
EC-CouncilCertified Ethical Hacker
Domain 3Objective 5
Maintaining Access and Persistence CEH Practice Questions (Page 3)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
9concepts
Questions 11–15
- 11
Which of the following is a common technique used for covering tracks?
Select an answer first - 12
A security analyst is investigating a compromised system and finds that the attacker has been maintaining access for several months. The analyst notices that the system's event logs have been modified to remove entries related to the attacker's activities. Which technique is the attacker using to avoid detection?
Select an answer first - 13
What is the purpose of covering tracks in the system hacking phases?
Select an answer first - 14
A security analyst is investigating a workstation where a user downloaded a 'free PDF converter' from a third-party website. The user reports that the software works as expected, but the analyst finds that the software also creates a hidden scheduled task that connects to an external IP address. Which type of malware is most likely present?
Select an answer first - 15
Which of the following is a common persistence mechanism used by attackers on Windows systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.