
EC-CouncilCertified Ethical Hacker
Domain 3Objective 6
Covering Tracks CEH Practice Questions (Page 5)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
10concepts
Questions 21–25
- 21
A Linux administrator suspects that an attacker has modified the `auth.log` file to remove failed login attempts. The administrator wants to verify whether the log has been tampered with. Which command or utility would be most appropriate to check the integrity of the log file?
Select an answer first - 22
Which rootkit detection technique involves comparing the current state of system files and registry keys to a known-good baseline?
Select an answer first - 23
A penetration tester has successfully escalated privileges on a Windows domain controller and wants to maintain access for a week-long assessment without being detected by the security operations center (SOC). Which action aligns with the purpose of covering tracks?
Select an answer first - 24
What is an Alternate Data Stream (ADS) in NTFS?
Select an answer first - 25
What is the goal of log manipulation and obfuscation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.