Skip to content
ScopefileGet the app

Technique fileIntro to ethical hacking

The five phases of ethical hacking, and how they map to the kill chain

EC-Council's five phases of ethical hacking run in order: reconnaissance, scanning, gaining access, maintaining access, clearing tracks. Lockheed Martin's Cyber Kill Chain cuts the same ground into seven steps, and MITRE ATT&CK catalogs it as tactics.

Exam
312-50
Domain
1 · Overview
Targets
9

A map, in order

The five phases sort the activity of an engagement by purpose. They anchor the Introduction to Ethical Hacking module and give every later module a place to hang: footprinting and scanning feed the first two phases, system hacking and malware the middle ones.

That makes this topic cheap and early. A couple of evenings here pays off across the whole blueprint, so put it in week one of your study plan and move on.

The five phases in order

EC-Council's sequence, from first contact to cleanup
EC-Council's sequence, from first contact to cleanup01Reconlearn the target02Scanningmap what answers03Gainingaccessfoothold04Maintainingaccesspersistence05ClearingtrackscleanupEC-Council's sequence, from first contact to cleanup01Reconlearn the target02Scanningmap what answers03Gaining accessfoothold04Maintaining accesspersistence05Clearing trackscleanup

Each phase from the defender's chair

What a defender can watch and control at every phase
PhaseWhat defenders watchControls that blunt it
ReconnaissanceUnusual interest in public assets, scraping of staff directoriesLimit what is published; awareness training
ScanningProbe patterns across many ports or hostsClose unused services; IDS alerting; scanning countermeasures
Gaining accessFailed logins, exploit signatures, odd process launchesPatching, MFA, hardening
Maintaining accessNew services, scheduled tasks, unexpected outbound connectionsEndpoint detection, egress filtering
Clearing tracksGaps or edits in logs, disabled auditingCentral log forwarding, integrity monitoring

Three frameworks, three vocabularies

The CEH phases next to two frameworks that cover similar ground
TraitCEH 5 phasesCyber Kill ChainMITRE ATT&CK
Owner (differs)EC-CouncilLockheed MartinMITRE
Count (differs)5 phases7 steps15 Enterprise tactics
Shape (differs)A linear engagementA linear intrusionA matrix of tactics and techniques
Last stage (differs)Clearing tracksActions on objectivesImpact (TA0040)
Typical use (differs)Structuring an engagementBreaking an intrusion earlyMapping detection coverage

Tinted rows marked ≠: at least one of the 3 differs from the others.

Kill chain step count from Lockheed Martin; ATT&CK v19.2 tactic count from attack.mitre.org. Both checked Oct 11, 2026.

Place the activity

Some items use EC-Council's five names, others borrow kill chain or ATT&CK terms; the option notes say which model each answer comes from.

Answered 0/9Hits 0

T-01

Which of the following represents the five stages of a penetration testing process?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: the EC-Council model runs from reconnaissance and scanning to gaining access, maintaining access and clearing or covering tracks.
  2. BBreaking access is not a phase name; the third phase is gaining access, where vulnerabilities are exploited.
  3. CPreparation and investigation are not phases of the hacking model; this sequence drops scanning and covering tracks.
  4. DMonitoring is not one of the five phases; after gaining access the attacker works to maintain that access.
T-02

You have just finished examining social media profiles and public posts related to the employees of a company you are going to pen-test. Based on the stages outlined by the EC-Council, in which stage of hacking are you currently?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AClearing tracks comes last, when an attacker removes logs and artifacts after compromising a system.
  2. BCorrect: reviewing public social media profiles and posts is passive information gathering, which is the reconnaissance phase.
  3. CGaining access involves actually exploiting a weakness, which has not happened yet when only public profiles were reviewed.
  4. DScanning actively probes the target's hosts and services, while reading public posts never touches the target's systems.
T-03

Which of the following activities does NOT typically take place during the reconnaissance phase of ethical hacking?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ANetwork scanning is formally its own phase, but light active probing often overlaps with active reconnaissance, so it is not the clearest exclusion.
  2. BGathering public information from websites, registries and social media is the core of passive reconnaissance.
  3. CCorrect: exploitation belongs to the gaining-access phase, after reconnaissance and scanning have identified targets and weaknesses.
  4. DSocial engineering is commonly used during reconnaissance to collect names, roles and internal details about the target.
T-04

In the context of ethical hacking, which phase involves the actual exploitation to gain unauthorized access to a system?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AScanning identifies live hosts, open ports and vulnerabilities but does not exploit them.
  2. BMaintaining access follows exploitation and focuses on persistence, not on the initial break-in.
  3. CCorrect: gaining access is the phase where discovered vulnerabilities are exploited to enter a system.
  4. DReconnaissance gathers information about the target before any system is touched or exploited.
T-05

Which ethical hacking phase is considered the least aggressive when evaluating a company's digital security?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: reconnaissance relies mostly on passive, public information gathering with little or no direct contact with target systems, making it the least aggressive phase.
  2. BExploitation actively attacks vulnerabilities to gain access, which is the most intrusive part of an engagement rather than the least aggressive.
  3. CMaintaining access means keeping a foothold on compromised systems through persistence, which happens only after an intrusion and is highly aggressive.
  4. DScanning sends probes directly to target hosts and ports, so it interacts with systems and is more aggressive than passive reconnaissance.
T-06

In the context of cyber security, which stage of an attack involves erasing traces to prevent detection by the victim?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGaining access is the exploitation phase, not the phase where evidence is removed.
  2. BScanning maps hosts and services early in the attack and leaves traces rather than erasing them.
  3. CCorrect: clearing or covering tracks means removing logs and artifacts to avoid detection, which is why centralized, tamper-resistant logging matters.
  4. DMaintaining access is about persistence on the compromised system, not about erasing evidence of the intrusion.
T-07

You have completed using OpenVAS for vulnerability scanning on a network. According to the EC-Council's stages of ethical hacking, which stage are you about to leave?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AReconnaissance gathers information without actively probing for vulnerabilities, which comes later.
  2. BGaining access is where vulnerabilities are exploited, which is the phase you would enter next, not the one you are leaving.
  3. CCorrect: vulnerability scanning with a tool like OpenVAS belongs to the scanning phase, so finishing it means moving toward gaining access.
  4. DClearing tracks is the final phase, focused on removing evidence after a compromise.
T-08

At which stage of an ethical hacking engagement does an attacker design and build the tools necessary for a targeted attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARemediation is the defender's work of fixing weaknesses after testing, not a stage of building attack tools.
  2. BReconnaissance gathers information about the target, which feeds the next stage but does not include building tools.
  3. CCorrect: weaponization, a stage of the Lockheed Martin Cyber Kill Chain rather than the five CEH phases, pairs an exploit with a deliverable payload.
  4. DExploitation is when the prepared weapon is triggered against a vulnerability, after it has been built and delivered.
T-09

What is the primary purpose of the MITRE ATT&CK framework?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: MITRE ATT&CK is a knowledge base of real-world adversary tactics and techniques used for threat modeling, detection engineering and emulation.
  2. BATT&CK has no regulatory role; it is a descriptive knowledge base, not a set of internet usage rules.
  3. CATT&CK does not monitor users; it catalogs adversary behavior that defenders can map their telemetry against.
  4. DATT&CK documents observed attacker behavior rather than building products, although vendors map their tools to it.

Frameworks and defenders

Why does CEH use five phases when the kill chain has seven steps?

The two models cut the same process at different points. Lockheed Martin's Cyber Kill Chain splits the early work more finely and names command and control on its own; EC-Council folds those into five phases (checked Oct 11, 2026). Neither count is more correct; use the vocabulary of whichever model a source names.

How do defenders use these models?

The kill chain frames a simple goal: break the intrusion at the earliest step you can. ATT&CK is more granular, so security teams map their detections against its tactics to see where coverage is thin.

Do the phases say anything about who the attacker is?

No. The phases describe the work; the actor behind it is a separate axis covered in the hacker classes. A state-sponsored group and a script kiddie move through the same sequence.

Sources