Home Quizzes Quiz Detail
Practice Quiz

Certified Ethical Hacker Version 11 (CEHv11) Practice Test

10 questions 5.0 rating Mobile friendly
$69.00

Unlock the full practice quiz

Get complete access to the questions, explanations and printable quiz resources.

Full access: unlock all quiz questions and explanations.
Printable review: access the full quiz PDF with correct answers after purchase.

About this Exam

Prepare with the Certified Ethical Hacker Version 11 (CEHv11) Practice Test practice quiz. This question bank includes 10 questions covering tool, host, target, provides, and ethical. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

Sample Questions

Question 1
Which tool would you use to obtain system information such as host name and uptime?
PsInfo
PsLoggedOn
PsList
PsShutdown
Explanation:
To quickly gather basic system details like the host name and how long the system has been running, PsInfo is the right choice. This Sysinternals tool is designed to query a machine and display essential system information, including the host name, uptime, OS version, and other details, either locally or on a remote computer. The other tools in the Ps family serve different purposes—PsLoggedOn shows who’s logged on, PsList lists processes, and PsShutdown handles shutdown/reboot actions—so they wouldn’t provide a straightforward view of host name and uptime.
Question 2
Which publication is a paid resource known for publishing industry reports?
The Wall Street Transcript
MarketWatch
LexisNexis
Business Wire
Explanation:
The Wall Street Transcript stands out because it operates on a subscription model and is known for delivering in-depth industry reports and analyses for investors. This publication curates and publishes detailed sector-focused reports that readers pay to access, making it a paid resource specifically dedicated to industry insights. MarketWatch provides market news and data, often free or with optional premium services, but it isn’t primarily a repository of targeted industry reports you subscribe to. LexisNexis is a paid research platform for legal, news, and business information, not a publication known for publishing standalone industry reports to subscribers. Business Wire distributes press releases, not in-depth industry reports published for subscribers. So the paid resource known for publishing industry reports is The Wall Street Transcript.
Question 3
Which command scans the target IP address for an open NFS port (2049) and the NFS services running on it?
ntpdate
ntpq
rpcinfo
ntptrace
Explanation:
NFS runs over RPC, so to find an open NFS port and the services it provides you check the RPC service registry on the target. The tool that asks the registry (the portmapper) what RPC programs are registered, their versions, and which ports they listen on is ideally suited for this. By querying the target, you’ll see the NFS program (with its versions) and the port it’s using, which commonly appears as the NFS port 2049. This confirms both that NFS is available and exactly which port it’s on. Other options are focused on time synchronization or NTP-related tasks, not on discovering RPC-based services like NFS.
Question 4
Which technique can be used to determine if an IP or service is a threat source within a security framework?
Cisco IPS Source IP Reputation Filtering
RFC 3704 Filtering
Traffic Pattern Analysis
Event Log Analysis
Explanation:
Reputation-based filtering uses threat intelligence to classify IP addresses and other sources as known threats. In a security framework, evaluating whether an IP or service is a threat source lets the system block or limit traffic from that source before it reaches sensitive resources. Cisco IPS Source IP Reputation Filtering does this directly by consulting threat-intelligence feeds to mark certain source IPs as malicious or suspicious and enforce blocking or restrictions accordingly, reducing exposure from compromised hosts, botnets, or scanners. RFC 3704 Filtering is about preventing spoofed addresses by ensuring packets have believable source addresses, not about judging whether the source itself is harmful. Traffic Pattern Analysis examines how traffic behaves to spot anomalies, which helps detect potential threats but doesn’t inherently tag a source as a threat by reputation. Event Log Analysis involves reviewing logs to detect and investigate incidents after they occur, rather than proactively identifying threat sources at the entry point.
Question 5
Which technology detects runtime attacks and provides visibility into vulnerabilities in real-time apps?
Security misconfiguration
N-Stalker Web App Security Scanner
BeEF
Runtime Application Self Protection
Explanation:
Runtime Application Self-Protection is a security technology that sits inside the running application and watches its own execution in real time. It monitors data flows, code paths, and inputs as requests come in, applying security policies to detect suspicious activity that indicates an attack. When something malicious is detected, it can block or mitigate the attack immediately and provide detailed telemetry about what’s happening in the live app. This combination of real-time attack detection and visibility into the app’s vulnerabilities as it runs is what makes RASP the right choice for detecting runtime attacks in real-time applications. Other options are not designed to do this. A security misconfiguration refers to a type of vulnerability or risk, not a runtime protection mechanism. A web app security scanner like the N-Stalker is used to discover weaknesses by probing the app, not to protect and monitor it as it runs. BeEF focuses on browser exploitation and post-compromise activities, not on in-application runtime protection or real-time visibility.

Ready to test your knowledge?

Buy Now to Access

Additional Information

Certified Ethical Hacker Version 11 (CEHv11) Practice Test

This practice set contains 10 questions from the matching question bank and focuses on tool, host, target, provides, and ethical. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Frequently Asked Questions

This quiz contains a total of 10 practice questions carefully selected to test your knowledge on this subject.
Yes, you will have exactly 0 minutes to complete the exam. A countdown timer will be visible once you start.
Yes, you can retake this practice test as many times as you need. The questions and options may be randomized on subsequent attempts to ensure comprehensive learning.

Reviews

5.0

Based on 0 reviews

Leave a Review

No reviews yet. Be the first to review!