10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
The C)PEH exam has 100 questions and runs 2 hours.
These 10 free C)PEH questions are organized by exam domain, so you can see how each part of the Certified Professional Ethical Hacker blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Course Introduction
Question 1
Before powering on a deliberately vulnerable server VM, a tester reviews its network design. The server and a testing VM will run on the same laptop and must communicate with each other, but neither may reach the corporate LAN or the Internet. All exercise materials are already available locally. Choose the arrangement that meets those requirements.
Show answer & explanation
Correct answer: D - Attach both VMs only to the same internal network, with no additional adapter or routed uplink.
Domain 2: Introduction to Ethical Hacking
Question 2
During an approved assessment of a warehouse control application, operators report delayed conveyor-stop commands just as an active protocol check begins. The rules of engagement assign operational recovery to the warehouse team. The tester can immediately terminate the check. What is the tester's first responsibility?
Show answer & explanation
Correct answer: C - Stop the check, notify operations, and preserve the test logs.
Domain 3: Cybersecurity Foundation
Question 3
A service has an asset value of $600,000. Each successful incident is estimated to cause a 30% loss, with one incident expected every four years. A proposed control would reduce the frequency to once every ten years without changing the loss per incident. It costs $18,000 annually. For this decision, the company uses annualized loss reduction minus annual control cost; no other requirements or costs apply. Which recommendation follows from these estimates?
Show answer & explanation
Correct answer: A - Adopt; a $27,000 reduction in expected annual losses yields a $9,000 net annual benefit.
Domain 4: Reconnaissance & Enumeration
Question 4
An authorized Nmap UDP scan produces this line:
53/udp open|filtered domain
No UDP reply or ICMP error was received, and service/version detection was not performed. What can the tester record without overstating the evidence?
Show answer & explanation
Correct answer: D - The port may be open or filtered; the service label alone does not confirm that DNS is running.
Domain 5: Cryptography
Question 5
A storage service uses AES-256-GCM. Its worker processes share an encryption key, but each restarts its nonce counter at zero after a reboot. A review confirms that different records have been encrypted with the same key and nonce. Their authentication tags still verify. Which cryptographic conclusion should drive remediation?
Show answer & explanation
Correct answer: C - Nonce reuse can compromise both confidentiality and authentication.
Domain 6: Vulnerability Scanning & Analysis
Question 6
A vulnerability dashboard shows a CVSS v3.1 Base score of 8.2, an EPSS probability of 0.12, and an EPSS percentile of 0.96. A service owner describes this as a '96% chance that our server will be compromised this month.' Which interpretation should replace that statement?
Show answer & explanation
Correct answer: A - High technical severity, with an estimated 12% probability of exploitation activity in the wild over the next 30 days.
Domain 7: Web and Application Attacks
Question 7
Two customer accounts are authorized for an API assessment. Using account A's valid token, a tester requests account B's order by changing only the order identifier. The API returns B's complete order. Requests without a token are rejected, and both customers are entitled to use the order-viewing endpoint for their own orders. Where has the security boundary failed?
Show answer & explanation
Correct answer: B - Authorization to access the particular order requested
Domain 8: Exploitation and Post-Exploitation
Question 8
A tester has an authorized low-privilege session on a relay host. An internal inventory service cannot be reached directly from the tester's laptop, but its login page loads through a TCP port forward using that session. The inventory service is in scope; no credentials have been submitted and no exploit has been attempted against it. The demonstrated capability is:
Show answer & explanation
Correct answer: B - A pivoted connection to the inventory service, without evidence of its compromise
Domain 9: Social Engineering
Question 9
Finance receives a bank-account-change request from a supplier's usual email address. SPF, DKIM, and DMARC checks pass, and the message accurately references an unpaid invoice. The sender asks for the change before a payment due in two hours. Which verification most directly addresses the remaining fraud risk?
Show answer & explanation
Correct answer: A - Call the supplier at a previously verified number before changing the bank details.
Domain 10: Wireless Pentesting
Question 10
A complete, valid WPA2-Personal four-way handshake has been captured from an approved access point during a normal client connection. The SSID is known. The engagement permits passive capture and offline password auditing but excludes active wireless tests. How should the tester evaluate a supplied list of candidate passphrases?
Show answer & explanation
Correct answer: C - Test the candidates against the existing handshake capture offline.