Encryption stops sniffing, the Secure and HttpOnly flags limit cookie exposure, and regenerating the ID at login prevents session fixation. Session IDs in URLs leak through logs and referrers.

Question 13: Evasion

What is the main difference between an IDS and an IPS?

  1. An IDS is always hardware, an IPS is always software
  2. An IPS sits inline and can block traffic, while an IDS monitors and alerts
  3. An IDS encrypts traffic, an IPS decrypts it
  4. There is no difference

Answer: B. An intrusion prevention system is placed in the traffic path and can drop packets. A detection system usually watches a copy and raises alerts. Both need tuning to limit false positives.

Question 14: Web servers

What does the HTTP Strict-Transport-Security (HSTS) header do?

  1. Tells browsers to always use HTTPS for the site
  2. Blocks all cookies
  3. Hides the server version
  4. Forces a password change

Answer: A. HSTS instructs browsers to connect over HTTPS only for a set period, which reduces downgrade and SSL-stripping attacks. It does not hide server details.

Question 15: SQL injection

Which is the most effective primary defence against SQL injection?

  1. Parameterised queries (prepared statements)
  2. Blocking the word SELECT
  3. Using a longer database password
  4. Hiding error pages only

Answer: A. Parameterised queries keep user input as data, never as code. Input validation and least-privilege database accounts add depth. Keyword blocking is easy to bypass and hiding errors does not remove the flaw. See the OWASP cheat sheets.

Question 16: Web applications

What distinguishes stored XSS from reflected XSS?

  1. Stored XSS is saved on the server and served to later visitors; reflected XSS comes back in the immediate response to a crafted request
  2. Stored XSS only affects databases
  3. Reflected XSS only works on mobile
  4. They are the same thing

Answer: A. Stored XSS persists, for example in a comment field, and hits every viewer. Reflected XSS needs a victim to follow a crafted link. Defences: contextual output encoding, input validation and a Content Security Policy.

Question 17: Wireless

What is the main security improvement of WPA3-Personal over WPA2-Personal?

  1. It uses a longer SSID
  2. Its SAE handshake resists offline dictionary attacks on a captured handshake
  3. It hides the network automatically
  4. It removes the need for a password

Answer: B. With WPA2-PSK, a captured handshake can be attacked offline. WPA3 uses Simultaneous Authentication of Equals so each guess needs live interaction. Strong passphrases still matter.

Question 18: Mobile

Why is a rooted or jailbroken device a higher risk for corporate data?

  1. It removes platform security controls, so apps and malware can gain more access
  2. It always runs slower
  3. It cannot connect to Wi-Fi
  4. It disables the camera

Answer: A. Rooting bypasses sandboxing and the integrity checks the OS provides. Mobile device management can detect compromised devices and block them from corporate resources.

Question 19: IoT and OT

Why do many IoT botnets succeed in compromising devices at scale?

  1. Devices ship with default or weak credentials and are exposed to the internet
  2. IoT devices use quantum encryption
  3. They are always offline
  4. They have no network interface

Answer: A. Default credentials and exposed management interfaces are the common entry. Defences: change defaults, update firmware, segment IoT on its own VLAN and block inbound access.

Question 20: Cloud

In an IaaS model such as virtual machines in a public cloud, who is normally responsible for patching the guest operating system?

  1. The cloud provider
  2. The customer
  3. The internet service provider
  4. The hardware vendor

Answer: B. Under the shared responsibility model the provider secures the underlying infrastructure, while the customer secures the operating system, applications, data and access. The split changes by service model, so read the provider's documentation.

Question 21: Cryptography

Which is the best choice for storing user passwords in a database?

  1. A fast unsalted hash such as MD5
  2. Reversible encryption with one shared key
  3. A slow, salted password hashing function such as bcrypt or Argon2
  4. Plain text in a protected table

Answer: C. Password storage should resist guessing at high speed. Slow, salted functions make each guess expensive and stop identical passwords from sharing a hash. Fast unsalted hashes are quickly cracked.

Question 22: Process

What must be in place before any penetration test begins?

  1. A signed authorisation and agreed scope and rules of engagement
  2. A copy of the target's source code
  3. An internet-facing test server
  4. A list of employee passwords

Answer: A. Written permission defines what may be tested and when. Without it, testing can be unlawful under the IT Act, 2000. Authorisation is the line between ethical hacking and a crime.

How to read your result

Count by topic, not by total. If you missed two questions in the same module, that module needs another pass. A strong score on this set does not predict the real exam, since the real one is longer and uses different wording. What it does show is whether you understand the reasoning. For the hands-on side, work through a lab for each module. See the Nmap reference guide and the OWASP Top 10 for the scanning and web topics.

Next steps

Pick your three weakest topics and spend this week on them in a lab. If you want a trainer-led route, see our CEH v13 AI course, or the CEH v13 AI Master route if you plan to take the practical exam too. For strategy, read how to pass CEH in the first attempt.

Related reading

Frequently Asked Questions

There is no legitimate PDF of real CEH questions. Sites offering one are selling leaked or invented content, which is often outdated and risky to use. Use original practice questions, official courseware and your own lab instead.

Using leaked exam content breaches the candidate agreement you accept with EC-Council, and the certifying body can ban you or revoke the certificate. Even apart from rules, dumps are unreliable and teach little.

The CEH v13 theory exam (312-50) has 125 multiple-choice questions and a 4-hour limit. EC-Council sets the passing score by exam form, so confirm the current format on its official page before you book.

CEH v12 has been retired and the current version is CEH v13 AI. The fundamentals overlap, but tools and topics have changed, so practise with questions and material aimed at v13.

Answer without notes, read every explanation including for questions you got right, list the topics you missed, and revisit them in a lab. Then take a fresh set later. Repeating the same questions only tests your memory.

It follows 20 modules: reconnaissance, scanning, enumeration, vulnerability analysis, system hacking, malware, sniffing, social engineering, denial of service, session hijacking, evasion, web servers and applications, SQL injection, wireless, mobile, IoT and OT, cloud and cryptography.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Aayushi Sinha

With a passion for staying on the cutting edge of technology trends, I am dedicated to delivering content that not only informs but also inspires. Whether you need in-depth analysis pieces, informative guides, or thought-provoking opinion pieces, I craft content that resonates with tech enthusiasts and professionals alike.