Skip to content
ScopefileGet the app

Live firemixed domains312-50

CEH practice test

A free CEH practice test drawn from all nine blueprint domains of exam 312-50. Answer a question and every option opens with its own note: why the key holds, and what each wrong pick mixed up.

Exam
312-50
Targets
45
Domains
9

Mixed set, nine domains

Leave the filter on all domains for the exam's spread, or tap one domain once you have read its module files. A card locks when you answer, so your first pick is the one that counts.

Answered 0/45Hits 0

T-01Overview

During a penetration test of a healthcare provider's network, you capture unencrypted traffic containing what appears to be patient names, dates of birth, and diagnosis codes. Your engagement scope covers network security testing but does not explicitly mention PHI handling procedures. What is your MOST appropriate immediate action?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWaiting until the end of testing leaves regulated health data exposed and unreported for days, which breaks the duty to escalate sensitive discoveries promptly.
  2. BDeleting captured data on your own destroys evidence the client may need for breach assessment, and the decision belongs to the client, not the tester.
  3. CWritten authorization for network testing does not cover handling protected health information, so continuing as planned ignores a scope gap you just found.
  4. DCorrect: stopping the capture, preserving what was collected with chain of custody and escalating to the compliance officer protects patients, evidence and the client's obligations.
T-02Overview

During an authorized engagement, a penetration tester discovers evidence of an ongoing financial breach. The incident response policy is undocumented. What is the MOST appropriate immediate action?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: the tester works for the client, so evidence of a live breach goes straight to the designated point of contact, who owns the response decision.
  2. BIsolating a subnet is a containment action only the client may authorize; a tester doing it unilaterally can break production and exceeds the engagement scope.
  3. CHunting the external actor before reporting delays the client's response and turns a scoped test into an unauthorized investigation of a third party.
  4. DContacting a regulator directly bypasses the client, who decides on regulatory notification, and stopping silently leaves the people who must act uninformed.
T-03Overview

Which of the following is an example of a compensating control?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABadge access to a facility is a standard preventive physical control applied as designed, not a substitute for a control that cannot be implemented.
  2. BCorrect: when duties cannot be separated, reviewing activity logs offsets that missing control, which is exactly what a compensating control does.
  3. CAntivirus on every computer is a baseline preventive technical control, not an alternative measure standing in for a control that is impossible to apply.
  4. DA traffic-filtering firewall is a primary preventive control in its intended role; nothing in this option compensates for a gap elsewhere.
T-04Recon

An organization successfully revoked a compromised TLS certificate and updated its Certificate Revocation List (CRL). However, an external penetration tester is still able to extract the domain name associated with this certificate during reconnaissance. Why is this possible?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Certificate Transparency logs are append-only public records, so revoking a certificate never removes its entry or the domain names it listed.
  2. BA CRL is published by the certificate authority, not served from internal name servers, and CT visibility has nothing to do with bypassing revocation checks.
  3. CLocal caching on the tester's machine is irrelevant; the domain is visible to anyone because the public CT log still holds the original certificate entry.
  4. DCertificate authorities do not automatically reissue revoked certificates; the name stays discoverable because the original CT log entry is permanent.
T-05Recon

During a reconnaissance engagement, you discover a domain registered with a privacy-protection service that is linked to confirmed phishing infrastructure. WHOIS shows only the registrar's contact details and a privacy proxy organization. What is the MOST appropriate lawful next step to report the abuse?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALaw-enforcement unmasking requests are a heavier legal process for investigators, not the first lawful step a reconnaissance team takes to report abuse.
  2. BDeceiving the privacy service to reveal the registrant is pretexting against a third party, which is outside any authorized engagement and potentially unlawful.
  3. CCorrect: the registrar's published abuse contact is the intended channel for reporting malicious domains, and supplying evidence lets the registrar act under its own policies.
  4. DUDRP is a trademark dispute process for domain ownership, not an abuse-reporting tool, and filing it without a trademark claim misuses the procedure.
T-06Recon

During a scoped engagement, an investigator identifies mail.target.com in Certificate Transparency logs but passive DNS shows no historical A records. Under what circumstance is active DNS resolution MOST justified?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAsking the client to run the query internally is one possible arrangement, but the deciding factor is scope and authorization, not who sends the query.
  2. BMissing passive DNS history does not grant permission for active queries; acting immediately skips the scope check that every active step requires.
  3. CCorrect: active resolution touches target infrastructure, so it is justified only once the hostname is confirmed in scope and active queries are explicitly authorized.
  4. DNo passive DNS history does not prove a host is unused; many internal or new hosts never appear in passive sensors, so ignoring it is a false conclusion.
T-07Recon

An organization relies exclusively on Endpoint Detection and Response (EDR) software to identify reconnaissance activities. Why is this architectural approach inadequate for detecting comprehensive network stealth scans?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHost-based logging does not drop incomplete handshakes by design; the limitation is that each agent sees only its own host, not the network-wide pattern.
  2. BEDR agents do not automatically whitelist local subnet traffic, and the gap described here is about cross-host correlation rather than allow-listing.
  3. CCorrect: a stealth scan is visible as a pattern across many hosts and ports, which needs network sensors, flow data or a SIEM that correlate beyond one endpoint.
  4. DEncryption is not the issue, because scan probes are mostly header-level traffic; the gap is the lack of correlated visibility across the network.
T-08Recon

An organization authorizes a penetration tester to scan its production network. The statement of work specifies port scanning but does not define scan windows, rate limits, escalation procedures, or rollback plans. What is the MOST critical deficiency in this authorization?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATool names and versions are useful detail, but their absence is far less dangerous than having no limits on when and how hard production is scanned.
  2. BReporting format and deadlines matter for deliverables, yet they do nothing to prevent outages or define what happens if scanning disrupts production.
  3. CLiability disclaimers protect the testing firm contractually but do not control operational risk to the client's production systems during the test.
  4. DCorrect: rules of engagement need scan windows, rate limits, escalation contacts and rollback plans, because those constraints keep authorized scanning from harming production.
T-09Recon

A penetration tester receives authorization to perform port discovery on a client's external web servers. During the scan, the tester identifies an open management interface on port 8443 and wants to run vulnerability probes to check for known exploits. What should the tester do NEXT?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AChecking for remote code execution goes beyond the authorized port discovery, so running it without new permission is an out-of-scope action on the client's system.
  2. BVersion detection and vulnerability scripts are active probes beyond discovery; launching them immediately ignores that the authorization covers port discovery only.
  3. CDocumenting the interface is right, but simply moving on drops a significant exposure without asking the client whether deeper testing is wanted and allowed.
  4. DCorrect: the authorization covers port discovery only, so vulnerability probing of the management interface needs explicit permission from the client first.
T-10Recon

While reviewing a packet capture of network reconnaissance activities, you observe several SNMP queries. Why does analyzing the SNMPv2c traffic pose a greater risk of credential leakage than SNMPv3?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABoth SNMP versions normally use unicast requests to a specific agent; broadcast behavior is not the reason version 2c leaks credentials.
  2. BSNMPv2c does not embed administrator password hashes in queries; its weakness is the plaintext community string that acts as a shared password.
  3. CSNMPv2c has no certificate-based authentication at all; it is SNMPv3 that adds user-based authentication and privacy, so this reverses the versions.
  4. DCorrect: SNMPv2c sends community strings in cleartext, while SNMPv3 adds user authentication and encryption, which is why defenders disable v1/v2c where possible.

A loop that turns misses into study time

  1. Filter to one domain

    Pick the domain you studied this week. A mixed run before you have read anything only measures guessing.
  2. Stop at two misses in a row

    Two in a row usually means a missing concept, and a slip rarely repeats. Read both debriefs in full, wrong options included.
  3. Reread one section

    Open the matching module from the CEH study guide and reread only the part your misses point to. Then go back to the filter.
  4. Move swapped terms to cards

    Pairs of terms that keep trading places belong in five-minute sessions with the CEH flashcards, away from the scenarios.

When to switch to the clock

This page shows a verdict after every answer. That is how you learn, and it is also why it flatters you: nobody hands you a verdict halfway through exam 312-50.

Once a domain holds up under the filter, move to the timed CEH mock exam. It holds every verdict until you finish, then scores you by domain. The real exam gives you four hours for a 125-question form (EC-Council, checked Oct 11, 2026), just under two minutes a question, and the mock keeps that pace.

Sources