Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 1Objective 5

Cyber Kill Chain Methodology CEH Practice Questions (Page 6)

Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
9concepts

Questions 26–30

  1. 26expert · hard

    A company has a limited security budget and must choose between two controls: (1) a network intrusion detection system (NIDS) that monitors for known attack signatures, and (2) a data loss prevention (DLP) solution that blocks outbound sensitive data. The company's primary concern is preventing data exfiltration. However, they also want to detect early-stage attacks. Which approach best balances the need to detect early-stage attacks and prevent data exfiltration?

    Select an answer first
  2. 27expert · hard

    A security team is investigating a compromised host that is using DNS tunneling for C2. The team wants to disrupt the C2 channel without losing visibility into the attacker's activity. Which approach best balances disruption and visibility?

    Select an answer first
  3. 28application · medium

    A penetration tester is simulating an attack against a client's air-gapped network. The tester creates a malicious USB drive containing an auto-run payload disguised as a PDF. Which Cyber Kill Chain phases are being exercised by this action?

    Select an answer first
  4. 29application · medium

    A security analyst is reviewing logs after a suspected breach. The attacker gathered employee email addresses from the company website and LinkedIn, then used that information to craft a targeted spear-phishing email. At which two phases of the Cyber Kill Chain did these actions occur?

    Select an answer first
  5. 30application · medium

    After exploiting a vulnerability in a web server, an attacker uploads a web shell and modifies the system startup scripts to ensure the shell survives reboots. Which Cyber Kill Chain phase is the attacker primarily executing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.