Free Certified Ethical Hacker (CEH) practice questions
Real exam-format questions from the CertBase Certified Ethical Hacker (CEH) bank — pick an answer and the answer key and explanation follow. No signup needed.
536 questions in the full bank · Bank updated July 2026
Question 01
Which Bluetooth attack involves stealing information such as contacts, calendars, or files from a target device?
Question 02
Insecure deserialization vulnerabilities arise when an application does what?
Question 03
In a pass-the-hash attack, what does the attacker leverage to authenticate as a user?
Question 04
AS-REP roasting is possible against which category of Active Directory accounts?
Question 05
Why does a switched network limit an attacker to only passively sniffing broadcast and their own unicast traffic by default?
Question 06
Which cloud misconfiguration most directly enables attackers to reach administrative services like SSH or RDP from anywhere on the internet?
Question 07
The Agent Smith style of mobile malware is characterized by:
Question 08
A UDP flood attack causes denial of service primarily by which mechanism?
Question 09
An unquoted Windows service path with spaces can be abused for privilege escalation because Windows may execute what?
Question 10
Within the Aircrack-ng suite, which tool's primary role is to put an interface into monitor mode and capture raw 802.11 frames?
Question 11
A web spider (crawler) is used during website footprinting to accomplish which task?
Question 12
What is the Google Hacking Database (GHDB)?
Detailed explanations like these run throughout the full bank.
One-time payment
Want the other 524 questions?
The full Certified Ethical Hacker (CEH) bank includes 536 questions with detailed explanations, progress tracking, and performance analytics. Pay once, keep it forever — no subscription.