ALL PASS, NO FAIL!

CEH v13 Module 19: Post-Exploitation & Incident Response — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 19 of 20

After access: privilege escalation, persistence, log tampering, data exfiltration, and incident response steps. Exam focus: tie the kill chain together — persistence, privilege escalation, log tampering, exfiltration — then switch sides for incident response: contain, eradicate, recover, and write the lessons-learned step that paper exams love.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Attackers establish persistence to:

Answer: D — Persistence (rootkits, WMI event subscriptions, startup items) survives cleanup attempts — hunting for anomalous persistence is core defense.

Question 2: Anti-forensics techniques include:

Answer: A — These actions destroy or distort evidence — defenders counter with centralized, append-only log shipping that attackers can't reach.

Question 3: Covering tracks via steganography hides data by:

Answer: D — Unlike encryption (hidden content), steganography hides the very existence of the message — detection relies on statistical analysis of carriers.

Question 4: The NIST SP 800-61 incident response lifecycle includes which phase?

Answer: C — NIST phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity (lessons learned).

Question 5: The final phase of the SANS incident response model is:

Answer: A — SANS order: Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned, closing the loop back into preparation.

Question 6: Volatility is a forensic tool for:

Answer: D — RAM holds what disk never sees — injected code, decrypted keys, running malware — making memory capture essential in modern IR.

Question 7: Chain of custody matters in digital forensics because it:

Answer: A — An unbroken, signed custody record is what keeps forensic findings usable in court or a formal investigation.

Question 8: A forensic disk image should be verified by:

Answer: A — Write-blocked acquisition + matching whole-media hashes demonstrates the image is bit-for-bit identical to the original.

Question 9: Indicators of Compromise (IOCs) are:

Answer: A — Email, network, host, and behavioral IOCs feed SIEM detection, threat intel sharing, and hunt hypotheses.

Question 10: SIEM platforms aid incident response by:

Answer: D — Centralized log analytics turn thousands of events into alerts — e.g., one admin account logging into 40 workstations in an hour.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Post-Exploitation & Incident Response practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 19 (Post-Exploitation & Incident Response). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 19 (Post-Exploitation & Incident Response) cover?

After access: privilege escalation, persistence, log tampering, data exfiltration, and incident response steps. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 19 flashcards at https://cehstudy.com/ceh-v13/module-19/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Post-Exploitation & Incident Response quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Post-Exploitation & Incident Response flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 19 (Post-Exploitation & Incident Response). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 19 page at https://cehstudy.com/ceh-v13/module-19/. No account or sign-up required.