Q2. Which of the below Burp tools is used for manually manipulating and reissuing individual HTTP requests, and analyzing the application’s responses.
- A. Burp Intruder
- B. Burp Repeater
- C. Burp Sequencer
- D. Burp Comparer
Correct Answer: B
Q3. Which display filter for Wireshark shows all TCP packets containing the word XYZ COrp?
- A. content== XYZ COrp
- B. tcp contains XYZ COrp
- C. display== XYZ COrp
- D. tcp.all contains == XYZ COrp
Correct Answer: B
Q4. Jack is an ethical hacker, and he is identifying the attack targets and other related information. What process is he executing?
- A. Vulnerability Assessment
- B. Enumeration
- C. Sniffing
- D. Port Scanning
Correct Answer: B
Q5. John performed a port scan on his company’s network and came to know that TCP port 123 is open. What is the default service that runs on that port?
- A. Telnet
- B. POP3
- C. Network Time Protocol
- D. DNS
Correct Answer: C
Q6. Select the three among OWASP Mobile Top 10 vulnerabilities. (Select THREE correct options)
- A. Improper Platform Usage
- B. Insufficient Cryptography
- C. Reverse Engineering
- D. Cross site scripting
Correct Answer: ABC
Q7. Which of the following DoS categories uses up all the system’s or service’s available bandwidth?
- A. Fragmentation attacks
- B. Volumetric attacks
- C. Application attacks
- D. TCP state-exhaustion attacks
Correct Answer: B
Q8. Web Application Hacking is a technique of mistreating web applications via HTTP or HTTPS for manipulating the web application through its graphical web interface. Identify from the following which is not a threat to web application.
- A. Reverse engineering
- B. DMZ protocol attack
- C. Command Injection
- D. Buffer Overflow
Correct Answer: A
Q9. A private corporation hired you as an Ethical Hacker to perform an external security assessment through penetration testing. What document specifies the nature of the testing, related violations, and protects both the organization’s interests and your liabilities as a tester?
- A. Non-Disclosure Agreement
- B. Project Scope
- C. Terms of Engagement
- D. Servive Level Agreement
Correct Answer: C
Q10. A teardrop attack is best described by which of the following?
- A. The attacker sends a packet with the identical source and destination addresses as the victim’s computer.
- B. The attacker delivers a series of overlapping, massive IP pieces.
- C. The attacker uses a faked address to transmit UDP Echo packets.
- D. To DoS targets, the attacker employs ICMP broadcast.
Correct Answer: B
Q11. During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?
- A. DynDNS
- B. DNS Scheme
- C. DNSSEC
- D. Split DNS
Correct Answer: D
Q12. Identify the points that are included in the results of a security testing. (Select THREE correct options)
- A. To analyze cost/benefit requirements for improving the system’s security
- B. To assess the status of monetary related requirements of the system
- C. To define a common mitigation for the most prioritized vulnerabilities
- D. To enhance other life cycle activities, such as risk assessments
Correct Answer: ADE
Q13. Identify some dynamic testing tools in Penetration testing. (Select TWO correct options)
- A. Burp Suite
- B. OWASP ZAP
- C. Process Monitor
- D. Wireshark
Correct Answer: AB
Q14. Which of the following is not part of THE CYBER KILL CHAIN?
- A. Weaponization
- B. Exploitation
- C. Exfiltration
- D. Threat Intelligence
Correct Answer: D
Q15. Identify the shell-based tool containing already existing exploits which can be used in the attack phase of Infra Penetration testing.
- A. Metasploit
- B. Wireshark
- C. Nessus
- D. OWASP ZAP
Correct Answer: A
Q16. Which of the below options is a NOT a type of cloud server
- A. Private cloud servers
- B. Public cloud servers
- C. Dedicated cloud servers
- D. Merged cloud servers
Correct Answer: D
Q17. Type of testing where an assessor tries to imitate real world attacks to find out paths to circumvent the security measures of an application, network or system is called __________.
- A. Black Box Testing
- B. White Box Testing
- C. Grey Box Testing
- D. Penetration Testing
Correct Answer: D
Q18. Which of the below service providers provides the least amount of built-in security
- A. IAAS
- B. PAAS
- C. SAAS
- D. None of the Above
Correct Answer: A
Q19. Which of the following describes active sniffing? (Select TWO correct options)
- A. Active sniffing is usually required when hubs are in place.
- B. Active sniffing is usually required when switches are in place.
- C. Active sniffing is harder to detect than passive sniffing.
- D. Active sniffing is easier to detect than passive sniffing.
Correct Answer: BD
Q20. Which of the below Burp tools is used for carrying out automated customized attacks against web applications. It is highly configurable and can be used to perform a wide range of tasks to make the testing faster and more effective.
- A. Burp Intruder
- B. Burp Repeater
- C. Burp Sequencer
- D. Burp Comparer
Correct Answer: A
Q21. _________________ is considered as an essential element in cloud computing by CSA.
- A. Identity and Access Management
- B. Virtualization
- C. Multi-Tenancy
- D. Router
Correct Answer: C
Q22. Which of the below Burp tools is used for performing a visual “diff” between any two items of data, such as pairs of similar HTTP messages.
- A. Burp Intruder
- B. Burp Repeater
- C. Burp Sequencer
- D. Burp Comparer
Correct Answer: D
Q23. Which of the following precautions needs to be taken before using a public exploit?
- A. Verify the source of the exploit
- B. Run the exploit directly on target
- C. Evaluate the exploit in a sandbox environment
- D. Read and understand the exploit code before execution
Correct Answer: ACD
Q24. When a given condition is met, which virus kind gets executed?
- A. Sparse Infector
- B. Multipartite
- C. Metamorphic
- D. Cavity
Correct Answer: A
Q25. ____________ is NOT part of the threat hunting loop.
- A. Creating the Hypothesis
- B. Attacking the attacker
- C. Inform and enrich analytics
- D. Uncover new patterns and TPPs
Correct Answer: B
Q26. Which of the following Wireshark filters would show all traffic coming from or going to the 192.168.15.0/24 subnet? (Select TWO correct options)
- A. ip.addr == 192.168.15.0/24
- B. ip.src == 192.168.15.0/24 and ip.dst == 192.168.15.0/24
- C. ip.src == 192.168.15.0/24 or ip.dst == 172.168.15.0/24
- D. ip.src == 192.168.15.0/24 and ip.dst == 192.168.15.0/24
Correct Answer: AC
Q27. Choose the significant capabilities required in a network vulnerability scanner.
- A. Compatibility with computers and servers of all sizes
- B. Detection of security holes in local or remote hosts
- C. Detection of missing security updates and patches
- D. All the given options are correct
Correct Answer: D
Q28. In Symmetric key cryptography if there are 10 number of users, how many numbers of secret keys are required.
- A. 10.0
- B. 45.0
- C. 108.0
- D. 1225.0
Correct Answer: B
Q29. A hacker is ‘spoofing’ Person-A. He sends a message to Person-B. To convince Person-B that the message is from Person-A, the attacker needs to ‘forge’ the signature. The only way to forge the signature is by knowing ______________
- A. Persons A’s Public key
- B. Person A’s private key
- C. Person B’s private key
- D. Person B’s Public key
Correct Answer: B
Q30. Which nmap option can be used to run a very rapid scan when you are not bothered about being detected?
- A. nmap -T0
- B. nmap -A
- C. nmap -O
- D. nmap -T5
Correct Answer: D
Q31. Senku has been scanning the network of the client on which she is performing a vulnerability assessment test. During a port search, she discovers open ports in the 139 range. What is the most likely protocol to be listening on those ports?
- A. Finger
- B. FTP
- C. Samba
- D. SMB
Correct Answer: D
Q32. Select the best practices to be followed in order to prevent ‘Insecure Communcation’ mobile vulnerability. (Select THREE correct options)
- A. Use strong, industry standard cipher suites with appropriate key lengths.
- B. Use certificates signed by a trusted CA provider.
- C. Use network layer for communcation as its secure and is not susceptible to eavesdropping.
- D. Apply SSL/TLS to transport channels that the mobile app will use to transmit sensitive information
Correct Answer: ABD
Q33. Which of the http response codes tell that the site is temporarily redirected?
- A. 410.0
- B. 402.0
- C. 302.0
- D. 310.0
Correct Answer: C
Q34. Which of the below Burp tools is used for analyzing the quality of randomness in an application’s session tokens or other important data items that are intended to be unpredictable.
- A. Burp Intruder
- B. Burp Repeater
- C. Burp Sequencer
- D. Burp Comparer
Correct Answer: C
Q35. Select the following model whose infrastructure security is managed and owned by vendor.
- A. Hybrid
- B. Public
- C. Private/Community
- D. None of the above
Correct Answer: C
Q36. Which of the following steps can be taken after gaining initial foothold?
- A. Port Scanning
- B. Privilege Escalation
- C. Covering Tracks
- D. Pivoting
Correct Answer: BCD
Q37. Where is the SAM file stored on a Windows 7 system?
- A. /etc/
- B. C:\Windows\System32\etc
- C. C:\Windows\System32\Config
- D. C:\Windows\System32\Drivers\Config
Correct Answer: C
Q38. Which of the following does not define a data transmission method that is in violation of a security policy?
- A. Backdoor Channel
- B. Session Hijacking
- C. Covert Channel
- D. Overt Channel
Correct Answer: D
Q39. Which among the below options is a compliance standard.
- A. PCI-DSS
- B. HIPPA
- C. GLBA
- D. All the above
Correct Answer: D
Q40. Which Wireshark filter can be used to check all incoming requests to an HTTP Web Server?
- A. traffic == All HTTP
- B. tcp.dstport==80
- C. udp.destination is HTTP
- D. http.request==All
Correct Answer: B
Q41. You are a test engineer. You are asked to perform source code testing and analyze data flow, coding practices, exception and error handling within the system. Which testing will you employ to meet the objective?
- A. Black Box Testing
- B. White Box Testing
- C. Grey Box Testing
- D. a and b
Correct Answer: B
Q42. Which of the following works at Layer 5 of the OSI model?
- A. Stateful firewall
- B. Packet-filtering firewall
- C. Circuit-level firewall
- D. Application-level firewall
Correct Answer: C
Q43. Who is the issuer of public key infrastructure certificates.
- A. Certificate Authority
- B. Script Kiddie
- C. Resource Access Control Facility
- D. None of the above
Correct Answer: A
Q44. Web servers make files and web pages available through the internet. Different web server attacks exploit misconfigurations and bugs to compromise the server. Which of the following is not an appropriate method to deface a web server?
- A. IP address spoofing
- B. FTP server intrusion
- C. Fetching credentials through MiTM
- D. DNS attack through cache poisoning
Correct Answer: A
Q45. Which of the following lists are valid data-gathering activities associated with a risk assessment?
- A. Threat identification, vulnerability identification, control analysis
- B. Threat identification, response identification, mitigation identification
- C. Attack profile, defense profile, loss profile
- D. System profile, vulnerability identification, security determination
Correct Answer: A
Q46. Select the most used cryptography method by today’s internet business and users.
- A. Encrypting File System
- B. Single Sign On
- C. Public Key Infrastructure
- D. Output feedback
Correct Answer: C
Q47. What is a hacker technique that uses a search engine to reveal misconfigurations or security vulnerabilities in websites available publicly?
- A. Active Reconnaissance
- B. Passive Reconnaissance
- C. Google Hacking
- D. WHOIS Lookup
Correct Answer: C
Q48. Choose the points to be considered during report preparation for penetration testing. (Select THREE correct options)
- A. Details of each step need not to be considered
- B. Details of fixing and cleaning the systems
- C. Information regarding the most prioritized vulnerabilities and risks
- D. Penetration testing overall summary
Correct Answer: BDE
Q49. Which of the below options is not considered as a best practice to ensure IoT devices are physically secure?
- A. Put in tamper resistant case
- B. Camouflage the device
- C. Disable the device when tampered with
- D. Deploy only authenticated devices
Correct Answer: B
Q50. Select the standard for inter-operable cloud based key management.
- A. PMIK
- B. AIMK
- C. KMIP
- D. AIMC
Correct Answer: C
Q51. Threat agent with physical access to data that has been encrypted improperly, or mobile malware acting on an adversary’s behalf is responsible for which of the following OWASP Mobile Vulnerability?
- A. Insecure Authorization
- B. Poor Code Quality
- C. Insufficient Cryptography
- D. Cross site scripting
Correct Answer: C
Q52. Select the CORRECT statements regarding Dynamic Application Security Testing (DAST). (Select THREE options)
- A. A process that uses penetration tests on applications while they are running
- B. Performed without a view into the internal source code or application architecture
- C. Considered as a black-box security approach
- D. Examines the application from the inside, searching its source code for conditions that indicate that a security vulnerability might be present
Correct Answer: ABC
Q53. The members of a team are trying to identify deviation from regular traffic patterns and recognize any signs of compromise. Their main motive is to detect, oppose and weaken any attack performed by adversaries. To which of the following teams do these members belong?
- A. Red Team
- B. Blue Team
- C. Purple Team
- D. Grey Team
Correct Answer: B
Q54. Malicious hacker without the proper knowledge are termed as ______________
- A. White Hat Hacker
- B. Red Hat Hacker
- C. Black Hat Hacker
- D. Script Kiddies
Correct Answer: D
Q55. Select the CORRECT statements regarding Black Box Testing. (Select THREE options)
- A. Black Box Testing revolves around internal configuration of the system, software or network.
- B. Black Box Testing is effective on large-scale programming application
- C. In Black Box Testing, all the properties of an application may not be tested
- D. Black Box Testing covers all code path and is more thorough than other testing approaches
Correct Answer: BC
Q56. Which security check process uses penetration tests on applications while they are running?
- A. White-box security testing
- B. Grey-box security testing
- C. DAST
- D. SAST
Correct Answer: C
Q57. An attacker found a shop’s web app granted ‘collaborator’ access without authentication. He exploited this to create a partner account with the same business e-mail which gave the attacker login access to the store with full permissions. What suggestion(s) would you recommend mitigating this scenario? Choose any 3 correct options that may apply.
- A. Single-factor authentication for all logins
- B. Deny IP addresses from which suspicious activities detected
- C. Deny setting of common passwords/patterns and mandating complexity
- D. Rate-limit login attempts via tracing cookies or IP addresses to prevent spoofing
Correct Answer: BCD
Q58. Identify the default Nmap scan technique out of the following.
- A. TCP SYN port scan
- B. TCP ACK port scan
- C. UDP port scan
- D. DNS Resolution
Correct Answer: A
Q59. Which encryption standard does LM employ?
- A. MD5
- B. SHA-1
- C. DES
- D. SHA-2
Correct Answer: C
Q60. Dan’s network users don’t have to remember long passwords. Dan’s network requires a token and a four-digit PIN for access. What is the best way to describe this authentication measure?
- A. Multifactor authentication
- B. Three-factor authentication
- C. Two-factor authentication
- D. Token authentication
Correct Answer: C
Q61. Which of the following tools is used to gather e-mail accounts, names, subdomains, IPs and URLs from public source?
- A. nmap
- B. netcat
- C. theHarvester
- D. hydro
Correct Answer: C
Q62. In salting, a random value called ________ is added to every plaintext password and their combination is hashed & stored in the database.
- A. Digital signature
- B. Salt
- C. Secret key
- D. Private key
Correct Answer: B
Q63. Select the nmap command to be used to run a TCP scan on all the ports of a machine with IP Address 10.0.0.60?
- A. nmap -sT -p- 10.0.0.60
- B. nmap -sT -allp- 10.0.0.60
- C. nmap -sT -p -65535 10.0.0.60
- D. nmap -sT -p- 10.0.0.0/20
Correct Answer: A
Q64. Ray wants to exclude IP address 10.0.0.60 from the nmap scan. Which command should he use?
- A. nmap 10.0.0.0/24 –exclude -ip 10.0.0.60
- B. nmap 10.0.0.0/24 –exc 10.0.0.60
- C. nmap 10.0.0.0/24 –exc -ip -10.0.0.60
- D. nmap 10.0.0.0/24 –exclude 10.0.0.60
Correct Answer: D
Q65. Rahul got access to server as a normal user and wanted to increase the access to administrator. What method should Rahul use to increase the access rights?
- A. Pivoting
- B. Privilege escalation
- C. Moving up
- D. Escalating request
Correct Answer: B
Q66. RSA Algorithm is used for symmetric key cryptography.
- A. true
- B. false
- C. Option D:
Correct Answer: B
Q67. An attacker will typically download the targeted app from an app store and analyze it within their own local environment using a suite of different tools to exploit which OWASP Mobile Top 10 Vulnerability?
- A. Insecure Authorization
- B. Poor Code Quality
- C. Insufficient Cryptography
- D. Reverse Engineering
Correct Answer: D
Q68. Which of the following requests will give accurate result of the target being live?
- A. HTTP
- B. DNS
- C. ICMP echo
- D. TCP
Correct Answer: C
Q69. An attacker will typically exploit ___________ vulnerability by supplying carefully crafted inputs to the victim. These inputs are passed onto code that resides within the mobile device where exploitation takes place. Typical types of attacks will exploit memory leaks and buffer overflows.
- A. Insecure Authorization
- B. Poor Code Quality
- C. Insufficient Cryptography
- D. Cross site scripting
Correct Answer: B
Q70. Jamie wants to conduct security assessment to determine the effectiveness of a new application. He decided to get the vital information directly from the developers and testers of the application. Which Assessment method should he employ?
- A. Testing
- B. Examination
- C. Interviewing
- D. Analyzing
Correct Answer: C
Q71. Select the best practices to be followed in order to prevent ‘Insecure Authorization’ Mobile vulnerability. (Select THREE correct options)
- A. Verify the roles and permissions of the authenticated user using only information contained in backend systems.
- B. Backend code should independently verify incoming identifiers associated with a request that come along with the identify match up and belong to the incoming identity
- C. Secure coding and configuration practices must be used on server-side of the mobile application.
- D. Rely only on roles or permission information that comes from the mobile device itself
Correct Answer: ABC
Q72. On which is the National Vulnerability Database primarily built upon?
- A. Vulnerabilities
- B. NVD
- C. Patch
- D. CVE identifiers
Correct Answer: D
Q73. Which of the following can migrate the machine’s actual operating system into a virtual machine?
- A. Hypervisor-level rootkit
- B. Kernel-level rootkit
- C. Virtual rootkit
- D. Library-level rootkit
Correct Answer: A
Q74. In an attack on Linux machine, the attacker dumped password file from /etc/passwd. The contents of the file are ______________
- A. the passwords of all the users.
- B. the passwords of all the sudo and root users.
- C. the passwords of all the root users.
- D. No passwords
Correct Answer: D
Q75. Select the tool used for Blackjacking
- A. BBproxy
- B. BBAttacker
- C. BBJacking
- D. Blackburried
Correct Answer: A
Q76. _________ is considered as an IoT threat defined by its collection of hijacked devices used to launch massive attacks on networks.
- A. IOT Botnet
- B. IOT Malware
- C. IOT Ransomware
- D. Shadow IOT
Correct Answer: A
Q77. Which of the following Google dork is used to give out all the sub domains of XYZ COrp.com
- A. site:XYZ COrp.com
- B. inurl:XYZ COrp.com
- C. subdomain:XYZ COrp.com
- D. sub:XYZ COrp.com
Correct Answer: A
Q78. Which of the following option(s) are correct?
- A. System Exploit != System Compromise
- B. System Exploit = System Compromise
- C. System Exploit + Successful Attack != System Compromise
- D. System Exploit + Successful Attack = System Compromise
Correct Answer: AD
Q79. What is an attack technique that tricks users into clicking a webpage element which is invisible or disguised as another element?
- A. Grunt Plugin Install
- B. Wapplayzer technology
- C. Recx Analysis
- D. Clickjacking
Correct Answer: D
Q80. Keanue executed the following command. Which of the following flags are set? #nmap -sX domain.XYZ.com
- A. ACK flag is set.
- B. SYN and ACK flag are set.
- C. URG, PUSH and FIN are set
- D. SYN, PUSH, FIN and XMAS flag are set.
Correct Answer: C
Q81. What is SMB’s equivalent in UNIX based machines?
- A. Simba
- B. Samba
- C. SMBU
- D. USMB
Correct Answer: B
Q82. Identify some discovery phase tools in Infra Penetration testing. (Select THREE correct options)
- A. Nmap
- B. Wireshark
- C. Nessus
- D. OWASP ZAP
Correct Answer: ABC
Q83. Which of the following processes evaluates the adherence of an organization to its security policy?
- A. Vulnerability Assessment
- B. Risk Assessment
- C. Security Auditing
- D. Penetration Testing
Correct Answer: C
Q84. Select the correct statements regarding Penetration testing. (Select TWO correct options)
- A. Pentest helps in identifying known vulnerabilities
- B. Check effectiveness of the overall security policies
- C. Expose the components publicly for testing
- D. Find the loopholes which can lead to the theft of sensitive data
Correct Answer: BD
Q85. Which of the tools can be used to find exploits in internal network without internet?
- A. Metasploit
- B. Searchsploit
- C. Locate
- D. Search
Correct Answer: B
Q86. Your team of Ethical Hackers was recently engaged by a corporation to assess the security of its network infrastructure. The corporation wants the attack to be as realistic as possible. Apart from the name of their firm, they provided no further information. What stage of security testing would your team immediately begin?
- A. Scanning
- B. Escalation
- C. Enumeration
- D. Reconnaissance
Correct Answer: D
Q87. Which of the following would be considered a passive online password attack?
- A. Guessing passwords against an IPC$ share
- B. Sniffing subnet traffic to intercept a password
- C. Running John, the Ripper on a stolen copy of the SAM
- D. Sending a specially crafted PDF to a user for that user to open
Correct Answer: B
Q88. Select the correct option regarding symmetric key cryptography.
- A. Requires Public key and Private Key
- B. Requires secure exchange of keys before establishing secure communication
- C. Provides Integrity
- D. Provides Non-Repudiation
Correct Answer: B
Q89. Which is the DAST vulnerability scanner component that helps to navigate through applications and discover as many URLs as possible?
- A. SCA
- B. Crawler
- C. Detector
- D. Manager
Correct Answer: B
Q90. Which of the following is the correct syntax for creating a command shell on port 56 using Netcat on Windows systems?
- A. nc -r 56 -c cmd.exe
- B. nc -p 56 -o cmd.exe
- C. nc -L 56 -t -e cmd.exe
- D. nc -port 56 -s -o cmd.exe
Correct Answer: C
Q91. ‘There is a vulnerability existing, but there is no threat.’ Choose the risk function appropriately.
- A. Extreme Risk
- B. Moderate Risk
- C. Low Risk
- D. Little/No Risk
Correct Answer: D
Q92. The wireshark filter for traffic related to DNS is ———–
- A. dns
- B. port == 53
- C. udp.port == 53
- D. 53.0
Correct Answer: ABC
Q93. Select the possible threat agents for OWASP Mobile Insecure Communcation Vulnerability. (Select THREE correct options)
- A. An adversary that shares the victims local network (compromised or monitored Wi-Fi)
- B. An adversary that shares Carrier or network devices (routers, cell towers, proxy’s, etc);
- C. Malware present in victims mobile device
- D. Adversary with physical access to victims mobile
Correct Answer: ABC
Q94. Which of the below Burp tools is used to load Burp extensions, to extend Burp’s functionality using own or third-party code.
- A. Burp Target
- B. Burp Proxy
- C. Burp Decoder
- D. Burp Extender
Correct Answer: D
Q95. Through the mobile interface, an adversary is able to feed malicious inputs or unexpected sequences of events to a vulnerable endpoint. Under which OWASP Mobile Top 10 Vulnerability will this incident fall?
- A. Improper Platform Usage
- B. Insufficient Cryptography
- C. Insecure Data Storage
- D. Cross site scripting
Correct Answer: A
Q96. Choose the right sequence of penetration testing steps.
- A. Planning -> Reconnaissance -> Discovery -> Reporting
- B. Preparation -> Discovery -> Reconnaissance -> Reporting
- C. Analyzing Information & Risks -> Preparation -> Final Analysis
- D. d. Analyzing Active Intrusion attempts -> Report Preparation -> Final Analysis
Correct Answer: A
Q97. What is at the top of the Pyramid of Pain that helps to detect the adversary?
- A. TTPs
- B. Host Artifacts
- C. Hash Values
- D. Domain Names
Correct Answer: A
Q98. Select the model type which is not trusted in terms of security.
- A. Public
- B. Private
- C. Hybrid
- D. None of the above
Correct Answer: A
Q99. Which of the below Burp tools is used in intercepting web proxy that operates as a man-in-the-middle between the end browser and the target web application. It lets the user intercept, inspect and modify the raw traffic passing in both directions.
- A. Burp Target
- B. Burp Proxy
- C. Burp Decoder
- D. Burp Extender
Correct Answer: B
Q100. Which of the following are appropriate active sniffing techniques against a switched network? (Select TWO correct options)
- A. ARP poisoning
- B. MAC flooding
- C. SYN flooding
- D. Birthday attack
Correct Answer: AB
Q101. Identify some passive reconnaissance discovery phase tools in Web Penetration testing. (Select TWO correct options)
- A. Nmap
- B. Wireshark
- C. Nessus
- D. OWASP ZAP
Correct Answer: BD
Q102. ______________is the name of the encryption or decryption key known only to the party or parties that exchange secret messages.
- A. Digital Certificate
- B. Private Key
- C. E-signature
- D. Security token
Correct Answer: B
Q103. A user is contacted by a member of the IT staff by SMS, the user follows up by calling IT on the internal video conference tool. This is an example of ———
- A. Vishing
- B. Smishing
- C. Social Engineering
- D. None of the above
Correct Answer: D
Q104. OWASP ZAP tool spiders web application to record requests and responses sent to each page in a penetration testing. What are the two available spiders for performing this operation? (Select TWO correct options)
- A. Traditional ZAP spider
- B. New ZAP spider
- C. Wolf spider
- D. AJAX spider
Correct Answer: AD
Q105. Which amongst the following commercial tools can be used by an ethical hacker for cybersecurity investigations?
- A. Shodan
- B. Maltego
- C. Metasploit Pro
- D. Burp Suite Enterprise
Correct Answer: B
Q106. Which of the below Burp tools contains detailed information about your target applications, and lets you drive the process of testing for vulnerabilities.
- A. Burp Target
- B. Burp Proxy
- C. Burp Decoder
- D. Burp Extender
Correct Answer: A
Q107. What occurs when an IDS does not properly identify a malicious packet entering the network?
- A. False negative
- B. False positive
- C. True negative
- D. True positive
Correct Answer: A
Q108. Choose the three types of assessment methods that determine effectiveness of an entity if it meets specified security objectives under security assessment. (Select THREE correct options)
- A. Planning
- B. Testing
- C. Examination
- D. Interviewing
Correct Answer: BCD
Q109. __________ is a not-for-profit organization with a mission to “promote the use of best practices for providing security assurance within Cloud.
- A. CAS
- B. CSA
- C. SAC
- D. CCS
Correct Answer: B
Q110. ________ is an NMAP script that is used to detect HTTP request methods such as GET, POST, HEAD, PUT, DELETE etc.
- A. http-request
- B. http-headers
- C. http-methods
- D. http-enum
Correct Answer: C
Q111. ___________ vulnerability occurs when development team assumes that users or malware will not have access to a mobile device’s filesystem and subsequent sensitive information in data-stores on the device.
- A. Improper Platform Usage
- B. Insufficient Cryptography
- C. Insecure Data Storage
- D. Cross site scripting
Correct Answer: C
Q112. How long is the IV used in WEP
- A. 32 bits
- B. 16 bits
- C. 48 bits
- D. 24 bits
Correct Answer: D
Q113. A bank engaged a penetration tester to conduct a penetration test. The tester began looking for IP ranges owned by the bank, performing DNS lookups on the bank’s servers, reading news articles about the bank online, watching bank employees’ arrival and departure, searching the bank’s job postings (paying special attention to IT-related jobs), and visiting the bank’s corporate office dumpster. In which phase of the penetration test is the tester now?
- A. Information reporting
- B. Vulnerability assessment
- C. Active information gathering
- D. Passive information gathering
Correct Answer: D
Q114. Which of the below Burp tools is used for performing manual or intelligent decoding and encoding of application data.
- A. Burp Target
- B. Burp Proxy
- C. Burp Decoder
- D. Burp Extender
Correct Answer: C
Q115. ___________ provides data authentication and authorization between client and service.
- A. WS-Secure Conversion
- B. SAML
- C. WS-Security
- D. WS-Trust
Correct Answer: B
Q116. You are doing a vulnerability assessment in your enterprise network 192.168.1.0/24. You have saved 100 target IP addresses on Desktop in a list file scan.txt. What should be the command if you want to scan all those targets using Nmap.
- A. nmap 192.168.1.1-99
- B. nmap -iL root/Desktop/scan.txt
- C. nmap -iR 100
- D. nmap scanme 192.168.1.0
Correct Answer: B
Q117. As a cryptographic technique, hashing helps in ensuring ___________of the data or messages being exchanged between two parties
- A. Confidentiality
- B. Availability
- C. Integrity
- D. Authentication
Correct Answer: C
Q118. _____________ testing has the ability to test both internal coding structure and presentation layer.
- A. Black Box Testing
- B. White Box Testing
- C. Grey Box Testing
- D. Blue Box Testing
Correct Answer: C
Q119. In Public key cryptography if there are 10 number of users, how many numbers of keys are required.
- A. 10.0
- B. 45.0
- C. 20.0
- D. 8.0
Correct Answer: C
Q120. ‘A penetration test is a simulated cyber-attack against computer system(s) to check for exploitable vulnerabilities.’ State True or False.
- A. true
- B. FALSE
- C. Option D:
Correct Answer: A
Q121. Carly wants to perform an nmap scan to scan only standard ports used for FTP traffic. What would be the corresponding nmap command that needs to be executed?
- A. nmap -p 10021
- B. nmap -p 443
- C. nmap -p 21
- D. nmap -p 123
Correct Answer: C
Q122. _____________ are the physical devices or software programs that route inbound/outbound data between controllers, devices and sensors which provide an additional level of security for IOT data while in transit.
- A. IOT Sensors
- B. IOT Gateways
- C. IOT Portcullis
- D. IOT Actuators
Correct Answer: B
Q123. Penetration tests, vulnerability tests, and risk assessments are all performed by an ethical hacker for a large security research organization. As a favor, a friend who recently started a business, requests the hacker to conduct a penetration test and vulnerability assessment on the new business. What should the hacker do next before beginning work on this project?
- A. Start by foot printing the network and mapping out a plan of attack
- B. Ask the employer for authorization to perform the work outside the company
- C. Begin the reconnaissance phase with passive information gathering and then move into active information gathering
- D. Use social engineering techniques on the friend’s employees to help identify areas that may be susceptible to attack
Correct Answer: B
Q124. Which of the following propagates without human interaction?
- A. Trojan
- B. Worm
- C. Virus
- D. MITM
Correct Answer: B
