ALL PASS, NO FAIL!

CEH v13 Module 6: System Hacking — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 6 of 20

Gaining access to systems: SAM/NTLM/Kerberos attacks, password cracking, buffer overflows, and privilege escalation. Exam focus: local versus remote privilege escalation come up constantly — know hash cracking with John and Hydra, SUID and service-account abuse, buffer overflow basics, and how to confirm a system is yours without tripping its alarms.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Where are local Windows password hashes stored by the Security Accounts Manager (SAM)?

Answer: C — SAM stores LM/NTLM one-way hashes in that registry-hive file; the file can't be copied while Windows is running, which is why memory dumping (Mimikatz) is common. Domain accounts live in ntds.dit.

Question 2: NTLM authentication operates by:

Answer: A — The server sends a random challenge; the client computes a response from its NT hash; the server verifies it — no password ever travels on the wire (NTLMv2 is stronger but still weaker than Kerberos).

Question 3: In Kerberos, after authenticating to the Authentication Server, a client first receives:

Answer: B — Login → AS issues TGT → TGT is presented to the Ticket Granting Server to request individual service tickets (TGS).

Question 4: Password spraying differs from a classic dictionary attack because it:

Answer: D — Spraying (e.g., 'Password123' across the whole user base) stays under per-account lockout thresholds, unlike hammering one account.

Question 5: LLMNR and NetBIOS-NS poisoning attacks are most commonly performed with which tool?

Answer: B — Responder poisons LLMNR/NBT-NS/mDNS name-resolution requests, tricking Windows hosts into sending NTLMv2 hashes to the attacker.

Question 6: AS-REP roasting targets users who:

Answer: C — With pre-auth disabled, the KDC returns an AS-REP ticket that can be captured and cracked offline to recover the user's password.

Question 7: In a classic stack-based buffer overflow, which register does the attacker overwrite to redirect execution?

Answer: B — Controlling EIP lets the attacker point execution at injected shellcode; ESP tracks the stack top and EBP marks the stack base.

Question 8: Gaining access from a standard user to an administrator or root account is called:

Answer: B — Vertical = moving up in privilege (user → admin); horizontal = moving sideways to another account at the same level.

Question 9: The DCSync attack allows an attacker to:

Answer: C — Using replication rights (e.g., Mimikatz lsadump::dcsync), the attacker queries the DC as if it were another DC, dumping domain hashes.

Question 10: Which technique abuses a vulnerable Windows component via registry manipulation to bypass UAC?

Answer: D — If a scheduled FodHelper key points at a malicious binary, launching that 'system' helper triggers a UAC bypass — a common Windows privesc trick (also eventvwr and COM handler hijacking).

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 System Hacking practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 6 (System Hacking). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 6 (System Hacking) cover?

Gaining access to systems: SAM/NTLM/Kerberos attacks, password cracking, buffer overflows, and privilege escalation. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 6 flashcards at https://cehstudy.com/ceh-v13/module-06/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this System Hacking quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH System Hacking flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 6 (System Hacking). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 6 page at https://cehstudy.com/ceh-v13/module-06/. No account or sign-up required.