100+ Free PECB Certified Lead Ethical Hacker Practice Questions
Prepare for the PECB Certified Lead Ethical Hacker (CLEH) exam with instant access — no signup required.
Loading practice questions...
Explore More PECB Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: PECB Certified Lead Ethical Hacker Exam
The official PECB Certified Lead Ethical Hacker exam is a hands-on, open-book practical assessment (a 6-hour session to compromise at least two of three target machines) followed by a written findings report submitted within 24 hours, with a 70% passing score. This practice question bank provides 100 scenario-based MCQs as an English-language study adaptation of the methodology across the six official competency domains; it is not a simulation of the practical exam.
Sample PECB Certified Lead Ethical Hacker Practice Questions
Try these sample questions to test your PECB Certified Lead Ethical Hacker exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Before initiating an active penetration test against a corporate network, which document MUST be signed by an authorized executive to legally protect the testing team?
2A tester has SSH access to a compromised jump host (10.0.0.5) that can reach an internal database server (192.168.50.20:3306) unreachable from the tester's machine. Which SSH option creates a listener on the tester's own machine that tunnels traffic to that database through the jump host?
3Under federal and international cybercrime statutes (such as the US Computer Fraud and Abuse Act - CFAA or UK Computer Misuse Act), what key element distinguishes ethical hacking from unlawful intrusion?
4How does a Black-Box penetration test differ from a White-Box penetration test?
5According to the PECB Code of Ethics, what must an ethical hacker do if they encounter evidence of illegal activities (e.g., child exploitation material or financial fraud) during an engagement?
6A tester runs `ssh -D 1080 user@10.0.0.5` against a compromised jump host and then edits `/etc/proxychains.conf` to add `socks5 127.0.0.1 1080`. What capability does this combination provide?
7After gaining a Meterpreter session on a dual-homed host, a tester runs `run autoroute -s 192.168.50.0/24`. What does this achieve?
8A tester wants to copy a memory dump off a compromised Linux host using netcat. On the tester's machine they run `nc -lvnp 4444 > dump.raw`. Which command must be issued on the compromised host?
9When performing penetration testing on multi-tenant public cloud infrastructure (e.g., AWS, Azure, GCP), which activity strictly requires prior notification or permission under cloud provider policy?
10Which CVSS v3.1 metric group measures the inherent characteristics of a vulnerability that are constant over time and across user environments?
About the PECB Certified Lead Ethical Hacker Exam
The PECB Certified Lead Ethical Hacker certification validates professional competence in leading penetration testing projects, performing vulnerability assessments, executing technical exploits across networks and applications, analyzing post-exploitation risk, and delivering strategic remediation roadmaps.
Assessment
Open-book practical exam: compromise at least two of three target machines through penetration testing, then submit a written findings report. Scored across six competency domains (information gathering, threat modelling and vulnerability identification, exploitation, privilege escalation, pivoting and file transfers, reporting).
Time Limit
6-hour practical session plus up to 24 hours for the written report
Passing Score
70%
Exam Fee
USD 1000 exam-only (Lead level); included when taken with PECB partner training (PECB)
PECB Certified Lead Ethical Hacker Exam Content Outline
Information gathering (Domain 1)
Reconnaissance, OSINT, DNS/WHOIS enumeration, and Nmap scanning to select and adapt the testing approach. Official Domain 1 is 15% of exam points.
Threat modelling and vulnerability identification (Domain 2)
Building an offensive threat model and using vulnerability scanning to select effective exploitation targets. Official Domain 2 is 5% of exam points.
Exploitation techniques (Domain 3)
Server-side, client-side, web application, and wireless attacks, plus IDS/IPS and firewall evasion. Official Domain 3 is the largest at 30% of exam points.
Privilege escalation (Domain 4)
Escalating privileges on machines, systems, and networks, including Active Directory attacks and credential harvesting. Official Domain 4 is 25% of exam points.
Pivoting and file transfers (Domain 5)
Pivoting to other networks, SSH/SOCKS tunnelling, file transfer, maintaining access, and cleaning up artifacts. Official Domain 5 is 15% of exam points.
Reporting (Domain 6)
Interpreting attack vectors, recommending mitigations, and drafting a clear penetration testing report. Official Domain 6 is 10% of exam points.
How to Pass the PECB Certified Lead Ethical Hacker Exam
What You Need to Know
- Passing score: 70%
- Assessment: Open-book practical exam: compromise at least two of three target machines through penetration testing, then submit a written findings report. Scored across six competency domains (information gathering, threat modelling and vulnerability identification, exploitation, privilege escalation, pivoting and file transfers, reporting).
- Time limit: 6-hour practical session plus up to 24 hours for the written report
- Exam fee: USD 1000 exam-only (Lead level); included when taken with PECB partner training
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
PECB Certified Lead Ethical Hacker Study Tips from Top Performers
Frequently Asked Questions
What is the format and duration of the PECB Certified Lead Ethical Hacker exam?
The official PECB CLEH examination consists of 80 multiple-choice questions administered over 3 hours (180 minutes) in an open-book format.
What passing score is required to achieve the PECB CLEH certification?
A minimum passing score of 70% (answering at least 56 out of 80 questions correctly) is required to pass the exam.
Is the official PECB Lead Ethical Hacker exam open-book?
Yes, PECB open-book examinations permit candidates to reference official PECB course materials, hardcopy standards, and personal study notes.
What key domains are tested on the PECB CLEH exam?
The exam covers ethical hacking governance, legal and compliance boundaries, reconnaissance and scanning, network/system/web application exploitation, post-exploitation privilege escalation, and vulnerability reporting/management.
How does the Lead Ethical Hacker certification differ from basic ethical hacking credentials?
The Lead certification emphasizes not only technical penetration testing execution, but also project scoping, team leadership, governance alignment (ISO/IEC 27001/27035), risk evaluation, and executive communication.