WorksheetsVolume 2
Total questions: 29
Worksheet time: 58mins
Which TCP flag indicates that a connection should be torn down abruptly?
Responses?
ACK
URG
FIN
RST
Which of the following is a challenge of working with OSINT data?
Responses?
Using bitcoin to pay for access to data services
Properly decrypting various data sources
Converting different HTML and XML versions
Collecting from numerous and disparate data sources
What is the following Google search designed to do?
wireless site:somecompany.net
Search for all instances of the term "wireless" on the somecompany.net website
Find pages similar to somecompany.net that also mention the term "wireless"
Display all pages containing both the terms "somecompany.net" and "wireless site"
Display all pages with the term "wireless" in them that link to somecompany.net
When interrogating a DNS server to discover information about the target domain, what tool can be used in controlling the output of DNS queries with more granularity?
dnsstuff
Dig
mxtoolbox
dnsquery
DeepBlueCLI is an open-source framework that automatically parses Windows event logs. What log does DeepBlueCLI parse when you run it with no arguments?
.\DeepBlue.ps1
PowerShell Event Log
Security Event Log
Application Event Log
System Event Log
When performing reconnaissance, what data is collected before sending any packets to the target?
Open ingress ports
A network diagram
Open egress ports
Open-source intelligence
Which tool can detect attacks by analyzing offline Windows event log files?
DeepBlueCLI
Metasploit Log Analyzer
SRUM-Dump
PowerShell Empire
What header field in IPv6 is similar to the TTL field in an IPv4 header?
Class
Flow Label
TTL
Hop Limit
Which tool uses a list of hostnames or IP addresses to collect X.509 certificates and cipher details, saving the output in a JSON-formatted file?
TLS-Scan
EyeWitness
nmap
grep
End users often configure SMB services to copy files or to share printers on their workstations. What TCP port number does the SMB protocol use?
554
3074
443
445
What are the components of a TCP three-way handshake, listed in the correct sequence?
SYN, SYN-ACK, ACK
SYN, ACK, SYN
SYN, ACK, SYN-ACK
SYN-ACK, ACK-SYN
What tool is designed to work with and parse JSON data?
jayson
JQ
jquery
jsonparse
Nmap sweeps through each target address before launching a port scan. When running without root privileges on a Linux machine, what type of TCP packet does it send to port 80?
FIN
RST
SYN
ACK
An attacker downloads a PDF from a target's website and wants to exploit a vulnerability in the PDF. What tool can the attacker use to view information about the tool that was used to create the PDF?
Exiftool
Exifpdf
Listpdf
Pdflist
Which of the following is a characteristic of UDP?
It uses acknowledgments.
It is connection oriented.
It is connection-less.
Its sequence numbers are preserved.
What gives an attacker all records associated with a DNS domain?
Zone transfer
Reverse lookup
DNS lookup
Record transfer
From where are OSINT data generally collected?
Nmap and Nessus
Metasploit and PowerShell Empire
Public websites and third-party API services
Through exploiting a vulnerability and exfiltrating data
What tool can be used to efficiently scan large IP ranges, such as cloud service provider IP ranges?
ping
Nmap
wget
Masscan
DeepBlueCLI searches which of the following to find unusual behavior or characteristics?
Windows registry hives
Windows Volume Shadow Copy
Windows running processes
Windows event logs
Techniques describe the means by which adversaries achieve tactical goals. What is the format of a MITRE ATT&CK technique ID?
TTP1110
TE1110
TA1110
T1110
Which of the following is a challenge presented to an attacker when scanning cloud targets as opposed to non-cloud targets?
Less likely to be monitored and logged
Potential to bypass ACL filters
Difficult to identify the owner of a given target
May reveal information about non-cloud assets
Which step do non-discriminating attackers skip?
Scanning
Cleaning up tracks
Maintaining persistence
Reconnaissance
While reviewing logs from a web server, a web administrator notices that every page on a company's site was accessed within a span of six minutes. What is this indicative of?
A web hoster
A web crawler
A web skipper
A web walker
Which of the following tools can be utilized in a Linux system to search for the username associated with a specific SID?
net view
enum
wmic useraccount list brief
rpcclient
The adversary tactics, techniques, and procedures from the MITRE ATT&CK Framework are based on which of the following?
Open Web Application Security Project (OWASP)
Cutting-edge security research papers
Observations from real-world attacks
Vulnerability databases
During reconnaissance, what internet-based tool helps an attacker procure a list of cloud providers used for a given website?
EyeWitness
openssl
Masscan
BuiltWith
Which Nmap command will disable port scanning and focus solely on host discovery?
sudo nmap -Pn 192.168.1.1-254
sudo nmap -sS -sV 192.168.1.1-254
sudo nmap -sn 192.168.1.1-254
sudo nmap -sC 192.168.1.1-254
Which of the following is an SMB enumeration tool that identifies SMB servers and shares, then enumerates files using a specified username and password? This tool also reports if a particular file can be read, written to, or deleted by the same credentials with which it ran.
Masscan
rpcclient
smbclient
SMBeagle
Microsoft SMB version 3.1.1 is aimed at speed, flexibility, and extreme security. It also added support for advanced encryption and pre-authentication integrity to prevent Machine-in-the-Middle (MitM) attacks. What is the minimum server version that supports Microsoft SMB version 3.1.1?
Win2K8R2
Win2K12
Win2K16
Win2K3
