====================================================================
Total: 376 Unique Questions | 20 Modules | Text-Only Format
====================================================================
Module 1: Introduction to Ethical Hacking
—————————————–
Q1. Before initiating any security assessment on a client’s network, what documentation is critical to protect the testing team from potential legal liability?
A. A verbal agreement with the IT manager
B. A signed statement of work and formal authorization
C. A list of all vulnerabilities found during the scan
D. A handoff document for the information assurance team
→ Answer: B
Q2. You are hired to test a network where you are given IP ranges and network diagrams but no credentials. What type of testing methodology does this describe?
A. White Box
B. Black Box
C. Gray Box
D. Blue Box
→ Answer: C
Q3. Which operating system distribution is specifically designed with pre-loaded tools for penetration testing and security auditing?
A. Windows Server 2019
B. Security Onion
C. Kali Linux
D. Ubuntu Desktop
→ Answer: C
Q4. Bollards, cipher locks, and mantraps are examples of which category of security controls?
A. Logical Controls
B. Administrative Controls
C. Physical Controls
D. Technical Controls
→ Answer: C
Q5. In a penetration test scenario where the tester has no prior knowledge of the target other than the company name, what is this assessment style called?
A. White Box
B. Gray Box
C. Black Box
D. Crystal Box
→ Answer: C
Q6. Which international standard outlines the “Plan, Do, Check, Act” cycle for implementing and validating information security controls?
A. NIST 800-53
B. ISO 27002
C. ISO 27001
D. NIST 800-161
→ Answer: C
Q7. You are preparing a final report for a penetration test engagement. Which section is most appropriate for the client’s senior leadership team, who may not have technical expertise?
A. Technical Analysis Report
B. Executive Summary Report
C. Project Scope Document
D. Detailed Vulnerability List
→ Answer: B
Q8. Which security principle requires that critical tasks be split between two or more individuals to prevent fraud or error?
A. Least Privilege
B. Job Rotation
C. Separation of Duties
D. Mandatory Vacation
→ Answer: C
Q9. A manager requests that access to a file server be restricted to prevent data leaks. You warn that this may hinder employee productivity. Which element of the CIA triad is primarily at risk here?
A. Confidentiality
B. Integrity
C. Availability
D. Non-Repudiation
→ Answer: C
Q10. Your organization mandates the use of cross-cut shredders for disposing of classified documents. What type of security control is this policy?
A. Physical Control
B. Technical Control
C. Administrative Control
D. Logical Control
→ Answer: C
Q11. During a policy audit, you find that security administrators are not following the published security policies. What is the best course of action?
A. Terminate the administrators immediately.
B. Ignore the discrepancy.
C. Recommend regular reviews and updates to the policies.
D. Allow administrators to create their own rules.
→ Answer: C
Q12. Which security property is primarily addressed when implementing AES encryption?
A. Integrity
B. Availability
C. Confidentiality
D. Non-Repudiation
→ Answer: C
Q13. What is the governing council of the CEH exam?
A. (ISC)²
B. EC-Council
C. CompTIA
D. Microsoft
→ Answer: B
Q14. What is one advantage an attacker has over a defender/victim?
A. Time
B. TOR network forums
C. Money
D. Metasploit
→ Answer: A
Q15. You are team leader for your financial firm. You set a policy in place that all coworkers must clean off their desk, empty trash, shred sensitive documents, and secure other critical documents in their respective containers at the end of the day. What is the common name for such a policy?
A. Clean room policy
B. Clean desk policy
C. Sanitization policy
D. Wrapping up policy
→ Answer: B
Q16. Which of the following is considered an administrative control?
A. Biometric device
B. Mantrap
C. Security policy
D. Access control list
→ Answer: C
Q17. What is the most important task you should perform as part of a penetration test?
A. Get informed approval
B. Write a report
C. Get a contract in place
D. Compromise all systems
→ Answer: A
Q18. Which of the following describes a “soft” control?
A. User agreement
B. Access control list
C. Biometrics
D. Security clerk
→ Answer: A
Q19. What capability does a backdoor provide to the adversary?
A. Backdoors can corrupt data software.
B. They destroy cryptographic keys in the TPM.
C. They provide low-level formatting operations.
D. They provide remote access to the client.
→ Answer: D
Q20. Which of the following describes the collection of human physical attributes for use in performing electronic authentication?
A. Personal identification card
B. Hair and fingerprints
C. Biometrics
D. Type 3 control
→ Answer: C
Q21. Which of these is not used for biometrics?
A. Voice
B. Iris
C. Hair
D. Fingerprint
→ Answer: C
Q22. What is the process that changes a private IP address to a public address at the gateway?
A. NAT
B. PRAT
C. GNAT
D. NAT-T
→ Answer: A
Q23. What are the two types of intrusion detection systems?
A. NIDS and SIDS
B. HIDS and SIDS
C. IDS and IPS
D. HIDS and NIDS
→ Answer: D
Q24. What is one disadvantage of a single sign-on (SSO) strategy?
A. It offers a single point of failure for authentication.
B. There is no replication for security policies.
C. Passwords are stored in plain text.
D. User accounts are easily accessible.
→ Answer: A
Q25. What is the name of the entity that may be used to hold certificates and keys in case the primary keys or certificates are unavailable?
A. Government safe
B. Hot site
C. Escrow
D. Offsite backup
→ Answer: C
Q26. When a user authenticates once to a resource and is then permitted to access additional applications without the need to reauthenticate, what form of authentication is being used?
A. Once sign-on
B. Nonce sign-on
C. Kerberos
D. Single sign-on
→ Answer: D
Q27. What does a router separate?
A. Collision domains
B. Broadcast domains
C. Switching domains
D. Routing loops
→ Answer: B
Q28. Which of the following is considered a framework for penetration testing?
A. Metasploit
B. Cain & Abel
C. Nessus
D. Security Onion
→ Answer: A
Q29. In Windows, what command can you use to hide a file?
A. +h attrib <filename>
B. h+ <filename>
C. filename attrib+h
D. attrib +h <filename>
→ Answer: D
Q30. Which of the following is a correct MAC address?
A. 00-12-3e-ff-d4-98
B. 3i-45-fa-90-25-1b
C. ff-ff-ff-ff-ff-ff-fg
D. 65-23-ab-cb-a9
→ Answer: A
Module 2: Footprinting and Reconnaissance
—————————————–
Q31. An attacker gathers intelligence about a target by reviewing public job postings and social media profiles without touching the target’s network. What phase is this?
A. Scanning
B. Passive Reconnaissance
C. Active Reconnaissance
D. Gaining Access
→ Answer: B
Q32. Which regional internet registry manages IP address allocation for organizations located in the United States and Canada?
A. RIPE NCC
B. APNIC
C. ARIN
D. LACNIC
→ Answer: C
Q33. What technique involves searching through discarded trash containers to find sensitive documents?
A. Shoulder Surfing
B. Dumpster Diving
C. Phishing
D. Tailgating
→ Answer: B
Q34. Which open-source utility is best suited for harvesting email addresses from search engines and PGP servers?
A. Nmap
B. theHarvester
C. Wireshark
D. Netcat
→ Answer: B
Q35. When beginning reconnaissance, which professional networking site is most likely to reveal employee roles and technology stacks?
A. Instagram
B. LinkedIn
C. TikTok
D. Pinterest
→ Answer: B
Q36. Which of the following provides free information about a website that includes phone numbers, the administrator’s email, and even the domain registration authority?
A. nslookup
B. dig
C. Whois.net
D. Ping
→ Answer: C
Q37. What is significant about RFC 1918?
A. It signifies non-routable IP addresses.
B. It signifies the use of web proxy servers.
C. It describes the usage of DMZs.
D. It covers the authentication header in IPSec.
→ Answer: A
Q38. What site would you use to gather financial information about a company, including 10-K reports?
A. EDGAR
B. HAL
C. MOLES
D. Google
→ Answer: A
Q39. Which federal law mandates securing medical records at rest and in transit?
A. PCI
B. HIPAA
C. FISMA
D. PATRIOT Act
→ Answer: B
Q40. Which of the following acronyms represent the institution that governs North America IP space?
A. ICANN
B. PIR
C. ARIN
D. APNIC
→ Answer: C
Q41. As an attacker, you are searching social media sites as well as job listings. What phase of the attack are you in?
A. Casing the target
B. Gaining access
C. Maintaining access
D. Reconnaissance
→ Answer: D
Q42. As an attacker, which of the following resources would be the best place to begin reconnaissance of your target?
A. Nmap using the –sO switch
B. Suricata
C. LinkedIn
D. Calling the help desk masquerading as an authorized user
→ Answer: C
Q43. Which of the following is considered a passive reconnaissance action?
A. Searching through the local paper
B. Calling Human Resources
C. Using the nmap -sT command
D. Conducting a man-in-the-middle attack
→ Answer: A
Q44. You are sitting inside of your office, and you notice a strange person in the parking lot with what appears to be a tall antenna connected to a laptop. What is the stranger most likely doing?
A. Brute-forcing their personal electronic device
B. Wardriving
C. Warflying
D. Bluesnarfing
→ Answer: B
Q45. If you were looking up information about a company in Brazil, which RIR would you be looking in for data?
A. AFRINIC
B. RIPE
C. APNIC
D. LACNIC
→ Answer: D
Q46. As a black hat, you are conducting a reconnaissance operation on a potential target. You gather intelligence by using publicly available information, conducting stakeouts of the facility, and observing workers as they enter and leave the premises from across the street. What phase of the hacking methodologies are you operating within?
A. Footprinting
B. Fingerprinting
C. Enumeration
D. Passive reconnaissance
→ Answer: D
Q47. What tactic are you using if you are using the keyword filename:?
A. Footprinting
B. Doxing
C. Google Hacking
D. IoT device lookup
→ Answer: C
Q48. Which of the following is considered open-source information?
A. Newspaper
B. Trade secrets
C. Information obtained from dumpster diving
D. Information obtained from a man-in-the-middle attack
→ Answer: A
Q49. As a business analyst, you study and collect information about your competitor using Google and the competitor’s website and products. Which of the following best defines the actions you are performing?
A. Google hacking
B. Espionage
C. Competitive intelligence
D. Tradecraft
→ Answer: C
Q50. Where would you go to get the name and contact information for the administrator of a domain?
A. DNS
B. EDGAR
C. RIR
D. LinkedIn
→ Answer: C
Q51. Which of the following best indicates a top-level parent domain?
A. sybex.com
B. .org
C. www.wiley.com
D. www.
→ Answer: B
Q52. Which of the following is a top-level domain in DNS?
A. myserver.com
B. .com
C. http://myserver.com
D. http://www.myserver.com
→ Answer: B
Q53. What is the process of sending data to a device over Bluetooth without having to go through the pairing process called?
A. Bluejacking
B. Blueboxing
C. Bluesnarfing
D. Bluebugging
→ Answer: A
Q54. You are walking around downtown picking up on open wireless access points. As you identify these access points, you place a symbol on a nearby building. What activity are you conducting?
A. War walking
B. Wardriving
C. Footprinting
D. Warchalking
→ Answer: D
Q55. You are driving in your vehicle looking for wireless access points to connect to. What type of attack are you conducting?
A. War dialing
B. Drive-by scanning
C. Warchalking
D. Wardriving
→ Answer: D
Q56. What type of attack would you be conducting in a car using a laptop with a Wi-Fi card in it?
A. Wardriving
B. DoS
C. Scanning
D. War dialing
→ Answer: A
Q57. Which of the following tools allows you to create certificates that are not officially signed by a CA?
A. Cain & Abel
B. Nmap
C. Ettercap
D. Darkether
→ Answer: A
Q58. Which of the following allows the adversary to forge certificates for authentication?
A. Wireshark
B. Ettercap
C. Cain & Abel
D. Ncat
→ Answer: C
Q59. What tool could you use locally on a Kali Linux or Parrot OS system to look for exploits available across different platforms, which may also provide exploit source code?
A. Empire
B. Metasploit
C. Nmap
D. searchsploit
→ Answer: D
Q60. What tool would you use to look for proof of concept exploit code on a system like Kali or ParrotOS?
A. Nessus
B. Zed Attack Proxy
C. Searchsploit
D. EDGAR
→ Answer: C
Module 3: Scanning Networks
—————————
Q61. During a port scan, you send a SYN packet and receive a SYN/ACK response. What does this indicate about the port?
A. The port is closed.
B. The port is open.
C. The port is filtered.
D. The host is down.
→ Answer: B
Q62. Which Nmap switch is used specifically to detect the operating system of a target host?
A. -sS
B. -O
C. -sV
D. -Pn
→ Answer: B
Q63. What is the default Time-To-Live (TTL) value typically seen in packets originating from a Windows system?
A. 64
B. 255
C. 128
D. 32
→ Answer: C
Q64. Which port range is designated as “Well-Known Ports” and usually requires root or admin privileges to bind?
A. 1024–49151
B. 49152–65535
C. 0–1023
D. 1–255
→ Answer: C
Q65. Why might an attacker choose a TCP Connect scan (-sT) over a SYN Stealth scan (-sS)?
A. It is faster.
B. It avoids logging on the target.
C. It does not require raw socket privileges.
D. It is less likely to be detected by firewalls.
→ Answer: C
Q66. What is the total bit length of an IPv6 address?
A. 32 bits
B. 64 bits
C. 128 bits
D. 256 bits
→ Answer: C
Q67. Which protocol operates at the Transport layer and is connectionless?
A. TCP
B. IP
C. UDP
D. ICMP
→ Answer: C
Q68. What tool is commonly used to retrieve service banners from open ports?
A. Ping
B. Telnet
C. Traceroute
D. ARP
→ Answer: B
Q69. In a TCP header, which flag is set to indicate the sender wants to terminate the connection gracefully?
A. SYN
B. RST
C. FIN
D. URG
→ Answer: C
Q70. What is the maximum theoretical payload size for a UDP datagram?
A. 1500 bytes
B. 65,507 bytes
C. 65,535 bytes
D. 32,768 bytes
→ Answer: B
Q71. If a company has been given a /24 network from its Internet service provider, what CIDR notation would need to be used for each network if the company needed to have eight networks out of that allocation?
A. /27
B. /26
C. /28
D. /8
→ Answer: A
Q72. How many subnets can be provided using a /26 Classless Inter-Domain Routing (CIDR) from a /24 allocation?
A. 1
B. 2
C. 3
D. 4
→ Answer: D
Q73. Using Nmap, which switch command enables a UDP connections scan of a host?
A. -sS
B. -sX
C. -PT
D. -sU
→ Answer: D
Q74. Using Nmap, what is the correct command to scan a target subnet of 192.168.0.0/24 using a ping sweep and identifying operating systems?
A. nmap -sn -O 192.168.0.0/24
B. nmap -sN -V 192.168.0.0/24
C. nmap -sT -P 192.168.0.0/24
D. nmap -Ps -O 192.168.0.0/24
→ Answer: A
Q75. Which of the following switches for the Nmap command does nothing but fingerprinting an operating system?
A. -O
B. -sFRU
C. -sA
D. -sX
→ Answer: A
Q76. Which Nmap parameter would allow you to perform tasks like getting the Server Message Block workgroup a system is in?
A. –script
B. -sScript
C. -sSMB
D. -sX
→ Answer: A
Q77. Which of these is a GUI tool that runs under Windows and can be used to perform ping sweeps and port scans?
A. MegaPing
B. Ettercap
C. Dsniff
D. Nmap
→ Answer: A
Q78. Which of the following scanners provides ping sweeps and at times can be very noisy if not properly configured?
A. Angry IP
B. Cain & Abel
C. nmap -sT -T0
D. Nslookup
→ Answer: A
Q79. What utility could you use if you wanted to be specific about individual fields to set while you were sending network messages to gather information about remote hosts?
A. hping
B. Ettercap
C. Nmap
D. pingcraft
→ Answer: A
Q80. What is the address length used by IPv6?
A. 32 bits
B. 128 bytes
C. 32 bytes
D. 128 bits
→ Answer: D
Q81. What is the length of an IPv6 address?
A. 64 bits
B. 128 bits
C. 256 bits
D. 32 bits
→ Answer: B
Q82. Which of the following functions is no longer utilized within IPv6?
A. Multicast
B. Anycast
C. Unicast
D. Broadcast
→ Answer: D
Q83. What is one of the advantages of IPv6 over IPv4 from a security perspective?
A. IPv4 has a smaller address space.
B. IPv6 allows for header authentication.
C. IPv6 is more flexible about extensions.
D. IPv6 is typically represented in hexadecimal.
→ Answer: B
Q84. Which of the following best describes the ICMP Type 8 code?
A. Device is being filtered
B. Network route is incorrect or missing
C. Echo request
D. Destination unreachable
→ Answer: C
Q85. What is the default port number for Telnet?
A. 21
B. 23
C. 53
D. 443
→ Answer: B
Q86. What is the default port used for DNS?
A. 80
B. 22
C. 8080
D. 53
→ Answer: D
Q87. On which port does a standard DNS zone transfer operate?
A. 53
B. 80
C. 8080
D. 25
→ Answer: A
Q88. What is the default port used in POP3?
A. 110
B. 53
C. 443
D. 125
→ Answer: A
Q89. Which of the following services is registered for port 110?
A. SNMP
B. RPC
C. POP3
D. LDAP
→ Answer: C
Q90. What is the default command port for FTP?
A. 22
B. 21
C. 20
D. 23
→ Answer: B
Q91. On what default port(s) does SCP operate?
A. TCP port 22
B. TCP port 21
C. TCP port 24
D. TCP ports 21 and 22
→ Answer: A
Q92. What standard port does SFTP use?
A. 20
B. 21
C. 22
D. 20 and 21
→ Answer: C
Q93. What is the default TCP port for HTTPS encrypted web traffic?
A. 443
B. 8080
C. 80
D. 22
→ Answer: A
Q94. What is the default port used by DNS?
A. 80
B. 22
C. 8080
D. 53
→ Answer: D
Q95. What port number or numbers is/are associated with the IP protocol?
A. 0 to 65535
B. No ports
C. 53
D. 80
→ Answer: B
Q96. What is the default TCP port does SSH utilize?
A. Port 22
B. Port 21
C. Port 443
D. Port 25
→ Answer: A
Q97. What is the default port number for Telnet?
A. 21
B. 23
C. 53
D. 443
→ Answer: B
Q98. Which of the following port ranges will show you the ports requiring administrative access?
A. 0 to 1023
B. 0 to 255
C. 1024 to 49151
D. 1 to 128
→ Answer: A
Q99. What are two common ports used to connect to a web server?
A. 80 and 25
B. 80 and 8080
C. 443 and 53
D. 20 and 21
→ Answer: B
Q100. Aside from port 80, what is another common port used to connect to a web server?
A. 8080
B. 21
C. 54
D. 110
→ Answer: A
Module 4: Enumeration
———————
Q101. What is the major vulnerability for an ARP request?
A. It sends out an address request to all the hosts on the LAN.
B. The address is returned with a username and password in cleartext.
C. The address request can cause a DoS.
D. The address request can be spoofed with the attacker’s MAC address.
→ Answer: D
Q102. Where is the password file located on a Windows system?
A. C:\Windows\temp
B. C:\Win\system\config
C. C:\Windows\accounts\config
D. C:\Windows\system32\config
→ Answer: D
Q103. In the Windows SAM file, what security identifier would indicate to the adversary that a given account is an administrator account?
A. 500
B. 1001
C. ADM
D. ADMIN_500
→ Answer: A
Q104. What command would the adversary use to show all the systems within the domain using the command-line interface in Windows?
A. netstat -R/domain
B. net view/<domain_name>:domain
C. net view/domain:<domain_name>
D. netstat/domain:<domain_name>
→ Answer: C
Q105. In Linux, what file allows you to see user information such as full name, phone number, and office information?
A. Shadow file
B. Passwd file
C. Userinfo file
D. Useraccount file
→ Answer: B
Q106. In Linux, what designator is used to uniquely identify a user account?
A. GID
B. SID
C. UID
D. PID
→ Answer: C
Q107. In Linux, which of the following accounts denotes the administrator?
A. Admin
B. Administrator
C. root
D. su
→ Answer: C
Q108. Where are logs located on Linux systems?
A. /home/log
B. /var/log
C. /log/
D. /home/system32/log
→ Answer: B
Q109. What command can you use to switch to a different user in Linux?
A. swu
B. user
C. sudo
D. su
→ Answer: D
Q110. What directory holds the basic commands in the Linux OS?
A. /etc
B. /bin
C. /
D. /config
→ Answer: B
Q111. Which of the following denotes the root directory in Linux OS?
A. \
B. /
C. C:\
D. root/
→ Answer: B
Q112. In Linux, where is the password file stored?
A. /etc/passwd
B. /etc/shadow
C. /etc/user/password
D. /shadow/etc
→ Answer: B
Q113. What file within the Linux OS contains administrative information about a user?
A. /etc/shadow
B. /etc/passwd
C. /home
D. /home/profile
→ Answer: B
Q114. What command has been used to display the network configuration in Linux OS?
A. ipconfig
B. netstat
C. ls
D. ifconfig
→ Answer: D
Q115. In Windows, what is the command to display the ARP cache?
A. ifconfig/-a
B. arp -a
C. -a arp
D. ipconfig/arp -a
→ Answer: B
Q116. What utility is used to gather information about NetBIOS configurations on Windows systems?
A. netstat
B. Nmap
C. nbtstat
D. Ping
→ Answer: C
Q117. What tool could you use on a Windows system to collect information about the Windows network, including the workgroup or domain you are connected to?
A. ipconfig
B. netstat
C. MSConfig
D. nbtstat
→ Answer: D
Q118. Which of the following services is associated with TCP port 389?
A. LDAP
B. IMAP
C. SMB
D. RPC
→ Answer: A
Q119. What port number is used by NetBIOS for name services?
A. UDP port 137
B. TCP port 139
C. UDP port 190
D. None
→ Answer: A
Q120. What three services are usually included with the NetBIOS protocol?
A. NBT, NetBIOS session, and NetBIOS datagram
B. NBT, asymmetric session, and NetBIOS datagram
C. NetBIOS datagram, NBT, and NetBIOS AD
D. NetBIOS datagram, NBT, and NetBIOS SCP
→ Answer: A
Q121. Which of the following are not objects in Active Directory?
A. Users
B. Computers
C. Printers
D. Files
→ Answer: D
Q122. What sets up a null session using Windows?
A. ftp://yourdomain.com
B. C$\yourdomain.com
C. net use\yourdomain\ipc$””/u:””
D. netcat yourdomain
→ Answer: C
Q123. Which of the following is the protocol used by Microsoft Windows systems for authentication from one system to another?
A. SESAME
B. Diameter
C. Kerberos
D. HIDS
→ Answer: C
Q124. In Kerberos, which ticket is presented to a server to grant access to a service?
A. TGS
B. KDC
C. TGT
D. AS
→ Answer: A
Module 5: Vulnerability Analysis
——————————–
Q125. Which of the following describes a race condition?
A. Where two conditions occur at the same time and there is a chance that arbitrary commands can be executed with a user’s elevated permissions, which can then be used by the adversary
B. Where two conditions cancel one another out and arbitrary commands can be used based on the user privilege level
C. Where two conditions are executed under the same user account
D. Where two conditions are executed simultaneously with elevated user privileges
→ Answer: A
Q126. Which option describes the concept of injecting code into a portion of data in memory that allows for arbitrary commands to be executed?
A. Buffer overflow
B. Crash
C. Heap spraying
D. Format string
→ Answer: A
Q127. What is patch management?
A. Deploying patches when they are available
B. Making determinations about patch disposition for business systems
C. Deploying patches at the end of the month
D. Determining what vulnerabilities are currently on your network and deploying patches immediately to eliminate the threat
→ Answer: B
Q128. Which instruction value is used to invoke a NOP (non-operating procedure)?
A. 0x99
B. 0x91
C. 0xGH
D. 0x90
→ Answer: D
Q129. Which of the following tools is used exclusively to scan for vulnerabilities on a target system or a network?
A. Snort
B. Ncat
C. Nessus
D. Metasploit
→ Answer: C
Q130. Which of the following best describes a vulnerability?
A. A threat being potentially realized
B. A weakness in a system
C. A threat actor
D. An incident
→ Answer: B
Q131. What is the biggest problem with using rainbow tables for password cracking?
A. Disk space utilization
B. Processor utilization
C. Low success rate
D. Not used for password cracking
→ Answer: A
Q132. Which of the following password cracking methods is the fastest?
A. Dictionary attack
B. Brute force
C. Birthday attack
D. Reverse hash matching
→ Answer: A
Q133. What is the act of guessing every possible password combination of an account?
A. Brute force
B. Pass the hash
C. Dictionary attack
D. Social engineering
→ Answer: A
Q134. Which of the following tools can be used to crack passwords?
A. Cain & Abel
B. ToneLoc
C. Wireshark
D. WarVOX
→ Answer: A
Q135. Of the following, which allows you to conduct password cracking?
A. LOIC
B. John the Ripper
C. CPU Dump
D. Wireshark
→ Answer: B
Q136. Which of the following is an optimal way of discovering passwords in plain text?
A. Intercepting an SSH connection
B. Following a TCP stream
C. Intercepting SSL traffic
D. Cracking an account using John the Ripper
→ Answer: B
Q137. What is the encryption key length in DES?
A. 64
B. 128
C. 56
D. 80
→ Answer: C
Q138. Which of the following encryption ciphers replaced DES and was renamed AES?
A. RSA
B. AES
C. Rijndael
D. RC5
→ Answer: C
Q139. What is the name of the algorithm that was selected to be the Advanced Encryption Standard?
A. Rijndael
B. Lucifer
C. Feistel
D. Skipjack
→ Answer: A
Q140. Which encryption was selected by NIST as the principal method for providing confidentiality after the DES algorithm?
A. 3DES
B. Twofish
C. RC4
D. AES
→ Answer: D
Q141. You are a CISO for a giant tech company. You are charged with implementing an encryption cipher for your new mobile devices that will be introduced in 2022. What encryption standard will you most likely choose?
A. RC4
B. MD5
C. AES
D. Skipjack
→ Answer: C
Q142. What key sizes in bits are used within AES?
A. 64 and 128
B. 128, 192, and 256
C. 128 and 256
D. 256
→ Answer: B
Q143. Which of the following passwords will take the most effort to crack?
A. P@$$w0rd
B. Pass123
C. @()!_
D. Thisismypasswordandnoonecanstealit
→ Answer: D
Q144. Which password is more secure?
A. keepyourpasswordsecuretoyourself
B. pass123!!
C. P@$$w0rD
D. KeepY0urPasswordSafe!
→ Answer: D
Q145. Which of the following is the fastest password cracking method?
A. Dictionary attack
B. Brute force
C. Birthday attack
D. Reverse hash matching
→ Answer: A
Q146. What is the biggest drawback from using anti-malware software?
A. It takes up processing resources.
B. It must have up-to-date virus definitions.
C. Anti-malware software is expensive.
D. It can be centrally or independently administered.
→ Answer: B
Q147. What is a major drawback of most antivirus software?
A. It can be extremely slow.
B. It must have the latest virus definitions.
C. It can take up a lot of host resources.
D. It requires a lot of effort to administer.
→ Answer: B
Q148. In virus scanning, what is the telltale sign of a virus?
A. Hash value
B. Signature
C. Definition
D. Trojan
→ Answer: B
Q149. What does a vulnerability scanner like Nessus not use to identify vulnerabilities?
A. Exploited service
B. Banners
C. Application headers
D. Vulnerability signature
→ Answer: A
Module 6: System Hacking
————————
Q150. In which phase within the ethical hacking framework do you alter or delete log information?
A. Scanning and enumeration
B. Gaining access
C. Reconnaissance
D. Covering tracks
→ Answer: D
Q151. You are part of the help desk team. You receive a ticket from one of your users that their computer is periodically slow. The user also states that from time to time, documents have either disappeared or have been moved from their original location to another. You remote desktop to the user’s computer and investigate. Where is the most likely place to see if any new processes have started?
A. The Processes tab in Task Manager
B. C:\Temp
C. The Logs tab in Task Manager
D. C:\Windows\System32\User
→ Answer: A
Q152. You are an attacker who has successfully infiltrated your target’s web server. You performed a web defacement on the targeted organization’s website, and you were able to create your own credential with administrative privileges. Before conducting data exfiltration, what is the next move?
A. Log into the new user account that you created.
B. Go back and delete or edit the logs.
C. Ensure that you log out of the session.
D. Ensure that you migrate to a different session and log out.
→ Answer: B
Q153. Where is the logfile that is associated with the activities of the last user that signed in within a Linux system?
A. /var/log/user_log
B. /var/log/messages
C. /var/log/lastlog
D. /var/log/last_user
→ Answer: C
Q154. What command in Windows allows you to bring up a list of startup items, including their locations in the Registry or the file system?
A. Mslookup
B. MSConfig
C. Regedit
D. iexplorer.exe
→ Answer: B
Q155. The SAM log file entry is located in what part of a Windows Registry system?
A. HKEY_LOCAL_MACHINE\SAM
B. HKEY_LOCAL_SAM
C. HKEY_LOCAL_MACHINE\WINDOWS
D. HKEY_SYSTEM_MACHINE\SAME.L
→ Answer: A
Q156. What is the password file of a Windows system located in which of the following directories?
A. C:\System32\Windows\config
B. \etc\win\config
C. C:\System\Windows\config
D. C:\Windows\System32\config
→ Answer: D
Q157. In Windows, what command can you use to hide a file?
A. +h attrib <filename>
B. h+ <filename>
C. filename attrib+h
D. attrib +h <filename>
→ Answer: D
Q158. What do NTFS alternate data streams provide?
A. They can hide a file behind another file.
B. They prevent a file from being changed.
C. They prevent a file from being moved.
D. They prevent an unauthorized user from viewing the file.
→ Answer: A
Q159. What is the issue when there is no boundary being checked or validated in programming?
A. The program will assign its own values.
B. The program does not validate if the input values can be stored without overwriting the next memory segment.
C. The program executes without checking what other programs are open.
D. Memory allocation has already been reserved for a program.
→ Answer: B
Q160. When writing a program, what is one of the fundamental tasks that should be done when declaring a variable?
A. Assign a random value to it.
B. Do not assign a value because it can corrupt data.
C. Initialize the variable.
D. A variable does not need to be initialized.
→ Answer: C
Q161. What is a heap?
A. A static allocation of memory
B. A memory segment located within the CPU
C. Memory that is swapped to the hard drive
D. Memory allocation of a size and location that is assigned dynamically
→ Answer: D
Q162. What is the region in memory that is assigned to a process or a program when it is initiated?
A. Cluster
B. Stack
C. Heap
D. Pointer
→ Answer: B
Q163. What is a buffer used for?
A. Dynamic data storage
B. Static data storage
C. Data in transit
D. Processing power
→ Answer: B
Q164. What type of attack would the following code be vulnerable to? char[5] attacker; strcpy(attacker,”cat/etc/passwd”); scanf(&attacker);
A. Buffer overflow
B. SQL injection
C. Command injection
D. Heap spraying
→ Answer: A
Q165. What application exploit type works against dynamic memory allocations?
A. Return to libc
B. Heap spraying
C. Buffer overflow
D. Stack smashing
→ Answer: B
Q166. Why is address space layout randomization successful against buffer overflow attacks?
A. Return address keeps changing
B. Stack no longer exists
C. Return address is wrapped
D. Stack pointer moves
→ Answer: A
Q167. What type of application has impacted Ring 0?
A. Root access
B. Malware
C. Rootkit
D. Trojan virus
→ Answer: C
Q168. Malware installed at the kernel is very difficult to detect with products such as antivirus and anti-malware programs. What is this type of malware called?
A. Ransomware
B. Rootkit
C. Vampire tap
D. Worm
→ Answer: B
Q169. What type of malware can be used to provide backdoor access to a system?
A. Trojan
B. Rootkit
C. Root virus
D. Spyware
→ Answer: B
Q170. Which of the following tools allows you to capture passwords from the system Registry as well as from memory of a compromised system?
A. Nmap
B. LSASS
C. CryptCat
D. Mimikatz
→ Answer: D
Q171. You’ve just compromised a system using Metasploit. What module would you now load to collect passwords from memory?
A. dumphash
B. autoroute
C. mimikatz
D. siddump
→ Answer: C
Q172. What operating-system-agnostic feature of Metasploit would you use to perform tasks on a compromised system, including getting keystrokes?
A. Meterpreter
B. Metainterpreter
C. Spelunker
D. Mimikatz
→ Answer: A
Q173. If you’ve compromised a system that has multiple network interfaces, what technique could you use to gain access to the other networks using the compromised system?
A. Kerberoasting
B. Trampolining
C. Privilege escalation
D. Pivoting
→ Answer: D
Q174. What is it called when you use a victim system as a router to get to other networks behind the compromised system?
A. Piggybacking
B. Social engineering
C. Pivoting
D. Auto-networking
→ Answer: C
Q175. A new user in a company is given a minimal set of privileges. As they are promoted and move to different positions, they continue to gain more privileges. What is this called?
A. Privilege creep
B. Position creep
C. Access creep
D. Privilege escalation
→ Answer: A
Q176. Which of the following is part of the overall portion of the SID?
A. UID
B. RID
C. USD
D. L5R
→ Answer: B
Q177. The guest account under a Windows system has the RID of what?
A. Not a RID, but a SID of 502
B. RID 501
C. RID 1001
D. RID 1000
→ Answer: B
Q178. Which is the initial value of the SID that is used to annotate an administrator’s account?
A. 500
B. 100
C. 5000
D. 1
→ Answer: A
Module 7: Malware Threats
————————-
Q179. Which type of malware is likely the most impactful?
A. Worm
B. Dropper
C. Ransomware
D. Virus
→ Answer: C
Q180. As an attacker, you successfully exploited your target using a service that should have been disabled. The service had vulnerabilities that you were able to exploit with ease. There appeared to be a large cache of readily accessible information. What may be the issue here?
A. The administrator did not apply the correct patches.
B. The web server was improperly configured.
C. You are dealing with a honeypot.
D. The firewall was not configured correctly.
→ Answer: C
Q181. An application that is designed to look like a known legitimate application but is actually malicious in nature is considered what type of malware?
A. Spyware
B. Rootkit
C. Adware
D. Trojan
→ Answer: D
Q182. A user reports that they have downloaded a music file from the Internet. They inform you that when they opened the file, it seemed as though it installed an application, and then the user was prompted to send a payment of $500 to a PayPal account to get the key to decrypt their hard drive. The user no longer has access to their desktop. What could be the issue?
A. The user is experiencing a hoax.
B. The user downloaded and installed ransomware.
C. The user installed malware.
D. The user downloaded the wrong music file.
→ Answer: B
Q183. What technique would a malware author use to try to make it past an anti-malware solution?
A. Disassembly
B. Obfuscation
C. Reverse engineering
D. Dropper
→ Answer: B
Q184. Which of the following is an application that does not need a host or human interaction to disrupt and corrupt data?
A. Worm
B. Virus
C. Trojan
D. Malware
→ Answer: A
Q185. What type of virus can change or rewrite itself every time it infects a new file?
A. Polymorphic virus
B. Metamorphic virus
C. Trojan virus
D. Shell virus
→ Answer: B
Q186. Which of the following malware achieved a historical first by causing physical damage to a nuclear reactor facility?
A. Stuxnet
B. Blue’s Revenge
C. ILOVEYOU virus
D. BackOrifice
→ Answer: A
Q187. Due to the ILOVEYOU virus, Microsoft implemented a new business practice in its software to prevent such attacks from occurring again. What was it?
A. Disabling the macro features in Microsoft Office by default
B. Disabling the CD-ROM autorun feature
C. Setting user profiles to disabled
D. Removing HEKY_LOCAL_MACHINE\USER
→ Answer: A
Q188. Microsoft Office and other office suite applications have a feature that should be turned off to prevent malware from executing or spreading. What feature should be disabled?
A. Mail
B. FTP client
C. Auto-update feature
D. Macro feature
→ Answer: D
Q189. Apache OpenOffice and Microsoft Office have a built-in feature that allows the user to automate a series of specified commands. These commands usually assist with daily routine tasks. This feature can be used in conjunction with launching malware. What feature is this?
A. File sharing services
B. Object Link
C. Macro
D. Compression
→ Answer: C
Q190. Software that creates pop-up advertisement messages while visiting websites is known as what?
A. Adware
B. Malware
C. Pop-up blocker
D. Freeware
→ Answer: A
Q191. Which of the following is a good practice that includes the ability to isolate systems and detect attacks and may also include preventive measures?
A. Defense in depth
B. Security measure
C. Baseline configuration
D. Defensible network architecture
→ Answer: D
Q192. Which of these technologies would you use to remove malware in the network before it got to the endpoint?
A. Antivirus
B. Endpoint detection and response
C. Stateful firewall
D. Unified threat management device
→ Answer: D
Q193. What tool could you safely use to perform dynamic analysis on a malware sample?
A. strings
B. Cuckoo Sandbox
C. Ollydbg
D. Cutter
→ Answer: B
Q194. Which type of software is considered a framework, a set of preinstalled tools, that aids in compromising and exploiting targeted systems?
A. Cain & Abel
B. Metasploit
C. Mutavault
D. Ettercap
→ Answer: B
Q195. What tool could you use to easily create an executable that could be deployed on a system to connect back to a command and control system?
A. msfvenom
B. hping3
C. ven0m0us
D. OpenVAS
→ Answer: A
Q196. A system is compromised and is able to spawn a connection back to the adversary. What do you call the system or infrastructure the adversary is using to connect back to?
A. Command and control
B. Command processor
C. Shellcode manager
D. Command manager
→ Answer: A
Q197. Which of the following tools uses Metasploit to launch attacks like phishing campaigns?
A. Setoolkit
B. Ettercap
C. Mimikatz
D. Netcat
→ Answer: A
Module 8: Sniffing
——————
Q198. Why would an attacker want to avoid tapping into a fiber-optic line?
A. It costs a lot of money to tap into a fiber line.
B. If done wrong, it could cause the entire connection signal to drop, therefore bringing unwanted attention from the targeted organization.
C. The network traffic would slow down significantly.
D. Tapping the line could alert an IPS/IDS.
→ Answer: B
Q199. Which packet sniffing tool allows you to specify the individual fields you want printed in the output?
A. Nmap
B. tshark
C. tcpdump
D. Snoop
→ Answer: B
Q200. What is the result of conducting a MAC flood on a switch?
A. The switch would fail to respond.
B. It would create a DoS.
C. The switch would operate as if it were a hub.
D. The switch would continue to operate as normal.
→ Answer: C
Q201. Which of the following is the correct way to search for a specific IP address in Wireshark using a display filter?
A. ip.addr= 192.168.1.100
B. ip== 192.168.1.100
C. ip= 192.168.1.199
D. ip.addr== 192.168.1.100
→ Answer: D
Q202. To sniff, what mode must your network adapter be configured to in order to pull frames off an Ethernet or wireless network that aren’t addressed to you?
A. Active
B. Promiscuous
C. Stealth
D. CSMA/CD mode
→ Answer: B
Q203. To capture all traffic to/from a specific workstation on a Cisco switch, which port configuration should you implement?
A. SPAN port
B. SPAM port
C. Trunk port
D. STP port
→ Answer: A
Q204. What is a content-addressable memory table?
A. A table of IP addresses
B. A table used to view NetBIOS names
C. A table of MAC addresses associated with ports
D. A list of domain names tied to IP addresses
→ Answer: C
Q205. When a layer 2 switch is flooded, what mode does it default to?
A. Fail open mode, where it mimics a hub.
B. Fail closed, where nothing is passed anymore.
C. Layer 2 switches process IP packets and not datagrams.
D. Layer 2 switches cannot be flooded because they are collision domains.
→ Answer: A
Q206. What mode on a network interface is necessary to capture traffic?
A. Promiscuous mode
B. Monitor mode
C. Capture mode
D. Interface mode
→ Answer: A
Q207. What do you need to enable on a network interface that allows you to see the radio headers in the communication?
A. Promiscuous mode
B. Radio mode
C. Monitor mode
D. Capture mode
→ Answer: C
Q208. To sniff wireless traffic at layer 2, what must you have set on your wireless adapter?
A. Transport mode
B. Promiscuous mode
C. Transparency mode
D. Monitor mode
→ Answer: D
Q209. What must a user have in order to sniff the full stack of wireless traffic?
A. Wireless device set to promiscuous mode
B. Wireless device that has 2.4 GHz and 5 GHz set to read only
C. Wireless device set to monitor mode
D. Ettercap set to clone
→ Answer: C
Q210. Which of the following applications is used to inspect packets?
A. Wireshark
B. Cain & Abel
C. Aircrack
D. Nmap
→ Answer: A
Q211. Which of the following tools allows some users to monitor all network activity?
A. Nmap
B. Metasploit
C. Wireshark
D. Netcraft
→ Answer: C
Q212. What tool could you use to assist in capturing radio headers on wireless networks?
A. Nmap
B. Ettercap
C. Airmon-ng
D. Ophcrack
→ Answer: C
Q213. Which of the following tools can be used to steal cookies between a client and a server to use in a replay attack?
A. Mouse
B. Ferret
C. Ratpack
D. Nezumi
→ Answer: B
Q214. What would you use the program packETH for?
A. Packet crafting
B. Ethernet testing
C. Man-in-the-middle attack
D. IP analysis
→ Answer: A
Q215. What utility will display active network connections on a host?
A. Netcat
B. netstat
C. Nmap
D. Ns
→ Answer: B
Q216. Which of the following allows the adversary to obtain password information over the network in a passive manner?
A. Sniffing
B. Man in the middle
C. Password cracking
D. Account creation
→ Answer: A
Q217. Which of the following is an application that provides ARP spoofing?
A. Cain & Abel
B. Evercrack
C. Kismet
D. John the Ripper
→ Answer: A
Q218. What technique might you use if you had access to a local (physical) network but the network used switches and you wanted to see all the traffic?
A. DNS poisoning
B. Phishing
C. ARP spoofing
D. Packet fragmentation
→ Answer: C
Q219. How does ARP spoofing work?
A. Sending gratuitous ARP requests
B. Sending gratuitous ARP responses
C. Filling up the ARP cache
D. Flooding a switch
→ Answer: B
Q220. What tool can be used to spoof a MAC address?
A. MAC and Cheese
B. Cheesy MAC
C. GodSMAC
D. arpspoof
→ Answer: D
Q221. What is the process called when you’re trying to inject bogus entries into the ARP table?
A. Enumeration
B. RARP
C. ARP poisoning
D. L2 dumping
→ Answer: C
Q222. If you were to ARP poison the default gateway, what would be the expected results?
A. You will receive traffic on that specific virtual local area network.
B. You will receive all the traffic on the current network associated with the gateway.
C. You will not receive any traffic.
D. You may cause a DoS on the network.
→ Answer: B
Module 9: Social Engineering
—————————-
Q223. You are the senior manager in the IT department for your company. What is the most cost-effective way to prevent social engineering attacks?
A. Install HIDS.
B. Ensure that all patches are up-to-date.
C. Monitor and control all email activity.
D. Implement security awareness training.
→ Answer: D
Q224. You are a passenger in an airport terminal. You glance across the terminal and notice a man peering over the shoulder of a young woman as she uses her tablet. What do you think he is doing?
A. Wardriving
B. Shoulder surfing
C. War shouldering
D. Shoulder jacking
→ Answer: B
Q225. What type of social engineering attack uses SMS (text) messages to communicate with the victim?
A. Smishing
B. Vishing
C. Phishing
D. Kishing
→ Answer: A
Q226. An email contains a link with the subject line “Congratulations on your cruise!” and is sent to the finance person at a company. The email instructs the reader to click a hyperlink to claim the cruise. When the link is clicked, the reader is presented with a series of questions within an online form, such as name, Social Security number, and date of birth. What type of attack would this be considered?
A. Email phishing
B. Spear phishing
C. Social engineering
D. Identity theft
→ Answer: B
Q227. During an annual security training course you are facilitating, you place a call to another employee picked randomly who is not part of the training class. In this call, you state that you work in the help desk department and request their password in order to reset an account you noticed is locked. What risk are you demonstrating?
A. Social engineering
B. Weak passwords
C. Malware being installed by workers
D. Spam emails circulating the office
→ Answer: A
Q228. You call into the city manager’s office claiming to be a part of the help desk team. You ask the clerk for her username and password to install the latest Microsoft Office suite. What type of attack are you conducting?
A. Social engineering
B. Piggybacking
C. Masquerading
D. Tailgating
→ Answer: A
Q229. An attacker is dressed as a postal worker. Holding some large boxes, he follows a group of workers to make his drop-off in the back of the facility. What is the attacker trying to conduct?
A. Phishing
B. Sliding
C. Piggybacking
D. Shimming
→ Answer: C
Q230. As a black hat, you forge an identification badge and dress in clothes associated with a maintenance worker. You attempt to follow other maintenance personnel as they enter the power grid facility. What are you attempting to do?
A. Piggybacking
B. Social engineering
C. Tailgating
D. Impersonating
→ Answer: C
Q231. What is the act of looking over the shoulder of a victim to capture the information being displayed on their machine?
A. Piggybacking
B. Impersonation
C. Shoulder surfing
D. Shoulder peering
→ Answer: C
Q232. Which option describes the act of rummaging through trash to find important data?
A. Dumpster swimming
B. Social engineering
C. Dumpster collection
D. Dumpster diving
→ Answer: D
Q233. Which of the following activities describes the act of a person rummaging through a trash container looking for sensitive information?
A. Trash jumping
B. Dumpster party
C. Trash diving
D. Dumpster diving
→ Answer: D
Q234. What is an advantage of a phone call over a phishing email?
A. You are able to go into more detail with pretexting using a conversation.
B. Phishing attacks are rarely successful.
C. Not everyone has email, but everyone has a phone.
D. Pretexting requires the use of a phone.
→ Answer: A
Q235. Why might you use a phone call for a social engineering attack over a phishing message?
A. Phishing attacks don’t guarantee success.
B. Pretexting only works over the phone.
C. Pretexting is more detailed on the phone.
D. More people have phones than email.
→ Answer: D
Q236. What type of attack might you use if you want to collect credentials by calling a user?
A. Spam
B. Social engineering
C. Whaling
D. Manipulation
→ Answer: B
Q237. As part of an assessment on an organization you working for, you decide to conduct a social engineering attack to gather credentials that you will use later. What type of attack would be the most efficient if you wanted to get credentials from an administrator?
A. Man-in-the-middle
B. Pharming
C. Spear phishing
D. Phishing
→ Answer: C
Q238. You are a system administrator for a law firm. You are informed that a few users are indicating that they are receiving email messages from the help desk asking for their username and password to confirm ticket creation. They indicate they have not opened any tickets with the help desk. What is likely going on?
A. Smishing
B. Phishing
C. Vishing
D. Fishing
→ Answer: B
Q239. A city clerk received an email providing details about transferring money to a supplier. The email provides a URL asking for credentials for city bank accounts so payments can be made to the supplier. The email address does not match the one used by the supplier. What may be the issue here?
A. Spear phishing
B. Theft
C. Whaling
D. Tradecraft
→ Answer: A
Q240. You receive a text message providing a link to a website with a message indicating you have vulnerabilities in your phone that need to be checked. What sort of an attack is this likely to be?
A. Spear phishing
B. Vishing
C. Smishing
D. Whaling
→ Answer: C
Q241. What method is used to send a malicious URL using a text message?
A. Smishing
B. Vishing
C. Phishing
D. Whaling
→ Answer: A
Q242. Which of the following tools could you use to fully automate a social engineering attack, like sending out a phishing campaign?
A. Nmap
B. Metasploit
C. Setoolkit
D. Aircrack
→ Answer: C
Q243. Which of the following best describes steganography?
A. A symmetric encryption algorithm
B. Allowing the public to use your private key
C. Hiding information within a picture or concealing it in an audio format
D. Encrypting data using transposition and substitution
→ Answer: C
Module 10: Denial-of-Service
—————————-
Q244. What year did the Ping of Death first appear?
A. 1992
B. 1989
C. 1990
D. 1996
→ Answer: D
Q245. Which is the best example of a denial-of-service (DoS) attack?
A. A victim’s computer is infected with a virus.
B. A misconfigured switch is in a switching loop.
C. An adversary is forging a certificate.
D. An adversary is consuming all available memory of a target system by opening as many “half-open” connections on a web server as possible.
→ Answer: D
Q246. Which type of packet does a Fraggle attack use to create a DoS attack?
A. TCP
B. IP
C. ICMP
D. UDP
→ Answer: D
Q247. Which of the following denial-of-service attacks would be most likely to be successful today?
A. Fraggle
B. Smurf
C. Slowloris
D. None of the above
→ Answer: C
Q248. What is a network of zombie computers used to execute a DDoS on a target system called?
A. Botnet
B. Whaling
C. Social engineering
D. DoS
→ Answer: A
Q249. You are a security administrator working at a movie production company. One of your daily duties is to check the IDS logs when you are alerted. You notice that you received a lot of incomplete three-way handshakes, your memory performance has been dropping significantly on your web server, and customers are complaining of really slow connections. What could be the actual issue?
A. DoS
B. DDoS
C. Smurf attack
D. SYN flood
→ Answer: D
Q250. You are an administrator overseeing IT security operations for a local bank. As you review logs from the prior day, you notice a very high rate of UDP packets targeting your web server that are coming from your clients all at the same time. What could be the culprit?
A. Smurf attack
B. DDoS
C. SYN flood attack
D. Fraggle attack
→ Answer: D
Q251. Which of the following attacks sends fragmented UDP packets to a Windows system using port 53 or other UDP ports that may cause the system to crash?
A. Fraggle
B. Bonk
C. Smash the stack
D. Smurf
→ Answer: B
Q252. Which of the following attacks uses UDP packets to target the broadcast address and cause a DDoS?
A. Smurf
B. Fraggle
C. Land
D. Teardrop
→ Answer: B
Q253. What type of attack is a Fraggle attack?
A. XML entity
B. False error
C. Fragmentation
D. Amplification
→ Answer: D
Q254. Which tool causes sockets to be used up and can cause services to freeze or crash?
A. Nmap
B. Slowloris
C. Cain & Abel
D. John the Ripper
→ Answer: B
Q255. Which of the following tools can be used to DDoS a target system?
A. LOIC
B. SIMM
C. Cain & Abel
D. AOL Punter
→ Answer: A
Q256. As a black hat, you are targeting a server room that contains important data. Which unconventional method would you use to DoS the entire room?
A. Target the routers by DDoS.
B. Conduct a Fraggle attack on the servers.
C. Target the HVAC units.
D. Change all the administrator login information.
→ Answer: C
Q257. A method that defends against a flooding attack and massive DoS attacks is referred to as what?
A. Defense in depth
B. Spam blocker
C. Flood safe
D. Flood guard
→ Answer: D
Q258. Which type of network uses a group of zombie computers to carry out the commands of the bot master?
A. Zombie net
B. Zombie group
C. Botnet
D. Bot heard
→ Answer: C
Module 11: Session Hijacking
—————————-
Q259. What is the purpose of a man-in-the-middle attack?
A. Gaining access
B. Maintaining access
C. Hijacking a session
D. Covering tracks
→ Answer: C
Q260. What is the primary objective of a Man-in-the-Middle (MitM) attack?
A. To crash the server
B. To intercept and potentially alter communication between two parties
C. To physically steal the hardware
D. To delete database records
→ Answer: B
Q261. Which of the following must be conducted first in order to hijack a session?
A. Track the session.
B. Desynchronize the session.
C. Inject the adversary’s packet into the stream.
D. Disrupt the stream first and then inject the adversary’s packet information.
→ Answer: A
Q262. Which flag is used to forcibly terminate a partially open TCP connection?
A. FIN
B. RST
C. ACK
D. SYN
→ Answer: B
Q263. What is the process of falsifying data, such as changing a source IP address?
A. Phishing
B. Spoofing
C. Sniffing
D. Scanning
→ Answer: B
Q264. The act of falsifying data is also known as what?
A. Boink
B. Packet crafting
C. Spoofing
D. Data diddling
→ Answer: C
Q265. Which of the following allows the adversary to jump from the web directory to another part of the file system?
A. Directory traversal
B. Pivoting
C. Directory hopping
D. Directory shifting
→ Answer: A
Q266. In the TCP three-way handshake, which is next after the initial SYN packet is sent?
A. An ACK is received.
B. A SYN is received.
C. A SYN/ACK is sent.
D. An ACK is sent.
→ Answer: C
Q267. What completes the three-way handshake in the TCP connection?
A. RST
B. SYN/ACK
C. ACK
D. FIN
→ Answer: C
Q268. Which is the last step in the TCP three-way handshake?
A. ACK
B. SYN
C. SYN/ACK
D. FIN
→ Answer: A
Q269. What steps does the TCP handshake follow as described by the flags that are set?
A. FIN, ACK, FIN
B. SYN, SYN, ACK
C. SYN, ACK, FIN
D. SYN, SYN/ACK, ACK
→ Answer: D
Q270. What flag is used to order a connection to terminate?
A. SYN
B. FIN
C. PSH
D. RST
→ Answer: B
Q271. Which flag is used to terminate a connection that is only partially open?
A. FIN
B. RST
C. URG
D. SYN
→ Answer: B
Q272. What UDP flag forces a connection to terminate at both ends of the circuit?
A. RST
B. FIN
C. None
D. URG and RST
→ Answer: C
Q273. Which flags would create a half-open connection if they are not responded to?
A. FIN
B. SYN
C. SYN/ACK
D. URG
→ Answer: B
Q274. Which of the following has no flags set and does not respond if a port is open?
A. XMAS scan
B. NULL scan
C. Half-open connection
D. ACK scan
→ Answer: B
Module 12: Evading IDS, Firewalls, and Honeypots
————————————————
Q275. What is the difference between a traditional firewall and an IPS?
A. Firewalls don’t generate logs.
B. An IPS cannot drop packets.
C. An IPS does not follow rules.
D. An IPS can inspect and drop packets.
→ Answer: D
Q276. You are the security administration for your local city. You just installed a new IPS. Other than plugging it in and applying some basic IPS rules, no other configuration has been made. You come in the next morning, and you discover that there was so much activity generated by the IPS in the logs that it is too time-consuming to view. What most likely caused the huge influx of logs from the IPS?
A. The clipping level was established.
B. A developer had local admin rights.
C. The LAN experienced a switching loop.
D. The new rules were poorly designed.
→ Answer: D
Q277. Why would the adversary encode their payload before sending it to the target victim?
A. Encoding the payload will not provide any additional benefit.
B. By encoding the payload, the adversary actually encrypts the payload.
C. The encoded payload can bypass the firewall because there is no port associated with the payload.
D. Encoding the payload may bypass IPS/IDS detection because it changes the signature.
→ Answer: D
Q278. Of the following methods, which one acts as a middleman between an external network and the private network by initiating and establishing the connection?
A. Proxy server
B. Firewall
C. Router
D. Switch
→ Answer: A
Q279. Which type of firewall would you use if you wanted to have the firewall check for malware as it passed through the firewall?
A. Web application firewall
B. Stateful firewall
C. Next-generation firewall
D. Stateless firewall
→ Answer: C
Q280. Which type of firewall would operate at layer 7 of the OSI model?
A. Stateful firewall
B. Deep packet inspection firewall
C. Web application firewall
D. Access control list
→ Answer: C
Q281. A stateful firewall device operates at what layer of the OSI model?
A. Layer 2
B. Layer 4
C. Layer 7
D. Layer 3
→ Answer: B
Q282. What type of control is a firewall?
A. Barrier
B. Administrator
C. Logical
D. Physical
→ Answer: C
Q283. A firewall that blocks all traffic by default is known as what?
A. Implicit allow
B. Implicit deny
C. Deny all
D. Implicit prevent all
→ Answer: B
Q284. What is the default security posture of a secure firewall?
A. Implicit Allow
B. Implicit Deny
C. Allow All
D. Log Only
→ Answer: B
Q285. For an anomaly-based IPS to function correctly, what must be established first?
A. Signature Database
B. Network Baseline
C. User Profiles
D. Patch Levels
→ Answer: B
Q286. For an anomaly-based IPS to run optimally, what first must be determined?
A. Updated signatures
B. Accurate rules set
C. Updated firmware
D. Network baseline set
→ Answer: D
Q287. Which character is used in Snort rules to indicate “NOT”?
A. #
B. !
C. $
D. &
→ Answer: B
Q288. What is a unique identifier that is used in Snort?
A. SID
B. ID
C. PID
D. NID
→ Answer: A
Q289. Which rule type allows for logs and alerts in Snort?
A. Drop
B. Pass
C. Alert
D. Block
→ Answer: C
Q290. Using Snort, which rule type allows for notification only if there is a match?
A. Drop
B. Alert
C. Pass
D. Block
→ Answer: B
Q291. In Snort, which part of the rule dictates the source, destination, rule type, and direction?
A. Rule body
B. Rule action
C. Rule header
D. Rule connection
→ Answer: C
Q292. What is one concern for using a SYN scan, even if you are going low and slow?
A. Half-open connections.
B. It’s inaccurate.
C. You are performing a full connect.
D. Firewalls block all SYN messages.
→ Answer: A
Q293. As an attacker, you are trying to prevent an IDS from alerting your presence to the network administrators. You determine that the rules that are set in place by the firewall are pretty effective and you dare not risk any more attempts to get past the security appliances. What is one method that may defeat the security policies set in place by the IDS and other security appliances?
A. Firewalking
B. Conducting a reverse shell exploit
C. Session splicing
D. Using HTTP
→ Answer: C
Q294. What technique might you be able to use to get around older intrusion detection systems when sending traffic into a network?
A. Fragmentation
B. ARP spoofing
C. DNS hijacking
D. Phishing
→ Answer: A
Q295. Which technique helps evade older IDS systems by breaking packets into smaller pieces?
A. Phishing
B. Fragmentation
C. DNS Hijacking
D. ARP Spoofing
→ Answer: B
Q296. Which of the following has the best chance of alerting on previously unknown attacks on a network?
A. Signature-based IDS
B. Packet-based IDS
C. Behavior-based IDS
D. Rule-based IDS
→ Answer: C
Q297. A traditional HIDS uses which method for detection?
A. Signature base
B. Anomaly base
C. Firewall rules
D. Statistically anomaly
→ Answer: A
Q298. What must a signature-based IDS have in order to be effective?
A. An up-to-date set of rules
B. A baseline
C. Active rules
D. Access to update user profiles
→ Answer: A
Q299. What would you use an intrusion detection system for?
A. Blocking traffic
B. Filtering traffic based on header information
C. Generating alerts on traffic
D. Logging system messages
→ Answer: C
Q300. What are the two types of intrusion detection systems?
A. NIDS and SIDS
B. HIDS and SIDS
C. IDS and IPS
D. HIDS and NIDS
→ Answer: D
Module 13: Hacking Web Servers
——————————
Q301. What tool would you use to conduct banner grabbing?
A. aescrypt
B. Ettercap
C. netstat
D. Telnet
→ Answer: D
Q302. Which of the following can you use to conduct banner grabbing?
A. Telnet
B. Ping
C. nmap -sP
D. del*.*
→ Answer: A
Q303. As part of hardening a server, which of the following would the administrator want to configure prior to putting it into the DMZ?
A. Disable unnecessary ports
B. Open all ports
C. Disable all accounts
D. Reduce file restrictions
→ Answer: A
Q304. What tool could you use if you wanted to identify directories that did not show up in the spider of a website?
A. Wireshark
B. DIRB
C. Kismet
D. Setoolkit
→ Answer: B
Q305. You are trying to black box test a web application, but it’s being resistant to attack because of an authentication page at the top. What tool would you not use to find some direct access pages?
A. Metasploit
B. hping3
C. dirb
D. Burp Suite
→ Answer: B
Module 14: Hacking Web Applications
———————————–
Q306. What method of exploitation might allow the adversary to pass arbitrary SQL queries within the URL?
A. SQL injection
B. XSS
C. Spear phishing
D. Ruby on Rails injection method
→ Answer: A
Q307. Which input value would you utilize in order to evaluate and test for SQL injection vulnerabilities?
A. SQL test
B. admin and password
C. || or |!
D. 1=1′
→ Answer: D
Q308. Which method would be targeting the client in a web-based communication?
A. Cross-site scripting (XSS)
B. SQL injection
C. XML external entity
D. Command injection
→ Answer: A
Q309. What type of attack is being used if you were to see <!ENTITY xxe SYSTEM “file:///etc/passwd”> in your web server logs?
A. SQL injection
B. XSS
C. Command injection
D. XXE
→ Answer: D
Q310. Which option describes a server-side attack targeting web applications?
A. SQL injection
B. Cross-site malware injection
C. Cross-site scripting
D. SQL site scripting
→ Answer: A
Q311. Which of these attacks targets the client in a web application?
A. XML external entity
B. Cross-site scripting
C. SQL injection
D. Command injection
→ Answer: B
Q312. What type of attack is being used if you were to see <!ENTITY xxe SYSTEM in your logs?
A. XML entity injection
B. Cross-site scripting
C. Command injection
D. Cross-site request forgery
→ Answer: A
Q313. Which of the following would you not be able to access using an XML external entity injection attack?
A. Internal web page
B. File on the target system
C. User cookie from the browser
D. Network configuration
→ Answer: C
Q314. Which of the following allows the adversary to jump from the web directory to another part of the file system?
A. Directory traversal
B. Pivoting
C. Directory hopping
D. Directory shifting
→ Answer: A
Q315. This fragment is found in web server logs. What kind of attack is likely to be happening? && cat /etc/shadow
A. SQL injection
B. XML external entity
C. Cross-site request forgery
D. Command injection
→ Answer: D
Q316. As a black hat, you are sending inputs to a web application to be sent to the LDAP server. What are you trying to conduct?
A. SQL injection
B. X.25 injection
C. LDAP injection
D. LDAP fuzzing
→ Answer: C
Q317. What would you use to inspect HTTP messages to determine whether there was attack traffic in the message so a decision could be made about whether to allow the traffic or not?
A. Stateful firewall
B. Anti-malware
C. Load balancer
D. Web application firewall
→ Answer: D
Q318. As a security administrator, your web application firewall logs show the following. What do you think is going on? 10; DROP TABLE users–
A. CSRF
B. SQLI
C. XSS
D. XXE
→ Answer: B
Module 15: SQL Injection
————————
Q319. In SQL, which of the following allows an individual to update a table?
A. DROP
B. ADD
C. COPY
D. UPDATE
→ Answer: D
Q320. In SQL, what input value or term means everything?
A. *
B. ALL
C. SELECT
D. FROM
→ Answer: A
Q321. Which of the following deletes the Clients table within an SQL database?
A. UPDATE TABLE Clients
B. SELECT * FROM Clients
C. INSERT TABLE Clients
D. DROP TABLE Clients
→ Answer: D
Module 16: Hacking Wireless Networks
————————————
Q322. Your security team notifies you that they are seeing the same SSID being advertised in your vicinity, but the BSSID is different from ones they are aware of. What type of attack is this?
A. Deauthentication attack
B. Wardriving
C. MAC spoofing
D. Evil twin
→ Answer: D
Q323. Which encryption standard is used in WEP?
A. AES
B. RC5
C. MD5
D. RC4
→ Answer: D
Q324. What type of authentication is used in WPA2 to ensure the validity of both the client and the access point?
A. Two-way handshake
B. Three-way handshake
C. Four-way handshake
D. Five-way handshake
→ Answer: C
Q325. What is the value of using the four-way handshake in WPA2?
A. Encrypts traffic
B. Prevents replay attacks
C. Ensures multifactor authentication is in use
D. Performs host checking
→ Answer: B
Q326. What are the two types of wireless network?
A. Passive, active
B. Point-to-point, multicast
C. Infrastructure, active
D. Ad hoc, infrastructure
→ Answer: D
Q327. Which authentication protocol is used in WPA2?
A. CCMP
B. 3DES
C. AES
D. LEAP
→ Answer: A
Q328. During the course of testing, you identify a WAP that you are going to exploit. You discover that the WAP is using WEP. Which method will you utilize in order to exploit the WAP?
A. The encryption algorithm, which is RC4
B. The initialization vector (IV)
C. The password
D. The username and password
→ Answer: B
Q329. Which of the following is associated with security access in a wireless network?
A. WPA
B. 802.1X
C. Radius
D. TACACS+
→ Answer: B
Module 17: Hacking Mobile Platforms
———————————–
Q330. What might be a quick and easy way to attempt to compromise a mobile device?
A. SQL injection
B. Buffer overflow
C. Remote screen lock
D. Smishing
→ Answer: D
Module 18: IoT Hacking
———————-
Q331. What common protocol may be used to communicate with IoT devices on home or business networks?
A. SNMP
B. ICMP
C. SMTP
D. HTTP
→ Answer: D
Module 19: Cloud Computing
————————–
Q332. What cloud service would you be most likely to use if you wanted to share documents with another person?
A. Software as a Service
B. Platform as a Service
C. Storage as a Service
D. Infrastructure as a Service
→ Answer: C
Q333. If a web application is using a RESTful API, NoSQL databases, and microservices in containers, what style of design is it likely using?
A. Model-view-controller
B. Cloud-native design
C. Traditional architecture
D. NoSQL design
→ Answer: B
Q334. When considering the risks of local storage vs. third-party cloud storage, which statement is most accurate?
A. Cloud storage is more secure because the commercial vendor has trained security professionals.
B. When storage is local, you are responsible and accountable for the storage services.
C. You can sue the cloud provider for damages.
D. The cloud has more layers of security than traditional local storage infrastructures.
→ Answer: B
Q335. What do we call the model used to determine who has to handle patching of systems at a cloud services provider?
A. Shared responsibility
B. Bell-LaPadula
C. Carnegie Mellon Maturity
D. Ford model
→ Answer: A
Q336. If your organization is using Google’s GSuite for email and document editing, what type of cloud service are you making use of?
A. Software as a Service
B. Storage as a Service
C. Infrastructure as a Service
D. Platform as a Service
→ Answer: A
Q337. Who has responsibility for the operating system in a Platform as a Service (PaaS) offering with a cloud provider?
A. Client
B. Provider
C. Both
D. Neither
→ Answer: B
Q338. Which of these would be a very common vulnerability in cloud computing deployments that could lead to exploitation?
A. Weak encryption
B. Bad programming
C. Lack of policies
D. Weak access management
→ Answer: D
Q339. Which of the following is the highest classification level used by the U.S. government?
A. Top Secret
B. Secret
C. For Your Eyes Only
D. Confidential
→ Answer: A
Q340. What is a computing platform that provides a solution, hosted with a service provider, that customers could build applications on top of?
A. Platform as a Service
B. Software as Service
C. FTP
D. Web application
→ Answer: A
Q341. What cloud offering gives the customer the most responsibility?
A. Platform as a Service
B. Software as a Service
C. Storage as a Service
D. Infrastructure as a Service
→ Answer: D
Q342. If you were moving your IT infrastructure from on-premise to a cloud service provider, what might you be most concerned about that would be different from what you have already?
A. Password complexity
B. No encryption
C. Application design complexity
D. Inability to implement security controls
→ Answer: D
Q343. Which of these would not be a reason to use automation in a cloud environment?
A. Fault tolerance
B. Repeatability
C. Consistency
D. Testability
→ Answer: A
Module 20: Cryptography
———————–
Q344. Which encryption was selected by NIST as the principal method for providing confidentiality after the DES algorithm?
A. 3DES
B. Twofish
C. RC4
D. AES
→ Answer: D
Q345. Which encryption algorithm is a symmetric stream cipher?
A. AES
B. ECC
C. RC4
D. PGP
→ Answer: C
Q346. What is the advantage of using SSH for command-line traffic?
A. SSH encrypts the traffic and credentials.
B. You cannot see what the adversary is doing.
C. Data is sent in the clear.
D. A and B.
→ Answer: A
Q347. What does a checksum indicate?
A. That the data has made it to its destination
B. That the three-way TCP/IP handshake finished
C. That there were changes to the data during transit or at rest
D. The size of the data after storage
→ Answer: C
Q348. Out of the following, which is one of RSA’s registered key strengths?
A. 1,024 bits
B. 256 bits
C. 128 bits
D. 512 bits
→ Answer: A
Q349. To provide non-repudiation for email, which algorithm would you choose to implement?
A. AES
B. DSA
C. 3DES
D. Skipjack
→ Answer: B
Q350. Which of the following best describes DNS poisoning?
A. The adversary intercepts and replaces the victim’s MAC address with their own.
B. The adversary replaces their malicious IP address with the victim’s IP address for the domain name.
C. The adversary replaces the legitimate domain name with the malicious domain name.
D. The adversary replaces the legitimate IP address that is mapped to the fully qualified domain name with the malicious IP address.
→ Answer: D
Q351. Which of the following allows the adversary to forge certificates for authentication?
A. Wireshark
B. Ettercap
C. Cain & Abel
D. Ncat
→ Answer: C
Q352. This protocol is used for authentication purposes; it sends cleartext usernames and passwords with no forms of encryption or a means of challenging. What authentication protocol is this?
A. CHAP
B. POP
C. PAP
D. MSCHAP
→ Answer: C
Q353. What would you use “something you are” for?
A. Challenge-response authentication
B. Token-based authentication
C. Single-factor authentication
D. Multifactor authentication
→ Answer: D
Q354. When two or more authentication methods are used, what is it called?
A. Multitiered authentication factor
B. Multifactor authentication
C. Multicommon factor authentication
D. Multiauthentication factor
→ Answer: B
Q355. Which of the following has no key associated with it?
A. MD5
B. AES
C. Skipjack
D. PGP
→ Answer: A
Q356. Which of the following describes the X.509 standard?
A. It defines the LDAP structure.
B. It is a symmetric encryption algorithm.
C. It uses a sandbox method for security.
D. It describes the standard for creating a digital certificate.
→ Answer: D
Q357. Which of the following best describes steganography?
A. A symmetric encryption algorithm
B. Allowing the public to use your private key
C. Hiding information within a picture or concealing it in an audio format
D. Encrypting data using transposition and substitution
→ Answer: C
Q358. What process would you use to help ensure only the right people got access to sensitive information?
A. Data classification
B. Data masking
C. Data encryption
D. Data processing
→ Answer: A
Q359. What Transport layer protocol does DHCP operate with?
A. IP
B. TCP
C. ICMP
D. UDP
→ Answer: D
Q360. Which of the following encryption algorithms uses two large prime numbers?
A. RSA
B. AES
C. El Gamal
D. RC5
→ Answer: A
Q361. What can be said about asymmetric encryption?
A. The two keys are not related mathematically.
B. The two keys are mathematically related.
C. Both keys do the same thing.
D. One key is shared between both parties.
→ Answer: B
Q362. What protection characteristics are in use with IPSec transport mode?
A. The header is encrypted.
B. Both payload and message are encrypted.
C. It provides authentication to the sender’s data.
D. It provides encryption to the payload only.
→ Answer: D
Q363. Which of the following defines the private, non-routable IP address ranges?
A. RFC 1929
B. RFC 1918
C. NIST 1918
D. RFC 1921
→ Answer: B
Q364. Which DNS record maps an IPv4 address to a hostname?
A. MX
B. A
C. AAA
D. MR
→ Answer: B
Q365. What type of attack would you use if you wanted to gather passwords using the ticket-exchange protocol commonly used on networks that use Windows servers?
A. EternalBlue
B. Smurf
C. Kerberoasting
D. Rainbow tables
→ Answer: C
====================================================================
📋 SUMMARY: Questions Per Module (Final Count)
===================================================================
Module 1: Introduction to Ethical Hacking → 30 questions
Module 2: Footprinting and Reconnaissance → 30 questions
Module 3: Scanning Networks → 40 questions
Module 4: Enumeration → 25 questions
Module 5: Vulnerability Analysis → 25 questions
Module 6: System Hacking → 30 questions
Module 7: Malware Threats → 20 questions
Module 8: Sniffing → 25 questions
Module 9: Social Engineering → 22 questions
Module 10: Denial-of-Service → 16 questions
Module 11: Session Hijacking → 17 questions
Module 12: Evading IDS, Firewalls, Honeypots → 27 questions
Module 13: Hacking Web Servers → 5 questions
Module 14: Hacking Web Applications → 14 questions
Module 15: SQL Injection → 4 questions
Module 16: Hacking Wireless Networks → 9 questions
Module 17: Hacking Mobile Platforms → 1 question
Module 18: IoT Hacking → 1 question
Module 19: Cloud Computing → 13 questions
Module 20: Cryptography → 23 questions
