wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CEH Pre Assessment

Total questions: 10

Worksheet time: 10mins

Name
Class
Date
1.
Which of the following techniques are NOT relevant in preventing arp spoof attack?
a)
Arpwatch
b)
Static MAC Entries
c)
Secure ARP Protocol
d)
Kernel based patches
2.
What term describes the amount of risk that remains after the vulnerabilities are classified, and the countermeasures have been deployed?
a)
Inherent risk
b)
Impact risk
c)
Residual risk
d)
Deferred risk
3.
Darius and Mathew were performing internal vulnerability scan within the corporate network and reported the results to his manager.Manager found that it was not performed correctly because there were some mismatches on comparing both of them. He was expecting the same results, as both the scans were performed at the same time, using the same tools and the same IP ranges. The results simply showed more findings in Darius' scan compared to Mathew's scan.What was the most probably root cause?
a)
Administrator of the scanned system updated most of the vulnerabilities
b)
One of the scan was blocked by IPS
c)
One of the scan was blocked by IDS
d)
Mathew's scan was blocked by Firewall
4.
During an Xmas scan, what indicates a port is closed?
a)
RST
b)
SYN
c)
ACK
d)
No return response
5.
What is the purpose of DNS AAAA record?
a)
Authorization, Authentication and Auditing record
b)
Address prefix record
c)
IPv6 address resolution record
d)
Address database record
6.
An attacker is trying to redirect the traffic of a small office. That office is using their own mail server, DNS server and NTP server because of the importance of their jobs. The attacker gains access to the DNS server and redirects the direction www.google.com to his own IP address. Now, when the employees of the office want to go to Google, they are being redirected to the attacker's machine. What is the name of this kind of attack?
a)
DNS Spoofing
b)
ARP Poisoning
c)
Smurf Attack
d)
MAC Flooding
7.
Max saw a guy (Mario) who looked like a janitor who was holding a lot of boxes. Max held the door open for Mario. Mario was able to access the company without identification. What kind of attack is this?
a)
Tailgating
b)
Session Hijacking
c)
None of them
d)
Phishing
8.
What type of analysis is performed when an attacker has partial knowledge of the inner-workings of the application?
a)
Announced
b)
White-box
c)
Black-box
d)
Grey-box
9.
An enterprise recently moved to a new office, and the new neighborhood is a little risky. The CEO wants to monitor the physical perimeter and the entrance doors 24 hours. What is the best option to do this job?
a)
Use an IDS in the entrance doors and install some of them near the corners
b)
Install a CCTV with cameras pointing to the entrance doors and the street
c)
Use lights in all the entrance doors and along the company's perimeter
d)
Use fences in the entrance doors
10.
Which method of password cracking takes the most time and effort?
a)
Dictionary attack
b)
Brute force
c)
Rainbow tables
d)
Shoulder surfing