Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CertiProf Ethical Hacking Professional Certification Exam CEHPC Exam Questions

Page: 1 / 13 Total 125 questions

Want more questions? Get Premium Access.

Question 1

What is a lateral movement?

Correct Answer: B. It refers to the tactics used by an attacker to move or spread laterally through an organization's network once he has gained initial access to a system or device.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents: Lateral movement is a critical phase in the lifecycle of a modern cyberattack, describing the techniques threat actors use to progressively move through a network after gaining an initial foothold. Once an attacker compromises a single endpoint---often a low-privilege user's workstation---they do not necessarily have access to the sensitive data they seek. Lateral movement is the process of moving from that initial 'entry point' to other systems within the same internal environment to locate high-value assets, such as domain controllers, file servers, or sensitive databases.

This process typically involves three main steps: internal reconnaissance, credential harvesting, and gaining access to additional systems. For example, an attacker might use tools to dump credentials from the memory of the first compromised machine and then use those credentials to log into a neighboring server. By 'pivoting' from one machine to another, the attacker expands their control across the organization's infrastructure.

For a penetration tester, simulating lateral movement is essential for demonstrating the true risk of a breach. It proves that a single compromised account can lead to a full network takeover if internal security controls are weak. Common defenses against lateral movement include network segmentation, which creates barriers between different departments, and the 'Principle of Least Privilege,' which ensures that users only have access to the specific resources they need for their jobs. By identifying paths for lateral movement, ethical hackers help organizations implement 'Zero Trust' architectures, ensuring that even if one device is compromised, the rest of the network remains isolated and protected from further spread.


Question 2

What is Nmap?

Correct Answer: C. It is an open-source Linux command line tool used to scan IP addresses and ports on a network and to detect installed applications.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents: Nmap, short for 'Network Mapper,' is one of the most critical tools in the reconnaissance and scanning phases of a penetration test. It is an open-source command-line utility primarily used for network discovery and security auditing. While many beginners associate it simply with 'pinging' devices (Option A), its functionality is significantly more sophisticated, allowing a tester to map out an entire network infrastructure, identify active hosts, and determine the specific services (and their versions) running on open ports.

In the pentesting process, Nmap is used to perform 'Active Reconnaissance.' By sending specially crafted packets to a target IP address, Nmap analyzes the responses to determine the operating system of the target (OS Fingerprinting), the types of firewalls or filters in use, and the specific applications listening on various ports. This information is vital for the next phase of an attack, as it allows the ethical hacker to identify specific versions of software that may have known vulnerabilities.

Nmap supports various scanning techniques, such as TCP SYN scans (stealthy), UDP scans, and comprehensive Scripting Engine (NSE) scans that can even detect common misconfigurations or vulnerabilities automatically. However, it is important to distinguish Nmap from an exploitation tool (Option B); while it identifies the 'door' and 'what is behind it,' it does not perform the actual 'break-in' or exploitation. In a professional environment, Nmap provides the foundation for the attack surface analysis, giving the pentester a clear picture of what services are exposed and providing the necessary data to plan a targeted and efficient security assessment.


Question 3

What is Nmap?

Correct Answer: A. It is an open-source command-line tool used to scan IP addresses and ports on a network and to detect services, operating systems, and running applications.
Explanation:

Nmap, also known as Network Mapper, is a widely used open-source tool in ethical hacking and penetration testing. It plays a critical role during the reconnaissance and scanning phases of ethical hacking, where the primary goal is to collect information about target systems in a legal and authorized manner. Ethical hackers rely on Nmap to understand the structure and exposure of a network before moving forward with deeper security testing.

The tool works by sending various types of packets to target hosts and analyzing the responses. Based on these responses, Nmap can identify active hosts, open and closed ports, running services, service versions, operating systems, and even certain firewall and intrusion detection configurations. This information is essential for identifying potential weaknesses such as unnecessary open ports, misconfigured services, or outdated software.

Option A correctly defines Nmap because it accurately reflects its purpose as a scanning and discovery tool rather than an exploitation utility. Option B is incorrect because Nmap does not exploit vulnerabilities; exploitation is typically performed using specialized frameworks such as vulnerability scanners or exploitation platforms. Option C is also incorrect because although Nmap can perform host discovery similar to ping, it offers far more advanced capabilities than simple network reachability checks.

From an ethical hacking perspective, Nmap supports preventive and defensive security objectives. By revealing network visibility issues and configuration flaws, it enables organizations to harden systems, reduce attack surfaces, and comply with security best practices. When used ethically and with proper authorization, Nmap is a foundational tool for strengthening information security.


Question 4

What is the results report document?

Correct Answer: B. A document that details findings, including identified vulnerabilities and exposed sensitive information.
Explanation:

The results report document is a critical deliverable in the penetration testing process, making option B the correct answer. This document summarizes the findings of the engagement, including discovered vulnerabilities, exposed sensitive information, attack paths, and the potential impact on the organization.

A professional penetration testing report typically includes an executive summary, methodology, scope, risk ratings, technical details, evidence, and remediation recommendations. The goal is not just to list vulnerabilities but to help stakeholders understand risk severity and business impact.

Option A is incorrect because incomplete work is usually addressed separately in project management documentation. Option C is incorrect because agreements and authorization documents are handled before testing begins, not in the results report.

From an ethical hacking standpoint, the results report supports transparency, accountability, and improvement. Ethical hackers must ensure findings are accurate, reproducible, and clearly explained. Poor reporting can reduce the value of an otherwise successful test.

The report also serves as a roadmap for remediation, allowing organizations to prioritize fixes, improve controls, and reduce future attack surfaces. High-quality reporting is a defining characteristic of professional ethical hacking.


Question 5

What is malware?

Correct Answer: B. Refers to any software specifically designed to damage, infect, steal data or otherwise cause a nuisance to a device, network or computer system, without the owner's consent.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents: Malware, short for 'malicious software,' is a broad category of intrusive software developed by cybercriminals to compromise the confidentiality, integrity, or availability of a victim's data. It encompasses a wide variety of threats, including viruses, worms, Trojans, ransomware, and spyware. The defining characteristic of malware is that it is installed and executed on a system without the explicit consent or knowledge of the owner, with the primary intent of causing harm, stealing sensitive information, or gaining unauthorized access.

Managing malware as a security threat involves understanding its infection vectors and payload behaviors. Viruses attach themselves to legitimate files and spread through user interaction, while worms are self-replicating and spread across networks automatically by exploiting vulnerabilities. Trojans disguise themselves as useful programs to trick users into executing them, often opening 'backdoors' for further exploitation. Ransomware, one of the most profitable forms of malware today, encrypts a user's files and demands payment for the decryption key.

Ethical hackers study malware to develop better detection signatures and behavioral analysis techniques. By analyzing how malware obfuscates its code or communicates with a Command and Control (C2) server, security professionals can implement better endpoint protection and network monitoring. Protecting against malware requires a multi-layered defense strategy, including up-to-date antivirus software, regular system patching, and user awareness training to prevent the execution of suspicious attachments or links. Understanding the diverse nature of malware is essential for any cybersecurity expert, as it remains the primary tool used by attackers to gain a foothold within targeted organizations.


Question 6

What is risk assessment?

Correct Answer: B. Is the process of comparing the results of the risk analysis with the risk assessment criteria to determine whether the risk or its magnitude is acceptable or tolerable.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents: Risk assessment is a systematic and critical component of information security management. It is the process of identifying, analyzing, and evaluating risks to determine their significance and to prioritize how they should be addressed. According to formal security standards, it involves comparing the findings of a risk analysis---which identifies threats and vulnerabilities---against established risk assessment criteria. These criteria represent the organization's 'risk appetite,' or the level of risk they are willing to accept in exchange for pursuing their business objectives.

The risk assessment process typically involves three major steps:

Identification: Finding out what could happen and why (e.g., identifying that a database is vulnerable to SQL injection).

Analysis: Determining the likelihood of a threat occurring and the potential impact it would have on the organization's confidentiality, integrity, or availability.

Evaluation: Deciding whether the resulting risk level is acceptable or tolerable.

If a risk is deemed intolerable, the organization must decide on a treatment strategy: Mitigation (reducing the risk via controls like firewalls), Transfer (buying insurance), Avoidance (stopping the risky activity), or Acceptance (acknowledging the risk if the cost of fixing it is too high). For an ethical hacker, a risk assessment provides the context for their work; it helps them understand which assets are most critical to the business and ensures that their findings are prioritized based on actual business impact rather than just technical severity.


Question 7

What is a "backdoor" in terms of computer security?

Correct Answer: C. A hidden access to a system that allows bypassing normal authentication.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents: A 'backdoor' is a method, often hidden or undocumented, of bypassing normal authentication or encryption in a computer system, cryptosystem, or algorithm. In the realm of managing information security threats, backdoors represent one of the most dangerous risks because they provide persistent, unauthorized access to a system without the knowledge of the administrators. Once a backdoor is established, the attacker can return to the system at any time, even if the original vulnerability they used to gain entry---such as a weak password or a software bug---has been patched.

Backdoors can be implemented in several ways. Some are 'Software Backdoors,' where a developer might intentionally (or accidentally) leave a hardcoded username and password in the code for debugging purposes. Others are 'Malicious Backdoors' installed by a Trojan or a rootkit after a system has been compromised. For example, a hacker might install a 'Reverse Shell' that periodically 'calls home' to the attacker's server, asking for commands. This effectively creates a secret entrance that bypasses the firewall's inbound rules.

Managing this threat requires a multi-layered approach. 'Integrity Monitoring' tools are essential; they alert administrators if system files or binaries are modified, which could indicate the presence of a backdoor. Additionally, 'Egress Filtering' helps detect backdoors that attempt to communicate with an external Command and Control (C2) server. From an ethical hacking perspective, identifying backdoors is a key part of 'Post-Exploitation.' During a penetration test, the goal is not just to get in, but to show how an attacker could maintain their presence. By understanding that a backdoor is specifically designed to circumvent standard security checks, professionals can better implement 'Zero Trust' architectures and regular auditing to ensure that the only way into a system is through the front door, with full authentication.


Question 8

According to what was covered in the course, is it possible to perform phishing outside our network?

Correct Answer: A. Yes, the learned method works outside the local network and has been proven to be used by attackers to their advantage.
Explanation:

Phishing attacks are not limited to local networks, making option A the correct answer. Modern phishing techniques are designed to operate over the internet and target victims globally using email, messaging platforms, social networks, and malicious websites.

In ethical hacking and cybersecurity training, phishing demonstrations often begin in controlled or local environments to teach fundamental concepts safely. However, the same techniques---such as fake login pages, credential harvesting, and social manipulation---are widely used by attackers outside local networks. These attacks rely on human interaction rather than network proximity.

Option B is incorrect because phishing does not require local network access. Option C is incorrect because phishing works across many devices, including desktops, laptops, and mobile phones.

From a security trends perspective, phishing remains one of the most effective and prevalent cyberattack methods. Attackers continuously adapt their techniques to bypass email filters and exploit human trust. Ethical hackers study phishing to help organizations improve awareness, email security, and authentication mechanisms.

Understanding that phishing operates beyond local environments reinforces the importance of user training, multi-factor authentication, and proactive monitoring. Ethical testing helps organizations reduce the risk posed by phishing attacks in real-world scenarios.


Question 9

What is "sniffing" in terms of hacking?

Correct Answer: A. Monitoring and capturing of data transmitted over a network.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents: Sniffing is a passive information security element that involves the interception and monitoring of data packets as they traverse a computer network. Using a tool known as a 'packet sniffer' or 'protocol analyzer' (such as Wireshark or tcpdump), an individual can capture raw network traffic in real-time. This technique is inherently 'passive' because it does not necessarily alter the data; it simply records it for analysis.

In the context of ethical hacking, sniffing is used during the 'Enumeration' and 'Vulnerability Analysis' phases. If a network uses unencrypted protocols---such as HTTP, FTP, or Telnet---a sniffer can capture sensitive information in 'cleartext,' including usernames, passwords, and the contents of private communications. This highlights the critical importance of encryption protocols like HTTPS and SSH, which render sniffed data unreadable to unauthorized observers.

Sniffing can be performed on both wired and wireless networks. On a switched network, an attacker might use advanced techniques like 'ARP Spoofing' to trick the network into sending traffic through their machine so it can be sniffed. For security professionals, sniffing is also a vital defensive tool. It is used for troubleshooting network performance issues and for 'Intrusion Detection,' where administrators monitor traffic patterns for signs of malicious activity or data exfiltration. Understanding how sniffing works allows ethical hackers to emphasize the need for end-to-end encryption. It serves as a reminder that data is vulnerable not just at its destination, but at every 'hop' it takes across the network, making robust transport-layer security a non-negotiable element of modern infrastructure.


Question 10

do you update Linux (Kali) from the console?

Correct Answer: A. sudo apt-get update.
Explanation:

Comprehensive and Detailed 250 to 300 words of Explanation From Ethical Hacking documents:

Updating a Debian-based Linux distribution like Kali Linux is a fundamental administrative task that ensures the system has the latest metadata regarding available software packages. The command sudo apt-get update is the standard method used within the console to synchronize the local package index with the remote repositories. When this command is executed, the apt (Advanced Package Tool) utility reads the /etc/apt/sources.list file to identify the URLs of the repositories. It then connects to these servers and downloads the latest package lists, which contain information about version numbers, dependencies, and descriptions of every software package available for that specific distribution version.

Using sudo is mandatory because modifying the package database requires root-level (administrative) privileges. It is important to distinguish between 'updating' and 'upgrading.' The update command does not actually install or change any existing software on the machine; it simply refreshes the 'table of contents' so the system knows which packages have newer versions waiting to be installed. Once the update is complete, a secondary command---typically sudo apt-get upgrade or sudo apt-get dist-upgrade---is required to actually download and apply the new software versions to the system. In the context of ethical hacking, keeping a Kali Linux instance updated is critical for security and tool functionality. Outdated systems may lack the latest exploit modules in frameworks like Metasploit or may contain vulnerabilities that could be exploited by an adversary if the hacking machine is connected to a hostile network. Proper maintenance of the terminal environment ensures that penetration testing tools operate with the highest degree of reliability and that the researcher's environment remains secure against known threats.