ALL PASS, NO FAIL!

CEH v13 Module 1: Introduction to Ethical Hacking — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 1 of 20

Foundations of ethical hacking: the CIA triad, risk analysis, threat actors, and pentest frameworks like the Cyber Kill Chain and PTES. Exam focus: definitional precision matters here — classify hacker types, put the five stages of hacking in order, and match each pentest model to its trade-offs, because Module 1 concepts resurface across later modules.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: What are the three principles of the CIA triad in information security?

Answer: A — The CIA triad is Confidentiality (encryption, access controls), Integrity (hash functions, checksums), and Availability (redundancy, backups, DoS protection).

Question 2: Which formula best represents risk calculation?

Answer: B — Risk = Threats × Vulnerabilities × Impact, also expressed as Consequence × Likelihood.

Question 3: In the Cyber Kill Chain (Lockheed Martin), what is the first phase of a cyber attack?

Answer: A — The seven phases are: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, and Actions on Objectives.

Question 4: In the MITRE ATT&CK framework, which layer represents the WHY an adversary performs an action?

Answer: D — Tactics are the goals (why); techniques describe how they are achieved; sub-techniques and procedures go further into implementation detail.

Question 5: An attacker with limited skill who uses ready-made tools to carry out attacks is known as a:

Answer: C — Script kiddies use pre-packaged exploits and tools without deep understanding, unlike skilled black hats or organized APT groups.

Question 6: The three standard phases of a penetration test are:

Answer: D — Pen tests run Preparation (scope, rules of engagement), Assessment (the actual testing), and Conclusion (reporting and remediation recommendations).

Question 7: How does penetration testing differ from vulnerability assessment?

Answer: D — Vulnerability assessment is broader and shallower (find and quantify); penetration testing digs deeper by exploiting to prove real-world impact.

Question 8: Which of the following is NOT one of the seven phases of the Penetration Testing Execution Standard (PTES)?

Answer: D — PTES phases: Pre-engagement, Intelligence Gathering, Threat Modeling, Vulnerability Analysis, Exploitation, Post-Exploitation, Reporting. Code review is not a PTES phase.

Question 9: In risk analysis, how is Annualized Loss Expectancy (ALE) calculated?

Answer: C — ALE = Single Loss Expectancy (SLE) × Annual Rate of Occurrence (ARO) — the expected monetary loss per year.

Question 10: Which security property guarantees that a sender cannot deny having sent a message?

Answer: D — Non-repudiation (e.g., via digital signatures) prevents senders from denying the origin or content of a message.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Introduction to Ethical Hacking practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 1 (Introduction to Ethical Hacking). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 1 (Introduction to Ethical Hacking) cover?

Foundations of ethical hacking: the CIA triad, risk analysis, threat actors, and pentest frameworks like the Cyber Kill Chain and PTES. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 1 flashcards at https://cehstudy.com/ceh-v13/module-01/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Introduction to Ethical Hacking quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Introduction to Ethical Hacking flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 1 (Introduction to Ethical Hacking). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 1 page at https://cehstudy.com/ceh-v13/module-01/. No account or sign-up required.