Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Volume 2

Total questions: 29

Worksheet time: 58mins

Name
Class
Date
1.

Which TCP flag indicates that a connection should be torn down abruptly?

Responses?

a)

ACK

b)

URG

c)

FIN

d)

RST

2.

Which of the following is a challenge of working with OSINT data?

Responses?

a)

Using bitcoin to pay for access to data services

b)

Properly decrypting various data sources

c)

Converting different HTML and XML versions

d)

Collecting from numerous and disparate data sources

3.

What is the following Google search designed to do?

wireless site:somecompany.net

a)

Search for all instances of the term "wireless" on the somecompany.net website

b)

Find pages similar to somecompany.net that also mention the term "wireless"

c)

Display all pages containing both the terms "somecompany.net" and "wireless site"

d)

Display all pages with the term "wireless" in them that link to somecompany.net

4.

When interrogating a DNS server to discover information about the target domain, what tool can be used in controlling the output of DNS queries with more granularity?

a)

dnsstuff

b)

Dig

c)

mxtoolbox

d)

dnsquery

5.

DeepBlueCLI is an open-source framework that automatically parses Windows event logs. What log does DeepBlueCLI parse when you run it with no arguments?

.\DeepBlue.ps1

a)

PowerShell Event Log

b)

Security Event Log

c)

Application Event Log

d)

System Event Log

6.

When performing reconnaissance, what data is collected before sending any packets to the target?

a)

Open ingress ports

b)

A network diagram

c)

Open egress ports

d)

Open-source intelligence

7.

Which tool can detect attacks by analyzing offline Windows event log files?

a)

DeepBlueCLI

b)

Metasploit Log Analyzer

c)

SRUM-Dump

d)

PowerShell Empire

8.

What header field in IPv6 is similar to the TTL field in an IPv4 header?

a)

Class

b)

Flow Label

c)

TTL

d)

Hop Limit

9.

Which tool uses a list of hostnames or IP addresses to collect X.509 certificates and cipher details, saving the output in a JSON-formatted file?

a)

TLS-Scan

b)

EyeWitness

c)

nmap

d)

grep

10.

End users often configure SMB services to copy files or to share printers on their workstations. What TCP port number does the SMB protocol use?

a)

554

b)

3074

c)

443

d)

445

11.

What are the components of a TCP three-way handshake, listed in the correct sequence?

a)

SYN, SYN-ACK, ACK

b)

SYN, ACK, SYN

c)

SYN, ACK, SYN-ACK

d)

SYN-ACK, ACK-SYN

12.

What tool is designed to work with and parse JSON data?

a)

jayson

b)

JQ

c)

jquery

d)

jsonparse

13.

Nmap sweeps through each target address before launching a port scan. When running without root privileges on a Linux machine, what type of TCP packet does it send to port 80?

a)

FIN

b)

RST

c)

SYN

d)

ACK

14.

An attacker downloads a PDF from a target's website and wants to exploit a vulnerability in the PDF. What tool can the attacker use to view information about the tool that was used to create the PDF?

a)

Exiftool

b)

Exifpdf

c)

Listpdf

d)

Pdflist

15.

Which of the following is a characteristic of UDP?

a)

It uses acknowledgments.

b)

It is connection oriented.

c)

It is connection-less.

d)

Its sequence numbers are preserved.

16.

What gives an attacker all records associated with a DNS domain?

a)

Zone transfer

b)

Reverse lookup

c)

DNS lookup

d)

Record transfer

17.

From where are OSINT data generally collected?

a)

Nmap and Nessus

b)

Metasploit and PowerShell Empire

c)

Public websites and third-party API services

d)

Through exploiting a vulnerability and exfiltrating data

18.

What tool can be used to efficiently scan large IP ranges, such as cloud service provider IP ranges?

a)

ping

b)

Nmap

c)

wget

d)

Masscan

19.

DeepBlueCLI searches which of the following to find unusual behavior or characteristics?

a)

Windows registry hives

b)

Windows Volume Shadow Copy

c)

Windows running processes

d)

Windows event logs

20.

Techniques describe the means by which adversaries achieve tactical goals. What is the format of a MITRE ATT&CK technique ID?

a)

TTP1110

b)

TE1110

c)

TA1110

d)

T1110

21.

Which of the following is a challenge presented to an attacker when scanning cloud targets as opposed to non-cloud targets?

a)

Less likely to be monitored and logged

b)

Potential to bypass ACL filters

c)

Difficult to identify the owner of a given target

d)

May reveal information about non-cloud assets

22.

Which step do non-discriminating attackers skip?

a)

Scanning

b)

Cleaning up tracks

c)

Maintaining persistence

d)

Reconnaissance

23.

While reviewing logs from a web server, a web administrator notices that every page on a company's site was accessed within a span of six minutes. What is this indicative of?

a)

A web hoster

b)

A web crawler

c)

A web skipper

d)

A web walker

24.

Which of the following tools can be utilized in a Linux system to search for the username associated with a specific SID?

a)

net view

b)

enum

c)

wmic useraccount list brief

d)

rpcclient

25.

The adversary tactics, techniques, and procedures from the MITRE ATT&CK Framework are based on which of the following?

a)

Open Web Application Security Project (OWASP)

b)

Cutting-edge security research papers

c)

Observations from real-world attacks

d)

Vulnerability databases

26.

During reconnaissance, what internet-based tool helps an attacker procure a list of cloud providers used for a given website?

a)

EyeWitness

b)

openssl

c)

Masscan

d)

BuiltWith

27.

Which Nmap command will disable port scanning and focus solely on host discovery?

a)

sudo nmap -Pn 192.168.1.1-254

b)

sudo nmap -sS -sV 192.168.1.1-254

c)

sudo nmap -sn 192.168.1.1-254

d)

sudo nmap -sC 192.168.1.1-254

28.

Which of the following is an SMB enumeration tool that identifies SMB servers and shares, then enumerates files using a specified username and password? This tool also reports if a particular file can be read, written to, or deleted by the same credentials with which it ran.

a)

Masscan

b)

rpcclient

c)

smbclient

d)

SMBeagle

29.

Microsoft SMB version 3.1.1 is aimed at speed, flexibility, and extreme security. It also added support for advanced encryption and pre-authentication integrity to prevent Machine-in-the-Middle (MitM) attacks. What is the minimum server version that supports Microsoft SMB version 3.1.1?

a)

Win2K8R2

b)

Win2K12

c)

Win2K16

d)

Win2K3