ALL PASS, NO FAIL!

CEH v13 Module 12: Evading IDS, Firewalls & Honeypots — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 12 of 20

Bypassing security controls: IDS evasion, packet manipulation, tunneling, and understanding honeypot defenses. Exam focus: for each bypass — fragmentation, low-and-slow, tunneling, protocol quirks — state both the offensive trick and the defensive countermeasure. Honeypot questions test what an attacker sees and what gets logged.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Splitting a malicious payload across packet fragments so no single fragment matches an IDS signature is:

Answer: C — If the sensor inspects before reassembly, fragments slip through — while the target reassembles and executes the full payload (Nmap -f does minimum fragmentation).

Question 2: Nmap's -D flag performs a:

Answer: B — 'nmap -D decoy1,decoy2,ME target' — IDS sees several apparent scanners and alert fatigue makes the true source ambiguous.

Question 3: The primary difference between an IDS and an IPS is:

Answer: C — IDS = detection/passive (NIDS or HIDS); IPS = prevention/active — it can drop packets, reset connections, and block sources.

Question 4: A honeypot is:

Answer: A — Production honeypots provide early warning; research/threat-intel honeypots collect TTPs, malware, and tooling for analysis.

Question 5: DNS tunneling exfiltrates data by:

Answer: A — Tools like iodine and dnscat2 carry data (and even full tunnels) inside seemingly harmless DNS traffic.

Question 6: Tunneling attacks evade firewalls by:

Answer: C — The outer wrapper matches an allowed rule; inspection of the inner payload is often skipped — the same idea behind TCP wrapping.

Question 7: Slowing a scan or attack to stay below rate thresholds is an evasion technique called:

Answer: D — Signature and rate-based sensors trigger on volume/patterns — creeping under thresholds blends malicious activity into normal noise.

Question 8: An attacker may detect a honeypot by noticing:

Answer: B — Low-fidelity honeypots (e.g., honeyd) have telltale quirks — incomplete implementations, timing oddities, MAC reuse.

Question 9: Network-based and host-based intrusion detection systems are abbreviated:

Answer: D — NIDS watches traffic at network chokepoints; HIDS monitors a single host's processes, files, and logs. Both can be signature- or anomaly-based.

Question 10: Encrypting attack traffic can defeat signature-based IPS because:

Answer: C — Encrypted payloads hide signatures; defenders respond with TLS decryption at inspection points, certificate pinning checks, and anomaly detection.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Evading IDS, Firewalls & Honeypots practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 12 (Evading IDS, Firewalls & Honeypots). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 12 (Evading IDS, Firewalls & Honeypots) cover?

Bypassing security controls: IDS evasion, packet manipulation, tunneling, and understanding honeypot defenses. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 12 flashcards at https://cehstudy.com/ceh-v13/module-12/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Evading IDS, Firewalls & Honeypots quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Evading IDS, Firewalls & Honeypots flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 12 (Evading IDS, Firewalls & Honeypots). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 12 page at https://cehstudy.com/ceh-v13/module-12/. No account or sign-up required.