
EC-CouncilCertified Ethical Hacker
Domain 1Objective 5
Cyber Kill Chain Methodology CEH Practice Questions (Page 5)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 21–25
- 21
Which activity is an example of exploitation in the Cyber Kill Chain?
Select an answer first - 22
What is the primary purpose of the installation phase in the Cyber Kill Chain?
Select an answer first - 23
During a ransomware incident, the attacker has already established C2 and is beginning to encrypt files. The incident response team must choose a course of action. Which action best balances the need to stop the encryption with the need to preserve evidence?
Select an answer first - 24
A security team is analyzing a sophisticated attack. The attacker used a malicious macro in a Word document delivered via email. The macro downloaded a second-stage payload that established persistence via a scheduled task and communicated with a C2 server using DNS tunneling. The team is planning defensive measures. Which of the following controls would be effective in disrupting multiple phases of the Cyber Kill Chain? (Select all that apply.)
Select an answer first - 25
Which activity is associated with the command and control phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.