Certified Professional Ethical Hacker Exam Prep
Free practice questions

Free C)PEH Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)PEH exam has 100 questions and runs 2 hours.

These 10 free C)PEH questions are organized by exam domain, so you can see how each part of the Certified Professional Ethical Hacker blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Course Introduction

Question 1

Before powering on a deliberately vulnerable server VM, a tester reviews its network design. The server and a testing VM will run on the same laptop and must communicate with each other, but neither may reach the corporate LAN or the Internet. All exercise materials are already available locally. Choose the arrangement that meets those requirements.

Show answer & explanation

Correct answer: D - Attach both VMs only to the same internal network, with no additional adapter or routed uplink.

Domain 2: Introduction to Ethical Hacking

Question 2

During an approved assessment of a warehouse control application, operators report delayed conveyor-stop commands just as an active protocol check begins. The rules of engagement assign operational recovery to the warehouse team. The tester can immediately terminate the check. What is the tester's first responsibility?

Show answer & explanation

Correct answer: C - Stop the check, notify operations, and preserve the test logs.

Domain 3: Cybersecurity Foundation

Question 3

A service has an asset value of $600,000. Each successful incident is estimated to cause a 30% loss, with one incident expected every four years. A proposed control would reduce the frequency to once every ten years without changing the loss per incident. It costs $18,000 annually. For this decision, the company uses annualized loss reduction minus annual control cost; no other requirements or costs apply. Which recommendation follows from these estimates?

Show answer & explanation

Correct answer: A - Adopt; a $27,000 reduction in expected annual losses yields a $9,000 net annual benefit.

Domain 4: Reconnaissance & Enumeration

Question 4

An authorized Nmap UDP scan produces this line: 53/udp open|filtered domain No UDP reply or ICMP error was received, and service/version detection was not performed. What can the tester record without overstating the evidence?

Show answer & explanation

Correct answer: D - The port may be open or filtered; the service label alone does not confirm that DNS is running.

Domain 5: Cryptography

Question 5

A storage service uses AES-256-GCM. Its worker processes share an encryption key, but each restarts its nonce counter at zero after a reboot. A review confirms that different records have been encrypted with the same key and nonce. Their authentication tags still verify. Which cryptographic conclusion should drive remediation?

Show answer & explanation

Correct answer: C - Nonce reuse can compromise both confidentiality and authentication.

Domain 6: Vulnerability Scanning & Analysis

Question 6

A vulnerability dashboard shows a CVSS v3.1 Base score of 8.2, an EPSS probability of 0.12, and an EPSS percentile of 0.96. A service owner describes this as a '96% chance that our server will be compromised this month.' Which interpretation should replace that statement?

Show answer & explanation

Correct answer: A - High technical severity, with an estimated 12% probability of exploitation activity in the wild over the next 30 days.

Domain 7: Web and Application Attacks

Question 7

Two customer accounts are authorized for an API assessment. Using account A's valid token, a tester requests account B's order by changing only the order identifier. The API returns B's complete order. Requests without a token are rejected, and both customers are entitled to use the order-viewing endpoint for their own orders. Where has the security boundary failed?

Show answer & explanation

Correct answer: B - Authorization to access the particular order requested

Domain 8: Exploitation and Post-Exploitation

Question 8

A tester has an authorized low-privilege session on a relay host. An internal inventory service cannot be reached directly from the tester's laptop, but its login page loads through a TCP port forward using that session. The inventory service is in scope; no credentials have been submitted and no exploit has been attempted against it. The demonstrated capability is:

Show answer & explanation

Correct answer: B - A pivoted connection to the inventory service, without evidence of its compromise

Domain 9: Social Engineering

Question 9

Finance receives a bank-account-change request from a supplier's usual email address. SPF, DKIM, and DMARC checks pass, and the message accurately references an unpaid invoice. The sender asks for the change before a payment due in two hours. Which verification most directly addresses the remaining fraud risk?

Show answer & explanation

Correct answer: A - Call the supplier at a previously verified number before changing the bank details.

Domain 10: Wireless Pentesting

Question 10

A complete, valid WPA2-Personal four-way handshake has been captured from an approved access point during a normal client connection. The SSID is known. The engagement permits passive capture and offline password auditing but excludes active wireless tests. How should the tester evaluate a supplied list of candidate passphrases?

Show answer & explanation

Correct answer: C - Test the candidates against the existing handshake capture offline.

The rest of the C)PEH blueprint

The C)PEH exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)PEH questions with explanations.

Continue in the free practice test →

View plans